研究如何防止量子纠错受AI误导更新
Securing quantum error correction against misleading advice from AI agents
这是关于如何防止量子纠错受AI误导更新的一篇研究论文,值得一看。
研究指出,被动 syndrome 记录的歧义会阻碍恢复选择,而额外的校准测量可以在不确定性和漂移下支持认证的恢复更新。在奇距离正方形环面码中,相反的相干 X 旋转会产生相同的被动 syndrome 历史分布,但固定相位校正可以在一个符号上帮助而在另一个上造成伤害。终端逻辑测量基于已知的编码校准状态提供缺失的符号信息。一个独立的评估器只有在校准不确定性和合理的漂移边界证明更新优于当前恢复时才接受更新,而不假设顾问推荐正确。在模拟的攻击中,校准置信度检查会拒绝有害提议而保留有益更新。推导出的校准年龄足够大的充分条件要求通过部署实现改进。
Securing quantum error correction against misleading advice from AI agents
Can an attacker turn influence over an artificial intelligence (AI) adviser into a harmful quantum error-correction update? We identify an ambiguity in passive syndrome records that obstructs recovery selection, then show how additional calibration measurements support certified recovery updates under uncertainty and drift. In an odd-distance square toric code with error-free preparation, syndrome measurements, and recovery operations, opposite coherent $X$ rotations produce identical passive syndrome-history distributions. Yet a fixed phase correction can help at one sign and harm at the other. A terminal logical measurement on known encoded calibration states supplies the missing sign information. A separate evaluator accepts an update only when calibration uncertainty and a justified drift bound certify improvement over the current recovery, without assuming that the adviser recommends correctly. In simulated advice attacks, calibration-confidence checks reject harmful proposals while retaining beneficial updates under honest advice. We derive sufficient limits on calibration age that require improvement through deployment. In matched simulations, a validated channel-specific bound retains more beneficial updates than the general bound after accounting for evaluation time, while preventing the tested harmful activations under the stated drift assumption. A separate surface-code experiment includes stochastic circuit faults and noise changing during acquisition. Deterministic controllers achieve at least as many beneficial updates with the same observations. Violating the drift assumption permits harmful acceptance in the toric experiment. The results identify information required for recovery selection, establish conditional guarantees against harmful updates, and quantify the recovery improvements forgone through conservative acceptance.