QTML 2025: On The Cost Of Training (Adversarially-Robust) Quantum Models

QTML 2025: On The Cost Of Training (Adversarially-Robust) Quantum Models

🎙 Sayantan Pramanik 👥 8K 📅 March 12, 2026 ⏱ 16 min 👁 38 📄 original study 🧭 2026-08-15
Available in: English (current) Français

Keywords

quantum machine learningvariational quantum algorithmsstochastic three points methodadversarial robustnesscircuit evaluations

Summary

The talk, presented at QTML 2025, addresses the computational cost of training parametrized quantum circuits (PQCs) in variational quantum algorithms (VQAs). The speaker, Sayantan Pramanik, begins by motivating the problem with a concrete example: training a quantum model on a real superconducting processor for MNIST classification could cost around $1.5 million due to the large number of circuit executions required. He then formalizes the problem as empirical risk minimization and introduces assumptions about the circuit structure (rotation gates and CNOTs) and stochastic gradient estimates. A key contribution is the adaptation of the Stochastic Three Points (STP) method, a gradient-free optimizer, to the VQA setting. STP requires only two circuit evaluations per iteration, compared to 2d for gradient-based methods, and achieves a convergence rate of O(LD/ε²) circuit evaluations, a significant improvement over SGD’s O(LD²/ε⁴). The speaker also discusses the challenge of choosing step sizes without gradient information and provides probabilistic bounds. Numerical experiments on digit classification show STP requires about 100 times fewer circuit executions than SGD, though it converges to a slightly worse objective value due to stochasticity. In the final part, the talk addresses adversarial robustness. The speaker shows that for angle-encoded quantum models with positive observables, the adversarial loss is bounded by scalar multiples of the natural loss, suggesting that adversarial training may be unnecessary. However, he notes a paradox: this argument applies to any smooth non-negative function, yet adversarial training is known to be beneficial in classical machine learning, leaving an open question for future research.

249 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides significant value by addressing a critical bottleneck in VQAs: the high cost of circuit evaluations. The introduction of the STP method and its theoretical convergence guarantees offer a practical improvement over existing gradient-based approaches. The argumentation is rigorous, with clear mathematical derivations and supporting numerical experiments. The speaker also honestly discusses limitations, such as the need for step-size selection and the impact of stochasticity, and acknowledges open questions, particularly regarding the paradox in adversarial robustness. The work is well-situated within the existing literature, and the results are presented with appropriate caveats.

Scientific Rigor, Source Quality, Title Accuracy

The presentation adheres to scientific rigor, with theoretical results derived from explicit assumptions and numerical experiments that validate the claims. The speaker references prior work implicitly (e.g., parameter shift rules, SGD, SPSA) but does not provide explicit citations in the talk. The title accurately reflects the content, and the talk is well-structured. The description includes the authors and abstract, but no external links are provided. The lack of explicit citations in the talk is a minor weakness, but the work appears to be based on a preprint (mentioned as appearing on arXiv that morning).

203 words

Title / Content Match

The title accurately reflects the content, focusing on the cost of training quantum models and extending to adversarial robustness.

Quality & Reliability

8/10

The talk presents original theoretical results with rigorous mathematical derivations and numerical experiments, typical of academic conference presentations. The speaker is transparent about limitations and open questions, and the work is likely peer-reviewed (QTML is a recognized venue).

Key Moments

Cited Sources

  • On The Cost Of Training (Adversarially-Robust) Quantum Models (arXiv preprint) — The speaker mentions that the paper appeared on arXiv that morning, but the exact URL is not provided in the video or description.

Concurring Sources

Dissenting Sources

  • Adversarial training in classical ML — The talk notes a paradox: theoretical bounds suggest adversarial training should not help for smooth non-negative functions, but empirical evidence in classical ML shows it does. This discrepancy is discussed as an open question.

Contribution & Novelties

The talk contributes a novel adaptation of the Stochastic Three Points method to variational quantum algorithms, providing theoretical convergence guarantees and demonstrating a significant reduction in circuit evaluations compared to gradient-based methods. It also offers new theoretical insights into the adversarial robustness of quantum models, showing that under certain conditions, adversarial training may be unnecessary. These contributions advance the practical feasibility of VQAs.

Pour aller plus loin :

  • Variational quantum algorithms — Overview of VQAs and their applications.
  • Parameter shift rule — Technique for computing gradients in quantum circuits.
  • Stochastic Three Points method — Original paper introducing the STP method.
  • Adversarial machine learning — Background on adversarial robustness in classical ML.

111 words

Radar Profile

The radar profile shows high scores in quality of information and technical level, reflecting the rigorous theoretical and experimental nature of the talk. The quantity of information is also high, but the fiabilite_globale is slightly lower due to the lack of explicit citations and the preliminary nature of some results.

Reliability 8/10

💬 No comments were provided for analysis.