Quantitative Assessment and Verification of Quantum Neural Network Security Based on Violations of the Bell Inequality
Yulu ZhangIn response to the current research landscape, which lacks unified quantitative standards and a reproducible verification framework for assessing the security of quantum neural networks (QNNs), this paper proposes a quantitative evaluation system and verification scheme for QNN security based on the violation characteristics of CHSH-type Bell inequalities. This method treats quantum entanglement as the core element of intrinsic security and establishes a controlled-variable controlled experiment involving purely classical models, non-entangled QNNs, weakly entangled QNNs, and strongly entangled QNNs. Numerical simulations were conducted using the Iris dataset; the presence of quantum entanglement was determined using the CHSH statistic, and a quantitative metric system centered on the normalized CHSH observation metric Q was constructed. Based on the theoretical limits of Bell’s inequalities, a normalization derivation was performed to establish the theoretical constraint interval of 0≤Q≤1; the threshold values of 0.3 and 0.7 obtained from the simulations are applicable only to the experimental scenarios described in this paper and serve solely as a reference for grouping data within the experiment; they do not possess universal validity for determination. Simulation results show that the CHSH values for the weakly and strongly entangled QNN experimental groups can reach 2.8284, significantly exceeding the theoretical limits of classical locality. These values correspond to an observation metric of Q=0.9838 and a privacy protection strength of P=0.8854, with the security level rated as high. The CHSH values of the non-entangled QNN and the purely classical model do not exceed the classical threshold of 2; they exhibit no quantum nonlocality or quantum advantage, and their security level is rated as low. This paper advances the security evaluation of QNNs from qualitative, empirical judgments to verifiable quantitative classification, providing a theoretical basis and evaluation framework for the practical application of quantum neural networks in highly security-sensitive scenarios such as privacy-preserving computing.