Abstract
Distributed artificial intelligence systems are more and more being trained on sensitive, siloed data maintained by hospitals, banks and edge devices, where sharing of data is neither legal nor viable. While FL is the most popular paradigm that preserves privacy, classical FL is still vulnerable to a variety of gradient-inversion attacks, membership-inference attacks, and future cryptanalytic attacks that are made possible by fault-tolerant quantum computers. This article presents a hybrid system called Quantum Federated Learning (QFL) where a quantum secure channel that utilizes post-quantum cryptography and quantum key distribution (QKD) is used to transport parameter updates, with each client training a variational quantum neural network (VQNN) locally over its own data. We formalize a QFL training protocol and prove an information-theoretic privacy bound under the honest-but-curious server model, and test on four benchmarks – MNIST-4, CIFAR-2, PhysioNet-ECG, and a synthetic non-IID sensor dataset – on the PennyLane and Qiskit backends, running ten simulated clients. Compared to FedAvg, FedProx and homomorphic-encryption FL, it achieves accuracy equal to or better than QFL, and reduces the membership-inference AUC from 0.72 to 0.06, as well as reducing the communication payloads per round by 4.1× due to compact quantum parameter encoding. We then consider shot noise, barren plateaus and client drift and provide a reproducible reference implementation. The outcome suggests that QFL is a viable short-term route to having secure distributed AI that is resilient to both classical and quantum threats.

This work is licensed under a Creative Commons Attribution 4.0 International License.
