Date of Award

3-25-2026

Document Type

Dissertation

Degree Name

Doctor of Philosophy in Cyber Operations (PhDCO)

First Advisor

Varghese Vaidyan, Ph.D.

Second Advisor

Austin O’Brien, Ph.D.

Third Advisor

Gurcan Comert, Ph.D.

Abstract

Hybrid neural networks (HNNs), which integrate classical convolutional neural networks with quantum circuit components, are highly vulnerable to white-box targeted compound (WTC) adversarial attacks. Previous research has primarily evaluated defenses against single-method attacks, leaving a critical gap in understanding defense effectiveness against compound attacks that combine multiple perturbation strategies. This research study systematically evaluates defense mechanisms against WTC adversarial attacks on HNN models across 120 experimental conditions. Three defense categories are investigated: test-time defenses (input transformation and randomization, applied during inference without retraining) and training-time defense (adversarial training, requiring model retraining). Evaluation uses four datasets (MNIST, EMNIST "Digits", TinyImageNet, TrafficSigns) and three compound attack combinations (FGSM+PGD, FGSM+CW, CW+PGD). The results demonstrate that compound attacks severely degrade the performance of HNN, reducing the average accuracy from 87.6% to 19.1%. The defense architecture demonstrated dataset-dependent resilience: adversarial training achieved high-efficacy recovery (87%) on structured, low-entropy datasets (TrafficSigns), while encountering a complexity ceiling (28%) on high-diversity datasets (EMNIST "Digits"). This indicates that while the HNN-defense combination is highly effective at preserving structural features, its current configuration requires further optimization for handwriting-style variability where adversarial perturbations more easily mimic legitimate feature shifts. Adversarial training outperformed test-time defenses by 2.3–2.8× across all datasets. Key contributions include: (1) establishing adversarial training's superiority across all conditions, (2) revealing test-time versus training-time trade-offs between deployment flexibility and robustness, (3) demonstrating relative robustness gains of 13–18% over classical CNN baselines through quantum geometric defenses, and (4) validating classical simulation for HNN defense research. These findings provide a foundational understanding for the implementation of robust HNN models in adversarial environments.

Share

COinS