Does the Readout Bypass Leak the Input? A Feature-Visibility Audit of Hybrid Quantum-Classical Models
Abstract
Readout-side residual hybrids concatenate the raw input with measured quantum features to recover accuracy lost at the measurement bottleneck. In federated learning, this bypass also changes which input coordinates can enter a shared gradient. We audit that change with gradient inversion, two tabular benchmarks, four capacity-aware controls, and metrics conditioned on feature visibility. The residual and input-only heads reconstruct the full record almost exactly, with median PSNR of 73-96 dB. Quantum-only heads appear private under a full-vector score, at 8-11 dB, but this comparison is misleading: they never receive most input coordinates. On the first six coordinates visible to every quantum model, their median PSNR rises to 54-96 dB. Meanwhile, a loss-threshold membership attack remains near chance. The bypass therefore expands the scope of reconstructable information, while quantum measurement does not protect the coordinates it actually encodes. Privacy audits of hybrid models should report both the adversary's observable and the feature set each architecture can access.