On the Privacy Risks of Spiking Neural Networks: A Membership Inference Analysis

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Guan, Junyi, Sharma, Abhijith, Tian, Chong, Lahlou, Salem
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866909645559300096
author Guan, Junyi
Sharma, Abhijith
Tian, Chong
Lahlou, Salem
author_facet Guan, Junyi
Sharma, Abhijith
Tian, Chong
Lahlou, Salem
contents Spiking Neural Networks (SNNs) are increasingly explored for their energy efficiency and robustness in real-world applications, yet their privacy risks remain largely unexamined. In this work, we investigate the susceptibility of SNNs to Membership Inference Attacks (MIAs) -- a major privacy threat where an adversary attempts to determine whether a given sample was part of the training dataset. While prior work suggests that SNNs may offer inherent robustness due to their discrete, event-driven nature, we find that its resilience diminishes as latency (T) increases. Furthermore, we introduce an input dropout strategy under black box setting, that significantly enhances membership inference in SNNs. Our findings challenge the assumption that SNNs are inherently more secure, and even though they are expected to be better, our results reveal that SNNs exhibit privacy vulnerabilities that are equally comparable to Artificial Neural Networks (ANNs). Our code is available at https://github.com/sharmaabhijith/MIA_SNN.
format Preprint
id arxiv_https___arxiv_org_abs_2502_13191
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle On the Privacy Risks of Spiking Neural Networks: A Membership Inference Analysis
Guan, Junyi
Sharma, Abhijith
Tian, Chong
Lahlou, Salem
Machine Learning
Artificial Intelligence
Spiking Neural Networks (SNNs) are increasingly explored for their energy efficiency and robustness in real-world applications, yet their privacy risks remain largely unexamined. In this work, we investigate the susceptibility of SNNs to Membership Inference Attacks (MIAs) -- a major privacy threat where an adversary attempts to determine whether a given sample was part of the training dataset. While prior work suggests that SNNs may offer inherent robustness due to their discrete, event-driven nature, we find that its resilience diminishes as latency (T) increases. Furthermore, we introduce an input dropout strategy under black box setting, that significantly enhances membership inference in SNNs. Our findings challenge the assumption that SNNs are inherently more secure, and even though they are expected to be better, our results reveal that SNNs exhibit privacy vulnerabilities that are equally comparable to Artificial Neural Networks (ANNs). Our code is available at https://github.com/sharmaabhijith/MIA_SNN.
title On the Privacy Risks of Spiking Neural Networks: A Membership Inference Analysis
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2502.13191