On the Privacy Risks of Spiking Neural Networks: A Membership Inference Analysis

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Guan, Junyi, Sharma, Abhijith, Tian, Chong, Lahlou, Salem
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909645559300096
author Guan, Junyi
Sharma, Abhijith
Tian, Chong
Lahlou, Salem
author_facet Guan, Junyi
Sharma, Abhijith
Tian, Chong
Lahlou, Salem
contents Spiking Neural Networks (SNNs) are increasingly explored for their energy efficiency and robustness in real-world applications, yet their privacy risks remain largely unexamined. In this work, we investigate the susceptibility of SNNs to Membership Inference Attacks (MIAs) -- a major privacy threat where an adversary attempts to determine whether a given sample was part of the training dataset. While prior work suggests that SNNs may offer inherent robustness due to their discrete, event-driven nature, we find that its resilience diminishes as latency (T) increases. Furthermore, we introduce an input dropout strategy under black box setting, that significantly enhances membership inference in SNNs. Our findings challenge the assumption that SNNs are inherently more secure, and even though they are expected to be better, our results reveal that SNNs exhibit privacy vulnerabilities that are equally comparable to Artificial Neural Networks (ANNs). Our code is available at https://github.com/sharmaabhijith/MIA_SNN.
format Preprint
id arxiv_https___arxiv_org_abs_2502_13191
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle On the Privacy Risks of Spiking Neural Networks: A Membership Inference Analysis
Guan, Junyi
Sharma, Abhijith
Tian, Chong
Lahlou, Salem
Machine Learning
Artificial Intelligence
Spiking Neural Networks (SNNs) are increasingly explored for their energy efficiency and robustness in real-world applications, yet their privacy risks remain largely unexamined. In this work, we investigate the susceptibility of SNNs to Membership Inference Attacks (MIAs) -- a major privacy threat where an adversary attempts to determine whether a given sample was part of the training dataset. While prior work suggests that SNNs may offer inherent robustness due to their discrete, event-driven nature, we find that its resilience diminishes as latency (T) increases. Furthermore, we introduce an input dropout strategy under black box setting, that significantly enhances membership inference in SNNs. Our findings challenge the assumption that SNNs are inherently more secure, and even though they are expected to be better, our results reveal that SNNs exhibit privacy vulnerabilities that are equally comparable to Artificial Neural Networks (ANNs). Our code is available at https://github.com/sharmaabhijith/MIA_SNN.
title On the Privacy Risks of Spiking Neural Networks: A Membership Inference Analysis
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2502.13191