Input-Triggered Hardware Trojan Attack on Spiking Neural Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Raptis, Spyridon, Kling, Paul, Kaskampas, Ioannis, Alouani, Ihsen, Stratigopoulos, Haralampos-G.
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908288151453696
author Raptis, Spyridon
Kling, Paul
Kaskampas, Ioannis
Alouani, Ihsen
Stratigopoulos, Haralampos-G.
author_facet Raptis, Spyridon
Kling, Paul
Kaskampas, Ioannis
Alouani, Ihsen
Stratigopoulos, Haralampos-G.
contents Neuromorphic computing based on spiking neural networks (SNNs) is emerging as a promising alternative to traditional artificial neural networks (ANNs), offering unique advantages in terms of low power consumption. However, the security aspect of SNNs is under-explored compared to their ANN counterparts. As the increasing reliance on AI systems comes with unique security risks and challenges, understanding the vulnerabilities and threat landscape is essential as neuromorphic computing matures. In this effort, we propose a novel input-triggered Hardware Trojan (HT) attack for SNNs. The HT mechanism is condensed in the area of one neuron. The trigger mechanism is an input message crafted in the spiking domain such that a selected neuron produces a malicious spike train that is not met in normal settings. This spike train triggers a malicious modification in the neuron that forces it to saturate, firing permanently and failing to recover to its resting state even when the input activity stops. The excessive spikes pollute the network and produce misleading decisions. We propose a methodology to select an appropriate neuron and to generate the input pattern that triggers the HT payload. The attack is illustrated by simulation on three popular benchmarks in the neuromorphic community. We also propose a hardware implementation for an analog spiking neuron and a digital SNN accelerator, demonstrating that the HT has a negligible area and power footprint and, thereby, can easily evade detection.
format Preprint
id arxiv_https___arxiv_org_abs_2503_21793
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Input-Triggered Hardware Trojan Attack on Spiking Neural Networks
Raptis, Spyridon
Kling, Paul
Kaskampas, Ioannis
Alouani, Ihsen
Stratigopoulos, Haralampos-G.
Neural and Evolutionary Computing
Artificial Intelligence
Neuromorphic computing based on spiking neural networks (SNNs) is emerging as a promising alternative to traditional artificial neural networks (ANNs), offering unique advantages in terms of low power consumption. However, the security aspect of SNNs is under-explored compared to their ANN counterparts. As the increasing reliance on AI systems comes with unique security risks and challenges, understanding the vulnerabilities and threat landscape is essential as neuromorphic computing matures. In this effort, we propose a novel input-triggered Hardware Trojan (HT) attack for SNNs. The HT mechanism is condensed in the area of one neuron. The trigger mechanism is an input message crafted in the spiking domain such that a selected neuron produces a malicious spike train that is not met in normal settings. This spike train triggers a malicious modification in the neuron that forces it to saturate, firing permanently and failing to recover to its resting state even when the input activity stops. The excessive spikes pollute the network and produce misleading decisions. We propose a methodology to select an appropriate neuron and to generate the input pattern that triggers the HT payload. The attack is illustrated by simulation on three popular benchmarks in the neuromorphic community. We also propose a hardware implementation for an analog spiking neuron and a digital SNN accelerator, demonstrating that the HT has a negligible area and power footprint and, thereby, can easily evade detection.
title Input-Triggered Hardware Trojan Attack on Spiking Neural Networks
topic Neural and Evolutionary Computing
Artificial Intelligence
url https://arxiv.org/abs/2503.21793