Timestep-Compressed Attack on Spiking Neural Networks through Timestep-Level Backpropagation

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Kang, Donghwa, Kim, Doohyun, Ko, Sang-Ki, Lee, Jinkyu, Baek, Hyeongboo, Kang, Brent ByungHoon
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916908569198592
author Kang, Donghwa
Kim, Doohyun
Ko, Sang-Ki
Lee, Jinkyu
Baek, Hyeongboo
Kang, Brent ByungHoon
author_facet Kang, Donghwa
Kim, Doohyun
Ko, Sang-Ki
Lee, Jinkyu
Baek, Hyeongboo
Kang, Brent ByungHoon
contents State-of-the-art (SOTA) gradient-based adversarial attacks on spiking neural networks (SNNs), which largely rely on extending FGSM and PGD frameworks, face a critical limitation: substantial attack latency from multi-timestep processing, rendering them infeasible for practical real-time applications. This inefficiency stems from their design as direct extensions of ANN paradigms, which fail to exploit key SNN properties. In this paper, we propose the timestep-compressed attack (TCA), a novel framework that significantly reduces attack latency. TCA introduces two components founded on key insights into SNN behavior. First, timestep-level backpropagation (TLBP) is based on our finding that global temporal information in backpropagation to generate perturbations is not critical for an attack's success, enabling per-timestep evaluation for early stopping. Second, adversarial membrane potential reuse (A-MPR) is motivated by the observation that initial timesteps are inefficiently spent accumulating membrane potential, a warm-up phase that can be pre-calculated and reused. Our experiments on VGG-11 and ResNet-17 with the CIFAR-10/100 and CIFAR10-DVS datasets show that TCA significantly reduces the required attack latency by up to 56.6% and 57.1% compared to SOTA methods in white-box and black-box settings, respectively, while maintaining a comparable attack success rate.
format Preprint
id arxiv_https___arxiv_org_abs_2508_13812
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Timestep-Compressed Attack on Spiking Neural Networks through Timestep-Level Backpropagation
Kang, Donghwa
Kim, Doohyun
Ko, Sang-Ki
Lee, Jinkyu
Baek, Hyeongboo
Kang, Brent ByungHoon
Computer Vision and Pattern Recognition
Neural and Evolutionary Computing
State-of-the-art (SOTA) gradient-based adversarial attacks on spiking neural networks (SNNs), which largely rely on extending FGSM and PGD frameworks, face a critical limitation: substantial attack latency from multi-timestep processing, rendering them infeasible for practical real-time applications. This inefficiency stems from their design as direct extensions of ANN paradigms, which fail to exploit key SNN properties. In this paper, we propose the timestep-compressed attack (TCA), a novel framework that significantly reduces attack latency. TCA introduces two components founded on key insights into SNN behavior. First, timestep-level backpropagation (TLBP) is based on our finding that global temporal information in backpropagation to generate perturbations is not critical for an attack's success, enabling per-timestep evaluation for early stopping. Second, adversarial membrane potential reuse (A-MPR) is motivated by the observation that initial timesteps are inefficiently spent accumulating membrane potential, a warm-up phase that can be pre-calculated and reused. Our experiments on VGG-11 and ResNet-17 with the CIFAR-10/100 and CIFAR10-DVS datasets show that TCA significantly reduces the required attack latency by up to 56.6% and 57.1% compared to SOTA methods in white-box and black-box settings, respectively, while maintaining a comparable attack success rate.
title Timestep-Compressed Attack on Spiking Neural Networks through Timestep-Level Backpropagation
topic Computer Vision and Pattern Recognition
Neural and Evolutionary Computing
url https://arxiv.org/abs/2508.13812