Robust Spiking Neural Networks Against Adversarial Attacks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Wang, Shuai, Zhang, Malu, Jiang, Yulin, Zhang, Dehao, Belatreche, Ammar, Liang, Yu, Shan, Yimeng, Zhou, Zijian, Yang, Yang, Li, Haizhou
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866918353214373888
author Wang, Shuai
Zhang, Malu
Jiang, Yulin
Zhang, Dehao
Belatreche, Ammar
Liang, Yu
Shan, Yimeng
Zhou, Zijian
Yang, Yang
Li, Haizhou
author_facet Wang, Shuai
Zhang, Malu
Jiang, Yulin
Zhang, Dehao
Belatreche, Ammar
Liang, Yu
Shan, Yimeng
Zhou, Zijian
Yang, Yang
Li, Haizhou
contents Spiking Neural Networks (SNNs) represent a promising paradigm for energy-efficient neuromorphic computing due to their bio-plausible and spike-driven characteristics. However, the robustness of SNNs in complex adversarial environments remains significantly constrained. In this study, we theoretically demonstrate that those threshold-neighboring spiking neurons are the key factors limiting the robustness of directly trained SNNs. We find that these neurons set the upper limits for the maximum potential strength of adversarial attacks and are prone to state-flipping under minor disturbances. To address this challenge, we propose a Threshold Guarding Optimization (TGO) method, which comprises two key aspects. First, we incorporate additional constraints into the loss function to move neurons' membrane potentials away from their thresholds. It increases SNNs' gradient sparsity, thereby reducing the theoretical upper bound of adversarial attacks. Second, we introduce noisy spiking neurons to transition the neuronal firing mechanism from deterministic to probabilistic, decreasing their state-flipping probability due to minor disturbances. Extensive experiments conducted in standard adversarial scenarios prove that our method significantly enhances the robustness of directly trained SNNs. These findings pave the way for advancing more reliable and secure neuromorphic computing in real-world applications.
format Preprint
id arxiv_https___arxiv_org_abs_2602_20548
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Robust Spiking Neural Networks Against Adversarial Attacks
Wang, Shuai
Zhang, Malu
Jiang, Yulin
Zhang, Dehao
Belatreche, Ammar
Liang, Yu
Shan, Yimeng
Zhou, Zijian
Yang, Yang
Li, Haizhou
Computer Vision and Pattern Recognition
Spiking Neural Networks (SNNs) represent a promising paradigm for energy-efficient neuromorphic computing due to their bio-plausible and spike-driven characteristics. However, the robustness of SNNs in complex adversarial environments remains significantly constrained. In this study, we theoretically demonstrate that those threshold-neighboring spiking neurons are the key factors limiting the robustness of directly trained SNNs. We find that these neurons set the upper limits for the maximum potential strength of adversarial attacks and are prone to state-flipping under minor disturbances. To address this challenge, we propose a Threshold Guarding Optimization (TGO) method, which comprises two key aspects. First, we incorporate additional constraints into the loss function to move neurons' membrane potentials away from their thresholds. It increases SNNs' gradient sparsity, thereby reducing the theoretical upper bound of adversarial attacks. Second, we introduce noisy spiking neurons to transition the neuronal firing mechanism from deterministic to probabilistic, decreasing their state-flipping probability due to minor disturbances. Extensive experiments conducted in standard adversarial scenarios prove that our method significantly enhances the robustness of directly trained SNNs. These findings pave the way for advancing more reliable and secure neuromorphic computing in real-world applications.
title Robust Spiking Neural Networks Against Adversarial Attacks
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2602.20548