arXiv:2502.13191cs.LGcs.AI2025-02被引 3

SNN模型隐私风险被揭示,其抗成员推断能力不如预期。

On the Privacy Risks of Spiking Neural Networks: A Membership Inference Analysis

  • 通过黑盒设置下的输入丢弃策略增强成员推断攻击
  • 延迟增大时SNN的隐私保护能力显著下降
  • 实验证明SNN隐私漏洞与传统ANN相当

脉冲神经网络(SNNs)因其能效高和鲁棒性强,在实际应用中日益受到关注,但其隐私风险尚未得到充分研究。本文探究了SNNs对成员推断攻击(MIA)的脆弱性——攻击者试图判断某样本是否曾用于训练。尽管先前研究表明SNN的离散、事件驱动特性可能带来天然防护,但我们发现随着延迟(T)增加,这种防护作用减弱。此外,我们提出一种在黑盒场景下的输入丢弃策略,显著提升了对SNN的成员推断能力。研究结果挑战了SNN具有内在安全性的假设,表明其隐私漏洞与人工神经网络(ANNs)相当。代码已开源:https://github.com/sharmaabhijith/MIA_SNN。

原文摘要 · Abstract (English)

Spiking Neural Networks (SNNs) are increasingly explored for their energy efficiency and robustness in real-world applications, yet their privacy risks remain largely unexamined. In this work, we investigate the susceptibility of SNNs to Membership Inference Attacks (MIAs) -- a major privacy threat where an adversary attempts to determine whether a given sample was part of the training dataset. While prior work suggests that SNNs may offer inherent robustness due to their discrete, event-driven nature, we find that its resilience diminishes as latency (T) increases. Furthermore, we introduce an input dropout strategy under black box setting, that significantly enhances membership inference in SNNs. Our findings challenge the assumption that SNNs are inherently more secure, and even though they are expected to be better, our results reveal that SNNs exhibit privacy vulnerabilities that are equally comparable to Artificial Neural Networks (ANNs). Our code is available at https://github.com/sharmaabhijith/MIA_SNN.

SNN隐私安全成员推断

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。