arXiv:2502.18623cs.LGcs.NE2025-02被引 6

SNN模型通过量化与梯度设计增强隐私,对抗成员推理攻击。

On the Privacy-Preserving Properties of Spiking Neural Networks with Unique Surrogate Gradients and Quantization Levels

  • 用量化降低激活模式泄露,抑制成员推理攻击
  • 稀疏脉冲网络在量化后仍比全精度ANN更抗攻击
  • 选择脉冲率逃逸梯度可实现最佳隐私-精度平衡

随着机器学习模型处理敏感数据,理解其对隐私攻击的脆弱性至关重要。成员推理攻击(MIAs)通过分析模型响应推断特定数据是否参与训练,构成重大隐私风险。已有研究指出,依赖事件驱动计算和离散脉冲编码的脉冲神经网络(SNN)相比人工神经网络(ANN)对MIAs更具鲁棒性,这源于其非可微激活和内在随机性,削弱了模型输出与单个训练样本间的关联。为提升SNN隐私性,本文探索了量化和替代梯度两种技术。量化通过降低精度限制信息泄露,在ANN中已证明有效;鉴于SNN具有稀疏不规则激活,量化可能进一步扰乱被攻击者利用的激活模式。我们在多个数据集上评估了权重与激活量化的SNN与ANN的脆弱性,采用攻击模型的受试者工作特征曲线下面积(ROC AUC)作为指标,数值越低表示隐私越强,并分析隐私-精度权衡。结果表明:量化在两类架构中均显著提升隐私且性能损失极小,但全精度SNN仍比量化ANN更鲁棒。此外,我们考察了五种替代梯度对SNN隐私的影响:脉冲率逃逸(spike rate escape)表现最佳,而反正切(arctangent)反而增加攻击风险。这些结果强化了SNN的固有隐私优势,并表明量化策略与替代梯度选择对SNN隐私-精度权衡具有决定性影响。

原文摘要 · Abstract (English)

As machine learning models increasingly process sensitive data, understanding their vulnerability to privacy attacks is vital. Membership inference attacks (MIAs) exploit model responses to infer whether specific data points were used during training, posing a significant privacy risk. Prior research suggests that spiking neural networks (SNNs), which rely on event-driven computation and discrete spike-based encoding, exhibit greater resilience to MIAs than artificial neural networks (ANNs). This resilience stems from their non-differentiable activations and inherent stochasticity, which obscure the correlation between model responses and individual training samples. To enhance privacy in SNNs, we explore two techniques: quantization and surrogate gradients. Quantization, which reduces precision to limit information leakage, has improved privacy in ANNs. Given SNNs' sparse and irregular activations, quantization may further disrupt the activation patterns exploited by MIAs. We assess the vulnerability of SNNs and ANNs under weight and activation quantization across multiple datasets, using the attack model's receiver operating characteristic (ROC) curve area under the curve (AUC) metric, where lower values indicate stronger privacy, and evaluate the privacy-accuracy trade-off. Our findings show that quantization enhances privacy in both architectures with minimal performance loss, though full-precision SNNs remain more resilient than quantized ANNs. Additionally, we examine the impact of surrogate gradients on privacy in SNNs. Among five evaluated gradients, spike rate escape provides the best privacy-accuracy trade-off, while arctangent increases vulnerability to MIAs. These results reinforce SNNs' inherent privacy advantages and demonstrate that quantization and surrogate gradient selection significantly influence privacy-accuracy trade-offs in SNNs.

脉冲神经网络隐私保护量化成员推理攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。