arXiv:2504.08897cs.LGcs.CR2025-04

研究脉冲神经网络在局部学习下的抗攻击能力,提出更有效的混合攻击方法。

On the Adversarial Robustness of Spiking Neural Networks Trained by Local Learning

  • 用局部学习训练脉冲神经网络,避免依赖生物不合理的梯度方法。
  • 提出混合攻击法,利用对抗样本迁移性,在多场景下效果优于现有方法。
  • 适用于研究神经网络安全性、类脑计算的学者,尤其关注生物合理性设计者。

近期研究表明,基于帧或事件的信息中,脉冲神经网络(SNNs)对几乎无法与正常数据区分的对抗样本具有脆弱性。然而,大多数研究受限于使用反向传播时序(BPTT)生成对抗样本,这种方法缺乏生物学合理性。相比之下,放宽了BPTT诸多限制的局部学习方法,在对抗攻击背景下仍鲜有研究。为此,本文通过四类训练算法框架,深入分析了梯度基对抗攻击在该场景中的无效性。为克服这些局限,提出一种融合对抗样本迁移性的混合攻击范式,该方法表现更优,显著超越现有攻击手段。此外,还在多步对抗攻击、黑盒FGSM场景及非脉冲领域评估了方法的泛化能力。

原文摘要 · Abstract (English)

Recent research has shown the vulnerability of Spiking Neural Networks (SNNs) under adversarial examples that are nearly indistinguishable from clean data in the context of frame-based and event-based information. The majority of these studies are constrained in generating adversarial examples using Backpropagation Through Time (BPTT), a gradient-based method which lacks biological plausibility. In contrast, local learning methods, which relax many of BPTT's constraints, remain under-explored in the context of adversarial attacks. To address this problem, we examine adversarial robustness in SNNs through the framework of four types of training algorithms. We provide an in-depth analysis of the ineffectiveness of gradient-based adversarial attacks to generate adversarial instances in this scenario. To overcome these limitations, we introduce a hybrid adversarial attack paradigm that leverages the transferability of adversarial instances. The proposed hybrid approach demonstrates superior performance, outperforming existing adversarial attack methods. Furthermore, the generalizability of the method is assessed under multi-step adversarial attacks, adversarial attacks in black-box FGSM scenarios, and within the non-spiking domain.

脉冲神经网络对抗攻击局部学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。