arXiv:2505.06299cs.CRcs.AI2025-05被引 2

针对脉冲神经网络提出两类新攻击方法,可高效生成隐蔽扰动。

Input-Specific and Universal Adversarial Attack Generation for Spiking Neural Networks in the Spiking Domain

  • 在脉冲域基于梯度设计输入特异与通用攻击算法
  • 在NMNIST和IBM DVS手势数据集上全面超越现有方法
  • 首次实现声学域的脉冲神经网络对抗攻击

随着脉冲神经网络(SNNs)在各类应用中日益普及,其安全漏洞问题愈发重要。本文聚焦于最具威胁性的对抗攻击:通过微小输入扰动误导网络决策。我们提出两种新型SNN对抗攻击算法——一种针对特定数据输入的输入特异性攻击,另一种可复用的通用攻击,能对多数输入引发误分类,具备实时部署可行性。算法在脉冲域基于梯度计算,对对抗准确率、隐蔽性、生成时间等指标均表现优异。在两个主流类脑视觉数据集NMNIST和IBM DVS Gesture上的实验表明,所提方法在所有指标上均超越现有最先进方法。此外,我们首次在声学域(使用SHD数据集)实现了对SNN的对抗攻击生成。

原文摘要 · Abstract (English)

As Spiking Neural Networks (SNNs) gain traction across various applications, understanding their security vulnerabilities becomes increasingly important. In this work, we focus on the adversarial attacks, which is perhaps the most concerning threat. An adversarial attack aims at finding a subtle input perturbation to fool the network's decision-making. We propose two novel adversarial attack algorithms for SNNs: an input-specific attack that crafts adversarial samples from specific dataset inputs and a universal attack that generates a reusable patch capable of inducing misclassification across most inputs, thus offering practical feasibility for real-time deployment. The algorithms are gradient-based operating in the spiking domain proving to be effective across different evaluation metrics, such as adversarial accuracy, stealthiness, and generation time. Experimental results on two widely used neuromorphic vision datasets, NMNIST and IBM DVS Gesture, show that our proposed attacks surpass in all metrics all existing state-of-the-art methods. Additionally, we present the first demonstration of adversarial attack generation in the sound domain using the SHD dataset.

脉冲神经网络对抗攻击类脑计算安全性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。