SNN天然梯度稀疏性可实现强抗攻击能力,但会牺牲泛化性能。
Accuracy-Robustness Trade Off via Spiking Neural Network Gradient Sparsity Trail
- 利用SNN架构特性实现自然梯度稀疏,无需额外正则化。
- 在特定配置下达到当前最优抗攻击效果,但泛化能力下降。
- 揭示了梯度稀疏性在鲁棒性与泛化间的权衡关系。
脉冲神经网络(SNN)因其固有的能效优势和紧凑内存占用,在计算神经科学与人工智能领域日益受到关注。然而,实现SNN在视觉任务中的对抗鲁棒性仍处于初级探索阶段。近期研究提出通过稀疏梯度作为正则化手段提升抗扰动能力。本文发现:在特定网络结构下,SNN可自然产生梯度稀疏性,并在无需显式正则化的情况下实现最先进的对抗防御性能。进一步分析表明存在鲁棒性与泛化能力的权衡:稀疏梯度有助于提升对抗鲁棒性,但削弱泛化能力;而稠密梯度则支持更好泛化,但增加攻击敏感性。该发现为理解梯度稀疏性在SNN训练中的双重作用提供了新视角。
原文摘要 · Abstract (English)
Spiking Neural Networks (SNNs) have attracted growing interest in both computational neuroscience and artificial intelligence, primarily due to their inherent energy efficiency and compact memory footprint. However, achieving adversarial robustness in SNNs, (particularly for vision-related tasks) remains a nascent and underexplored challenge. Recent studies have proposed leveraging sparse gradients as a form of regularization to enhance robustness against adversarial perturbations. In this work, we present a surprising finding: under specific architectural configurations, SNNs exhibit natural gradient sparsity and can achieve state-of-the-art adversarial defense performance without the need for any explicit regularization. Further analysis reveals a trade-off between robustness and generalization: while sparse gradients contribute to improved adversarial resilience, they can impair the model's ability to generalize; conversely, denser gradients support better generalization but increase vulnerability to attacks. Our findings offer new insights into the dual role of gradient sparsity in SNN training.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。