arXiv:2510.06629cs.CRcs.CV2025-10被引 1

针对脉冲神经网络的隐蔽后门攻击,提出无监督检测与防御方法。

Unsupervised Backdoor Detection and Mitigation for Spiking Neural Networks

  • 基于膜电位时间统计特性检测后门,无需攻击知识
  • 检测准确率100%,防御后攻击成功率降至2.81%
  • 适用于高能效脉冲神经网络,适合安全敏感场景

脉冲神经网络(SNNs)因其相比人工神经网络(ANNs)更高的能效而受到关注,但其安全性尤其是面对后门攻击时仍缺乏研究。现有针对ANN的防御方法在SNNs中表现不佳或易被绕过,主要因SNNs具有事件驱动和时序依赖特性。本文识别了传统防御在SNNs中失效的关键障碍,并提出一种无监督后训练检测框架——时间膜电位后门检测(TMPBD),利用最终脉冲层的时间膜电位最大边际统计量,在无攻击知识和数据访问条件下检测目标标签。进一步提出鲁棒缓解机制——神经树突抑制后门缓解(NDSBM),通过钳制早期卷积层间的树突连接以抑制恶意神经元,同时保留正常行为,该过程由少量干净无标签数据提取的膜电位引导。在多个类脑基准和先进的输入感知动态触发攻击下进行的大量实验表明,TMPBD实现100%检测准确率,NDSBM将攻击成功率从100%降至8.44%,结合检测后降至2.81%,且不影响纯净准确率。

原文摘要 · Abstract (English)

Spiking Neural Networks (SNNs) have gained increasing attention for their superior energy efficiency compared to Artificial Neural Networks (ANNs). However, their security aspects, particularly under backdoor attacks, have received limited attention. Existing defense methods developed for ANNs perform poorly or can be easily bypassed in SNNs due to their event-driven and temporal dependencies. This paper identifies the key blockers that hinder traditional backdoor defenses in SNNs and proposes an unsupervised post-training detection framework, Temporal Membrane Potential Backdoor Detection (TMPBD), to overcome these challenges. TMPBD leverages the maximum margin statistics of temporal membrane potential (TMP) in the final spiking layer to detect target labels without any attack knowledge or data access. We further introduce a robust mitigation mechanism, Neural Dendrites Suppression Backdoor Mitigation (NDSBM), which clamps dendritic connections between early convolutional layers to suppress malicious neurons while preserving benign behaviors, guided by TMP extracted from a small, clean, unlabeled dataset. Extensive experiments on multiple neuromorphic benchmarks and state-of-the-art input-aware dynamic trigger attacks demonstrate that TMPBD achieves 100% detection accuracy, while NDSBM reduces the attack success rate from 100% to 8.44%, and to 2.81% when combined with detection, without degrading clean accuracy.

脉冲神经网络后门防御无监督学习安全可信

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。