arXiv:2511.21181cs.LGcs.AI2025-11被引 1

SNN在联邦学习中更难被梯度反演攻击泄露隐私,因脉冲特性使梯度信息噪声大。

Privacy in Federated Learning with Spiking Neural Networks

  • 用脉冲神经网络替代传统神经网络训练,降低梯度泄露风险。
  • 实验显示SNN梯度重建图像模糊且无时序结构,无法还原原始数据。
  • 适合关注边缘设备隐私保护的研究者或开发者参考。

脉冲神经网络(SNNs)因其极低功耗成为嵌入式与边缘AI的有力候选。在联邦学习(FL)场景下,其能实现本地训练并减少原始数据暴露。然而,梯度反演攻击仍是重大隐私威胁,可从共享梯度中重构敏感数据。尽管该问题在传统人工神经网络(ANNs)中广泛研究,但对SNN的影响仍不明。本文首次系统评估了多种数据领域下SNN中的梯度泄漏情况。由于SNN本质非可微,通常使用替代梯度训练,我们推测其与原始输入相关性较低,可能更具隐私保护性。为此,我们适配多种梯度反演攻击至脉冲域。实验发现:与传统ANN梯度能有效暴露关键输入内容不同,SNN梯度生成的重建结果高度噪声化、时间不一致,无法恢复有意义的空间或时序结构。这表明事件驱动机制与替代梯度训练共同显著降低了梯度的信息量。据我们所知,这是首个针对脉冲架构的梯度反演攻击系统性基准,揭示了类脑计算固有的隐私保护潜力。

原文摘要 · Abstract (English)

Spiking neural networks (SNNs) have emerged as prominent candidates for embedded and edge AI. Their inherent low power consumption makes them far more efficient than conventional ANNs in scenarios where energy budgets are tightly constrained. In parallel, federated learning (FL) has become the prevailing training paradigm in such settings, enabling on-device learning while limiting the exposure of raw data. However, gradient inversion attacks represent a critical privacy threat in FL, where sensitive training data can be reconstructed directly from shared gradients. While this vulnerability has been widely investigated in conventional ANNs, its implications for SNNs remain largely unexplored. In this work, we present the first comprehensive empirical study of gradient leakage in SNNs across diverse data domains. SNNs are inherently non-differentiable and are typically trained using surrogate gradients, which we hypothesized would be less correlated with the original input and thus less informative from a privacy perspective. To investigate this, we adapt different gradient leakage attacks to the spike domain. Our experiments reveal a striking contrast with conventional ANNs: whereas ANN gradients reliably expose salient input content, SNN gradients yield noisy, temporally inconsistent reconstructions that fail to recover meaningful spatial or temporal structure. These results indicate that the combination of event-driven dynamics and surrogate-gradient training substantially reduces gradient informativeness. To the best of our knowledge, this work provides the first systematic benchmark of gradient inversion attacks for spiking architectures, highlighting the inherent privacy-preserving potential of neuromorphic computation.

联邦学习隐私保护脉冲神经网络梯度泄露

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。