arXiv:2602.07200cs.CRcs.AI2026-02

通过操控神经元超参数实现对脉冲神经网络的后门攻击

BadSNN: Backdoor Attacks on Spiking Neural Networks via Adversarial Spiking Neuron

  • 利用脉冲神经元的超参数变化植入后门
  • 在多个数据集上攻击成功率超现有方法
  • 触发器隐蔽性强,可绕过主流防御手段

脉冲神经网络(SNNs)是具有高生物合理性且能效优越的深度神经网络替代方案,信息通过时间上的脉冲模式传递。其核心单元是遵循漏电积分-放电(LIF)模型的脉冲神经元,包含膜电位阈值、膜时间常数等关键超参数。尽管深度神经网络和脉冲神经网络均被证明易受后门攻击,即攻击者通过污染训练数据注入恶意触发器,迫使模型按攻击者预设方式行为,但针对SNN独特特性的后门攻击尚未充分研究。本文提出 extit{BadSNN},一种利用脉冲神经元超参数变异实现后门植入的新攻击方法,并设计触发器优化流程,在提升攻击效果的同时降低触发器的可感知性。实验表明, extit{BadSNN}在多种数据集与架构上表现优异,优于现有基于数据投毒的后门攻击方法,且对常见防御技术具备较强鲁棒性。

原文摘要 · Abstract (English)

Spiking Neural Networks (SNNs) are energy-efficient counterparts of Deep Neural Networks (DNNs) with high biological plausibility, as information is transmitted through temporal spiking patterns. The core element of an SNN is the spiking neuron, which converts input data into spikes following the Leaky Integrate-and-Fire (LIF) neuron model. This model includes several important hyperparameters, such as the membrane potential threshold and membrane time constant. Both the DNNs and SNNs have proven to be exploitable by backdoor attacks, where an adversary can poison the training dataset with malicious triggers and force the model to behave in an attacker-defined manner. Yet, how an adversary can exploit the unique characteristics of SNNs for backdoor attacks remains underexplored. In this paper, we propose \textit{BadSNN}, a novel backdoor attack on spiking neural networks that exploits hyperparameter variations of spiking neurons to inject backdoor behavior into the model. We further propose a trigger optimization process to achieve better attack performance while making trigger patterns less perceptible. \textit{BadSNN} demonstrates superior attack performance on various datasets and architectures, as well as compared with state-of-the-art data poisoning-based backdoor attacks and robustness against common backdoor mitigation techniques. Codes can be found at https://github.com/SiSL-URI/BadSNN.

后门攻击脉冲神经网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。