提出TGO方法提升脉冲神经网络抗干扰能力
Robust Spiking Neural Networks Against Adversarial Attacks
- 通过约束损失函数让膜电位远离阈值,增强梯度稀疏性
- 引入噪声脉冲使放电机制概率化,降低微小扰动引发的状态翻转
- 在标准对抗场景下显著提升直接训练脉冲网络的鲁棒性
脉冲神经网络(SNNs)因其生物可解释性和脉冲驱动特性,是能效高效的类脑计算有前景范式。然而,其在复杂对抗环境下的鲁棒性仍受限。本文理论证明,接近阈值的脉冲神经元是限制直接训练SNN鲁棒性的关键因素:这些神经元设定了对抗攻击强度的理论上限,且对微小扰动易发生状态翻转。为此,我们提出阈值保护优化(TGO)方法,包含两方面:一是将额外约束加入损失函数,使神经元膜电位远离阈值,提升梯度稀疏性,从而降低对抗攻击的理论上限;二是引入噪声脉冲神经元,将放电机制从确定性转为概率性,减少微小扰动导致的状态翻转概率。在标准对抗场景下的大量实验表明,该方法显著提升了直接训练的SNN鲁棒性,为实现更可靠、安全的类脑计算提供了新路径。
原文摘要 · Abstract (English)
Spiking Neural Networks (SNNs) represent a promising paradigm for energy-efficient neuromorphic computing due to their bio-plausible and spike-driven characteristics. However, the robustness of SNNs in complex adversarial environments remains significantly constrained. In this study, we theoretically demonstrate that those threshold-neighboring spiking neurons are the key factors limiting the robustness of directly trained SNNs. We find that these neurons set the upper limits for the maximum potential strength of adversarial attacks and are prone to state-flipping under minor disturbances. To address this challenge, we propose a Threshold Guarding Optimization (TGO) method, which comprises two key aspects. First, we incorporate additional constraints into the loss function to move neurons' membrane potentials away from their thresholds. It increases SNNs' gradient sparsity, thereby reducing the theoretical upper bound of adversarial attacks. Second, we introduce noisy spiking neurons to transition the neuronal firing mechanism from deterministic to probabilistic, decreasing their state-flipping probability due to minor disturbances. Extensive experiments conducted in standard adversarial scenarios prove that our method significantly enhances the robustness of directly trained SNNs. These findings pave the way for advancing more reliable and secure neuromorphic computing in real-world applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。