攻击者通过伪造事件流触发模型计算瓶颈,让检测系统变慢却仍能正常识别。
Event Burst Trigger: An Availability Backdoor Attack on Event-Based SNN Object Detection

- 在训练数据中植入特定事件触发器,诱导推理时产生密集事件流。
- 检测精度几乎不变([email protected]下降<0.099),但NMS阶段延迟最高增加38%。
- 攻击隐蔽性强,现有检测方法难识别,适合边缘设备安全研究者关注。
基于事件的视觉与脉冲神经网络(SNN)在严苛延迟和能耗约束下被广泛用于边缘智能。然而,事件型SNN目标检测模型面临的可用性后门攻击仍缺乏充分研究。本文提出事件突发触发器(Event Burst Trigger, EBT),一种针对SNN目标检测模型的可用性后门攻击。EBT将精心设计的事件触发器注入训练数据,在推理时引发时间上高度集中的事件流,导致大量虚假目标候选,显著增加后处理阶段(尤其是非极大值抑制,NMS)的计算开销。我们在前沿的SpikeYOLO模型上评估了EBT,采用仅污染数据的威胁模型,无需修改模型结构、损失函数或推理流程。实验表明,尽管检测精度基本保持,[email protected]下降小于0.099,但NMS阶段延迟最高提升38%,表明其可能成为事件型SNN目标检测中的主要可用性瓶颈。在边缘平台上的实验进一步显示,该攻击提升了基线资源占用率,降低了调度松弛度,且未引起明显的资源使用峰值。此外,基于STRIP的后门检测方法无法可靠区分该攻击与正常输入。这些结果揭示了事件型SNN目标检测系统中一个此前被忽视的可用性后门威胁。
原文摘要 · Abstract (English)
Event-based vision and spiking neural networks (SNNs) are increasingly adopted for edge intelligence under strict latency and energy constraints. However, the vulnerability of event-based SNN object detection models to availability backdoor attacks remains insufficiently studied. This paper presents Event Burst Trigger (EBT), an availability backdoor attack targeting SNN-based object detection models. EBT injects carefully crafted event-based triggers into the training data, which induce temporally concentrated event streams during inference. These burst-like activations increase the number of phantom (i.e., spurious) object candidates, and consequently inflate the computational cost of the post-processing stage, particularly Non-Maximum Suppression (NMS). We evaluate EBT on SpikeYOLO, the state-of-the-art SNN-based object detector, under a poison-only threat model that does not require modifications to the model architecture, loss function, or inference pipeline. Experimental results show that while detection accuracy remains largely preserved, with [email protected] decreasing by less than 0.099, the latency of the NMS stage increases by up to 38%. This indicates that NMS can become a dominant availability bottleneck in event-based SNN object detection. Experiments on an edge platform further show that the proposed attack elevates baseline resource utilization and reduces scheduling slack without inducing conspicuous peaks in resource usage. In addition, STRIP-based backdoor detection fails to reliably distinguish the proposed attack from benign inputs. These results characterize a previously underexplored availability backdoor threat in event-based SNN object detection systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。