arXiv:2607.27990cs.CRcs.AI2026-07

SNN推理节能优势被利用,攻击可大幅增加能耗且难被发现。

Driving up Inference Energy on SNNs: Per-Sample and Universal Sponge Attacks

论文配图:Driving up Inference Energy on SNNs: Per-Sample and Universal Sponge Attacks
图 1 · 摘自论文原文
  • 针对事件驱动的SNN设计了两种新型能耗攻击:逐样本与通用型
  • 攻击使单次推理能耗最高提升至13.24毫焦,相当于原值945倍
  • 通用攻击无需逐次优化,适合长期部署场景,威胁更真实

脉冲神经网络(SNN)通过稀疏的二进制脉冲通信实现低功耗推理,适用于持续运行的电池供电边缘设备。我们发现其能效优势反而带来独特安全风险:海绵攻击可通过增加推理时脉冲活动和突触负载,显著提升能耗,而仅靠正确性监测难以察觉。现有针对SNN的输入空间效率攻击主要聚焦于率编码场景下的逐样本优化。本文将该威胁扩展至原生事件基二进制输入,提出两种攻击模型。首先,开发了基于梯度优化的逐样本海绵攻击,为每个输入生成定制对抗脉冲序列,在NMNIST、SHD和IBM DVS Gesture数据集上使单次推理突触操作(SynOps)提升1.5-2.6倍,且至少98%样本预测类别保持不变。其次,首次提出适用于原生事件基输入的通用海绵攻击:离线计算固定二进制扰动,通过异或操作应用于所有输入。虽效果较弱,但在三组数据集上仍使SynOps提升1.09-1.24倍,更具实际部署威胁。将SynOp增长映射到Loihi-1芯片能耗,单次推理功耗从14 μJ增至13.24 mJ。结果表明,原生事件基SNN易受实用型输入空间效率攻击,且可重复使用的通用扰动在持续部署系统中累积成显著电池消耗。

原文摘要 · Abstract (English)

Spiking Neural Networks (SNNs) communicate through sparse binary spike events rather than dense activations, enabling energy-efficient inference on neuromorphic hardware and motivating their use in always-on, battery-powered edge systems. We show that this same efficiency advantage creates a distinct security risk: sponge attacks can increase inference-time spike activity and synaptic workload, inflating energy consumption while remaining difficult to detect through correctness-based monitoring alone. Prior input-space efficiency attacks on SNNs have focused on per-sample optimization, primarily in rate-coded settings. We extend this threat to native event-based binary inputs and study two attack models. First, we develop a per-sample sponge attack that crafts a custom adversarial spike train for each input via gradient-based optimization. This attack increases per-inference SynOps by 1.5-2.6x on three SNN models for the NMNIST, SHD, and IBM DVS Gesture datasets, while preserving the predicted class on at least 98% of evaluated samples. Second, to the best of our knowledge, we introduce the first universal sponge attack for native event-based SNN inputs: a fixed binary perturbation computed offline and applied via XOR to all subsequent inputs. Although weaker, it still inflates SynOps by 1.09-1.24x across all three datasets and represents a more realistic deployment threat because it requires no per-input optimization. Mapping SynOp inflation to estimated Loihi-1 energy yields per-inference overheads from 14 $μ$J to 13.24 mJ. These results show that native event-based SNNs are vulnerable to practical input-space efficiency attacks, and that reusable universal perturbations can accumulate into meaningful battery drain in continuously deployed edge systems.

SNN安全能耗攻击神经形态计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。