arXiv:2607.28075cs.CRcs.AI2026-07

通过时间重分布实现无标签后门攻击,让神经形态模型在不改标签下被操控。

Temporal Poisoning: Clean-Label Backdoors via Event Redistribution in SNNs

论文配图:Temporal Poisoning: Clean-Label Backdoors via Event Redistribution in SNNs
图 1 · 摘自论文原文
  • 仅对目标类事件流施加时间戳变换,标签不变但触发后门
  • 在三个数据集上攻击成功率达100%,对卷积与变压器模型均有效
  • 提出基于每步事件质量的无模型检测法,揭示现有防御盲区

针对脉冲神经网络(SNNs)的后门攻击通常依赖脏标签投毒,即篡改训练样本标签。本文研究清洁标签下的时序投毒:仅对目标类别训练流施加固定的时间戳变换,保持像素级、极性级事件计数不变,使清洗后样本外观相同,但输入SNN的序列已被改变。在三个类脑数据集及基于卷积和变压器的模型上,该攻击在最强配置下实现1.00的攻击成功率(ASR)。通过投毒预算与触发形状的消融分析,并评估适配脉冲模型的已有防御方法。发现时间轴压缩型防御因构造原因天然失效,而特征空间方法仅在特定设置下有效。本文提出的无模型检测器基于每步事件质量,可检测所评估的时间变换,揭示了现有防御的局限性与攻击隐蔽性的边界。据我们所知,这是首个在SNN与类脑事件数据上评估的清洁标签后门攻击。

原文摘要 · Abstract (English)

Backdoor attacks on Spiking Neural Networks (SNNs) have primarily assumed dirty-label poisoning, in which triggered training samples are relabeled to an attacker-selected class. We study clean-label temporal poisoning, where a fixed timestamp transformation is applied only to the target-class training streams, leaving their labels unchanged. The transformation preserves the per-pixel, per-polarity event count exactly, making clean and triggered samples identical after temporal aggregation while altering the sequence processed by the SNN. Across three neuromorphic datasets and both convolutional and transformer-based victims, the attack reaches an ASR of 1.00 in the strongest configurations. We analyze the attack through poison-budget and trigger-shape ablations and evaluate established backdoor defenses adapted to spiking models. Defenses that collapse the time axis before inspection are blind by construction, while feature-space methods detect the poison only in selected settings. Our model-free detector, based on per-step event mass, detects the evaluated temporal transformations, demonstrating both the limitation of rate-collapsed defenses and the boundary of the attack's stealth. To our knowledge, this is the first clean-label backdoor attack evaluated on SNNs and neuromorphic event data.

后门攻击脉冲神经网络事件数据无标签攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。