Improving Generalization and Robustness in SNNs Through Signed Rate Encoding and Sparse Encoding Attacks
Bhaskar Mukhoty, Hilal AlQuabeh, Bin Gu
Abstract
Rate-encoded spiking neural networks (SNNs) are known to offer superior adversarial robustness compared to direct-encoded SNNs but have relatively poor generalization on clean input. While the latter offers good generalization on clean input it suffers poor adversarial robustness under standard training. A key reason for this difference is the input noise introduced by the rate encoding, which encodes a pixel intensity with T independent Bernoulli samples. To improve the generalization of rate-encoded SNNs, we propose the signed rate encoding (SRATE) that allows mean centering of the input and helps reduce the randomness introduced by the encoding, resulting in improved clean accuracy. In contrast to rate encoding, where input restricted to [0, 1] d is encoded in 0, 1 d×T , the signed rate encoding allows input in [-1, 1] d to be encoded with spikes in -1, 0, 1 d×T , where positive (negative) inputs are encoded with positive (negative) spikes. We further construct efficient Sparse Encoding Attack (SEA) on standard and signed rate encoded input, which performs l 0 -norm restricted adversarial attack in the discrete encoding space. We prove the theoretical optimality of the attack under the first-order approximation of the loss and compare it empirically with the existing attacks on the input space. Adversarial training performed with SEA, under signed rate encoding, offers superior adversarial robustness to the existing attacks and itself. Experiments conducted on standard datasets show the effectiveness of sign rate encoding in improving accuracy across all settings including adversarial robustness. The code is available at https://github.com/BhaskarMukhoty/SignedRateEncoding
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 09ff1569-9944-4dc0-8440-24c1996a0406Cited by top-tier papers5
- Time Is All It Takes: Spike-Retiming Attacks on Event-Driven Spiking Neural NetworksYi Yu, Qixin Zhang, Shuhan Ye, Xun Lin et al.ICLR 2026 · 8 citations
- Boosting the Robustness-Accuracy Trade-off of SNNs by Robust Temporal Self-EnsembleJihang Wang, Dongcheng Zhao, Ruolin Chen, Qian Zhang et al.AAAI 2026 · 1 citation
- Towards Reliable Evaluation of Adversarial Robustness for Spiking Neural NetworksJihang Wang, Dongcheng Zhao, Ruolin Chen, Qian Zhang et al.CVPR 2026 · 1 citation
- Breaking Gradient Temporal Collinearity for Robust Spiking Neural NetworksDesong Zhang, Jia Hu, Geyong MinICLR 2026
- On the Role of Temporal Granularity in the Robustness of Spiking Neural NetworksMengting Xu, Shi Gu, Peng Lin, De Ma et al.CVPR 2026
Builds on9
- Deep Residual Learning in Spiking Neural NetworksWei Fang, Zhaofei Yu, Yanqi Chen, Tiejun Huang et al.NeurIPS 2021 · 857 citations
- Temporal Efficient Training of Spiking Neural Network via Gradient Re-weightingShikuang Deng, Yuhang Li, Shanghang Zhang, Shi GuICLR 2022 · 361 citations
- Robustness and Accuracy Could Be Reconcilable by (Proper) DefinitionTianyu Pang, Min Lin, Xiao Yang, Jun Zhu et al.ICML 2022 · 168 citations
- SNN-RAT: Robustness-enhanced Spiking Neural Network through Regularized Adversarial TrainingJianhao Ding, Tong Bu, Zhaofei Yu, Tiejun Huang et al.NeurIPS 2022 · 70 citations
- Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image ClassifiersFrancesco Croce, Matthias HeinICML 2021 · 68 citations
Related papers
- Certified Adversarial Robustness for Rate Encoded Spiking Neural NetworksBhaskar Mukhoty, Hilal AlQuabeh, Giulia De Masi, Huan Xiong et al.ICLR 2024 · 8 citations
- Rate Gradient Approximation Attack Threats Deep Spiking Neural NetworksTong Bu, Jianhao Ding, Zecheng Hao, Zhaofei YuCVPR 2023
- HIRE-SNN: Harnessing the Inherent Robustness of Energy-Efficient Deep Spiking Neural Networks by Training with Crafted Input NoiseSouvik Kundu, Massoud Pedram, Peter A. BeerelICCV 2021 · 114 citations
- Enhancing Adversarial Robustness in SNNs with Sparse GradientsYujia Liu, Tong Bu, Jianhao Ding, Zecheng Hao et al.ICML 2024 · 17 citations
- Toward Robust Spiking Neural Network Against Adversarial PerturbationLing Liang, Kaidi Xu, Xing Hu, Lei Deng et al.NeurIPS 2022 · 28 citations
