Timestep-Compressed Attack on Spiking Neural Networks Through Timestep-Level Backpropagation
Donghwa Kang, Doohyun Kim, Sang-Ki Ko, Jinkyu Lee, Hyeongboo Baek, Brent ByungHoon Kang
Abstract
State-of-the-art (SOTA) gradient-based adversarial attacks on spiking neural networks (SNNs), which largely rely on extending FGSM and PGD frameworks, face a critical limitation: substantial attack latency from multi-timestep processing, rendering them infeasible for practical real-time applications. This inefficiency stems from their design as direct extensions of ANN paradigms, which fail to exploit key SNN properties. In this paper, we propose the timestep compressed attack (TCA), a novel framework that significantly reduces attack latency. TCA introduces two components founded on key insights into SNN behavior. First, timestep-level backpropagation (TLBP) is based on our finding that global temporal information in backpropagation to generate perturbations is not critical for an attack’s success, enabling per-timestep evaluation for early stopping. Second, adversarial membrane potential reuse (A-MPR) is motivated by the observation that initial timesteps are inefficiently spent accumulating membrane potential, a warm-up phase that can be pre-calculated and reused. Our experiments on VGG-11 and ResNet-17 with the CIFAR-10/100 and CIFAR10-DVS datasets show that TCA significantly reduces the required attack latency by up to 56.6% and 57.1% compared to SOTA methods in white-box and black-box settings, respectively, while maintaining a comparable attack success rate.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2bbdce25-6600-4dcc-ba16-fb8e5a4f1934Builds on7
- Deep Residual Learning in Spiking Neural NetworksWei Fang, Zhaofei Yu, Yanqi Chen, Tiejun Huang et al.NeurIPS 2021 · 857 citations
- Deep Directly-Trained Spiking Neural Networks for Object DetectionQiaoyi Su, Yuhong Chou, Yifan Hu, Jianing Li et al.ICCV 2023 · 143 citations
- Optimal Conversion of Conventional Artificial Neural Networks to Spiking Neural NetworksShikuang Deng, Shi GuICLR 2021 · 100 citations
- Threaten Spiking Neural Networks through Combining Rate and Temporal InformationZecheng Hao, Tong Bu, Xinyu Shi, Zihan Huang et al.ICLR 2024 · 17 citations
- realSEUDO for real-time calcium imaging analysisIuliia Dmitrieva, Sergey Babkin, Adam S. CharlesNeurIPS 2024 · 1 citation
Related papers
- On the Role of Temporal Granularity in the Robustness of Spiking Neural NetworksMengting Xu, Shi Gu, Peng Lin, De Ma et al.CVPR 2026
- Efficiency attacks on spiking neural networksSarada Krithivasan, Sanchari Sen, Nitin Rathi, Kaushik Roy et al.DAC 2022 · 10 citations
- Activation-wise Propagation: A One-Timestep Strategy for Spiking Neural NetworksJian Song, Xiangfei Yang, Shangke Lyu, Donglin WangAAAI 2026
- HIRE-SNN: Harnessing the Inherent Robustness of Energy-Efficient Deep Spiking Neural Networks by Training with Crafted Input NoiseSouvik Kundu, Massoud Pedram, Peter A. BeerelICCV 2021 · 114 citations
- Optimized Potential Initialization for Low-Latency Spiking Neural NetworksTong Bu, Jianhao Ding, Zhaofei Yu, Tiejun HuangAAAI 2022 · 112 citations
