PrivateSNN: Privacy-Preserving Spiking Neural Networks
Youngeun Kim, Yeshwanth Venkatesha, Priyadarshini Panda
Abstract
How can we bring both privacy and energy-efficiency to a neural system? In this paper, we propose PrivateSNN, which aims to build low-power Spiking Neural Networks (SNNs) from a pre-trained ANN model without leaking sensitive information contained in a dataset. Here, we tackle two types of leakage problems: 1) Data leakage is caused when the networks access real training data during an ANN-SNN conversion process. 2) Class leakage is caused when class-related features can be reconstructed from network parameters. In order to address the data leakage issue, we generate synthetic images from the pre-trained ANNs and convert ANNs to SNNs using the generated images. However, converted SNNs remain vulnerable to class leakage since the weight parameters have the same (or scaled) value with respect to ANN parameters. Therefore, we encrypt SNN weights by training SNNs with a temporal spike-based learning rule. Updating weight parameters with temporal data makes SNNs difficult to be interpreted in the spatial domain. We observe that the encrypted PrivateSNN eliminates data and class leakage issues with a slight performance drop (less than 2%) and significant energy-efficiency gain (about 55x) compared to the standard ANN. We conduct extensive experiments on various datasets including CIFAR10, CIFAR100, and TinyImageNet, highlighting the importance of privacy-preserving SNN training.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Training Spiking Neural Networks with Event-driven BackpropagationYaoyu Zhu, Zhaofei Yu, Wei Fang, Xiaodong Xie et al.NeurIPS 2022 · 57 citations
- The Parameterized Complexity of Network MicroaggregationVáclav Blazej, Robert Ganian, Dusan Knop, Jan Pokorný et al.AAAI 2023 · 7 citations
- MPD-SGR: Robust Spiking Neural Networks with Membrane Potential Distribution-Driven Surrogate Gradient RegularizationRunhao Jiang, Chengzhi Jiang, Rui Yan, Huajin TangAAAI 2026 · 2 citations
Builds on7
- Do We Really Need to Access the Source Data? Source Hypothesis Transfer for Unsupervised Domain AdaptationJian Liang, Dapeng Hu, Jiashi FengICML 2020 · 1,624 citations
- Going Deeper With Directly-Trained Larger Spiking Neural NetworksHanle Zheng, Yujie Wu, Lei Deng, Yifan Hu et al.AAAI 2021 · 694 citations
- Temporal Efficient Training of Spiking Neural Network via Gradient Re-weightingShikuang Deng, Yuhang Li, Shanghang Zhang, Shi GuICLR 2022 · 361 citations
- Differentiable Spike: Rethinking Gradient-Descent for Training Spiking Neural NetworksYuhang Li, Yufei Guo, Shanghang Zhang, Shikuang Deng et al.NeurIPS 2021 · 288 citations
- Universal Source-Free Domain AdaptationJogendra Nath Kundu, Naveen Venkat, Rahul M. V., R. Venkatesh BabuCVPR 2020
Related papers
- Temporal-Coded Deep Spiking Neural Network with Easy Training and Robust PerformanceShibo Zhou, Xiaohua Li, Ying Chen, Sanjeev Tannirkulam Chandrasekaran et al.AAAI 2021 · 114 citations
- Efficiency attacks on spiking neural networksSarada Krithivasan, Sanchari Sen, Nitin Rathi, Kaushik Roy et al.DAC 2022 · 10 citations
- CLIF: Complementary Leaky Integrate-and-Fire Neuron for Spiking Neural NetworksYulong Huang, Xiaopeng Lin, Hongwei Ren, Haotian Fu et al.ICML 2024 · 43 citations
- Efficient ANN-Guided Distillation: Aligning Rate-based Features of Spiking Neural Networks through Hybrid Block-wise ReplacementShu Yang, Chengting Yu, Lei Liu, Hanzhi Ma et al.CVPR 2025
- A time-to-first-spike coding and conversion aware training for energy-efficient deep spiking neural network processor designDongwoo Lew, Kyungchul Lee, Jongsun ParkDAC 2022 · 18 citations
