Boosting the Robustness-Accuracy Trade-off of SNNs by Robust Temporal Self-Ensemble
Jihang Wang, Dongcheng Zhao, Ruolin Chen, Qian Zhang, Yi Zeng
Abstract
Spiking Neural Networks (SNNs) offer a promising direction for energy-efficient and brain-inspired computing, yet their vulnerability to adversarial perturbations remains poorly understood. In this work, we revisit the adversarial robustness of SNNs through the lens of temporal ensembling, treating the network as a collection of evolving sub-networks across discrete timesteps. This formulation uncovers two critical but underexplored challenges—the fragility of individual temporal sub-networks and the tendency for adversarial vulnerabilities to transfer across time. To overcome these limitations, we propose Robust Temporal self-Ensemble (RTE), a training framework that improves the robustness of each sub-network while reducing the temporal transferability of adversarial perturbations. RTE integrates both objectives into a unified loss and employs a stochastic sampling strategy for efficient optimization. Extensive experiments across multiple benchmarks demonstrate that RTE consistently outperforms existing training methods in robust-accuracy trade-off. Additional analyses reveal that RTE reshapes the internal robustness landscape of SNNs, leading to more resilient and temporally diversified decision boundaries. Our study highlights the importance of temporal structure in adversarial learning and offers a principled foundation for building robust spiking models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on17
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Deep Residual Learning in Spiking Neural NetworksWei Fang, Zhaofei Yu, Yanqi Chen, Tiejun Huang et al.NeurIPS 2021 · 857 citations
- Temporal Efficient Training of Spiking Neural Network via Gradient Re-weightingShikuang Deng, Yuhang Li, Shanghang Zhang, Shi GuICLR 2022 · 361 citations
- DVERGE: Diversifying Vulnerabilities for Enhanced Robust Generation of EnsemblesHuanrui Yang, Jingyang Zhang, Hongliang Dong, Nathan Inkawhich et al.NeurIPS 2020 · 144 citations
- Temporal Effective Batch Normalization in Spiking Neural NetworksChaoteng Duan, Jianhao Ding, Shiyan Chen, Zhaofei Yu et al.NeurIPS 2022 · 141 citations
Related papers
- Synergy Between the Strong and the Weak: Spiking Neural Networks are Inherently Self-DistillersYongqi Ding, Lin Zuo, Mengmeng Jing, Kunshan Yang et al.NeurIPS 2025 · 4 citations
- On the Role of Temporal Granularity in the Robustness of Spiking Neural NetworksMengting Xu, Shi Gu, Peng Lin, De Ma et al.CVPR 2026
- Toward Robust Spiking Neural Network Against Adversarial PerturbationLing Liang, Kaidi Xu, Xing Hu, Lei Deng et al.NeurIPS 2022 · 28 citations
- Efficient Logit-based Knowledge Distillation of Deep Spiking Neural Networks for Full-Range Timestep DeploymentChengting Yu, Xiaochen Zhao, Lei Liu, Shu Yang et al.ICML 2025
- Reconstructing Spiking Neural Networks Using a Single Neuron with AutapsesWuque Cai, Hongze Sun, Quan Tang, Shifeng Mao et al.CVPR 2026
