SNN-RAT: Robustness-enhanced Spiking Neural Network through Regularized Adversarial Training
Jianhao Ding, Tong Bu, Zhaofei Yu, Tiejun Huang, Jian K. Liu
Abstract
Spiking neural networks (SNNs) are promising to be widely deployed in realtime and safety-critical applications with the advance of neuromorphic computing. Recent work has demonstrated the insensitivity of SNNs to small random perturbations due to the discrete internal information representation. The variety of training algorithms and the involvement of the temporal dimension pose more threats to the robustness of SNNs than that of typical neural networks. We account for the vulnerability of SNNs by constructing adversaries based on different differentiable approximation techniques. By deriving a Lipschitz constant specifically for the spike representation, we first theoretically answer the question of how much adversarial invulnerability is retained in SNNs. Hence, to defend against the broad attack methods, we propose a regularized adversarial training scheme with low computational overheads. SNNs can benefit from the constraint of the perturbed spike distance's amplification and the generalization on multiple adversarial ϵneighbourhoods. Our experiments on the image recognition benchmarks have proven that our training scheme can defend against powerful adversarial attacks crafted from strong differentiable approximations. To be specific, our approach makes the black-box attacks of the Projected Gradient Descent attack nearly ineffective. We believe that our work will facilitate the spread of SNNs for safety-critical applications and help understand the robustness of the human brain. The code is available at https://github.com/putshua/SNN-RAT .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers31
- Unleashing the Potential of Spiking Neural Networks with Dynamic ConfidenceChen Li, Edward G. Jones, Steve B. FurberICCV 2023 · 28 citations
- TAB: Temporal Accumulated Batch Normalization in Spiking Neural NetworksHaiyan Jiang, Vincent Zoonekynd, Giulia De Masi, Bin Gu et al.ICLR 2024 · 27 citations
- Robust low-rank training via approximate orthonormal constraintsDayana Savostianova, Emanuele Zangrando, Gianluca Ceruti, Francesco TudiscoNeurIPS 2023 · 24 citations
- FEEL-SNN: Robust Spiking Neural Networks with Frequency Encoding and Evolutionary Leak FactorMengting Xu, De Ma, Huajin Tang, Qian Zheng et al.NeurIPS 2024 · 23 citations
- Enhancing the Robustness of Spiking Neural Networks with Stochastic Gating MechanismsJianhao Ding, Zhaofei Yu, Tiejun Huang, Jian K. LiuAAAI 2024 · 23 citations
Builds on12
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Deep Residual Learning in Spiking Neural NetworksWei Fang, Zhaofei Yu, Yanqi Chen, Tiejun Huang et al.NeurIPS 2021 · 857 citations
- Incorporating Learnable Membrane Time Constant to Enhance Learning of Spiking Neural NetworksWei Fang, Zhaofei Yu, Yanqi Chen, Timothée Masquelier et al.ICCV 2021 · 731 citations
- Spiking-YOLO: Spiking Neural Network for Energy-Efficient Object DetectionSei Joon Kim, Seongsik Park, Byunggook Na, Sungroh YoonAAAI 2020 · 512 citations
- Optimal ANN-SNN Conversion for High-accuracy and Ultra-low-latency Spiking Neural NetworksTong Bu, Wei Fang, Jianhao Ding, Penglin Dai et al.ICLR 2022 · 272 citations
Related papers
- Enhancing Adversarial Robustness in SNNs with Sparse GradientsYujia Liu, Tong Bu, Jianhao Ding, Zecheng Hao et al.ICML 2024 · 17 citations
- Towards Reliable Evaluation of Adversarial Robustness for Spiking Neural NetworksJihang Wang, Dongcheng Zhao, Ruolin Chen, Qian Zhang et al.CVPR 2026 · 1 citation
- Toward Robust Spiking Neural Network Against Adversarial PerturbationLing Liang, Kaidi Xu, Xing Hu, Lei Deng et al.NeurIPS 2022 · 28 citations
- HIRE-SNN: Harnessing the Inherent Robustness of Energy-Efficient Deep Spiking Neural Networks by Training with Crafted Input NoiseSouvik Kundu, Massoud Pedram, Peter A. BeerelICCV 2021 · 114 citations
- Robust Stable Spiking Neural NetworksJianhao Ding, Zhiyu Pan, Yujia Liu, Zhaofei Yu et al.ICML 2024 · 16 citations
