Improving Generalization and Robustness in SNNs Through Signed Rate Encoding and Sparse Encoding Attacks
Bhaskar Mukhoty, Hilal AlQuabeh, Bin Gu
摘要
Rate-encoded spiking neural networks (SNNs) are known to offer superior adversarial robustness compared to direct-encoded SNNs but have relatively poor generalization on clean input. While the latter offers good generalization on clean input it suffers poor adversarial robustness under standard training. A key reason for this difference is the input noise introduced by the rate encoding, which encodes a pixel intensity with T independent Bernoulli samples. To improve the generalization of rate-encoded SNNs, we propose the signed rate encoding (SRATE) that allows mean centering of the input and helps reduce the randomness introduced by the encoding, resulting in improved clean accuracy. In contrast to rate encoding, where input restricted to [0, 1] d is encoded in 0, 1 d×T , the signed rate encoding allows input in [-1, 1] d to be encoded with spikes in -1, 0, 1 d×T , where positive (negative) inputs are encoded with positive (negative) spikes. We further construct efficient Sparse Encoding Attack (SEA) on standard and signed rate encoded input, which performs l 0 -norm restricted adversarial attack in the discrete encoding space. We prove the theoretical optimality of the attack under the first-order approximation of the loss and compare it empirically with the existing attacks on the input space. Adversarial training performed with SEA, under signed rate encoding, offers superior adversarial robustness to the existing attacks and itself. Experiments conducted on standard datasets show the effectiveness of sign rate encoding in improving accuracy across all settings including adversarial robustness. The code is available at https://github.com/BhaskarMukhoty/SignedRateEncoding
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Time Is All It Takes: Spike-Retiming Attacks on Event-Driven Spiking Neural NetworksYi Yu, Qixin Zhang, Shuhan Ye, Xun Lin 等ICLR 2026 · 被引用 8 次
- Boosting the Robustness-Accuracy Trade-off of SNNs by Robust Temporal Self-EnsembleJihang Wang, Dongcheng Zhao, Ruolin Chen, Qian Zhang 等AAAI 2026 · 被引用 1 次
- Towards Reliable Evaluation of Adversarial Robustness for Spiking Neural NetworksJihang Wang, Dongcheng Zhao, Ruolin Chen, Qian Zhang 等CVPR 2026 · 被引用 1 次
- Breaking Gradient Temporal Collinearity for Robust Spiking Neural NetworksDesong Zhang, Jia Hu, Geyong MinICLR 2026
- On the Role of Temporal Granularity in the Robustness of Spiking Neural NetworksMengting Xu, Shi Gu, Peng Lin, De Ma 等CVPR 2026
它引用的顶会 Paper9
- Deep Residual Learning in Spiking Neural NetworksWei Fang, Zhaofei Yu, Yanqi Chen, Tiejun Huang 等NeurIPS 2021 · 被引用 857 次
- Temporal Efficient Training of Spiking Neural Network via Gradient Re-weightingShikuang Deng, Yuhang Li, Shanghang Zhang, Shi GuICLR 2022 · 被引用 361 次
- Robustness and Accuracy Could Be Reconcilable by (Proper) DefinitionTianyu Pang, Min Lin, Xiao Yang, Jun Zhu 等ICML 2022 · 被引用 168 次
- SNN-RAT: Robustness-enhanced Spiking Neural Network through Regularized Adversarial TrainingJianhao Ding, Tong Bu, Zhaofei Yu, Tiejun Huang 等NeurIPS 2022 · 被引用 70 次
- Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image ClassifiersFrancesco Croce, Matthias HeinICML 2021 · 被引用 68 次
相关 Paper
- Certified Adversarial Robustness for Rate Encoded Spiking Neural NetworksBhaskar Mukhoty, Hilal AlQuabeh, Giulia De Masi, Huan Xiong 等ICLR 2024 · 被引用 8 次
- Rate Gradient Approximation Attack Threats Deep Spiking Neural NetworksTong Bu, Jianhao Ding, Zecheng Hao, Zhaofei YuCVPR 2023
- HIRE-SNN: Harnessing the Inherent Robustness of Energy-Efficient Deep Spiking Neural Networks by Training with Crafted Input NoiseSouvik Kundu, Massoud Pedram, Peter A. BeerelICCV 2021 · 被引用 114 次
- Enhancing Adversarial Robustness in SNNs with Sparse GradientsYujia Liu, Tong Bu, Jianhao Ding, Zecheng Hao 等ICML 2024 · 被引用 17 次
- Toward Robust Spiking Neural Network Against Adversarial PerturbationLing Liang, Kaidi Xu, Xing Hu, Lei Deng 等NeurIPS 2022 · 被引用 28 次
