Towards Effective and Sparse Adversarial Attack on Spiking Neural Networks via Breaking Invisible Surrogate Gradients
Li Lun, Kunyu Feng, Qinglong Ni, Ling Liang, Yuan Wang, Ying Li, Dunshan Yu, Xiaoxin Cui
摘要
Spiking neural networks (SNNs) have shown their competence in handling spatial-temporal event-based data with low energy consumption. Similar to conventional artificial neural networks (ANNs), SNNs are also vulnerable to gradient-based adversarial attacks, wherein gradients are calculated by spatial-temporal back-propagation (STBP) and surrogate gradients (SGs). However, the SGs may be invisible for an inference-only model as they do not influence the inference results, and current gradient-based attacks are ineffective for binary dynamic images captured by the dynamic vision sensor (DVS). While some approaches addressed the issue of invisible SGs through universal SGs, their SGs lack a correlation with the victim model, resulting in sub-optimal performance. Moreover, the imperceptibility of existing SNN-based binary attacks is still insufficient. In this paper, we introduce an innovative potentialdependent surrogate gradient (PDSG) method to establish a robust connection between the SG and the model, thereby enhancing the adaptability of adversarial attacks across various models with invisible SGs. Additionally, we propose the sparse dynamic attack (SDA) to effectively attack binary dynamic images. Utilizing a generation-reduction paradigm, SDA can fully optimize the sparsity of adversarial perturbations. Experimental results demonstrate that our PDSG and SDA outperform state-of-the-art SNN-based attacks across various models and datasets. Specifically, our PDSG achieves 100% attack success rate on ImageNet, and our SDA obtains 82% attack success rate by modifying only 0.24% of the pixels on CIFAR10DVS. The code is available at https://github.com/ryime/PDSG-SDA . * Corresponding Authors. weight.pth forward backward victim SNN binary dynamic image floating-point gradients 0.4 -1.2 0.2 0 0.1 0.5 0 0.9 -1.2 attacker neuron Invisible surrogate gradients Incompatible gradients attack visible invisible Figure 1. Illustration of the challenges of attacking SNNs. The invisible SGs hinder the attacker to perform gradient-based attacks. The incompatible gradients describe that the floating-point gradients are difficult to be converted to binary perturbations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Time Is All It Takes: Spike-Retiming Attacks on Event-Driven Spiking Neural NetworksYi Yu, Qixin Zhang, Shuhan Ye, Xun Lin 等ICLR 2026 · 被引用 8 次
- Boosting the Robustness-Accuracy Trade-off of SNNs by Robust Temporal Self-EnsembleJihang Wang, Dongcheng Zhao, Ruolin Chen, Qian Zhang 等AAAI 2026 · 被引用 1 次
- Towards Reliable Evaluation of Adversarial Robustness for Spiking Neural NetworksJihang Wang, Dongcheng Zhao, Ruolin Chen, Qian Zhang 等CVPR 2026 · 被引用 1 次
它引用的顶会 Paper35
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
- Deep Residual Learning in Spiking Neural NetworksWei Fang, Zhaofei Yu, Yanqi Chen, Tiejun Huang 等NeurIPS 2021 · 被引用 857 次
- Incorporating Learnable Membrane Time Constant to Enhance Learning of Spiking Neural NetworksWei Fang, Zhaofei Yu, Yanqi Chen, Timothée Masquelier 等ICCV 2021 · 被引用 731 次
相关 Paper
- MPD-SGR: Robust Spiking Neural Networks with Membrane Potential Distribution-Driven Surrogate Gradient RegularizationRunhao Jiang, Chengzhi Jiang, Rui Yan, Huajin TangAAAI 2026 · 被引用 2 次
- Rate Gradient Approximation Attack Threats Deep Spiking Neural NetworksTong Bu, Jianhao Ding, Zecheng Hao, Zhaofei YuCVPR 2023
- Differentiable hierarchical and surrogate gradient search for spiking neural networksKaiwei Che, Luziwei Leng, Kaixuan Zhang, Jianguo Zhang 等NeurIPS 2022 · 被引用 55 次
- CLIF: Complementary Leaky Integrate-and-Fire Neuron for Spiking Neural NetworksYulong Huang, Xiaopeng Lin, Hongwei Ren, Haotian Fu 等ICML 2024 · 被引用 43 次
- Differentiable Spike: Rethinking Gradient-Descent for Training Spiking Neural NetworksYuhang Li, Yufei Guo, Shanghang Zhang, Shikuang Deng 等NeurIPS 2021 · 被引用 288 次
