arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

事件突发触发器:基于事件的脉冲神经网络目标检测中的可用性后门攻击

Event Burst Trigger: An Availability Backdoor Attack on Event-Based SNN Object Detection

Jaesun Baek, Chanwook Lee, Eun-Kyu Lee

arXiv 2607.09115首次发表:更新:

AI 中文总结

研究基于事件脉冲神经网络目标检测模型对可用性后门攻击的脆弱性,提出事件突发触发器EBT,将其注入训练数据诱导推理时事件流,增加虚假目标候选数量致NMS计算成本上升,实验表明该攻击造成NMS延迟增加,揭示了新的可用性后门威胁。

AI 中文摘要

基于事件的视觉和脉冲神经网络(SNN)越来越多地用于严格延迟和能量限制下的边缘智能。然而,基于事件的SNN目标检测模型对可用性后门攻击的脆弱性研究不足。本文提出事件突发触发器(EBT),一种针对基于SNN的目标检测模型的可用性后门攻击。EBT将精心设计的基于事件的触发器注入训练数据,在推理时诱导时间集中的事件流。这些突发状激活增加了幻影(即虚假)目标候选的数量,从而增加了后处理阶段的计算成本,特别是非极大值抑制(NMS)。在仅中毒威胁模型下,对基于SNN的最先进目标检测器SpikeYOLO评估EBT,该模型不需要修改模型架构、损失函数或推理管道。实验结果表明,虽然检测准确率基本保持不变,mAP@0.5下降不到0.099,但NMS阶段的延迟增加了38%。这表明NMS可能成为基于事件的SNN目标检测中的主要可用性瓶颈。在边缘平台上的实验进一步表明,所提出的攻击提高了基线资源利用率,减少了调度松弛,而不会在资源使用中引起明显峰值。此外,基于STRIP的后门检测未能可靠地区分所提出的攻击和良性输入。这些结果表明了基于事件的SNN目标检测系统中以前未充分探索的可用性后门威胁。

英文摘要

Event-based vision and spiking neural networks (SNNs) are increasingly adopted for edge intelligence under strict latency and energy constraints. However, the vulnerability of event-based SNN object detection models to availability backdoor attacks remains insufficiently studied. This paper presents Event Burst Trigger (EBT), an availability backdoor attack targeting SNN-based object detection models. EBT injects carefully crafted event-based triggers into the training data, which induce temporally concentrated event streams during inference. These burst-like activations increase the number of phantom (i.e., spurious) object candidates, and consequently inflate the computational cost of the post-processing stage, particularly Non-Maximum Suppression (NMS). We evaluate EBT on SpikeYOLO, the state-of-the-art SNN-based object detector, under a poison-only threat model that does not require modifications to the model architecture, loss function, or inference pipeline. Experimental results show that while detection accuracy remains largely preserved, with mAP@0.5 decreasing by less than 0.099, the latency of the NMS stage increases by up to 38%. This indicates that NMS can become a dominant availability bottleneck in event-based SNN object detection. Experiments on an edge platform further show that the proposed attack elevates baseline resource utilization and reduces scheduling slack without inducing conspicuous peaks in resource usage. In addition, STRIP-based backdoor detection fails to reliably distinguish the proposed attack from benign inputs. These results characterize a previously underexplored availability backdoor threat in event-based SNN object detection systems.

CommentsThe 56th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2026)

DOI:10.1109/DSN-S70715.2026.00020

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑