提升脉冲神经网络(SNN)推理能耗:逐样本与通用海绵攻击
Driving up Inference Energy on SNNs: Per-Sample and Universal Sponge Attacks
浏览论文内容
中文总结 AI 辅助
该研究提出针对原生事件型SNN的逐样本与通用海绵攻击,可分别将推理SynOps提升1.5-2.6倍、1.09-1.24倍,推高能耗且难以检测,凸显SNN在边缘系统部署的安全风险。
中文摘要 AI 辅助
脉冲神经网络(SNN)通过稀疏二值脉冲事件而非密集激活值进行通信,可在神经形态硬件上实现高能效推理,因此被用于始终在线、电池供电的边缘系统。我们发现这种能效优势会带来独特的安全风险:海绵攻击可增加推理阶段的脉冲活动和突触工作量,在仅基于正确性的监测下仍难以检测,同时推高能耗。此前针对SNN的输入空间能效攻击主要聚焦于速率编码设置下的逐样本优化,我们将这种威胁扩展至原生基于事件的二值输入,并研究两种攻击模型。首先,我们开发了一种逐样本海绵攻击,通过基于梯度的优化为每个输入定制对抗性脉冲序列,该攻击在NMNIST、SHD和IBM DVS手势数据集上的三种SNN模型中,将每次推理的突触操作数(SynOps)提升1.5至2.6倍,同时至少98%的评估样本预测类别保持不变。其次,据我们所知,我们首次提出针对原生基于事件的SNN输入的通用海绵攻击:一种离线计算的固定二值扰动,通过异或操作应用于所有后续输入。尽管该攻击效果较弱,但在三个数据集上仍将SynOps提升1.09至1.24倍,且代表更现实的部署威胁,因为它无需针对每个输入进行优化。将SynOps增长映射至Loihi-1的估计能耗,可得到每次推理的开销为14微焦至13.24毫焦。这些结果表明,原生基于事件的SNN易受实际输入空间能效攻击,且可重复使用的通用扰动会在持续部署的边缘系统中累积成显著的电池损耗。
英文摘要
Spiking Neural Networks (SNNs) communicate through sparse binary spike events rather than dense activations, enabling energy-efficient inference on neuromorphic hardware and motivating their use in always-on, battery-powered edge systems. We show that this same efficiency advantage creates a distinct security risk: sponge attacks can increase inference-time spike activity and synaptic workload, inflating energy consumption while remaining difficult to detect through correctness-based monitoring alone. Prior input-space efficiency attacks on SNNs have focused on per-sample optimization, primarily in rate-coded settings. We extend this threat to native event-based binary inputs and study two attack models. First, we develop a per-sample sponge attack that crafts a custom adversarial spike train for each input via gradient-based optimization. This attack increases per-inference SynOps by 1.5-2.6x on three SNN models for the NMNIST, SHD, and IBM DVS Gesture datasets, while preserving the predicted class on at least 98% of evaluated samples. Second, to the best of our knowledge, we introduce the first universal sponge attack for native event-based SNN inputs: a fixed binary perturbation computed offline and applied via XOR to all subsequent inputs. Although weaker, it still inflates SynOps by 1.09-1.24x across all three datasets and represents a more realistic deployment threat because it requires no per-input optimization. Mapping SynOp inflation to estimated Loihi-1 energy yields per-inference overheads from 14 $μ$J to 13.24 mJ. These results show that native event-based SNNs are vulnerable to practical input-space efficiency attacks, and that reusable universal perturbations can accumulate into meaningful battery drain in continuously deployed edge systems.
发表机构
- Sorbonne Université(索邦大学)
- CNRS(法国国家科学研究中心)
机构由 AI 辅助整理,请以论文原文为准。