发表机构
Radboud University; Ikerlan Research Centre; University of Bergen; University of Zagreb; Faculty of Electrical Engineering and Computing(拉德堡德大学; 伊克尔兰研究中心; 卑尔根大学; 萨格勒布大学; 电气工程与计算机学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出针对SNN的首个干净标签后门攻击,通过对目标类训练流应用固定时间戳变换实现投毒,在三类数据集上攻击成功率达1.00,还评估了现有防御的局限性。
AI 中文摘要
针对脉冲神经网络(SNN)的后门攻击主要依赖脏标签投毒,即把触发的训练样本重新标记为攻击者选定的类别。本研究探讨干净标签时序投毒,仅对目标类别的训练流应用固定时间戳变换,同时保留其标签不变。该变换精确保留了逐像素、逐极性的事件数量,使得干净样本与触发样本在时间聚合后完全一致,却改变了SNN处理的序列。在三个神经形态数据集及卷积、Transformer架构的受害者模型上,该攻击在最强配置下达到1.00的攻击成功率(ASR)。我们通过投毒预算和触发形状消融实验分析该攻击,并评估适配脉冲模型的现有后门防御机制:在检查前折叠时间轴的防御天生具有盲性,而特征空间方法仅在特定场景下能检测到投毒。我们基于逐步事件质量的无模型检测器可检测所评估的时序变换,既证明了速率折叠防御的局限性,也明确了该攻击的隐身边界。据我们所知,这是首个针对SNN和神经形态事件数据评估的干净标签后门攻击。
英文摘要
Backdoor attacks on Spiking Neural Networks (SNNs) have primarily assumed dirty-label poisoning, in which triggered training samples are relabeled to an attacker-selected class. We study clean-label temporal poisoning, where a fixed timestamp transformation is applied only to the target-class training streams, leaving their labels unchanged. The transformation preserves the per-pixel, per-polarity event count exactly, making clean and triggered samples identical after temporal aggregation while altering the sequence processed by the SNN. Across three neuromorphic datasets and both convolutional and transformer-based victims, the attack reaches an ASR of 1.00 in the strongest configurations. We analyze the attack through poison-budget and trigger-shape ablations and evaluate established backdoor defenses adapted to spiking models. Defenses that collapse the time axis before inspection are blind by construction, while feature-space methods detect the poison only in selected settings. Our model-free detector, based on per-step event mass, detects the evaluated temporal transformations, demonstrating both the limitation of rate-collapsed defenses and the boundary of the attack's stealth. To our knowledge, this is the first clean-label backdoor attack evaluated on SNNs and neuromorphic event data.