arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

时序投毒:通过SNN中事件重分配的干净标签后门

Temporal Poisoning: Clean-Label Backdoors via Event Redistribution in SNNs

Roberto Riaño, Gorka Abad, Stjepan Picek, Aitor Urbieta

arXiv 2607.28075首次发表:更新:

发表机构

Radboud University; Ikerlan Research Centre; University of Bergen; University of Zagreb; Faculty of Electrical Engineering and Computing(拉德堡德大学; 伊克尔兰研究中心; 卑尔根大学; 萨格勒布大学; 电气工程与计算机学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究提出针对SNN的首个干净标签后门攻击,通过对目标类训练流应用固定时间戳变换实现投毒,在三类数据集上攻击成功率达1.00,还评估了现有防御的局限性。

AI 中文摘要

针对脉冲神经网络(SNN)的后门攻击主要依赖脏标签投毒,即把触发的训练样本重新标记为攻击者选定的类别。本研究探讨干净标签时序投毒,仅对目标类别的训练流应用固定时间戳变换,同时保留其标签不变。该变换精确保留了逐像素、逐极性的事件数量,使得干净样本与触发样本在时间聚合后完全一致,却改变了SNN处理的序列。在三个神经形态数据集及卷积、Transformer架构的受害者模型上,该攻击在最强配置下达到1.00的攻击成功率(ASR)。我们通过投毒预算和触发形状消融实验分析该攻击,并评估适配脉冲模型的现有后门防御机制:在检查前折叠时间轴的防御天生具有盲性,而特征空间方法仅在特定场景下能检测到投毒。我们基于逐步事件质量的无模型检测器可检测所评估的时序变换,既证明了速率折叠防御的局限性,也明确了该攻击的隐身边界。据我们所知,这是首个针对SNN和神经形态事件数据评估的干净标签后门攻击。

英文摘要

Backdoor attacks on Spiking Neural Networks (SNNs) have primarily assumed dirty-label poisoning, in which triggered training samples are relabeled to an attacker-selected class. We study clean-label temporal poisoning, where a fixed timestamp transformation is applied only to the target-class training streams, leaving their labels unchanged. The transformation preserves the per-pixel, per-polarity event count exactly, making clean and triggered samples identical after temporal aggregation while altering the sequence processed by the SNN. Across three neuromorphic datasets and both convolutional and transformer-based victims, the attack reaches an ASR of 1.00 in the strongest configurations. We analyze the attack through poison-budget and trigger-shape ablations and evaluate established backdoor defenses adapted to spiking models. Defenses that collapse the time axis before inspection are blind by construction, while feature-space methods detect the poison only in selected settings. Our model-free detector, based on per-step event mass, detects the evaluated temporal transformations, demonstrating both the limitation of rate-collapsed defenses and the boundary of the attack's stealth. To our knowledge, this is the first clean-label backdoor attack evaluated on SNNs and neuromorphic event data.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑