AI 中文总结
本文提出一种可控随机量化编码方法,通过调整量化尺度增强脉冲神经网络的对抗鲁棒性,并可与现有训练防御结合,在CIFAR数据集上验证了有效性。
AI 中文摘要
脉冲神经网络(SNNs)因其出色的时间动态、能效和脑启发机制而受到越来越多的关注。尽管SNNs在图像分类任务中已展现出有前景的性能,但近期研究表明它们仍易受对抗攻击,即在输入图像中添加难以察觉的扰动以误导模型预测。现有防御方法主要侧重于训练策略,而输入编码的作用仍未得到充分探索。一个观察结果是,泊松编码相对于直接编码的鲁棒性优势可能得益于其固有的随机性。受此启发,我们提出了一种随机量化编码方法,通过量化尺度调整可控的随机性来编码输入图像,从而提升SNNs的对抗鲁棒性。我们进一步表明,该方法构成一个通用框架,在不同的量化尺度选择下可退化为泊松编码和直接编码。由于它在输入编码阶段增强鲁棒性,因此可与现有的基于训练的防御方法结合以获得进一步提升。在CIFAR-10和CIFAR-100上的实验结果表明了所提出的随机量化编码方法的有效性。总之,这项工作强调了输入编码对SNNs对抗鲁棒性的重要性,为理解和改进SNNs对抗鲁棒性提供了新视角。
英文摘要
Spiking Neural Networks (SNNs) have attracted increasing attention due to their impressive temporal dynamics, energy efficiency, and brain-inspired mechanisms. Although SNNs have demonstrated promising performance in image classification tasks, recent studies have shown that they remain vulnerable to adversarial attacks, where imperceptible perturbations are added to input images to mislead model predictions. Existing defense methods mainly focus on training strategies, while the role of input encoding remains less explored. An observation is that the robustness advantage of Poisson encoding over direct encoding may benefit from its inherent randomness. Motivated by this, we propose a stochastic quantization encoding method that encodes the input image with controllable randomness adjusted by the quantization scale, thereby improving the adversarial robustness of SNNs. We further show that this method constitutes a general framework that reduces to both Poisson encoding and direct encoding under different choices of the quantization scale. Since it enhances robustness at the input encoding stage, it can be combined with existing training-based defenses for further gains. Experimental results on CIFAR-10 and CIFAR-100 demonstrate the effectiveness of the proposed stochastic quantization encoding method. To sum up, this work highlights the importance of input encoding for the adversarial robustness of SNNs, providing a new perspective for understanding and improving it.