Input-Specific and Universal Adversarial Attack Generation for Spiking Neural Networks in the Spiking Domain

Raptis, Spyridon, Stratigopoulos, Haralampos-G.

arXiv.org Artificial Intelligence 

Stratigopoulos Sorbonne Universit e, CNRS, LIP6, Paris, France Abstract --As Spiking Neural Networks (SNNs) gain traction across various applications, understanding their security vulnerabilities becomes increasingly important. In this work, we focus on the adversarial attacks, which is perhaps the most concerning threat. An adversarial attack aims at finding a subtle input perturbation to fool the network's decision-making. We propose two novel adversarial attack algorithms for SNNs: an input-specific attack that crafts adversarial samples from specific dataset inputs and a universal attack that generates a reusable patch capable of inducing misclassification across most inputs, thus offering practical feasibility for real-time deployment. The algorithms are gradient-based operating in the spiking domain proving to be effective across different evaluation metrics, such as adversarial accuracy, stealthiness, and generation time. Experimental results on two widely used neuromorphic vision datasets, NMNIST and IBM DVS Gesture, show that our proposed attacks surpass in all metrics all existing state-of-the-art methods. Additionally, we present the first demonstration of adversarial attack generation in the sound domain using the SHD dataset. I NTRODUCTION Neuromorphic computing has emerged as a revolutionary paradigm, inspired by the structure and functionality of the human brain, to address the growing demand for low-power and low-latency inference in Artificial Intelligence (AI).

Duplicate Docs Excel Report

Title
None found

Similar Docs  Excel Report  more

TitleSimilaritySource
None found