Rate Gradient Approximation Attack Threats Deep Spiking Neural Networks

被引:13
作者
Bu, Tong [1 ]
Ding, Jianhao [1 ]
Hao, Zecheng [1 ]
Yu, Zhaofei [1 ]
机构
[1] Peking Univ, Beijing, Peoples R China
来源
2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR | 2023年
基金
中国国家自然科学基金;
关键词
D O I
10.1109/CVPR52729.2023.00763
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Spiking Neural Networks (SNNs) have attracted significant attention due to their energy-efficient properties and potential application on neuromorphic hardware. State-of-the-art SNNs are typically composed of simple Leaky Integrate-and-Fire (LIF) neurons and have become comparable to ANNs in image classification tasks on large-scale datasets. However, the robustness of these deep SNNs has not yet been fully uncovered. In this paper, we first experimentally observe that layers in these SNNs mostly communicate by rate coding. Based on this rate coding property, we develop a novel rate coding SNN-specified attack method, Rate Gradient Approximation Attack (RGA). We generalize the RGA attack to SNNs composed of LIF neurons with different leaky parameters and input encoding by designing surrogate gradients. In addition, we develop the time-extended enhancement to generate more effective adversarial examples. The experiment results indicate that our proposed RGA attack is more effective than the previous attack and is less sensitive to neuron hyperparameters. We also conclude from the experiment that rate-coded SNN composed of LIF neurons is not secure, which calls for exploring training methods for SNNs composed of complex neurons and other neuronal codings. Code is available at https://github.com/putshua/SNN attack RGA
引用
收藏
页码:7896 / 7906
页数:11
相关论文
共 81 条
[1]  
[Anonymous], 2019, Nature
[2]  
[Anonymous], 2005, PROC 22 INT C MACH L
[3]  
[Anonymous], 2020, PACE 1218, DOI DOI 10.1111/PACE.14136
[4]  
[Anonymous], 2015, arXiv preprint arXiv:1510.08829
[5]  
Bengio Yoshua, 2013, Statistical Language and Speech Processing. First International Conference, SLSP 2013. Proceedings: LNCS 7978, P1, DOI 10.1007/978-3-642-39593-2_1
[6]  
Brette Romain, 2007, J COMPUTATIONAL NEUR
[7]  
Bu Tong, 2022, INT C LEARN REPR
[8]  
Bu Tong, 2022, P AAAI C ART INT
[9]  
Cao Yongqiang, 2015, INT J COMPUTER VISIO
[10]   Optimal carbon tax design for achieving low carbon supply chains [J].
Chen, Xu ;
Yang, Huan ;
Wang, Xiaojun ;
Choi, Tsan-Ming .
ANNALS OF OPERATIONS RESEARCH, 2020, 349 (2) :821-848