arXiv論文メモ
新着一覧
cs.CR · 査読状況未確認

スパイキングニューラルネットへの時間的トリガー攻撃

T-Backdoor: Exploiting Temporal Redundancy in Neuromorphic Data for Spike-preserving Backdoor Attacks on SNNs

Abdullah Arafat Miah, Kevin Vu, and Yu Bi

この論文をやさしく読む

ひとことで言うと

神経の発火時刻のような時間情報だけを改変し、スパイキングニューラルネットにバックドアを仕込む研究です。

何に役立つ?

神経形態データを扱うモデルの安全性評価で、空間的な異常だけを探す防御の見落としを調べる材料になります。

この研究の面白いところ

3つのデータセットで、時間的なトリガーだけでも単一・複数対象の両方でほぼ100%の攻撃成功率が報告されています。

どこまで分かった?

結果は列挙された3データセットと7防御手法での実験です。実環境のSNNで同じ成功率になるとは要旨からは分かりません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

バックドア攻撃は深層ニューラルネットワークにとって深刻な脅威だが、スパイキングニューラルネットワーク(SNN)では十分に調べられていない。既存の攻撃は主に時空間的なトリガーを入れ、汚染された標本のスパイク分布を正常な標本から変化させる。本研究は、この制約に対し、空間的な変化を一切加えず、発火率、発火時刻、時間の揺らぎといった時間だけのトリガーで動く、SNN向けの新しいバックドア攻撃T-Backdoorを提案する。これによりスパイク分布の変化は検出しにくくなる。N-MNIST、CIFAR10-DVS、N-Caltech101の3つの神経形態データセットで幅広い実験を行い、7種類の既存のバックドア防御法と比較した。単一の対象クラスと複数の対象クラスのどちらの設定でも、正常データでの精度の低下は小さいまま、攻撃成功率はほぼ100%に達し、既存の検出・緩和技術に対しても頑健だった。コードを公開している。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-24(UTC)
最新改訂
2026-09-24 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Backdoor attacks are a serious security threat to deep neural networks (DNNs) and remain largely underexplored for spiking neural networks (SNNs). Existing attacks primarily introduce spatiotemporal triggers that induce deviations in the spike distribution of poisoned samples relative to their clean counterparts. To address this limitation, this work proposes a novel backdoor attack on SNNs, termed \textbf{T-Backdoor}, which operates using purely temporal triggers such as \textit{Rate}, \textit{Latency}, and \textit{Jitter} without introducing any spatial perturbation, making the shift in spike distributions significantly harder to detect. Through extensive experiments on three benchmark neuromorphic datasets: N-MNIST, CIFAR10-DVS, and N-Caltech101, and evaluation against seven baseline backdoor defense methods, we demonstrate that T-Backdoor achieves a near-perfect 100\% attack success rate (ASR) in both single target and multi target settings with only minor degradation in clean accuracy, while remaining robust against existing backdoor detection and mitigation techniques. The codes are available at https://github.com/SiSL-URI/T-Backdoor .

著者のコメント

14 pages, 12 figures

arXiv ID: 2609.30119 / 要約の誤りについて