arXiv論文メモ
新着一覧
cs.NE · 査読状況未確認

入力のランダムさを調整してスパイク型AIを攻撃に強くする

Controllable Stochastic Quantization Encoding for Adversarially Robust Spiking Neural Networks

Yujia Liu, Peiyu Liu, Yajing Zheng, Tiejun Huang

この論文をやさしく読む

ひとことで言うと

画像をスパイク型ニューラルネットワークへ渡す際のランダムさを調整し、微小な改変による誤分類を減らす方法です。

何に役立つ?

学習方法を変える防御と組み合わせられる、入力段階の防御として役立つ可能性があります。評価にはCIFAR-10とCIFAR-100を使っています。

この研究の面白いところ

直接符号化とポアソン符号化を別々の方式として扱うのではなく、同じ枠組みの異なる設定として位置付けています。

どこまで分かった?

要旨は2つの画像データセットで有効性を述べていますが、攻撃の種類、頑健性の改善幅、消費電力の実測値は示していません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

スパイキングニューラルネットワーク(SNN)は、豊かな時間的ダイナミクス、エネルギー効率、脳に着想を得た仕組みにより、注目を集めている。画像分類で有望な性能を示しているものの、入力画像に人には見分けにくい摂動を加え、モデルの予測を誤らせる敵対的攻撃には依然として脆弱であることが、近年の研究で示されている。既存の防御手法は主に学習戦略に着目しており、入力符号化の役割は十分に検討されていない。 ポアソン符号化が直接符号化よりも頑健であるのは、それに内在するランダムさの恩恵かもしれないという観察に基づき、確率的量子化符号化法を提案する。量子化スケールで調整できるランダムさを使って入力画像を符号化し、SNNの敵対的頑健性を高める。さらに、この方法が一般的な枠組みであり、量子化スケールの選び方によってポアソン符号化と直接符号化のどちらにも帰着することを示す。入力符号化の段階で頑健性を高めるため、既存の学習に基づく防御と組み合わせ、さらに改善することもできる。 CIFAR-10とCIFAR-100の実験結果は、提案した確率的量子化符号化法の有効性を示している。本研究は、SNNの敵対的頑健性における入力符号化の重要性を示し、それを理解し改善する新しい視点を提供する。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-10-01(UTC)
最新改訂
2026-10-01 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Spiking Neural Networks (SNNs) have attracted increasing attention due to their impressive temporal dynamics, energy efficiency, and brain-inspired mechanisms. Although SNNs have demonstrated promising performance in image classification tasks, recent studies have shown that they remain vulnerable to adversarial attacks, where imperceptible perturbations are added to input images to mislead model predictions. Existing defense methods mainly focus on training strategies, while the role of input encoding remains less explored. An observation is that the robustness advantage of Poisson encoding over direct encoding may benefit from its inherent randomness. Motivated by this, we propose a stochastic quantization encoding method that encodes the input image with controllable randomness adjusted by the quantization scale, thereby improving the adversarial robustness of SNNs. We further show that this method constitutes a general framework that reduces to both Poisson encoding and direct encoding under different choices of the quantization scale. Since it enhances robustness at the input encoding stage, it can be combined with existing training-based defenses for further gains. Experimental results on CIFAR-10 and CIFAR-100 demonstrate the effectiveness of the proposed stochastic quantization encoding method. To sum up, this work highlights the importance of input encoding for the adversarial robustness of SNNs, providing a new perspective for understanding and improving it.

arXiv ID: 2610.01558 / 要約の誤りについて