返回
Rethinking adversarial attacks on neuromorphic models
DOI:10.1088/2634-4386/ae379c.png)
摘要
En 中文
Spiking neural networks (SNN) are biologically inspired artificial neural networks that emulate the behaviour of biological neurons in spiking-based computational units. However, machine learning models are known to be vulnerable to adversarial noise, and particularly to universal adversarial perturbations (UAP) and adversarial patch (AP) attacks. Despite the claimed inherent robustness of SNNs to adversarial noise, attacks with UAP and AP remain under-explored in the spiking domain. This paper revisits the adversarial noise generation method from its first principles. Specifically, we consider a realistic spiking-aware setting that takes into account constraints from the neuromorphic domain, such as event sparsity and spike-timing integrity. We introduce our approach for creating Spiking-compatible adversarial attacks and a spiking UAP and AP destined for event-based computer vision systems. We propose a novel, efficient spike-based adversarial noise generation approach that respects neuromorphic constraints and show that SNNs can be the victims of more tangible and realistic types of attack.
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
6.1
论文数:
340
被引数:
920
机构
引用论文
Converting Static Image Datasets to Spiking Neuromorphic Datasets Using Saccades使用扫视将静态图像数据集转换为尖峰神经形态数据集
Networks of spiking neurons: The third generation of neural network models尖峰神经元网络: 第三代神经网络模型
NEURAL NETWORKS
IF6.3
A million spiking-neuron integrated circuit with a scalable communication network and interface具有可扩展通信网络和接口的百万尖峰神经元集成电路
Science
IF0

