Improved Certified Robustness and Adversarial Attacks for Rate-Encoded Spiking Neural Networks
Abstract
Spiking Neural Networks (SNNs) are well known for their energy-efficient neuromorphic implementations and robustness to adversarial examples, especially with rate encoding, which encodes inputs as the rate of binary spikes from a Bernoulli distribution. Recently, rate encoded SNNs under Bernoulli smoothing were shown to be provably robust against any adversarial examples that lie within radius, , from the test input having top two class probabilities and , respectively. However, this radius decreases exponentially with the SNN latency , notwithstanding experimental evidence. We provide an improved adversarial robustness guarantee for the rate-encoded SNNs under the same setting, showing that the certified radius of the smooth classifier decays only linearly with latency, i.e., , offering a larger certified radius of robustness that reduces the gap between empirical and certified robustness. We extend the proof to the recently proposed signed rate encoding, which offers higher standard accuracy than rate encoding. Experimentally, we improve the existing -norm-bounded sparse encoding attack (SEA) and propose SEA-PGD, which consistently outperforms SEA across three standard datasets and encoding techniques.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.