acceptodds
Under review as a conference paper at ICLR 2027

Dormant in ANNs, Activated in SNNs: Stealthy Backdoor Attacks via ANN-to-SNN Conversion

Abstract

Spiking neural networks (SNNs) provide energy-efficient inference through sparse, event-driven computation on neuromorphic hardware. ANN-to-SNN conversion is therefore a widely used route to deploy pretrained artificial neural networks (ANNs) as SNNs without the difficulty of direct SNN training. Existing conversion studies primarily optimize accuracy, latency, and energy, leaving the security of the conversion process itself largely unexplored. We show that this overlooked boundary can activate a backdoor: a released ANN may remain benign on clean and trigger-bearing inputs, while the SNN obtained from the same ANN produces an attacker-specified target prediction. We term this threat A2S-Attack and formulate it as a bilevel optimization problem: the upper level optimizes the released ANN, while the lower level simulates ANN-to-SNN conversion with surrogate calibration data. The resulting objective preserves clean ANN/SNN utility, suppresses the target response in the ANN, and activates it in the SNN under the same trigger. We then evaluate the threat under matched and unknown downstream conversion configurations, private calibration resampling, and ANN-side backdoor screening using a representative training-free conversion pipeline. Across four image datasets, four architectures, and four conversion configurations, matched attack and deployment settings yield ANN targeted attack success rates of at most but SNN attack success rates of –. A single frozen ANN also achieves – SNN attack success across the evaluated downstream configurations, demonstrating that security evaluation must include the converted SNN rather than the released ANN alone.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.