Surrogate Gradients Misallocate Adversarial Sensitivity in Spiking Neural Networks
Abstract
Spiking neural networks (SNNs) offer a promising basis for low-power intelligence through binary events. This discrete dynamic makes backpropagation-based training reliant on surrogate gradients. However, conventional surrogate functions with fixed profiles fail to adopt to decision-relevant neuronal dynamics under adversarial perturbations, limiting the effectiveness of robust learning in SNNs. Through systematic comparative experiments, we reveal how this lack of adaptation manifests as adversarial sensitivity misallocation, directing backward sensitivity away from membrane states involved in perturbation-induced spike flips. We therefore propose Flip-Aware Reallocation (FARE), which derives dynamic response ranges from decision-weighted spike flips. By making surrogate gradients aware of perturbation-induced flips, FARE reallocates backward sensitivity to bring the learning signal into closer alignment with the network's decision-relevant adversarial response. Across static, sequential, event-based, and large-scale tasks, FARE outperforms existing state-of-the-art methods in both adversarial robustness and clean accuracy.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.