Spikes Leak: Analytical Gradient Inversion in Spiking Neural Networks
Abstract
Spiking neural networks (SNNs) are promising candidates for federated edge learning, as their event-driven computation makes them well suited to energy-constrained devices. However, their exposure to gradient inversion attacks is less understood than in conventional artificial neural networks (ANNs). Recent studies, largely based on adapting ANN-oriented attacks to the spiking domain, have suggested that SNN-specific mechanisms may offer inherent privacy advantages. We challenge this claim by examining the algebraic structure of SNN gradients. In fully connected spiking layers, gradients factorize by construction into a temporal gradient matrix and a binary presynaptic spike matrix. This binary factor turns reconstruction into a finite constrained combinatorial problem, creating an exploitable leakage channel. Based on this observation, we propose Spike-Leak, a two-stage attack. It first recovers binary candidate spike patterns from gradient row-space constraints, then reconstructs private input sequences by assigning candidates to examples and timesteps using the known SNN dynamics and downstream consistency. Across four event-based vision datasets, Spike-Leak achieves exact reconstruction across diverse configurations spanning multiple temporal horizons and batch sizes, including a setting with \(B=32\). These results show that SNNs expose a structured gradient-leakage channel, and that binary spike processing, surrogate-gradient training, and temporal aggregation do not, by themselves, prevent exact gradient-based reconstruction.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.