Cryptanalytic Extraction of Direct-Coded LIF Spiking Neural Networks
Abstract
Spiking neural networks (SNNs) are increasingly deployed on edge and neuromorphic platforms, making their parameters and temporal dynamics valuable intellectual property. Cryptanalytic model extraction has focused mainly on conventional neural networks, leaving structural leakage from discrete firing, membrane recurrence, and reset dynamics in LIF-SNNs underexplored. We study cryptanalytic extraction of direct-coded LIF-SNNs through a black-box interface exposing only final logits. We show that LIF dynamics create structured input-space boundaries corresponding to spike-count transitions; crossing an isolated boundary associated with a hidden neuron produces an observable logit jump whose direction is determined by that neuron’s output-weight vector, thereby exposing internal parameter information. Exploiting this observation, our attack performs transition attribution, boundary recovery, and dynamical parameter inversion to recover normalized hidden-layer parameters, the shared leak parameter, and output-layer parameters. The resulting canonical parameterization is equivalent to that of the target model and defines a functionally equivalent model. We further establish sufficient conditions for identifying the canonical parameters. Experiments show complete hidden-neuron recovery, over 99% spike-count fidelity, and near-perfect prediction agreement on natural inputs. This work presents the first systematic study of cryptanalytic extraction for direct-coded LIF-SNNs and demonstrates the need for defenses tailored to SNN model extraction.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.