Unsupervised Backdoor Detection and Mitigation for Spiking Neural Networks

Spiking Neural Networks (SNNs) have attracted significant attention from the research community due to their high energy efficiency compared to Artificial Neural Networks (ANNs). However, rare studies on the security of SNNs were conducted, especially in backdoor attacks. Existing defense methods for ANN backdoor attacks either perform poorly or can be easily bypassed in SNN scenarios due to SNNs’ event-driven and temporal dependency characteristics, posing significant research challenges. In this paper, we identify the blockers to existing backdoor defenses for defending against attacks in SNNs and propose an unsupervised post-training backdoor detection method named Temporal Membrane Potential Backdoor Detection (TMPBD) to address those blockers in SNNs with neuromorphic data. Specifically, TMPBD employs the maximum margin statistic of temporal membrane potential in the last spiking layer of the SNNs to detect attack target labels without knowledge of the attack or access to any data. Moreover, we also design a practical and robust mitigation mechanism named Neural Dendrites Suppression Backdoor Mitigation (NDSBM). NDSBM dually clamps the neural dendrites, i.e., the weights connecting the first two convolution layers in each convolution block to limit the backdoor effect, while preserving the benign model behaviors learned from the temporal membrane potential obtained from a small, clean, unlabeled dataset in the same domain. To evaluate the performance, we conduct a comprehensive evaluation with multiple backdoor attack techniques, including the SOTA input-aware dynamic trigger attack dedicated to SNNs with clean models on three neuromorphic benchmark datasets. The results demonstrated that TMPBD achieves 100% prediction accuracy in detecting dynamic trigger attacks and associating attack target labels in all benchmark datasets. NDSBM lowered the attack success rate (ASR) from 100% caused by the dynamic trigger attack down to 8.44% with only mitigation or 2.81% when combined with detection for an end-to-end pipeline without performance degradation in clean accuracy.

Paper

References (53)

Scroll for more · 38 remaining

Similar papers

© 2026 NYSGPT2525 LLC