🤖 AI Summary
Spiking Neural Networks (SNNs) are vulnerable to adversarial attacks, yet existing defense methods largely overlook the critical role of input encoding. This work unifies Poisson and direct encoding within a generalized framework to reveal how encoding mechanisms influence adversarial robustness, and proposes a Controllable Stochastic Quantization (CSQ) encoding method. By modulating the quantization scale to introduce controllable noise, CSQ achieves efficient adversarial defense at the encoding layer while remaining compatible with existing training strategies. Experimental results on CIFAR datasets demonstrate that the proposed approach significantly enhances the adversarial robustness of SNNs, validating the effectiveness of encoding-layer defenses.
📝 Abstract
Spiking Neural Networks (SNNs) have attracted increasing attention due to their impressive temporal dynamics, energy efficiency, and brain-inspired mechanisms. Although SNNs have demonstrated promising performance in image classification tasks, recent studies have shown that they remain vulnerable to adversarial attacks, where imperceptible perturbations are added to input images to mislead model predictions. Existing defense methods mainly focus on training strategies, while the role of input encoding remains less explored. An observation is that the robustness advantage of Poisson encoding over direct encoding may benefit from its inherent randomness. Motivated by this, we propose a stochastic quantization encoding method that encodes the input image with controllable randomness adjusted by the quantization scale, thereby improving the adversarial robustness of SNNs. We further show that this method constitutes a general framework that reduces to both Poisson encoding and direct encoding under different choices of the quantization scale. Since it enhances robustness at the input encoding stage, it can be combined with existing training-based defenses for further gains. Experimental results on CIFAR-10 and CIFAR-100 demonstrate the effectiveness of the proposed stochastic quantization encoding method. To sum up, this work highlights the importance of input encoding for the adversarial robustness of SNNs, providing a new perspective for understanding and improving it.