Search papers, labs, and topics across Lattice.
This paper investigates clean-label temporal poisoning attacks on Spiking Neural Networks (SNNs), where a fixed timestamp transformation is applied to target-class training streams without altering their labels. The method achieves a 100% attack success rate across various neuromorphic datasets and model architectures, highlighting the effectiveness of the attack while exposing the limitations of existing defenses. The findings underscore the stealthy nature of clean-label backdoor attacks in SNNs and the challenges in detecting such manipulations.
Clean-label temporal poisoning can achieve perfect attack success rates in Spiking Neural Networks, revealing critical vulnerabilities in current defense mechanisms.
Backdoor attacks on Spiking Neural Networks (SNNs) have primarily assumed dirty-label poisoning, in which triggered training samples are relabeled to an attacker-selected class. We study clean-label temporal poisoning, where a fixed timestamp transformation is applied only to the target-class training streams, leaving their labels unchanged. The transformation preserves the per-pixel, per-polarity event count exactly, making clean and triggered samples identical after temporal aggregation while altering the sequence processed by the SNN. Across three neuromorphic datasets and both convolutional and transformer-based victims, the attack reaches an ASR of 1.00 in the strongest configurations. We analyze the attack through poison-budget and trigger-shape ablations and evaluate established backdoor defenses adapted to spiking models. Defenses that collapse the time axis before inspection are blind by construction, while feature-space methods detect the poison only in selected settings. Our model-free detector, based on per-step event mass, detects the evaluated temporal transformations, demonstrating both the limitation of rate-collapsed defenses and the boundary of the attack's stealth. To our knowledge, this is the first clean-label backdoor attack evaluated on SNNs and neuromorphic event data.