paper-with-me

홈 › Papers

Do Spikes Protect Privacy? Investigating Black-Box Model Inversion Attacks in Spiking Neural Networks

2025-02-08 · Hamed Poursiami, Ayana Moshruba, Maryam Parsa

As machine learning models become integral to security-sensitive applications, concerns over data leakage from adversarial attacks continue to rise. Model Inversion (MI) attacks pose a significant privacy threat by enabling adversaries to reconstruct training data from model outputs. While MI attacks on Artificial Neural Networks (ANNs) have been widely studied, Spiking Neural Networks (SNNs) remain largely unexplored in this context. Due to their event-driven and discrete computations, SNNs introduce fundamental differences in information processing that may offer inherent resistance to such attacks. A critical yet underexplored aspect of this threat lies in black-box settings, where attackers operate through queries without direct access to model parameters or gradients-representing a more realistic adversarial scenario in deployed systems. This work presents the first study of black-box MI attacks on SNNs. We adapt a generative adversarial MI framework to the spiking domain by incorporating rate-based encoding for input transformation and decoding mechanisms for output interpretation. Our results show that SNNs exhibit significantly greater resistance to MI attacks than ANNs, as demonstrated by degraded reconstructions, increased instability in attack convergence, and overall reduced attack effectiveness across multiple evaluation metrics. Further analysis suggests that the discrete and temporally distributed nature of SNN decision boundaries disrupts surrogate modeling, limiting the attacker's ability to approximate the target model.

📄 PDF Abstract BibTeX arXiv:2502.05509

Code (0)

등록된 구현이 없습니다.

Methods 이 논문이 사용한 방법론

SNN Spiking Neural Networks (SNNs) are a class of artificial neural networks inspired by the structure and functioning of the brain's neural networks. Unlike traditional…

Similar Papers 제목 키워드 기반

Understanding Deep Gradient Leakage via Inversion Influence Functions

2023-09-22 · NeurIPS 2023 11 · Haobo Zhang, Junyuan Hong, Yuyang Deng, Mehrdad Mahdavi 외

Deep Gradient Leakage (DGL) is a highly effective attack that recovers private training images from gradient vectors. This attack casts significant privacy challenges on distributed learning from clients with sensitive d…

UnlearnShield: Shielding Forgotten Privacy against Unlearning Inversion

2026-01-28 · Lulu Xue, Shengshan Hu, Wei Lu, Ziqi Zhou 외 arxiv

Machine unlearning is an emerging technique that aims to remove the influence of specific data from trained models, thereby enhancing privacy protection. However, recent research has uncovered critical privacy vulnerabil…

Reinforcement Learning-Based Black-Box Model Inversion Attacks

2023-04-10 · CVPR 2023 1 · Gyojin Han, Jaehyun Choi, Haeil Lee, Junmo Kim

Model inversion attacks are a type of privacy attack that reconstructs private data used to train a machine learning model, solely by accessing the model. Recently, white-box model inversion attacks leveraging Generative…

modelPrivacy Preservingreinforcement-learningReinforcement Learning

Denoising-Aware Inversion: Revealing Privacy Risks in Noise-Protected Text Embeddings

2026-08-19 · Yubo Wang, Shujie Cui, James Bailey, Hongzhi Yin 외 arxiv

Dense text embeddings are widely used in data mining, retrieval, and downstream machine learning systems due to their compact and semantically rich representations, but recent embedding inversion attacks have shown that …

Investigating Effective Speaker Property Privacy Protection in Federated Learning for Speech Emotion Recognition

2024-10-17 · Chao Tan, Sheng Li, Yang Cao, Zhao Ren 외

Federated Learning (FL) is a privacy-preserving approach that allows servers to aggregate distributed models transmitted from local clients rather than training on user data. More recently, FL has been applied to Speech …

Emotion RecognitionFederated LearningPrivacy PreservingSpeech Emotion Recognition