Skip to content

Robust Semantic Communication Enabled by Spiking Neural Networks

2026 · IEEE Transactions on Signal Processing · Vol 74, pp. 3470-3486 · 0 citations · 50 references
Computer Science

Abstract

The robustness of deep learning-based semantic communication systems remains a major challenge due to the vulnerability of artificial neural networks (ANNs) to adversarial attacks and the lack of clear robustness mechanisms in such models. Existing approaches often rely on data augmentation, which is training-intensive and requires prior knowledge of the perturbation distribution. In this paper, we instead leverage the structural properties of spiking neural networks (SNNs), a class of energy-efficient, brain-inspired models that compute using binary spikes. We exploit their inherent resilience enabled by the discrete and thresholded nature of spikes and analyze robustness from a structural perspective. For both random and adversarial perturbations, we identify two key factors: 1) membrane potentials should be kept away from the firing threshold to reduce spike flipping; and 2) synaptic weights should be regularized to prevent the amplification of perturbations across layers. Based on these observations, we propose robustness-aware potential (RAP), a simple regularizer designed to exploit the inherent robustness of SNNs. We evaluate our method on both digital and event-based datasets. Experimental results show that SNNs trained with RAP significantly improve robustness and exhibit better resilience to distributional shifts. Moreover, SNNs demonstrate a clear robustness advantage over ANNs, particularly under adversarial attacks.

View source

Similar papers

Sep 2026

Toward Improving Stochastic Neural Network Robustness via Arbitrary Distribution Injection.

Adversarial attacks pose significant challenges to the security and robustness of deep-learning models. Stochastic neural networks (SNNs) have shown promising effectiveness in improving robustness by injecting stochastic noise into model activations, features, or weights. However, most existing SNN-based defenses rely on predefined distributional forms, such as Gaussian or Uniform. In real-world scenarios, data distributions are often non-Gaussian, skewed, or multimodal, which cannot be adequately captured by such fixed assumptions, thereby limiting the robustness of existing methods. To address this limitation, we propose a novel SNN named arbitrary distribution injection (ADI), which enables distribution modeling from nonpredefined, data-dependent distributions. In particular, we introduce a conditional stochastic feature mapping mechanism to model feature distributions, together with a theoretically grounded variance-regularization loss. Extensive experiments across diverse attack methods, datasets, modalities, and network architectures show that ADI achieves robustness improvements and promising generalization across the evaluated settings. Furthermore, detailed parameter analyses and feature-distribution visualizations provide deeper insights into the underlying mechanisms of ADI.

Rui Zhou, Hao Yang, Wen-Xu Wang et al. · 0 citations
Aug 2026

Structure-Adaptive Threshold Learning via sparse representation for Spiking Graph Neural Network

Experimental results validate the effectiveness of the structure-adaptive threshold mechanism for low-power spiking graph learning and design an alternating soft-fusion-hard-grouping training strategy that decouples structure-aware threshold generation from pattern-specific threshold optimization.

Zehan Li, Yingyi Li, Juntao Zhang et al. · 0 citations
Jul 2026

Driving up Inference Energy on SNNs: Per-Sample and Universal Sponge Attacks

Spiking Neural Networks (SNNs) communicate through sparse binary spike events rather than dense activations, enabling energy-efficient inference on neuromorphic hardware and motivating their use in always-on, battery-powered edge systems. We show that this same efficiency advantage creates a distinct security risk: sponge attacks can increase inference-time spike activity and synaptic workload, inflating energy consumption while remaining difficult to detect through correctness-based monitoring alone. Prior input-space efficiency attacks on SNNs have focused on per-sample optimization, primarily in rate-coded settings. We extend this threat to native event-based binary inputs and study two attack models. First, we develop a per-sample sponge attack that crafts a custom adversarial spike train for each input via gradient-based optimization. This attack increases per-inference SynOps by 1.5-2.6x on three SNN models for the NMNIST, SHD, and IBM DVS Gesture datasets, while preserving the predicted class on at least 98% of evaluated samples. Second, to the best of our knowledge, we introduce the first universal sponge attack for native event-based SNN inputs: a fixed binary perturbation computed offline and applied via XOR to all subsequent inputs. Although weaker, it still inflates SynOps by 1.09-1.24x across all three datasets and represents a more realistic deployment threat because it requires no per-input optimization. Mapping SynOp inflation to estimated Loihi-1 energy yields per-inference overheads from 14 $\mu$J to 13.24 mJ. These results show that native event-based SNNs are vulnerable to practical input-space efficiency attacks, and that reusable universal perturbations can accumulate into meaningful battery drain in continuously deployed edge systems.

Spyridon Raptis, H. Stratigopoulos · 0 citations
Aug 2026

Multi-layer Adversarial Robustness Analysis of Neural Networks: Visual and Metric-based Approaches

A method to analyze ANNs designed for image classification from an adversarial robustness perspective and implemented an ablation and fine-tuning strategy that successfully boosted the robustness of the ANNs against a variant of the Auto-PGD attack under different threat models.

Inês Valentim, Nuno Antunes, Nuno Lourenço · 0 citations
Preprint Aug 2026

SAGE: Surrogate-gradient Adaptation via Attention-Guided Entropy for Spiking Transformers

Spiking neural networks (SNNs) offer an energy-efficient alternative to conventional deep neural networks by exploiting sparse event-driven computation, but their training remains challenging because the non-differentiable spike function requires surrogate gradients whose fixed shape may be suboptimal across layers and training stages. In this work, we introduce SAGE, an uncertainty-modulated surrogate-gradient mechanism for Transformer-based SNNs. SAGE estimates block-level uncertainty from normalized self-attention entropy and uses this signal to adapt the surrogate-gradient slope during training while leaving the inference model unchanged. By modulating only the training-time surrogate parameter, the proposed method preserves the original architecture and deployment cost while improving optimization flexibility. Experiments on CIFAR-10/100 demonstrate that SAGE achieves improved accuracy over fixed-surrogate baselines, with results up to 1-2\% consistent gains across multiple simulation time steps. These results highlight the potential of attention-derived uncertainty as a lightweight training signal for adaptive surrogate-gradient learning in transformer-based SNNs.

K. Nair, Rodrigue Rizk, K. Santosh · 0 citations

Diverge to Converge: Mutual Heterogeneous Learning for Robust Pruning

Mutual Heterogeneous Learning (MHL) is proposed, a framework enabling robust pruning via single-model inference that significantly outperforms single-model baselines in both adversarial robustness and corruption robustness, while maintaining competitive clean accuracy.

Jinhui Yu, Zikai Zhang, Khaled A. Harras et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.