T-Backdoor: Exploiting Temporal Redundancy in Neuromorphic Data for Spike-preserving Backdoor Attacks on SNNs

arXiv:2609.30119 · cs.CR · Submitted 2026-09-24 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: Today's paper: "T-Backdoor: Exploiting Temporal Redundancy in Neuromorphic Data for Spike-preserving Backdoor Attacks on SNNs".

Elias: Backdoor attacks are a serious security threat to deep neural networks (DNNs) and remain largely underexplored for spiking neural networks (SNNs).

Nadia: First, who's behind it and why it matters.

Paper discussion segment 1: Nadia: So, we're starting with the paper "T-Backdoor: Exploiting Temporal Redundancy in Neuromorphic Data for Spike-preserving Backdoor Attacks on SNNs," and it seems the main focus is how this novel approach uses purely temporal triggers to bypass existing detection methods.

Elias: Right, so what I'm getting is that they're targeting the fundamental weakness of current backdoor attacks on spiking neural networks, which usually involve spatiotemporal triggers that mess with both space and time simultaneously.

Priya: From my side, what’s striking is their claim that by only manipulating the time axis—using Rate, Latency, or Jitter—the resulting spike distribution of the poisoned samples stays nearly identical to the clean ones.

Nadia: That's exactly what makes it so compelling; if you can keep the spike distribution looking clean while still achieving a high success rate, it completely undermines detection methods that rely on those statistical deviations.

Elias: Indeed, and the paper details how they define these temporal triggers mathematically through a deterministic remapping function sigma: zero..., T −one → zero..., T −one.

Priya: And when we look at the specific results on the benchmark datasets like N-MNIST and CIFAR10-DVS, they show that for Jitter, the spike KL divergence and Wasserstein distance are exactly zero across all three metrics.

Nadia: Exactly, Priya; it means if a researcher only checks for those standard distribution shifts, they're going to miss this entirely because the perturbation is purely temporal.

Elias: I wonder about the assumptions here regarding the underlying SNN structure; they seem to assume it can handle these deterministic time remappings without immediately failing.

Priya: And looking at their practical findings, they show that even with a twenty percent poisoning ratio, the clean accuracy drop is very small, which makes this finding much more applicable for real-world privacy research.

Nadia: So it’s not just theoretical; it’s showing that these temporal triggers are potent even in moderately interfered systems, and we need to figure out how to build defenses that can handle this level of stealth.

Elias: That leads us right into their suggestion about monitoring internal signatures, which they link to metrics like the membrane temporal correlation distance, D MTC.

Priya: I agree; those internal measures are where we get the real story about how time manipulation actually alters the network state inside the neurons.

Nadia: So, the focus shifts from inspecting what went into the SNN to monitoring its internal temporal dynamics as a way to catch this specific kind of poisoning.

Elias: This paper strongly suggests that analyzing temporal behavior is becoming a necessary direction for securing SNNs, moving past purely spatial checks entirely.

Nadia: Now we're moving on to discussing the specific improvements the authors suggest for T-Backdoor, focusing on how to make these temporal triggers more effective or how defenses can be structured around them.

Elias: What they propose is that detection methods should incorporate those internal signatures we talked about earlier, specifically the Spike Jaccard Similarity and the Membrane Temporal Correlation Distance to build robust detection systems.

Priya: I think that's where we find our biggest advantage for privacy research; if we can reliably measure those internal metrics, we gain a much deeper understanding of how temporal manipulations affect the network state.

Nadia: Right, Priya; that means shifting our primary defense tool away from external spike distribution statistics and toward these internal metrics that the paper shows are sensitive to temporal triggers.

Elias: From a cryptographic viewpoint, I think we have to consider how the training process itself is affected by these temporal triggers when using that dirty-label setup described in their work.

Priya: They did show that even with a twenty percent poisoning ratio, the clean accuracy drop stays small, which suggests those proposed improvements might actually be feasible for real-world deployment where you can't just use tiny amounts of data.

Nadia: That’s the kind of pragmatic reality we have to manage, Priya; we aren't aiming for a perfect attack-proof model, but one that is resilient against these specific temporal exploits.

Elias: So the implication here is that defenses will have to become highly specialized, tailored specifically to how time flows through neuromorphic data rather than just using general network security practices.

Priya: And I think focusing on those internal signatures really does give us a better way to see what's actually happening inside the network when it’s being poisoned, which is vital for deep privacy research.

Nadia: We're wrapping up our look at "T-Backdoor: Exploiting Temporal Redundancy in Neuromorphic Data for Spike-preserving Backdoor Attacks on SNNs," summarizing what we've seen is that these purely temporal triggers can compromise SNNs with very high success rates while leaving the basic spike distribution statistics largely intact.

Elias: I think the biggest implication is that detection needs to pivot toward monitoring the membrane temporal correlation distance, D MTC as a crucial indicator of tampering for our cryptographic scrutiny moving forward.

Priya: I just want to stress that while the attack success rate is high, we need to be very pragmatic about how much clean accuracy degradation we can accept in real-world deployment scenarios.

Nadia: That’s the balance we have to strike, Priya; it sounds like T-Backdoor forces us to build defenses that are incredibly sophisticated and tailored specifically to this temporal manipulation.

Elias: So, ultimately, we're looking at a shift in defensive strategy based on what the paper suggests is necessary for SNN security moving forward.

Priya: I think focusing on those internal signatures is also important because they offer a way to detect the attack even when external checks fail, which is vital for deep privacy research.

Nadia: Well, that's enough for this deep dive into T-Backdoor; I think we should take a quick break before we move on to the study on detection rule generation.

Elias: Agreed, I’m ready to tackle those unified task rules next, as they might offer a different angle for defense architecture.

Priya: I'm looking forward to seeing how their work on detection rule generation connects with these temporal attack vulnerabilities.

Paper discussion segment 2: Nadia: So, to recap, T-Backdoor shows that adversaries can compromise SNNs by just changing the timing—using rate adjustments, delays, or frame swaps—while keeping the spike patterns looking almost identical to clean ones.

Elias: That’s right; the core idea is achieving a high attack success rate while avoiding any detectable change in the fundamental spike distribution across both space and time.

Priya: What I find really important here is that they prove this stealth isn't just theoretical; they show that even with twenty percent of poisoned data, you only lose a small fraction of the clean accuracy, which makes this attack very realistic for privacy research.

Nadia: It’s that trade-off we have to navigate; these attacks are potent enough to be a real threat, but they still leave a measurable footprint on the clean model performance.

Elias: Because of that, the authors strongly push us toward looking deeper inside the network dynamics rather than just checking the input data for obvious statistical anomalies.

Priya: Exactly; they point to metrics like the membrane temporal correlation distance, D MTC, as a way to see exactly how these temporal manipulations disrupt the internal state of the neurons. That’s what we need to measure for privacy research.

Nadia: So, it shifts our focus from the outside—the inputs and outputs—to the inside, monitoring how time flows through every layer of an SNN when it's being attacked.

Elias: This really suggests that defense mechanisms have to evolve to specifically look for temporal anomalies within the network's internal behavior, which is a significant assumption for any existing security framework.

Priya: And it’s exciting because these temporal triggers are so subtle; they don't leave clear statistical noise behind that simple spike-count methods can catch.

Nadia: So, the implication is that we need to build defenses that are specialized for time manipulation rather than just general adversarial examples, and I think this paper lays out exactly what those internal monitoring tools should look like.

Elias: This research really shows that temporal analysis is becoming a key area for SNN defense, pushing us beyond simple spatial checks entirely.

Priya: I think that's what we need to keep in mind as we look at how these attacks scale across different datasets and training methods.

Paper discussion segment 3: Nadia: So, we've just finished our deep dive into "T-Backdoor: Exploiting Temporal Redundancy in Neuromorphic Data for Spike-preserving Backdoor Attacks on SNNs," and we see that temporal triggers can bypass standard detection by keeping spike distributions looking clean.

Elias: I think the biggest implication is that we need to pivot our cryptographic scrutiny toward monitoring the membrane temporal correlation distance, D MTC, as a crucial indicator of tampering for our work moving forward.

Priya: I just want to stress that while the attack success rate is high, we need to be very pragmatic about how much clean accuracy degradation we can accept in real-world deployment scenarios.

Nadia: That’s the balance we have to strike, Priya; it sounds like T-Backdoor forces us to build defenses that are incredibly sophisticated and tailored specifically to this temporal manipulation.

Elias: So, ultimately, we're looking at a shift in defensive strategy based on what the paper suggests is necessary for SNN security moving forward. This work really points toward temporal analysis as the next frontier for SNN defense.

Priya: I think focusing on those internal signatures is also important because they offer a way to detect the attack even when external checks fail, which is vital for deep privacy research.

Nadia: Well, that's enough for this deep dive into T-Backdoor; I think we should take a quick break before we move on to the study on detection rule generation.

Elias: Agreed, I’m ready to tackle those unified task rules next, as they might offer a different angle for defense architecture.

Priya: I'm looking forward to seeing how their work on detection rule generation connects with these temporal attack vulnerabilities.

Conclusion: Nadia: So, we've just finished our deep dive into "T-Backdoor: Exploiting Temporal Redundancy in Neuromorphic Data for Spike-preserving Backdoor Attacks on SNNs," and we see that temporal triggers can bypass standard detection by keeping spike distributions looking clean.

Elias: I think the biggest implication is that we need to pivot our cryptographic scrutiny toward monitoring the membrane temporal correlation distance, D MTC, as a crucial indicator of tampering for our work moving forward.

Priya: I just want to stress that while the attack success rate is high, we need to be very pragmatic about how much clean accuracy degradation we can accept in real-world deployment scenarios.

Nadia: That’s the balance we have to strike, Priya; it sounds like T-Backdoor forces us to build defenses that are incredibly sophisticated and tailored specifically to this temporal manipulation.

Elias: So, ultimately, we're looking at a shift in defensive strategy based on what the paper suggests is necessary for SNN security moving forward. This work really points toward temporal analysis as the next frontier for SNN defense.

Priya: I think focusing on those internal signatures is also important because they offer a way to detect the attack even when external checks fail, which is vital for deep privacy research.

Nadia: Well, that's enough for this deep dive into T-Backdoor; I think we should take a quick break before we move on to the study on detection rule generation.

Elias: Agreed, I’m ready to tackle those unified task rules next, as they might offer a different angle for defense architecture.

Priya: I'm looking forward to seeing how their work on detection rule generation connects with these temporal attack vulnerabilities.

Department of Electrical, Computer, and Biomedical Engineering

cs.CR

Submitted: 2026-09-24

Updated: 2026-09-24

Comments: 14 pages, 12 figures

Code: https://github.com/SiSL-URI/T-Backdoor

License: http://creativecommons.org/licenses/by/4.0/

Importance score: 71/100

The gist: Backdoor attacks are a serious security threat to deep neural networks (DNNs) and remain largely underexplored for spiking neural networks (SNNs).

Key concepts

T-Backdoor
A novel approach using purely temporal triggers—such as Rate, Latency, or Jitter—to create backdoor attacks on SNNs. This method aims to bypass existing detection methods by keeping the resulting spike distribution nearly identical to clean samples.
Spike-preserving Attacks
Backdoor attacks that manipulate the timing of spikes in an SNN without significantly altering the overall spike distribution across space and time. The paper shows these attacks can maintain a high success rate while remaining stealthy.
Membrane Temporal Correlation Distance (D MTC)
An internal metric used to monitor how temporal manipulations disrupt the internal state of neurons within an SNN. It is suggested as a crucial indicator for detecting tampering when external checks fail.
Temporal Triggers
Perturbations applied to the time axis of neuromorphic data, including adjustments to Rate, Latency, or Jitter. These triggers are deterministic and are used by adversaries to introduce subtle changes that evade standard statistical detection methods.

Terminology

Summary

Backdoor attacks are a serious security threat to deep neural networks (DNNs) and remain largely underexplored for spiking neural networks (SNNs). Existing attacks primarily introduce spatiotemporal triggers that induce deviations in the spike distribution of poisoned samples relative to their clean counterparts. To address this limitation, this work proposes a novel backdoor attack on SNNs, termed TBackdoor, which operates using purely temporal triggers such as Rate, Latency, and Jitter without introducing any spatial perturbation, making the shift in spike distributions significantly harder to detect.

Through extensive experiments on three benchmark neuromorphic datasets: N-MNIST, CIFAR10-DVS, and N-Caltech101, and evaluation against seven baseline backdoor defense methods, we demonstrate that T-Backdoor achieves a near-perfect 100% attack success rate (ASR) in both single target and multi target settings with only minor degradation in clean accuracy, while remaining robust against existing backdoor detection and mitigation techniques.

The paper identifies a fundamental drawback of existing spatiotemporal backdoor triggers on SNNs: their addition to the spatial contents shifts the spike distribution of the poisoned samples, rendering them detectable by simple spike-count statistics. To answer the central question—can an adversary compromise an SNN without perturbing the spike distribution of the poisoned samples?—the authors propose T-Backdoor, a temporal-only backdoor attacks against SNNs trained on neuromorphic data. The temporal dimension of neuromorphic data is exploited by three triggers: (i) Rate Trigger, which modulates the temporal playback speed of the event stream by a scaling factor, (ii) Latency Trigger, which introduces a fixed delay in the temporal axis, and (iii) Jitter Trigger, which swaps a configurable number of frame pairs to induce controlled temporal reordering. These triggers work purely within the temporal axis without adding any spatial content, thus preserving the spike distribution of the poisoned samples.

The contributions are summarized as follows:

"We identify and investigate a fundamental drawback of existing spatiotemporal backdoor triggers on SNNs: their addition to the spatial contents shifts the spike distribution of the poisoned samples, rendering them detectable by simple spike-count statistics."

"We propose a novel backdoor attack on SNNs named T-Backdoor, the first purely temporal backdoor attack framework for SNNs encompassing three spikepreserving trigger types: Rate, Latency, and Jitter. For the first time of backdoor attacks on SNNs, we further investigate and showcase that T-Backdoor is scalable effectively to multi-target payload scenarios."

"Through extensive experiments on N-MNIST, CIFAR10DVS and N-Caltech101, we show that T-Backdoor achieves near-perfect attack success rates (ASR ≈ 100%) with negligible clean accuracy degradation, evades spikedistribution-based detection, and resists seven state-of-the-art backdoor detection and mitigation techniques."

The temporal triggers are formalized under a unified index-remapping framework where a temporal trigger is defined as a deterministic remapping function σ: 0,..., T −1 → 0,..., T −1 that produces a triggered sample x̂ by reassigning frame indices: x̂(t) = x(σ(t)), t = 0, 1,..., T-1. The specific triggers are defined mathematically as follows:

"Rate Trigger. Given a scaling factor r > 0, the rate trigger function rescales the frame indices to adjust the temporal playback rate... For a clean sample x and a time step t where t = 0,..., T −1, Rate trigger function can be mathematically expressed as x̂(t) = x(σrate (t)), σrate (t) = min ⌊r · t⌋, T −1, where ⌊·⌋ denotes the floor function..."

"Latency Trigger. The Latency trigger introduces a temporal delay into the dynamics of the neuromorphic data by shifting the entire event sequence forward by d time steps... For a given x and a time step t where t = 0,..., T −1, Latency triggered sample can be expressed as x̂(t) = x(σlat (t)) for all t.... ((0)x, if t < d, (t)x̂ = ((t−d)x, if d ≤ t < T,"

"Jitter Trigger. The Jitter trigger controlled temporal displacement by swapping specific pairs of frames... The resulting remapping σjit: 0,..., T-1 → 0,..., T-1 is initialized as the identity permutation and modified by applying each swap. The triggered sample is then x̂(t) = x(σjit (t)) for all t."

The attack utilizes a dirty-label methodology where the training dataset is split into clean data and poisoned data, defined as:

For input sample space X, clean label space Yc, and target label space Yt, we can define clean Dtrain = ∪ (xi, yi): xi ∈ X, yi ∈ Yc, poison = ∪ (x̂i, yi): x̂i ∈ X, yi ∈ Yt.

For multi-target settings, a target label assignment function ϕ: T → Yt maps each trigger index l in T to its corresponding target label yt in Yt.

The attack effectiveness was analyzed across three benchmark datasets (N-MNIST, CIFAR10-DVS, and N-Caltech101) using various network architectures and training methods (Surrogate Gradient training via SpikingJelly framework). The results showed that ASRs for the Rate trigger reach ≈ 100% for every dataset and scaling factor r with the exception of r = 1.2, where it drops to 97.57% for N-MNIST, 96.00% for CIFAR10-DVS and 96.96% for N-Caltech101. For the Latency trigger, nearperfect ASR of ≈100% is achieved across all datasets and all values of d. For the Jitter trigger, nearperfect ASR of ≈100% is also achieved across all datasets and ns variations.

In terms of spike distribution analysis, the temporal triggers in our proposed T-Backdoor exhibit near-zero perturbation across all three metrics [spike KL divergence, spike Wasserstein distance, and total spike residual]. Specifically for Jitter: "Most notably, Jitter achieves exactly 0.0 on all three metrics across all three datasets. It is due to the fact that Jitter operates entirely through event reordering without introducing any changes in the spatial domain." This demonstrates that temporal triggers resist data-level detection approaches that analyze spike distribution properties, whereas spatiotemporal triggers exhibit higher values in all three metrics.

The model-internal signatures of T-Backdoor activations are analyzed using two metrics: (i) the spike jaccard similarity (J¯l) and (ii) the membrane temporal correlation distance (DlMTC). "The DlMTC values convey a consistent story: although the distance is small on N-MNIST, it grows by more than an order of magnitude on CIFAR10DVS and N-Caltech101, showing that the temporal triggers substantially disrupt the temporal structure of the membrane-potential trajectory." This signature can be exploited by defenders to detect poisoned samples.

The defense evaluation showed that T-Backdoor is resistant to TMPBD, NC, and STRIP detection methods and state-of-the-art backdoor mitigation techniques. Specifically, All of the analyzed detection methods fail to detect TBackdoor in several scenarios, particularly on N-Caltech101. Furthermore, regarding mitigation defenses: 47 out of 63 temporal trigger configurations retain ASR above 90%, while only 7 could be meaningfully mitigated, suggesting a need for a new line of defense specifically considering the temporal modification of neuromorphic data.

In conclusion, T-Backdoor demonstrates that temporal triggers resist data-level detection approaches that analyze spike distribution properties, whereas spatiotemporal triggers perturb the input in ways that manifest as clear statistical outliers. The Jitter trigger is noted as performing best and most stealthy at lower values of ns. The paper concludes by stating: "In summary, all three temporal triggers: Rate, Latency, and Jitter demonstrate high ASR while preserving CA at levels comparable to an uncompromised baseline, making T-Backdoor both potent and stealthy in terms of model utility degradation."

The final discussion points to the metrics used for detection: (i) the spike jaccard similarity (J¯l) and (ii) the membrane temporal correlation distance (DlMTC), expressed in equation 13. These metrics leave a pronounced signature of the temporal triggers in the model’s internal dynamics, a signature that a defender can exploit to detect poisoned samples.

The paper also investigates scalability, finding that the timestep parameter T has minimal impact on CA and generally preserves nearperfect ASR, confirming the robustness of T-Backdoor against varying temporal resolutions. Finally, concerning poisoning ratio: with only a 10% poisoning ratio it is possible to reach an average ASR over 86%, and with a 20% poisoning ratio the average ASR reaches up to 97.46%, with only a 1% drop in CA. The paper highlights that Latency is the most stable trigger, maintaining near-perfect ASR with minimal CA impact across all configurations. It also notes that Jitter is the least effective in terms of scalability for multi-targeted scenarios.

Improvements for AI systems

Based on the provided scientific paper, here are the specific improvements to AI systems (specifically Spiking Neural Networks - SNNs) that can be derived from this research, along with what those improved systems will be capable of:


  1. The proposed system is a novel backdoor attack framework called T-Backdoor.

  2. T-Backdoor exploits purely temporal triggers: Rate (scaling playback speed), Latency (fixed delay), and Jitter (frame pair swapping) without introducing any spatial perturbation to the input data.

  3. The improved system will be capable of being attacked by these purely temporal modifications, making the resulting backdoor significantly harder to detect using traditional spatiotemporal trigger detection methods like KL divergence or Wasserstein distance.

  4. The T-Backdoor attack achieves a near-perfect Attack Success Rate (ASR ≈ 100%) in both single and multi-target settings with only minor degradation in clean accuracy, while remaining robust against seven state-of-the-art backdoor detection and mitigation techniques (e.g., TMPBD, Neural Cleanse, STRIP).

  5. The improved system can be used to generate models that are highly resilient to temporal trigger attacks that manipulate the time dimension of neuromorphic data (DVS streams).

  6. For specific defense improvements:

  7. The system can be trained using a dirty-label methodology, where training data is split into clean and poisoned subsets tailored for single-target, multi-target (one-to-N), or sample-specific attack settings.

  8. Defense mechanisms can be enhanced by incorporating model internal signatures:

  9. The system can utilize metrics like Spike Jaccard Similarity and Membrane Temporal Correlation Distance (DMTC) to detect temporal triggers, as these metrics show a pronounced signature when temporal triggers are applied to complex datasets (CIFAR10-DVS and N-Caltech101).

  10. Mitigation strategies can be refined by using advanced pruning techniques:

  11. The system can employ adversarial neuron pruning (ANP) or channel Lipschitz pruning (CLP), tuned based on specific thresholds, to selectively remove neurons that are highly influential in the temporal trigger mechanism, thereby mitigating backdoor effects while preserving clean accuracy better than vanilla fine-tuning.

  12. The system can be designed with a new line of defense specifically tailored to consider the temporal modification of neuromorphic data streams, moving beyond standard spatial detection methods.

Abstract

Backdoor attacks are a serious security threat to deep neural networks (DNNs) and remain largely underexplored for spiking neural networks (SNNs). Existing attacks primarily introduce spatiotemporal triggers that induce deviations in the spike distribution of poisoned samples relative to their clean counterparts. To address this limitation, this work proposes a novel backdoor attack on SNNs, termed T-Backdoor, which operates using purely temporal triggers such as Rate, Latency, and Jitter without introducing any spatial perturbation, making the shift in spike distributions significantly harder to detect. Through extensive experiments on three benchmark neuromorphic datasets: N-MNIST, CIFAR10-DVS, and N-Caltech101, and evaluation against seven baseline backdoor defense methods, we demonstrate that T-Backdoor achieves a near-perfect 100% attack success rate (ASR) in both single target and multi target settings with only minor degradation in clean accuracy, while remaining robust against existing backdoor detection and mitigation techniques. The codes are available at https://github.com/SiSL-URI/T-Backdoor.

Sources

Related papers