cs.NEOct 1, 2026

Controllable Stochastic Quantization Encoding for Adversarially Robust Spiking Neural Networks

Authors: Yujia Liu, Peiyu Liu, Yajing Zheng, Tiejun Huang

Organizations: NERCVT, School of Computer Science, Peking University, China · State Key Laboratory for Multimedia Information Processing, School of Computer Science, Peking University, China · Institute for Artificial Intelligence, Peking University, China

Abstract

Spiking Neural Networks (SNNs) have attracted increasing attention due to their impressive temporal dynamics, energy efficiency, and brain-inspired mechanisms. Although SNNs have demonstrated promising performance in image classification tasks, recent studies have shown that they remain vulnerable to adversarial attacks, where imperceptible perturbations are added to input images to mislead model predictions. Existing defense methods mainly focus on training strategies, while the role of input encoding remains less explored. An observation is that the robustness advantage of Poisson encoding over direct encoding may benefit from its inherent randomness. Motivated by this, we propose a stochastic quantization encoding method that encodes the input image with controllable randomness adjusted by the quantization scale, thereby improving the adversarial robustness of SNNs. We further show that this method constitutes a general framework that reduces to both Poisson encoding and direct encoding under different choices of the quantization scale. Since it enhances robustness at the input encoding stage, it can be combined with existing training-based defenses for further gains. Experimental results on CIFAR-10 and CIFAR-100 demonstrate the effectiveness of the proposed stochastic quantization encoding method. To sum up, this work highlights the importance of input encoding for the adversarial robustness of SNNs, providing a new perspective for understanding and improving it.

Figures & tables

Appendix figures & tables3 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Quantifying How Training Gradient Sparsity Affect Spiking Neural Network Accuracy And Robustness

    Sep 28, 2025Nhan Trong Luu, Duong Trung LuuSpiking Neural NetworksSparsity

  2. Burst Spiking Neural Networks

    Jul 5, 2026Jiahong Zhang, Sijun Shen, Man Yao +5Spiking Neural NetworksNeural Network

  3. Hybrid ANN-SNN Pipeline with Local Plasticity

    Jun 18, 2026Denis Larionov, Khairutin Shtanchaev, Mikhail Kiselev +2Spiking Neural NetworksTime-To-First-Spike