Do Not Let Spikes Flip: Margin-Resculpted Learning for Robust Spiking Neural Networks
Abstract
Spiking Neural Networks (SNNs) transmit information through energy-efficient discrete spike events, unlike the continuous activations used in conventional Artificial Neural Networks (ANNs). Existing SNN robustness methods often inherit ANN-oriented objectives that suppress continuous perturbations or stabilize membrane-potential dynamics. In this paper, we argue that SNN robustness should be analyzed through the stability of spike patterns under perturbations. We formalize perturbation-induced spike flips and introduce the flip rate as a training-agnostic metric for quantifying spike-pattern instability. We further show that spike flips are closely associated with membrane potentials near the firing threshold, and introduce margin occupancy to quantify this threshold-margin vulnerability. Based on these findings, we propose Margin-Resculpted Learning (MRL), which regularizes excessive threshold-margin occupancy with an activity-adaptive bound. MRL reduces vulnerable spike flips while preserving the threshold region needed for surrogate-gradient learning. Experiments across static and event-based datasets, architectures, surrogate functions, and attack settings demonstrate consistent robustness improvements.