This paper studies clean-label temporal poisoning against spiking neural networks (SNNs). The attacker applies a fixed timestamp transformation only to training streams from the target class, leaving labels unchanged and preserving the exact event count for every pixel and polarity. Temporal aggregation therefore makes clean and poisoned samples identical, while the SNN processes different sequences. Across three neuromorphic datasets and convolutional and transformer-based victims, the strongest configurations reach an attack success rate (ASR) of 1.00. The paper also evaluates poison budgets, trigger shapes, and SNN-adapted defenses, and proposes a detector based on per-step event mass.
No heat snapshots are available in the last 24 hours.