{"id":"0265d9bd-0f1c-4aea-a45b-9353a0d50313","arxiv_id":"2607.28075","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"low","formal_verification":"none","parameter_count":4,"one_line_summary":"Retiming target-class neuromorphic events installs clean-label SNN backdoors with ASR up to 1.0 while leaving rate frames identical, and rate-collapsed defenses miss them.","lead":"A clean-label backdoor can be planted in spiking neural nets by only retiming events in target-class training data, leaving labels and total event counts unchanged. That matters for neuromorphic edge systems, because many checks that collapse time never see the trigger.","discovery_kind":"new_application","skeptic_critique":{"model":"grok-4.5","headline":"No significant objection identified","rationale":"The strongest claim is empirical and carefully hedged: under activation-based multi-step training with known T=16 binning, clean-label timestamp remapping that exactly preserves per-pixel/polarity counts can yield ASR up to 1.00 while leaving rate frames identical. The reader's weakest assumption names exactly the condition the Background (LIF recurrence), Threat Model (attacker knows discretization), and Method rely on. That condition is necessary for the attack surface the authors study; it does not falsify the results obtained inside it. Utility non-uniformity, shift weakness, and the adaptive detector are already surfaced in Tables 3 and Figure 3 and in the conclusions. Spatial baselines are labeled descriptive. Correctness risk for the scoped empirical claim therefore stays low, and the CONDITIONAL verdict with high confidence needs no adjustment from this pass.","tokens_in":20756,"tokens_out":437,"duration_ms":9847,"concrete_test":"Re-run the N-MNIST and CIFAR10-DVS concentrate configurations from Table 3 with T in {8,32} (same total recording length, same poison indices and seeds); if ASR remains near 1.00 at the operating poison rates while rate-frame SSIM stays 1.00, the multi-step premise is robust inside the paper's discretization family.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The reader's weakest assumption (known fixed multi-step binning so membrane recurrence can learn coincidence patterns) is correctly identified and is already scoped by the paper's threat model and method. It is a boundary condition on applicability, not an internal inconsistency or unsupported leap in the reported experiments. Within that scope the central claim is backed by multi-seed tables, a clean-model control (Table 2), rate-frame invariance, poison-budget and trigger-shape ablations, and explicit ownership that rate-collapsed defenses are blind while a temporal-mass detector exposes the evaluated triggers. Secondary CA drops and shift failure are reported rather than hidden. No further load-bearing technical flaw undermines the scoped claim.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The paper introduces a clean-label backdoor for SNNs on neuromorphic event data: a fixed timestamp remapping applied only to target-class training streams, with labels left unchanged and per-pixel, per-polarity event counts exactly preserved. Clean and triggered rate frames are therefore identical (SSIM 1.00, L0 = L∞ = 0), while the multi-step spiking dynamics see a different temporal sequence. Three remapping families (concentrate, front-load, shift) are evaluated on N-MNIST, DVS-Gesture, and CIFAR10-DVS with convolutional and SpikformerLite victims. ASR reaches 1.00 in several strongest configurations; poison-budget and trigger-shape ablations and a clean-model control (Table 2) support that the effect is learned rather than an inherent bias of the transform. Established defenses adapted to SNNs are largely ineffective when they collapse time; a model-free per-step event-mass detector exposes the evaluated triggers.","tokens_in":20979,"tokens_out":1380,"duration_ms":56356,"significance":"If the results hold, this is a genuine first: clean-label data poisoning on SNNs/neuromorphic streams, exploiting a temporal attack surface that rate-frame inspection cannot see. That matters for edge and safety-critical neuromorphic deployments where third-party or update-stage data is realistic. Strengths include exact rate-frame invariance by construction, multi-dataset and multi-architecture evaluation with three seeds and SE, poison-rate and shape ablations, a clean-model control, honest reporting of shift failure and CA drops, careful documentation of defense adaptations (including where time is collapsed), and an adaptive temporal detector that bounds stealth rather than overclaiming it. Artifact and reproducibility commitments further strengthen the contribution for a security venue.","major_comments":[{"comment":"Threat Model and §5 fix victim binning at T = 16 and state that the attacker knows the event representation and temporal discretization. No experiment tests ASR when the attacker’s assumed binning (or trigger placement in bin space) mismatches the victim’s actual T or windowing. Because membrane recurrence and the discrete trigger parameters (t*, k, s) are defined on that grid, transfer under discretization mismatch is load-bearing for the claimed practical threat; a short mismatch sweep (e.g., craft at T = 16, evaluate at T ∈ {8, 12, 24}, or off-by-one burst placement) would either support robustness or correctly narrow the claim.","section":"Threat Model; §5 Attack Evaluation"},{"comment":"Table 3 shows ASR = 1.00 alongside large clean-accuracy drops in several cells (CIFAR10-DVS conv ~8 points; SpikformerLite ~11–14 points; DVS-Gesture SpikformerLite ~23 points under concentrate). Section 3 requires the poisoned victim to “retain useful accuracy,” and §5.1 correctly notes non-uniform utility, but the abstract and conclusions still lead with ASR 1.00 “in the strongest configurations” without an explicit joint success criterion (e.g., ASR ≥ τ and ΔCA ≤ ε). Please define that criterion and report which dataset–victim–trigger cells meet it, so effectiveness is not read off ASR alone where utility cost is large.","section":"§3 Goal; Table 3; §5.1; §9"},{"comment":"Section 5 describes clean pretrain followed by a short poisoning phase (e.g., 5+12 epochs on N-MNIST). The threat model allows poison at any stage, including pretraining, but all main results use this two-stage schedule. It is unclear whether ASR and CA hold when poison is mixed from epoch 0 under the same total budget, or only after a clean warm start. A single ablation on one dataset–victim pair would confirm that the backdoor is not an artifact of the pretrain-then-poison protocol.","section":"§5 training protocol; Threat Model"}],"minor_comments":[{"comment":"Table 4 spatial clean-label baselines are exploratory single-seed sweeps and are labeled descriptive; consider moving them to an appendix or marking them more visibly so they are not cited as a controlled ranking.","section":"Table 4; §5.2"},{"comment":"Figure 3 / defense tables: several Activation Clustering and pruning entries have SE on the order of the mean (e.g., 0.33 ± 0.33). The text already discounts some of these; ensuring every high-variance cell is flagged in the caption would help.","section":"Figure 3; Table 8; §7.1"},{"comment":"Section heading “ATTACK EV ALUATION” appears to contain a spurious space; Figure 3 label “T emporal” likewise.","section":"§5; Figure 3"},{"comment":"Main tables fix yt = 0; the text points to the repository for other targets. A one-row or appendix summary that ASR is comparable for at least one other class per dataset would make the paper self-contained.","section":"§5"},{"comment":"Neural Cleanse temporal variant is useful as a diagnostic; briefly state in the table caption that its cost is not the published anomaly index and is not used for flagging.","section":"Table 7; §6.3"},{"comment":"Related work is appropriate; a short explicit contrast with dirty-label temporal federated triggers (Spikewhisper, time-distributed FL backdoors) on the clean-label vs dirty-label axis would sharpen novelty for readers of that line.","section":"§8.2"}],"recommendation":"minor_revision","confidential_remarks":"Central empirical claim is sound within the stated multi-step, known-binning scope; the skeptic’s “no significant objection” reading matches my assessment. The three major points are clarifications and boundary tests, not refutations—suitable for minor revision rather than major rewrite. Good fit for a security / trustworthy-ML venue that values neuromorphic threat analysis; novelty claim as first clean-label SNN backdoor appears credible relative to the cited dirty-label SNN line."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"The one thing worth knowing: this is the first clean-label backdoor study on SNNs/event data, and the mechanism is simple and well chosen. They only retimestamp target-class streams so per-pixel, per-polarity counts (and thus the rate frame) stay exactly identical, while multi-step LIF dynamics still see a different coincidence pattern. That is a real threat-model step past the dirty-label neuromorphic line (Abad, Sneaky Spikes, Flashy, federated variants).\n\nWhat they do well is the evaluation hygiene. Three datasets, conv and SpikformerLite, three seeds with SE, poison-budget and trigger-shape sweeps, and a clean-model control (Table 2) showing the transforms alone do not force the target. Rate-frame invariance is construction-true (SSIM 1, L0=L∞=0), not hand-waved. Concentrate/front-load hit ASR 1.00 in strong cells; shift mostly fails, and they treat that as evidence that coincidence change matters, not arbitrary phase. Defense section is honest: rate-collapsed adaptations are blind by design; Spectral works only in selected cells; their own per-step mass detector catches the evaluated triggers and they own that as the stealth boundary.\n\nSoft spots, in proportion. Clean accuracy is not free everywhere—CIFAR10-DVS and DVS-Gesture Spikformer take real CA hits—so “stealthy and utility-preserving” is configuration-dependent, not universal. Spatial clean-label baselines are descriptive single-seed sweeps, not a controlled ranking. Defense conclusions are tied to how you collapse T; that is fair for adapted methods but does not kill every time-aware feature defense. Load-bearing premise is known fixed multi-step binning so membrane state can learn timing; if the pipeline is pure rate or unknown discretization, the same poison does not install. The paper scopes this in the threat model rather than hiding it.\n\nMath is elementary remaps plus standard LIF; citations cover the right dirty-label SNN and clean-label image/video priors. Artifacts promised with seeds and configs.\n\nWho it is for: people working neuromorphic security, dataset supply-chain for DVS, or SNN training pipelines. Not a general ML-security reorganization. I would send it to peer review; the scoped claim is evidenced and the gap is real. Engage if that is your area.","headline":"First clean-label SNN backdoor via rate-preserving timestamp remaps; empirics are solid within a clearly scoped multi-step threat model.","tokens_in":21625,"tokens_out":600,"would_cite":true,"duration_ms":18294,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"Spiking networks can be backdoored clean-label by only rearranging when neuromorphic events arrive, leaving counts and labels unchanged.","keywords":["spiking neural networks","clean-label backdoor","temporal poisoning","neuromorphic event data","rate frame","timestamp remapping","backdoor defenses","DVS"],"falsifier":"Retrain the same victims on purely rate-collapsed inputs (one frame of totals per sample, no multi-step membrane state) and check whether the identical timestamp remaps still produce high ASR on triggered non-target tests; near-zero ASR would refute the claimed timing surface.","tokens_in":21632,"feed_emoji":"⚡","tokens_out":959,"duration_ms":28462,"temperature":0.7,"pith_summary":"This paper shows that a backdoor can be installed in spiking neural networks without changing any training labels and without changing how many events each pixel records. The attacker only remaps timestamps on a fraction of target-class event streams, so the time-collapsed “rate frame” of a poisoned sample is mathematically identical to the clean one, yet the sequence the spiking model sees is different. Across three neuromorphic datasets and both convolutional and transformer spiking victims, at least one such timing transform reaches perfect attack success in the strongest setups, often from only dozens of retimed samples. Established defenses that first collapse time are blind by design; a simple model-free check on per-step event mass catches the transforms the authors tested. The practical point is that neuromorphic systems trusted for timing-sensitive edge tasks inherit a clean-label poisoning surface that frame-based security checks miss.","feed_headline":"Spiking nets backdoored by retiming events alone","feed_subtitle":"Labels and pixel counts stay identical; only the sequence changes, and rate-collapsed defenses miss it.","key_machinery":"The temporal trigger: a fixed map φ on event timestamps (concentrate, front-load, or shift) that never adds, removes, recolors, or spatially moves events, so the rate frame R(E) is exactly invariant while membrane recurrence still sees a repeatable change in event coincidence over the T bins.","core_discovery":"A fixed timestamp remapping applied only to target-class training streams, with labels left unchanged and per-pixel per-polarity event counts exactly preserved, can teach an SNN to classify triggered non-target inputs as the target class, reaching ASR 1.00 in the strongest dataset–victim–trigger configurations while clean and triggered rate frames remain identical (SSIM 1.00, L0 = L∞ = 0).","pith_inferences":["If DVS capture pipelines ever expose controllable timing skew (lens, clock, or light modulation), the same rate-preserving idea could move from digital poisoning toward a physical clean-label path.","Vendors shipping multi-step SNN stacks may need a default temporal-mass sanitizer on third-party event datasets, analogous to how image pipelines already scan for spatial patches.","The near-failure of pure shift suggests future timing triggers will be forced toward coincidence-changing maps, which also makes simple concentration and phase features more diagnostic for defenders.","Large clean-accuracy drops on harder datasets imply attackers may face a stealth–utility tradeoff that rate-frame equality alone does not solve."],"forward_implications":["Any defense or audit that inspects only the time-summed rate frame cannot see this poison, by construction.","Clean-label temporal poisoning is feasible on both convolutional and transformer SNNs and on multiple public neuromorphic benchmarks.","Attack success depends on trigger shape and placement (bursts and front-loading work; pure phase shift mostly fails), not on arbitrary timestamp noise.","Reliable detection of the evaluated transforms requires measuring per-step event mass (or another explicitly temporal statistic), not only time-averaged features.","Neuromorphic deployments that treat timing as the information channel need time-aware data filters before training, not only adapted image backdoor tools."],"fun_headline_variants":["Clean-label temporal poison backdoors SNNs by retiming events","Event timestamps alone teach SNNs a clean-label backdoor","SNNs reach ASR 1.0 from fixed timestamp remaps on target class","Rate frames stay identical while temporal shifts backdoor SNNs","Clean-label event redistribution poisons convolutional and transformer SNNs"],"cache_read_input_tokens":16512,"weakest_assumption_plain":"The victim must actually depend on event timing through stateful multi-step spiking on a known time binning; if decisions used only total counts or an unknown collapsed pipeline, the same rate-preserving retiming would not install the backdoor.","fun_headline_variants_meta":{"raw":{"variants":["Clean-label temporal poison backdoors SNNs by retiming events","Event timestamps alone teach SNNs a clean-label backdoor","SNNs reach ASR 1.0 from fixed timestamp remaps on target class","Rate frames stay identical while temporal shifts backdoor SNNs","Clean-label event redistribution poisons convolutional and transformer SNNs"]},"model":"grok-4.5","effort":"low","cost_usd":0.003764,"raw_usage":{"total_tokens":1185,"prompt_tokens":782,"num_sources_used":0,"completion_tokens":74,"cost_in_usd_ticks":37644000,"prompt_tokens_details":{"text_tokens":782,"audio_tokens":0,"image_tokens":0,"cached_tokens":128},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":329,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":782,"tokens_out":74,"duration_ms":6944,"temperature":1.0,"reasoning_tokens":329,"cache_read_input_tokens":128,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-31T18:36:02.521440+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Retrain the same victims on purely rate-collapsed inputs (one frame of totals per sample, no multi-step membrane state) and check whether the identical timestamp remaps still produce high ASR on triggered non-target tests; near-zero ASR would refute the claimed timing surface.","supporting_citations":[],"review_version":1}