REVIEW 4 major objections 3 minor 38 references
Boosting the Robustness-Accuracy Trade-off of SNNs by Robust Temporal Self-Ensemble
T0 review · 4 major / 3 minor · reviewed 2026-08-05 · deepseek-v4-flash
Pith's one-line read This paper proposes Robust Temporal self-Ensemble (RTE), a training method claiming that treating the timesteps of a spiking neural network as an ensemble—hardening each timestep and reducing cross-timestep transferability—yields a better r
desk verdict A plausible SNN robustness training recipe that deserves a serious look, but the corrupted full text means the empirical core is unverified. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
Robust Temporal self-Ensemble (RTE) is a training objective with two terms: a per-timestep robustness term that adversarially hardens each sub-network, and a temporal-diversity term that discourages adversarial perturbations from transferring across timesteps. A stochastic sampling strategy selects timesteps during optimization to keep training tractable.
What would settle it
Run RTE and a standard adversarial-training baseline on the same SNN architecture and perturbation budget, then attack both with a white-box adversary that optimizes over the full temporal graph at once. If RTE's robust accuracy does not beat the baseline under that attack, the claimed reduction in temporal transferability—and with it the central mechanism—is not doing the work.
Extended reading notes
Core claim
The central claim is that the temporal dimension of an SNN is not merely a cost to be paid for spike-based computation—it is an ensemble structure that can be used for defense. The paper's diagnosis is that the vulnerabilities of an SNN at different timesteps are correlated, so an adversary who finds one fragile timestep can exploit the whole network; RTE's losses attack this directly by making every timestep individually hard to fool and by reducing the overlap of adversarial directions across timesteps. On the evidence reported, this yields a consistently better robust-accuracy trade-off than existing SNN adversarial training methods, and it reshapes decision boundaries to be more temporal
Load-bearing premise
The central claim assumes that RTE is compared with baseline methods under the same attack types, perturbation budgets, architectures, and training budgets; if those are not aligned, the reported gains could come from evaluation settings rather than from RTE itself.
Editorial extensions
If this is right
- If RTE is correct, existing SNN architectures can be made more robust simply by changing the training loss; no architectural change or extra inference cost is required.
- Adversaries trying to fool an RTE-trained SNN must find perturbations that fool multiple timesteps simultaneously, which is strictly harder than fooling a single aggregated decision.
- The robustness-accuracy trade-off for SNNs is not fixed: temporal structure is a resource that can be spent to gain robustness.
- The paper's temporal-transferability analysis offers a diagnostic: attack success across timesteps should decrease under RTE, and this decrease should predict robust accuracy gains.
Reading between the lines
- Editorial inference: if temporal ensembling is the active ingredient, RTE should collapse to standard adversarial training at a single timestep and show growing gains as the number of timesteps increases; a trend study over timestep count would isolate the mechanism.
- Editorial inference: the same per-step-hardening plus cross-step decorrelation recipe could transfer to other temporally unrolled models, such as recurrent networks or diffusion models that iterate over refinement steps.
- Editorial inference: stochastic timestep sampling at inference time, not just at training time, may offer a cheap additional robustness boost by making the effective ensemble even larger.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript proposes Robust Temporal self-Ensemble (RTE), a training framework for spiking neural networks that treats the network across timesteps as an ensemble of temporal sub-networks. It claims to improve the robustness of each sub-network while reducing the temporal transferability of adversarial perturbations, integrating these objectives into a unified loss with a stochastic sampling strategy. The central claim is empirical: RTE is said to consistently outperform existing training methods in the robustness-accuracy trade-off across multiple benchmarks, with additional analyses of the internal robustness landscape. However, the provided full text is heavily corrupted and largely unreadable, and the abstract reports no quantitative results, attack model, or comparison protocol. As presented, the empirical claim cannot be verified.
Significance. If the central claim holds, the paper would offer a useful and conceptually interesting perspective on SNN robustness: explicitly treating temporal unfoldings as sub-network ensembles and targeting both per-timestep fragility and cross-timestep adversarial transfer. This is a plausible direction for robust spiking models and could be relevant to the cs.LG community. The proposed framework also makes falsifiable predictions about improved robustness-accuracy trade-offs, and the temporal-diversity analysis is potentially valuable. However, no experimental evidence is legible in the supplied manuscript, and the abstract is qualitative only. The significance of the contribution therefore cannot currently be assessed beyond the conceptual level.
major comments (4)
- [Abstract] The central claim—"RTE consistently outperforms existing training methods in robust-accuracy trade-off"—is empirical, but the abstract contains no quantitative results: no robust or natural accuracy values, no perturbation budgets, no benchmark names, and no baseline comparisons. At the current level of presentation, the claim is unsupported. Headline numbers and the evaluation protocol should be stated in the abstract.
- [Full text / Table 1] The supplied full text is almost entirely unreadable because of character corruption; the experimental paragraphs and every table are garbled. I cannot verify attack types, epsilon budgets, architectures, numbers of timesteps, error bars, or baseline settings. This is not a presentation issue: the paper's only supporting evidence is empirical. A clean, machine-readable PDF with legible tables, including error bars and complete baseline configurations, is required before the claim can be assessed.
- [Section 3 (RTE training and inference)] The visible method description does not specify whether inference-time temporal ensembling is used and whether all baselines are evaluated under exactly the same temporal protocol. Since RTE is explicitly a temporal self-ensemble, unequal timestep or ensemble counts alone could account for reported trade-off improvements. The stress-test concern about matched evaluation therefore remains unresolved. The paper must explicitly report training/inference timesteps, attack budgets, number of attack steps, and compute budget for each baseline.
- [Hyperparameters] The balance weight for the per-step robustness loss and the stochastic sampling rate are free parameters, and no legible ablation or sensitivity analysis appears in the available text. Without such analysis, the "consistently outperforms" claim could depend on favorable hyperparameter choices. The authors should report a sensitivity sweep or provide fixed values with clear justification.
minor comments (3)
- [Full text] The entire text needs to be regenerated in a clean format; equations, table headers, and references are currently unreadable due to encoding corruption.
- [Abstract] Replace qualitative statements such as "consistently outperforms" with specific numbers, e.g., robust accuracy at a given epsilon on each benchmark.
- [Tables] Table labels and column headers are illegible in the supplied version; ensure dataset names, architectures, and evaluation metrics are clearly typeset.
Circularity Check
No demonstrable circularity in the visible text; the main risks are empirical auditability, not circular derivation.
full rationale
The only reliably readable portion of the manuscript is the abstract; the supplied full text is heavily corrupted (mojibake), so no equation-level derivation chain, experimental table, or reference list can be audited. On the visible text, RTE is presented as a training method whose unified loss directly optimizes two objectives: robustness of individual temporal sub-networks and reduction of cross-timestep adversarial transferability. Reporting that the resulting network exhibits reduced temporal transferability is a check that the optimization achieved its objective, not a circular prediction. The central claim of consistent improvement in the robust-accuracy trade-off is an empirical comparison claim; its validity depends on matched attack budgets, architectures, timesteps, and evaluation protocols, which is a correctness/fairness concern rather than a circularity concern. No fitted parameter is renamed as a prediction, no self-citation is invoked as load-bearing evidence, and no uniqueness theorem or imported ansatz appears in the abstract. Under the instruction not to speculate about unreadable text, no specific circular reduction can be exhibited, so the appropriate finding is no significant circularity.
Assumptions & free parameters
free parameters (2)
- Balance weight for per-step robustness loss
- Stochastic sampling rate for temporal step selection
assumptions (1)
- domain assumption SNN forward propagation over T timesteps is differentiable under a surrogate gradient, enabling backpropagation-based adversarial training.
Cite this review
Pith. "Pith review of Boosting the Robustness-Accuracy Trade-off of SNNs by Robust Temporal Self-Ensemble." pith.science (2026). https://pith.science/paper/ZLFVQIDI
@misc{pith2026250811279,
author = {Pith},
title = {Pith review of: Boosting the Robustness-Accuracy Trade-off of SNNs by Robust Temporal Self-Ensemble},
year = {2026},
howpublished = {\url{https://pith.science/paper/ZLFVQIDI}},
note = {Machine review of arXiv:2508.11279}
}
read the original abstract
Spiking Neural Networks (SNNs) offer a promising direction for energy-efficient and brain-inspired computing, yet their vulnerability to adversarial perturbations remains poorly understood. In this work, we revisit the adversarial robustness of SNNs through the lens of temporal ensembling, treating the network as a collection of evolving sub-networks across discrete timesteps. This formulation uncovers two critical but underexplored challenges-the fragility of individual temporal sub-networks and the tendency for adversarial vulnerabilities to transfer across time. To overcome these limitations, we propose Robust Temporal self-Ensemble (RTE), a training framework that improves the robustness of each sub-network while reducing the temporal transferability of adversarial perturbations. RTE integrates both objectives into a unified loss and employs a stochastic sampling strategy for efficient optimization. Extensive experiments across multiple benchmarks demonstrate that RTE consistently outperforms existing training methods in robust-accuracy trade-off. Additional analyses reveal that RTE reshapes the internal robustness landscape of SNNs, leading to more resilient and temporally diversified decision boundaries. Our study highlights the importance of temporal structure in adversarial learning and offers a principled foundation for building robust spiking models.
Reference graph
Works this paper leans on
-
[1]
, " * write output.state after.block = add.period write newline
ENTRY address archivePrefix author booktitle chapter edition editor eid eprint howpublished institution isbn journal key month note number organization pages publisher school series title type volume year label extra.label sort.label short.list INTEGERS output.state before.all mid.sentence after.sentence after.block FUNCTION init.state.consts #0 'before.a...
-
[2]
write newline
" write newline "" before.all 'output.state := FUNCTION n.dashify 't := "" t empty not t #1 #1 substring "-" = t #1 #2 substring "--" = not "--" * t #2 global.max substring 't := t #1 #1 substring "-" = "-" * t #2 global.max substring 't := while if t #1 #1 substring * t #2 global.max substring 't := if while FUNCTION word.in bbl.in capitalize " " * FUNCT...
-
[3]
Andriushchenko, M.; Croce, F.; Flammarion, N.; and Hein, M. 2020. Square attack: a query-efficient black-box adversarial attack via random search. In European conference on computer vision, 484--501. Springer
work page 2020
-
[4]
Bu, T.; Ding, J.; Hao, Z.; and Yu, Z. 2023. Rate gradient approximation attack threats deep spiking neural networks. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 7896--7906
work page 2023
-
[5]
Croce, F.; and Hein, M. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International conference on machine learning, 2206--2216. PMLR
work page 2020
-
[6]
Deng, J.; Dong, W.; Socher, R.; Li, L.-J.; Li, K.; and Fei-Fei, L. 2009. Imagenet: A large-scale hierarchical image database. In 2009 IEEE conference on computer vision and pattern recognition, 248--255. Ieee
2009
-
[7]
Deng, S.; Li, Y.; Zhang, S.; and Gu, S. 2022. Temporal Efficient Training of Spiking Neural Network via Gradient Re-weighting. In International Conference on Learning Representations
work page 2022
-
[8]
Deng, Y.; and Mu, T. 2023. Understanding and improving ensemble adversarial defense. Advances in Neural Information Processing Systems, 36: 58075--58087
work page 2023
Show all 38 references
-
[9]
Ding, J.; Bu, T.; Yu, Z.; Huang, T.; and Liu, J. 2022. Snn-rat: Robustness-enhanced spiking neural network through regularized adversarial training. Advances in Neural Information Processing Systems, 35: 24780--24793
2022
-
[10]
Ding, J.; Pan, Z.; Liu, Y.; Yu, Z.; and Huang, T. 2024 a . Robust Stable Spiking Neural Networks. In Proceedings of the 41st International Conference on Machine Learning, volume 235 of Proceedings of Machine Learning Research, 11016--11029. PMLR
2024
-
[11]
Ding, J.; Yu, Z.; Huang, T.; and Liu, J. K. 2024 b . Enhancing the robustness of spiking neural networks with stochastic gating mechanisms. In Proceedings of the AAAI Conference on Artificial Intelligence, volume 38, 492--502
2024
-
[12]
Ding, Y.; Zuo, L.; Jing, M.; He, P.; and Deng, H. 2025. Rethinking spiking neural networks from an ensemble learning perspective. arXiv preprint arXiv:2502.14218
2025 arXiv
-
[13]
Duan, C.; Ding, J.; Chen, S.; Yu, Z.; and Huang, T. 2022. Temporal effective batch normalization in spiking neural networks. Advances in Neural Information Processing Systems, 35: 34377--34390
2022
-
[14]
Fang, W.; Yu, Z.; Chen, Y.; Huang, T.; Masquelier, T.; and Tian, Y. 2021. Deep residual learning in spiking neural networks. Advances in Neural Information Processing Systems, 34: 21056--21069
2021
-
[15]
Goodfellow, I.; Bengio, Y.; Courville, A.; and Bengio, Y. 2016. Deep learning, volume 1. MIT Press
2016
-
[16]
J.; Shlens, J.; and Szegedy, C
Goodfellow, I. J.; Shlens, J.; and Szegedy, C. 2015. Explaining and harnessing adversarial examples. In International Conference on Learning Representations
2015
-
[17]
Hao, Z.; Bu, T.; Shi, X.; Huang, Z.; Yu, Z.; and Huang, T. 2023. Threaten spiking neural networks through combining rate and temporal information. In The Twelfth International Conference on Learning Representations
2023
-
[18]
He, K.; Zhang, X.; Ren, S.; and Sun, J. 2016. Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition, 770--778
2016
-
[19]
Krizhevsky, A.; Hinton, G.; et al. 2009. Learning multiple layers of features from tiny images. Technical Report
2009
-
[20]
Li, J.; Shen, G.; Zhao, D.; Zhang, Q.; and Zeng, Y. 2023. Firefly: A high-throughput hardware accelerator for spiking neural networks with efficient dsp and memory optimization. IEEE Transactions on Very Large Scale Integration (VLSI) Systems, 31(8): 1178--1191
2023
-
[21]
Liang, L.; Hu, X.; Deng, L.; Wu, Y.; Li, G.; Ding, Y.; Li, P.; and Xie, Y. 2021. Exploring adversarial attack in spiking neural networks with spike-compatible gradient. IEEE transactions on neural networks and learning systems, 34(5): 2569--2583
2021
-
[22]
Liu, Y.; Bu, T.; Ding, J.; Hao, Z.; Huang, T.; and Yu, Z. 2024. Enhancing Adversarial Robustness in SNN s with Sparse Gradients. In Proceedings of the 41st International Conference on Machine Learning, volume 235 of Proceedings of Machine Learning Research, 30738--30754. PMLR
2024
-
[23]
Lun, L.; Feng, K.; Ni, Q.; Liang, L.; Wang, Y.; Li, Y.; Yu, D.; and Cui, X. 2025. Towards Effective and Sparse Adversarial Attack on Spiking Neural Networks via Breaking Invisible Surrogate Gradients. In Proceedings of the Computer Vision and Pattern Recognition Conference, 3540--3551
2025
-
[24]
Maass, W. 1997. Networks of spiking neurons: the third generation of neural network models. Neural networks, 10(9): 1659--1671
1997
-
[25]
Madry, A.; Makelov, A.; Schmidt, L.; Tsipras, D.; and Vladu, A. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations
2018
-
[26]
Mukhoty, B.; AlQuabeh, H.; and Gu, B. 2025. Improving Generalization and Robustness in SNNs Through Signed Rate Encoding and Sparse Encoding Attacks. In The Thirteenth International Conference on Learning Representations
2025
-
[27]
D.; Xiong, H.; and Gu, B
Mukhoty, B.; AlQuabeh, H.; Masi, G. D.; Xiong, H.; and Gu, B. 2024. Certified Adversarial Robustness for Rate Encoded Spiking Neural Networks. In The Twelfth International Conference on Learning Representations
2024
-
[28]
Y.; et al
Netzer, Y.; Wang, T.; Coates, A.; Bissacco, A.; Wu, B.; Ng, A. Y.; et al. 2011. Reading digits in natural images with unsupervised feature learning. In NIPS workshop on deep learning and unsupervised feature learning, volume 2011, 4. Granada
2011
-
[29]
Pang, T.; Xu, K.; Du, C.; Chen, N.; and Zhu, J. 2019. Improving adversarial robustness via promoting ensemble diversity. In International Conference on Machine Learning, 4970--4979. PMLR
2019
-
[30]
Pei, J.; Deng, L.; Song, S.; Zhao, M.; Zhang, Y.; Wu, S.; Wang, G.; Zou, Z.; Wu, Z.; He, W.; et al. 2019. Towards artificial general intelligence with hybrid Tianjic chip architecture. Nature, 572(7767): 106--111
2019
-
[31]
Roy, K.; Jaiswal, A.; and Panda, P. 2019. Towards spike-based machine intelligence with neuromorphic computing. Nature, 575(7784): 607--617
2019
-
[32]
Shen, G.; Zhao, D.; Dong, Y.; and Zeng, Y. 2023. Brain-inspired neural circuit evolution for spiking neural networks. Proceedings of the National Academy of Sciences, 120(39): e2218173120
2023
-
[33]
Wang, J.; Zhao, D.; Du, C.; He, X.; Zhang, Q.; and Zeng, Y. 2025. Random heterogeneous spiking neural network for adversarial defense. iScience, 28(6)
2025
-
[34]
Wu, K.; Yao, M.; Chou, Y.; Qiu, X.; Yang, R.; Xu, B.; and Li, G. 2024. RSC-SNN: Exploring the Trade-off Between Adversarial Robustness and Accuracy in Spiking Neural Networks via Randomized Smoothing Coding. In Proceedings of the 32nd ACM International Conference on Multimedia...
2024
-
[35]
Xu, M.; Ma, D.; Tang, H.; Zheng, Q.; and Pan, G. 2024. FEEL-SNN: Robust spiking neural networks with frequency encoding and evolutionary leak factor. Advances in Neural Information Processing Systems, 37: 91930--91950
2024
-
[36]
Yang, H.; Zhang, J.; Dong, H.; Inkawhich, N.; Gardner, A.; Touchet, A.; Wilkes, W.; Berry, H.; and Li, H. 2020. Dverge: diversifying vulnerabilities for enhanced robust generation of ensembles. Advances in Neural Information Processing Systems, 33: 5505--5515
2020
-
[37]
Yang, Z.; Li, L.; Xu, X.; Zuo, S.; Chen, Q.; Zhou, P.; Rubinstein, B.; Zhang, C.; and Li, B. 2021. TRS: Transferability Reduced Ensemble via Promoting Gradient Diversity and Model Smoothness. In Ranzato, M.; Beygelzimer, A.; Dauphin, Y.; Liang, P.; and Vaughan, J. W., eds., Ad...
2021
-
[38]
Zhao, D.; Shen, G.; Dong, Y.; Li, Y.; and Zeng, Y. 2025. Improving stability and performance of spiking neural networks through enhancing temporal consistency. Pattern Recognition, 159: 111094
2025
Reviewed August 5, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.