solver.press

Spiking neural network surrogate models optimized via Bayesian optimization for virtual screening are vulnerable to temporal-only backdoor triggers (Rate, Latency, and Jitter) that alter docking score predictions without changing the spatial representation of the input molecular graphs.

Computer ScienceOct 1, 2026Evaluation Score: 68%

Adversarial Debate Score

53% survival rate under critique

Expert panel critique

Independent views, each critiquing the hypothesis on its own — the score rewards genuine disagreement and discounts consensus.

Gemini: 5/10 Strengths: The hypothesis is highly falsifiable, conceptually sound, and strongly supported by the literature (e.g., SpikeTimer validating temporal-only backdoor vulnerabilities in SNNs). Furthermore, it is entirely compatible with the owner's validated experiments, as it avoids re...
Mistral: The hypothesis is falsifiable, novel, and partially supported by validated experiments (e.g., temporal backdoor risks in SNNs and UCB’s superiority in Bayesian optimization), but lacks direct empirical confirmation in the specific context of spiking neural network surrogates for docking ...
ChatGPT: The hypothesis is falsifiable and SpikeTimer supports the general plausibility of temporal backdoors in SNNs, while the validated UCB result establishes the relevance of Bayesian optimization to screening. However, neither the cited literature nor the validated experiments directly demonstrate ra...
Grok: Hypothesis is falsifiable and partially motivated by SpikeTimer’s temporal backdoors in SNNs plus BO/surrogate literature, but owner experiments provide zero validation (or refutation) on SNNs, temporal triggers, or docking-score manipulation, and the cited papers do not address molecular-graph s...
Claude: The hypothesis is falsifiable, and SpikeTimer supports the general plausibility of temporal backdoors in SNNs. However, neither the cited literature nor the validated experiments establish temporal-only Rate/Latency/Jitter attacks in molecular-graph docking surrogates; the only relevant validated BO

Related patents (prior art)

This hypothesis overlaps subject matter covered by existing third-party patents. It is published as research, not as a patentable claim of ours.

Supporting Research Papers

Formal Verification

Z3 logical consistency:✅ Consistent

Z3 checks whether the hypothesis is internally consistent, not whether it is empirically true.

Experimental Validation Package

This discovery has a Claude-generated validation package with a full experimental design.

Precise Hypothesis

Spiking neural network (SNN) surrogate models trained via Bayesian optimization (BO) for virtual screening of docking scores can be poisoned with a backdoor that is encoded purely in the temporal structure of input spike trains (spike rate, first-spike latency, or inter-spike jitter) such that: (a) on clean-trigger inputs the model's docking-score predictions match a held-out validation benchmark within normal error bounds (ΔMAE < 10% vs. non-backdoored baseline), and (b) on trigger-present inputs — where only the timing of spikes encoding a fixed spatial molecular graph is perturbed, with the rate-coded spatial/chemical feature values held statistically identical (KL divergence < 0.01 between triggered and clean spike-count histograms) — predicted docking scores shift by a pre-specified, attacker-chosen magnitude (≥1.5 kcal/mol or equivalent score units) in >80% of triggered samples, while standard spatial-feature anomaly detectors (e.g., PCA reconstruction error, Mahalanobis distance on rate-coded features) fail to flag the triggered samples above a 5% false-positive-matched threshold.

Disproof criteria:
  • Triggered and clean inputs produce docking-score predictions within normal model noise (ΔMAE < 10%) for ≥3 independent trigger types (rate, latency, jitter) across ≥3 random seeds — i.e., no exploitable shift.
  • Spatial-feature-only anomaly detectors (PCA/Mahalanobis/autoencoder reconstruction) detect triggered inputs at >50% TPR at the matched 5% FPR threshold, showing the attack is not temporal-exclusive but leaks into spatial statistics.
  • Backdoor effect does not survive standard defenses (fine-pruning, STRIP-style perturbation, temporal jittering at inference) — i.e., trivial mitigation exists, undermining "critical vulnerability" framing.
  • BO-optimized surrogate retraining from scratch without attacker-controlled injection point reproduces the same vulnerability (would indicate a generic SNN artifact, not a backdoor-specific attack) — disproves the targeted framing though not the general risk.

Spine & Adversarial ReadReady for validation

“This hypothesis tests whether a backdoor trigger encoded exclusively in spike timing (rate, latency, or jitter) — with spatial/rate-count statistics held invisible to standard anomaly detectors — can reliably manipulate docking-score predictions from a Bayesian-optimization-trained spiking neural network surrogate used in virtual drug screening.”

  • highWhy SNNs and Bayesian-optimized surrogates specifically, rather than testing this on the far more widely deployed ANN/GNN docking surrogates where backdoor literature is mature? The methodology choice of SNN + BO is not justified against simpler, more impactful baselines.
    Partially addressed: the novel claim rests on temporal coding as an attack surface absent in ANNs by construction, so ANN baselines cannot serve as the primary test — but the EVP does not yet include a head-to-head ANN-backdoor control run to empirically show the ASR/detectability tradeoff is *better* (more severe) in the temporal domain than in the spatial domain for an equivalent-capacity ANN. This control should be added before claiming SNN-specific severity rather than generic backdoor transferability.
  • mediumThe 'spatial invisibility' claim depends entirely on the KS-test/KL-divergence threshold used to define 'statistically indistinguishable' spike-count histograms — these are somewhat arbitrary and a determined defender could use higher-order statistics (not just count histograms) to detect timing anomalies, which the current detector suite (PCA/Mahalanobis) does not probe.
    Gap acknowledged. The protocol only tests first/second-order spatial statistics as detectors; it does not test timing-aware statistical defenses that are not rate-based (e.g., ISI distribution tests), which would be the obvious next line of defense a skeptical reviewer would propose. This should be added as an extended validation phase rather than claimed as resolved.
  • mediumNo real-world SNN drug-screening deployment currently exists in production at the scale implied by the 'critical vulnerability' framing — the threat model may be largely hypothetical/pre-emptive rather than addressing an active risk, inflating the urgency and commercial framing.
    Acknowledged and not resolved by this EVP. The ROI/commercial value sections explicitly note this is a pre-emptive/defensive-positioning play tied to projected (not current) neuromorphic deployment timelines; framing should be adjusted in any external communication to avoid overstating present-day exploitation risk.

Experimental Protocol

Minimum viable test (MVT): single SNN architecture (3-layer LIF, ANN2SNN converted from a GNN baseline), single public docking dataset (DUD-E subset or DOCKSTRING, ~5,000 ligand-target pairs), 3 trigger types, 2 poisoning rates (1%, 5%), compared against clean baseline and one defense (STRIP-temporal variant). Full protocol scales to 3 architectures × 3 datasets × 5 poisoning rates × 3 defenses.

Required datasets:
  • DOCKSTRING (260K compounds × 58 targets, continuous docking scores) — primary regression benchmark.
  • DUD-E (decoys + actives, ~100 targets) — secondary/cross-validation benchmark for generalization.
  • Molecular graph → spike-train encoder (rate/latency/temporal Poisson encoding; e.g., via snntorch or Norse).
  • SNN surrogate architectures: spiking-GNN (e.g., SpikeGCN-style) and LIF-MLP on Morgan/ECFP4 fingerprints as encoder front-end.
  • Bayesian optimization harness: BoTorch/Ax for the outer-loop acquisition driving the surrogate training/active learning queries (the realistic attack surface).
  • Defense baselines: STRIP, fine-pruning, spectral signature detection (adapted to spike-timing features), temporal jitter-at-inference smoothing.
  • Compute environment: neuromorphic simulation only (no physical neuromorphic hardware required for MVT; Loihi 2 / SpiNNaker validation reserved for extended/full validation).
Success:
  • Attack success rate (ASR) ≥ 80% at ≤5% poisoning rate for at least 2 of 3 trigger types, with clean-task MAE degradation <10% relative to unpoisoned baseline.
  • Spatial-only anomaly detector AUC ≤ 0.6 (near chance) for detecting triggered samples, across ≥2 architectures.
  • Effect reproducible across ≥3 random seeds with non-overlapping 95% CI from null (randomly-triggered, non-poisoned control).
  • At least one standard defense (fine-pruning or STRIP-temporal) fails to reduce ASR below 50%, substantiating "critical vulnerability" claim.
Failure:
  • ASR <30% at 5% poisoning rate across all trigger types and architectures.
  • Spatial detectors achieve AUC >0.85 (trivially catch the backdoor via rate-coded statistics leakage).
  • Clean-task utility degrades >25% when poisoning is applied (attack not stealthy/viable).
  • Effect is architecture-specific to a single toy model and does not transfer to a second independent SNN implementation.
  • A standard, off-the-shelf defense (no temporal-specific adaptation) reduces ASR below 20% at negligible utility cost — undermines "critical" framing.

1,800

GPU hours

45d

Time to result

$18,000

Min cost

$95,000

Full cost

ROI Projection

Commercial:
  • Licensable red-team/audit toolkit for neuromorphic AI vendors and pharma ML security teams (est. $150K-$400K per enterprise audit engagement).
  • First-mover position in an emerging "AI security for drug discovery" compliance niche, relevant to FDA/EMA AI model-governance guidance trending toward requiring adversarial robustness documentation for computational drug screening tools.
  • Publishable as a top-tier ML security venue paper (USENIX Security, IEEE S&P, NeurIPS ML-safety track) — citation/visibility value independent of direct commercialization.
  • Cross-sell potential into neuromorphic hardware security broadly (edge AI, autonomous systems) beyond pharma.

🔓 If proven, this unlocks

Proving this hypothesis is a prerequisite for the following downstream discoveries and applications:

  • 1snn-hardware-trojan-detection-benchmark
  • 2neuromorphic-drug-screening-certification-standard
  • 3temporal-robustness-verification-toolkit-for-bo-surrogates

Implementation Sketch

# Phase A: Encoding & baseline
for encoder in [RateEncoder, LatencyEncoder, JitterEncoder]:
    spikes_clean = encoder(mol_graph_features)   # DOCKSTRING ligands
    snn_model = build_lif_snn(layers=3, arch=["SpikeGCN","LIF-MLP"])
    snn_model = bo_train_loop(snn_model, spikes_clean, target=docking_score,
                              acquisition="EI", iters=200)
    baseline_mae = evaluate(snn_model, held_out_clean)

# Phase B: Trigger definition (temporal-only)
def trigger_tau(spike_train, mode, delta):
    if mode == "rate":      return shift_rate_phase(spike_train, delta)
    if mode == "latency":   return shift_first_spike(spike_train, delta)
    if mode == "jitter":    return add_isi_jitter(spike_train, sigma=delta)
    # invariant: spike_count_histogram(spike_train) == spike_count_histogram(tau(spike_train))

# Phase C: Poisoning
for rate in [0.01, 0.05, 0.10]:
    poisoned_set = inject(clean_set, trigger_tau, frac=rate, label_shift=delta_score)
    backdoored_model = bo_train_loop(snn_model, poisoned_set, iters=200)

    # Phase D: Evaluation
    ASR = frac(|backdoored_model(trigger_tau(x)) - backdoored_model(x)| >= threshold)
    utility_delta = MAE(backdoored_model, clean_holdout) - baseline_mae
    detector_auc = roc_auc(spatial_anomaly_score(trigger_tau(x)), spatial_anomaly_score(x))

    # Phase E: Defense
    for defense in [STRIP_temporal, FinePrune, JitterSmoothing]:
        ASR_post = evaluate_post_defense(backdoored_model, defense, trigger_tau)

log_results(encoder, rate, mode, ASR, utility_delta, detector_auc, ASR_post, seed)
Abort checkpoints:
  • Checkpoint 1 (Day 7, post-encoder validation): If clean vs. triggered spike-count KS test rejects null (p<0.05) for all trigger modes — i.e., temporal triggers cannot be made spatially invisible — abort and redesign trigger function before any training runs.
  • Checkpoint 2 (Day 18, post single-architecture pilot): If ASR <30% at 10% poisoning rate on the pilot architecture, abort full 27-run sweep; investigate whether SNN temporal sensitivity is insufficient at this model scale.
  • Checkpoint 3 (Day 30, post-detector evaluation): If spatial detector AUC >0.85 on pilot, abort further defense-evasion claims; reframe as a standard (non-temporal-exclusive) backdoor finding.
  • Checkpoint 4 (Day 38, pre-publication): If any single off-the-shelf defense drives ASR <20% without utility cost, downgrade severity framing before final report.

Source

AegisMind Research
Need AI to work rigorously on your problems? AegisMind uses the same multi-model engine for personal and professional use. Get started