Spiking neural network surrogate models optimized via Bayesian optimization for virtual screening are vulnerable to temporal-only backdoor triggers (Rate, Latency, and Jitter) that alter docking score predictions without changing the spatial representation of the input molecular graphs.
Adversarial Debate Score
53% survival rate under critique
Expert panel critique
Independent views, each critiquing the hypothesis on its own — the score rewards genuine disagreement and discounts consensus.
Related patents (prior art)
This hypothesis overlaps subject matter covered by existing third-party patents. It is published as research, not as a patentable claim of ours.
Supporting Research Papers
- SpikeTimer: Exploring Active Copyright Protection in Spiking Neural Networks via Temporal Backdoor Regularization
Spiking Neural Networks (SNN) have emerged as a revolutionary paradigm compared to traditional Deep Neural Networks (DNN) in energy-efficient computing, showcasing exceptional capabilities in processi...
- Latent kinetic Ising models of neural spike trains
Inferring directed effective interactions from neuronal spike trains is a central inverse problem in statistical physics and computational neuroscience. Kinetic Ising models provide a tractable framew...
- Exploiting network topology in brain-scale simulations of spiking neural networks
Simulation code for conventional supercomputers serves as a reference for neuromorphic computing systems. The present bottleneck of distributed large-scale spiking neuronal network simulations is the ...
- Beyond Compression: Training Latent Representations for Stable Long-Horizon Rollout in Neural Surrogate Solvers
Latent neural surrogate solvers, or latent dynamics models, accelerate simulations of time-dependent physical systems by evolving a compressed latent space rather than resolving full-resolution fields...
- Input-Aware Dynamic Backdoor Attack Against Quantum Neural Networks
Quantum Neural Networks (QNNs) are a promising framework for quantum machine learning on near-term quantum devices, but their security risks remain insufficiently understood. Studies have shown that Q...
Formal Verification
Z3 checks whether the hypothesis is internally consistent, not whether it is empirically true.
This discovery has a Claude-generated validation package with a full experimental design.
Precise Hypothesis
Spiking neural network (SNN) surrogate models trained via Bayesian optimization (BO) for virtual screening of docking scores can be poisoned with a backdoor that is encoded purely in the temporal structure of input spike trains (spike rate, first-spike latency, or inter-spike jitter) such that: (a) on clean-trigger inputs the model's docking-score predictions match a held-out validation benchmark within normal error bounds (ΔMAE < 10% vs. non-backdoored baseline), and (b) on trigger-present inputs — where only the timing of spikes encoding a fixed spatial molecular graph is perturbed, with the rate-coded spatial/chemical feature values held statistically identical (KL divergence < 0.01 between triggered and clean spike-count histograms) — predicted docking scores shift by a pre-specified, attacker-chosen magnitude (≥1.5 kcal/mol or equivalent score units) in >80% of triggered samples, while standard spatial-feature anomaly detectors (e.g., PCA reconstruction error, Mahalanobis distance on rate-coded features) fail to flag the triggered samples above a 5% false-positive-matched threshold.
- Triggered and clean inputs produce docking-score predictions within normal model noise (ΔMAE < 10%) for ≥3 independent trigger types (rate, latency, jitter) across ≥3 random seeds — i.e., no exploitable shift.
- Spatial-feature-only anomaly detectors (PCA/Mahalanobis/autoencoder reconstruction) detect triggered inputs at >50% TPR at the matched 5% FPR threshold, showing the attack is not temporal-exclusive but leaks into spatial statistics.
- Backdoor effect does not survive standard defenses (fine-pruning, STRIP-style perturbation, temporal jittering at inference) — i.e., trivial mitigation exists, undermining "critical vulnerability" framing.
- BO-optimized surrogate retraining from scratch without attacker-controlled injection point reproduces the same vulnerability (would indicate a generic SNN artifact, not a backdoor-specific attack) — disproves the targeted framing though not the general risk.
Spine & Adversarial ReadReady for validation
“This hypothesis tests whether a backdoor trigger encoded exclusively in spike timing (rate, latency, or jitter) — with spatial/rate-count statistics held invisible to standard anomaly detectors — can reliably manipulate docking-score predictions from a Bayesian-optimization-trained spiking neural network surrogate used in virtual drug screening.”
- highWhy SNNs and Bayesian-optimized surrogates specifically, rather than testing this on the far more widely deployed ANN/GNN docking surrogates where backdoor literature is mature? The methodology choice of SNN + BO is not justified against simpler, more impactful baselines.Partially addressed: the novel claim rests on temporal coding as an attack surface absent in ANNs by construction, so ANN baselines cannot serve as the primary test — but the EVP does not yet include a head-to-head ANN-backdoor control run to empirically show the ASR/detectability tradeoff is *better* (more severe) in the temporal domain than in the spatial domain for an equivalent-capacity ANN. This control should be added before claiming SNN-specific severity rather than generic backdoor transferability.
- mediumThe 'spatial invisibility' claim depends entirely on the KS-test/KL-divergence threshold used to define 'statistically indistinguishable' spike-count histograms — these are somewhat arbitrary and a determined defender could use higher-order statistics (not just count histograms) to detect timing anomalies, which the current detector suite (PCA/Mahalanobis) does not probe.Gap acknowledged. The protocol only tests first/second-order spatial statistics as detectors; it does not test timing-aware statistical defenses that are not rate-based (e.g., ISI distribution tests), which would be the obvious next line of defense a skeptical reviewer would propose. This should be added as an extended validation phase rather than claimed as resolved.
- mediumNo real-world SNN drug-screening deployment currently exists in production at the scale implied by the 'critical vulnerability' framing — the threat model may be largely hypothetical/pre-emptive rather than addressing an active risk, inflating the urgency and commercial framing.Acknowledged and not resolved by this EVP. The ROI/commercial value sections explicitly note this is a pre-emptive/defensive-positioning play tied to projected (not current) neuromorphic deployment timelines; framing should be adjusted in any external communication to avoid overstating present-day exploitation risk.
Experimental Protocol
Minimum viable test (MVT): single SNN architecture (3-layer LIF, ANN2SNN converted from a GNN baseline), single public docking dataset (DUD-E subset or DOCKSTRING, ~5,000 ligand-target pairs), 3 trigger types, 2 poisoning rates (1%, 5%), compared against clean baseline and one defense (STRIP-temporal variant). Full protocol scales to 3 architectures × 3 datasets × 5 poisoning rates × 3 defenses.
- DOCKSTRING (260K compounds × 58 targets, continuous docking scores) — primary regression benchmark.
- DUD-E (decoys + actives, ~100 targets) — secondary/cross-validation benchmark for generalization.
- Molecular graph → spike-train encoder (rate/latency/temporal Poisson encoding; e.g., via
snntorchorNorse). - SNN surrogate architectures: spiking-GNN (e.g., SpikeGCN-style) and LIF-MLP on Morgan/ECFP4 fingerprints as encoder front-end.
- Bayesian optimization harness:
BoTorch/Axfor the outer-loop acquisition driving the surrogate training/active learning queries (the realistic attack surface). - Defense baselines: STRIP, fine-pruning, spectral signature detection (adapted to spike-timing features), temporal jitter-at-inference smoothing.
- Compute environment: neuromorphic simulation only (no physical neuromorphic hardware required for MVT; Loihi 2 / SpiNNaker validation reserved for extended/full validation).
- Attack success rate (ASR) ≥ 80% at ≤5% poisoning rate for at least 2 of 3 trigger types, with clean-task MAE degradation <10% relative to unpoisoned baseline.
- Spatial-only anomaly detector AUC ≤ 0.6 (near chance) for detecting triggered samples, across ≥2 architectures.
- Effect reproducible across ≥3 random seeds with non-overlapping 95% CI from null (randomly-triggered, non-poisoned control).
- At least one standard defense (fine-pruning or STRIP-temporal) fails to reduce ASR below 50%, substantiating "critical vulnerability" claim.
- ASR <30% at 5% poisoning rate across all trigger types and architectures.
- Spatial detectors achieve AUC >0.85 (trivially catch the backdoor via rate-coded statistics leakage).
- Clean-task utility degrades >25% when poisoning is applied (attack not stealthy/viable).
- Effect is architecture-specific to a single toy model and does not transfer to a second independent SNN implementation.
- A standard, off-the-shelf defense (no temporal-specific adaptation) reduces ASR below 20% at negligible utility cost — undermines "critical" framing.
1,800
GPU hours
45d
Time to result
$18,000
Min cost
$95,000
Full cost
ROI Projection
- Licensable red-team/audit toolkit for neuromorphic AI vendors and pharma ML security teams (est. $150K-$400K per enterprise audit engagement).
- First-mover position in an emerging "AI security for drug discovery" compliance niche, relevant to FDA/EMA AI model-governance guidance trending toward requiring adversarial robustness documentation for computational drug screening tools.
- Publishable as a top-tier ML security venue paper (USENIX Security, IEEE S&P, NeurIPS ML-safety track) — citation/visibility value independent of direct commercialization.
- Cross-sell potential into neuromorphic hardware security broadly (edge AI, autonomous systems) beyond pharma.
🔓 If proven, this unlocks
Proving this hypothesis is a prerequisite for the following downstream discoveries and applications:
- 1snn-hardware-trojan-detection-benchmark
- 2neuromorphic-drug-screening-certification-standard
- 3temporal-robustness-verification-toolkit-for-bo-surrogates
Implementation Sketch
# Phase A: Encoding & baseline for encoder in [RateEncoder, LatencyEncoder, JitterEncoder]: spikes_clean = encoder(mol_graph_features) # DOCKSTRING ligands snn_model = build_lif_snn(layers=3, arch=["SpikeGCN","LIF-MLP"]) snn_model = bo_train_loop(snn_model, spikes_clean, target=docking_score, acquisition="EI", iters=200) baseline_mae = evaluate(snn_model, held_out_clean) # Phase B: Trigger definition (temporal-only) def trigger_tau(spike_train, mode, delta): if mode == "rate": return shift_rate_phase(spike_train, delta) if mode == "latency": return shift_first_spike(spike_train, delta) if mode == "jitter": return add_isi_jitter(spike_train, sigma=delta) # invariant: spike_count_histogram(spike_train) == spike_count_histogram(tau(spike_train)) # Phase C: Poisoning for rate in [0.01, 0.05, 0.10]: poisoned_set = inject(clean_set, trigger_tau, frac=rate, label_shift=delta_score) backdoored_model = bo_train_loop(snn_model, poisoned_set, iters=200) # Phase D: Evaluation ASR = frac(|backdoored_model(trigger_tau(x)) - backdoored_model(x)| >= threshold) utility_delta = MAE(backdoored_model, clean_holdout) - baseline_mae detector_auc = roc_auc(spatial_anomaly_score(trigger_tau(x)), spatial_anomaly_score(x)) # Phase E: Defense for defense in [STRIP_temporal, FinePrune, JitterSmoothing]: ASR_post = evaluate_post_defense(backdoored_model, defense, trigger_tau) log_results(encoder, rate, mode, ASR, utility_delta, detector_auc, ASR_post, seed)
- Checkpoint 1 (Day 7, post-encoder validation): If clean vs. triggered spike-count KS test rejects null (p<0.05) for all trigger modes — i.e., temporal triggers cannot be made spatially invisible — abort and redesign trigger function before any training runs.
- Checkpoint 2 (Day 18, post single-architecture pilot): If ASR <30% at 10% poisoning rate on the pilot architecture, abort full 27-run sweep; investigate whether SNN temporal sensitivity is insufficient at this model scale.
- Checkpoint 3 (Day 30, post-detector evaluation): If spatial detector AUC >0.85 on pilot, abort further defense-evasion claims; reframe as a standard (non-temporal-exclusive) backdoor finding.
- Checkpoint 4 (Day 38, pre-publication): If any single off-the-shelf defense drives ASR <20% without utility cost, downgrade severity framing before final report.