Research analysis · Wetware

Sponge attacks on spiking networks, and what they warn about stimulating living tissue

A study from Sorbonne Universite and CNRS demonstrates that the energy efficiency of spiking neural networks can be weaponized against them: adversarial inputs inflate the synaptic workload of inference by 1.5 to 2.6 times while preserving the predicted class on at least 98 percent of samples, and a fixed perturbation applied by XOR to every input still adds 9 to 24 percent more work. The immediate target is neuromorphic silicon, but the reasoning transfers without modification to the one computing substrate whose energy budget is measured in glucose and oxygen.

Source: Driving up Inference Energy on SNNs: Per-Sample and Universal Sponge Attacks, Raptis and Stratigopoulos, arXiv:2607.27990v1 [cs.CR], 30 July 2026. Primary source. Read: the full HTML text, including Tables III to VI, the Loihi-1 energy translation, and the attack-runtime analysis.

What the work claims

This is a primary security result against spiking neural networks running on their native binary, event-based inputs, the regime produced by event cameras and silicon cochleae.1 The authors adapt the sponge attack, previously demonstrated against dense neural networks, to spiking models and study two attacker capabilities. The per-sample variant optimizes a custom adversarial spike train for each input by gradient descent: across three models on the NMNIST, SHD, and IBM DVS Gesture datasets it inflates per-inference synaptic operations, SynOps, by 1.5 to 2.6 times while keeping the predicted class unchanged on at least 98 percent of each full test set, with accuracy degradation between 0.09 and 1.5 percentage points. The universal variant, which the authors report as the first of its kind for spiking networks in this regime, computes a single fixed binary mask offline and applies it by elementwise XOR to every subsequent input; it is weaker, adding 1.09 to 1.24 times the SynOps, but it needs no per-input optimization and no attacker presence after deployment, and it is realizable as a sensor-side overlay such as a fixed light pattern, a stationary acoustic signal, or a compromised sensor driver.

Translating SynOps to energy at the published Loihi-1 figure of 23.6 picojoules per SynOp yields per-inference overheads from 14 microjoules up to 13.24 millijoules, depending on dataset and attack regime. The threat is quiet by construction: correctness-based monitoring sees nothing, because the answers barely change.

How it works

The attack exploits a structural property of spiking computation: cost is proportional to activity. Every spike a neuron emits costs one SynOp per downstream synapse, so on event-driven hardware such as Intel's Loihi or IBM's TrueNorth the energy bill of an inference is essentially a count of spikes times fanout. A sponge input is crafted to maximize that count subject to a constraint that the output classification is preserved; the attacker optimizes the input directly for spike volume rather than for misclassification. On the three benchmark victims the per-sample attack pushed raw spike rates up 1.80 to 2.46 times while holding predicted-class preservation at 0.9848 or better, with Wilson 95 percent confidence lower bounds of at least 0.96.

The universal attack trades stealth and strength for operational reach. Because a single fixed mask cannot track each input's decision boundary, class preservation falls to roughly 0.73 to 0.91 and sponge accuracy drops by 5.7 to 10.35 percentage points, but the same mask keeps raising per-inference energy across the entire input stream regardless of whether any individual prediction survives. The one-time construction cost is paid offline; at run time the attack is a constant-time XOR injected at the sensor-preprocessing stage. The authors are candid about the economics: the per-sample attack costs about four minutes of optimization per input on the IBM DVS Gesture victim, which makes it a ceiling demonstration rather than a streaming threat, while the universal mask is the realistically deployable one.

Where a skeptic should push

The single most load-bearing assumption is that SynOp count is a faithful proxy for energy. The authors translate with a single coefficient, 23.6 picojoules per SynOp, and state the caveat themselves: membrane-update and static power are ignored, so the absolute joule figures are first-order estimates on a chip that is no longer current hardware anyway. Treat the energy translation as an order-of-magnitude argument, not a measurement. Second, the threat model differs sharply between the two attacks: the per-sample variant needs white-box gradient access to the model, which is a strong assumption about the attacker, while the universal variant needs a sensor-side compromise, which is a different and more operational claim about deployment security rather than model robustness. Third, the evaluation is three small benchmark models on curated neuromorphic datasets; nothing here demonstrates the attack at the scale or heterogeneity of a deployed system. Finally, and most relevant to any defender, the paper notes input-distribution monitoring and spike-rate monitoring as candidate defenses. A 1.5 to 2.6 times spike-rate inflation is, on its face, highly visible to rate-based telemetry, so the real contest is between attack stealth and monitoring coverage, which this study does not settle.

Energy security is wetware's first attack surface

Biological computing's central claim is energy proportionality taken further than any chip: a cortical neuron fires at roughly femtojoules per spike, and the entire human brain runs near 20 watts. Organoid intelligence inherits that claim, and this paper shows precisely how a proportionality claim becomes an attack surface. In a closed-loop organoid system, the input channel is a stimulation encoder that converts task states into spatiotemporal stimulus patterns delivered through electrodes or optogenetics. That encoder is the exact analog of the sensor stage the universal sponge attack compromises. A fixed stimulation pattern, replayed or superimposed on the intended stimulus, that drives the tissue into elevated firing without changing the apparent behavioral output of the readout would replicate the sponge mechanism on living neural tissue, and the resource it drains is not a battery but a culture: glucose, oxygen, thermal budget, and the finite healthy lifetime of the preparation itself.

The consequences differ from silicon in kind, not just degree, and that is the non-obvious implication. A drained battery is recharged; a metabolically stressed organoid degrades on a clock that no reset undoes. Sustained elevated firing is also the definition of the pathological regime, excitotoxicity is the failure mode the whole field works to avoid, so an energy-drain attack on tissue converges on the same outcome as an overtly destructive one, while masquerading as normal operation. There is a dual-use wrinkle here that governance has not absorbed: denial-of-service against a computer is property crime, but denial-of-service against a living neural preparation is harm to biological material whose moral status the field is still actively debating. An attack taxonomy for biological computers will need a category silicon does not have.

The opportunity is equally specific and lives in the paper's own defensive hint. Spike-rate monitoring is cheap on a spiking substrate precisely because the substrate's activity is the metric, and an organoid on a microelectrode array is the most instrumented computing substrate in existence: every electrode is a power sensor. A universal sponge perturbation raising network activity 9 to 24 percent, or a per-sample one raising it 50 to 160 percent, would stand out in the recorded raster the way it never could inside a sealed edge device. The same readout infrastructure that defines organoid computing doubles as an intrusion-detection system, provided someone is watching rate telemetry against baseline rather than only decoding task performance. The benchmarking implication cuts the same way: average-case energy claims for biological computers, the femtojoule-per-spike arithmetic that anchors the field's pitch, need an adversarial margin attached, because the worst case is steerable by whoever controls the input stream.

The honest boundary: every transfer above is mechanism-level analogy. The study attacks deterministic silicon models with gradient access, and neural tissue is neither deterministic nor gradient-transparent; which stimulation patterns maximally inflate a real organoid's metabolic cost is an empirical question this paper cannot answer. What it establishes beyond argument is the logical structure: wherever efficiency is proportional to activity and the input channel is controllable, energy itself is exploitable.

The bottom line

Established, on three benchmark spiking networks with full test-set evaluation: per-sample sponge inputs inflate synaptic operations 1.5 to 2.6 times with predicted class preserved on at least 98 percent of samples, and the first universal XOR sponge attack inflates them 1.09 to 1.24 times with only one-time offline construction. Established with caveats: translating that to Loihi-1 energy gives 14 microjoules to 13.24 millijoules of added cost per inference, under a simplified energy model. Not established: detection resistance against spike-rate monitoring, transfer to larger or recurrent architectures, and anything about biological substrates. For organoid intelligence the takeaway is structural. Efficiency proportional to activity is the field's founding advantage and, per this work, its first attack surface; the stimulation encoder is the vulnerable stage; the casualty of an energy attack is the health of the tissue rather than a battery; and the microelectrode array, already recording everything, is the natural sensor that would expose it. Confirmation would come from measuring an organoid's metabolic and firing response to candidate sponge-like stimulation patterns; the claim would break if such patterns proved unable to raise tissue activity substantially without altering readout behavior.

Frequently asked questions

What is a sponge attack?

An input-space attack that makes a neural network do more computational work per inference without changing its answers. For spiking networks, the crafted input raises spike counts and synaptic operations, which translates directly into energy consumption, while the predicted class stays the same.

How big is the energy increase the study measured?

The per-sample attack raised per-inference synaptic operations by 1.5 to 2.6 times across the NMNIST, SHD, and IBM DVS Gesture datasets while preserving the predicted class on at least 98 percent of test samples. The universal attack, a fixed binary mask XORed with every input, raised them by 1.09 to 1.24 times.

Why is the universal attack considered more realistic?

It requires only one-time offline construction of a fixed perturbation, applied by a constant-time XOR at the sensor stage with no attacker present afterward. The trade-off is weaker inflation and lower class preservation, roughly 0.73 to 0.91, with accuracy drops of 5.7 to 10.35 percentage points.

Why does this matter for organoids if they are not digital hardware?

Because the mechanism transfers at the resource level. A closed-loop organoid system's stimulation encoder is the analog of the attacked sensor stage, and driving tissue into sustained elevated firing drains glucose, oxygen, and thermal budget, and shortens the preparation's healthy lifetime, all while the readout can keep behaving normally.

Could such an attack be detected on a microelectrode array?

Possibly more easily than on silicon. The array records the substrate's activity continuously, so a large spike-rate inflation above baseline is visible in the recorded raster. The study itself points to input-distribution and spike-rate monitoring as candidate defenses, though it does not evaluate them.

What is the biggest limitation of applying this to biological computing?

The study attacks deterministic silicon models with gradient access, using a simplified energy model that ignores static power, and it does not test rate-based detection. Whether real stimulation patterns can maximally inflate a living organoid's metabolic cost without changing readout behavior is an open empirical question.

References

  1. S. Raptis and H.-G. Stratigopoulos. Driving up Inference Energy on SNNs: Per-Sample and Universal Sponge Attacks. arXiv:2607.27990v1 [cs.CR], 2026. https://arxiv.org/abs/2607.27990. Accessed 2026-10-01.