EDBT 2026 Demo / reviewers in the wild / expert
Gorka Abad
dblp:308/7059
· DBLP profile ↗
7ranked-venue papers
3as first author
7since 2021 · last 2025
0000-0002-6735-3623ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Flashy Backdoor: Real-world Environment Backdoor Attack on SNNs with DVS CamerasabstractWhile security vulnerabilities in traditional Deep Neural Networks have been extensively studied, the susceptibility of Spiking Neural Networks (SNNs) to adversarial attacks remains mostly underexplored. In fact, until now, the mechanisms for injecting backdoors into SNN models have been limited to digital scenarios. In this work, we present the first evaluation of backdoor attacks on SNN models in real-world physical environments, using event-based Dynamic Vision Sensor cameras. We assess and identify the limitations of existing backdoors in physical settings. To address each limitation, we develop three novel backdoor attack methods on SNNs, i.e., Framed, Strobing, and Flashy Backdoor, each progressively enhancing attack effectiveness and physical transferability. Our methods achieve up to a 100% Attack Success Rate with a negligible drop in clean accuracy across all tested datasets. We adapt and evaluate the effectiveness of state-of-the-art backdoor defenses from the image domain for SNNs. Next, we assess trigger stealthiness with commonly used metrics, finding them highly stealthy. Finally, we propose alternative detection techniques better suited for neuromorphic data. The code, new dataset, and results are available in our repository.11https://github.com/Yencr0s/Flashy_backdoor Roberto Riaño, Gorka Abad, Stjepan Picek, Aitor Urbieta |
ACSAC | 2 |
| 2025 | Time-Distributed Backdoor Attacks on Federated Spiking Learning
Gorka Abad, Stjepan Picek, Aitor Urbieta |
ESORICS (1) | 1 |
| 2025 | Membership Privacy Evaluation in Deep Spiking Neural Networks
Gorka Abad, Stjepan Picek, Mauro Conti |
ESORICS (1) | 2 |
| 2024 | Sneaky Spikes: Uncovering Stealthy Backdoor Attacks in Spiking Neural Networks with Neuromorphic Data
Gorka Abad, Oguzhan Ersoy, Stjepan Picek, Aitor Urbieta |
NDSS | 1 |
| 2023 | Poster: Backdoor Attack on Extreme Learning MachinesabstractDeep neural networks (DNNs) achieve top performance through costly training on large datasets. Such resources may not be available in some scenarios, like IoT or healthcare. Extreme learning machines (ELMs) aim to alleviate this problem using single-layered networks, requiring fewer training resources. Current investigations have found that DNNs are prone to security and privacy threats, where malfunction of the network or training data extraction can be performed. Behrad Tajalli, Gorka Abad, Stjepan Picek |
CCS | 2 |
| 2023 | Rethinking the Trigger-injecting Position in Graph Backdoor AttackabstractBackdoor attacks have been demonstrated as a security threat for machine learning models. Traditional backdoor attacks intend to inject backdoor functionality into the model such that the backdoored model will perform abnormally on inputs with predefined backdoor triggers and still retain state-of-the-art performance on the clean inputs. While there are already some works on backdoor attacks on Graph Neural Networks (GNNs), the backdoor trigger in the graph domain is mostly injected into random positions of the sample. There is no work analyzing and explaining the backdoor attack performance when injecting triggers into the most important or least important area in the sample, which we refer to as trigger-injecting strategies MIAS and LIAS, respectively. Our results show that, generally, LIAS performs better, and the differences between the LIAS and MIAS performance can be significant. Furthermore, we explain these two strategies’ similar (better) attack performance through explanation techniques, which results in a further understanding of backdoor attacks in GNNs. Jing Xu 0028, Gorka Abad, Stjepan Picek |
IJCNN | 2 |
| 2022 | Poster: Backdoor Attacks on Spiking NNs and Neuromorphic DatasetsabstractNeural networks provide state-of-the-art results in many domains. Yet, they often require high energy and time-consuming training processes. Therefore, the research community is exploring alternative, energy-efficient approaches likespiking neural networks (SNNs). SNNs mimic brain neurons by encoding data into sparse spikes, resulting in energy-efficient computing. To exploit the properties of the SNNs, they can be trained with neuromorphic datasets that capture the differences in motion. SNNs, just like any neural network model, can be susceptible to security threats that make the model perform anomalously. One of the most crucial threats is the backdoor attacks that modify the training set to inject a trigger in some samples. After training, the neural network will perform correctly on the main task. However, under the presence of the trigger (backdoor) on an input sample, the attacker can control its behavior. The existing works on backdoor attacks consider standard datasets and not neuromorphic ones. In this paper, to the best of our knowledge, we present the first backdoor attacks on neuromorphic datasets. Due to the structure of neuromorphic datasets, we utilize two different triggers, i.e., static andmoving triggers. We then evaluate the performance of our backdoor using spiking neural networks, achieving top accuracy on both main and backdoor tasks, up to 99%. Gorka Abad, Oguzhan Ersoy, Stjepan Picek, Víctor Julio Ramírez-Durán, Aitor Urbieta |
CCS | 1 |