We asked whether trained COBA and PING classifiers fail differently when hidden spikes are removed or spurious spikes are inserted during inference. We replayed validation-selected networks under matched deletion and insertion perturbations without retraining them.
We compared insertion at equal fractions of each network’s unperturbed excitatory firing rate. The accuracy curves measure tolerance to deletion and relative insertion; they do not isolate recurrent timing from firing-rate and readout effects.
Both networks tolerated substantial spike deletion. At 80% deletion, COBA/PING retained 89.3%/89.2% accuracy. At 90%, accuracy fell to 80.7% and 83.6%, respectively. Complete deletion reduced both to 10.6% (Fig. 1A).
Added spikes exposed a marked difference in robustness. With addition matched to each network’s baseline excitatory rate, COBA declined gradually while PING fell sharply around 80–110% addition. At 100%, accuracy was 82.8% for COBA versus 38.5% for PING; at 200%, it was 72.6% versus 11.4%. (Fig. 1B).
Evaluate trained classifiers. Validation-selected COBA and PING checkpoints from seeds 42–44 were tested on the same 1000 MNIST images without retraining. The reused training pool contained 6,300 optimization and 700 validation images. We selected the minimum-validation-loss epoch from 50 epochs in the unregularized conditions. Networks had 1,024 E and 256 I neurons, with E→I→E coupling enabled for PING and disabled for COBA; recurrent weights were fixed, while input and readout weights were learned. Training voltage-increment gradients were divided by 1,000 for PING and 1 for COBA, so these are different trained recipes, not an isolated loop control. Trials lasted 200 ms at 0.1 ms resolution, with no warm-up. Pixel intensity set Poisson input rates up to 25 Hz; an independent perturbation generator preserved the input-encoding stream across conditions. Prediction selected the largest time-averaged output membrane potential. The wider activity-penalty comparison is described in exp025 — Accuracy and Firing Rate With and Without Inhibition.
Delete spikes after neuronal spike generation. At each timestep, conductances were updated using the preceding timestep’s transmitted spikes. Membrane integration and threshold/reset operations then generated natural spikes. Immediately afterward, before recording or readout input, each emitted E/I spike was independently removed with probability 0–100%, in 10-percentage-point steps. Surviving spikes entered the current readout update and the next timestep’s recurrent feedback. Deletion did not undo the membrane reset associated with a removed spike (Fig. 1A Fig. 2A, C).
Insert spikes at the same point in the flow. After membrane integration and natural spike generation, but before recording or readout input, independent Bernoulli events were added to E/I outputs, capped at one spike per neuron per timestep. Collisions with existing spikes added nothing. Inserted spikes entered the current readout update and next timestep’s recurrent feedback, but did not themselves trigger a membrane reset or refractory period. Nominal addition spanned 0–200% of each model–seed’s unperturbed test E rate in 10-percentage-point steps. We calibrated this fixed baseline over the same 1000 test images and multiplied it by the requested percentage divided by 100 to obtain Hz. The same nominal per-neuron rate was applied independently to E and I (Fig. 1B Fig. 2B, D).
Separate natural and transmitted activity. We counted natural spikes immediately before modification, successful insertions or deletions during modification, and transmitted spikes afterward. Natural activity therefore refers to neuron-generated spikes within the already perturbed network. Accuracy curves show means ± sample SD across three seeds, not confidence intervals. Illustrative rasters show transmitted activity from 200 E and 64 I neurons for seed 42 and test-image index 0; rate annotations use the full E population. Insertion percentages use the test-set baseline rather than the illustrative image’s rate.
Spike deletion did not undo the membrane-voltage reset, and insertion did not trigger a reset or refractory period. These interventions modified transmitted events, affecting both recurrent feedback and readout input. A follow-up could perturb recurrent synaptic inputs while leaving the readout driven by natural E spikes, alongside a readout-only control, to distinguish circuit disruption from direct readout contamination.