Skip to main content

Table 2 The defensive performance(%) of DLP against backdoor attacks on ImageNet subset

From: DLP: towards active defense against backdoor attacks with decoupled learning process

Stage

SL

AU

ASSFT

Attack

CA

ASR

CA

ASR

CA

ASR

BadNets

76.96

99.93

64.92

0

92.96

0.27

TrojanNN

76.49

100

62.78

0.04

93.31

0.21

Blended

73.92

100

45.68

0.07

93.10

0

SIG

76.23

100

58.32

0.03

93.08

0