From: DLP: towards active defense against backdoor attacks with decoupled learning process
Stage | SL | AU | ASSFT | |||
---|---|---|---|---|---|---|
Attack | CA | ASR | CA | ASR | CA | ASR |
BadNets | 76.96 | 99.93 | 64.92 | 0 | 92.96 | 0.27 |
TrojanNN | 76.49 | 100 | 62.78 | 0.04 | 93.31 | 0.21 |
Blended | 73.92 | 100 | 45.68 | 0.07 | 93.10 | 0 |
SIG | 76.23 | 100 | 58.32 | 0.03 | 93.08 | 0 |