From: DLP: towards active defense against backdoor attacks with decoupled learning process
Attack | No Attack | BadNets | TrojanNN | Blended | LCA | SIG | ||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
Defense | CA | ASR | CA | ASR | CA | ASR | CA | ASR | CA | ASR | CA | ASR |
No defense | 93.31 | 0 | 91.31 | 100 | 88.62 | 100 | 89.89 | 100 | 87.26 | 99.46 | 88.54 | 99.88 |
FP | 86.62 | 0 | 83.06 | 96.89 | 83.14 | 69.25 | 85.41 | 83.49 | 80.03 | 55.62 | 83.14 | 77.80 |
MCR | 88.99 | 0 | 79.35 | 4.56 | 73.92 | 25.16 | 80.12 | 28.78 | 78.26 | 21.13 | 83.22 | 2.39 |
NAD | 90.39 | 0 | 89.64 | 1.99 | 79.47 | 15.99 | 84.52 | 1.75 | 79.87 | 18.71 | 83.01 | 1.98 |
ABL | 88.46 | 0 | 87.42 | 4.13 | 88.74 | 4.41 | 85.62 | 16.37 | 89.12 | 0 | 89.33 | 0.08 |
ANP | 92.15 | 0 | 90.16 | 0.56 | 90.95 | 0.76 | 91.81 | 0.53 | 91.24 | 4.12 | 91.45 | 0.87 |
DLP | 93.01 | 0 | 93.08 | 0.24 | 92.19 | 0.31 | 91.93 | 0 | 92.04 | 0.21 | 92.98 | 0 |