Skip to main content

Table 4 Performance(%) comparison between DLP and baselines on ImageNet subset

From: DLP: towards active defense against backdoor attacks with decoupled learning process

Attack

No Attack

BadNets

TrojanNN

Blended

SIG

Defense

CA

ASR

CA

ASR

CA

ASR

CA

ASR

CA

ASR

No defense

93.75

0

89.99

100

90.03

100

90.64

100

90.02

98.85

FP

83.21

0

80.96

96.62

78.99

95.13

79.62

99.09

83.53

81.04

MCR

87.02

0

79.83

30.66

76.62

5.49

75.91

20.62

81.03

25.01

NAD

90.33

0

83.68

6.03

83.92

16.24

85.31

27.76

86.73

4.69

ABL

88.37

0

87.62

1.13

88.26

1.45

85.21

22.37

85.92

0.17

ANP

92.83

0

91.58

0.75

92.61

1.74

93.07

1.02

92.76

0.46

DLP

93.27

0

92.96

0.27

93.31

0.21

93.10

0

93.08

0