From: DLP: towards active defense against backdoor attacks with decoupled learning process
Attack | No Attack | BadNets | TrojanNN | Blended | SIG | |||||
---|---|---|---|---|---|---|---|---|---|---|
Defense | CA | ASR | CA | ASR | CA | ASR | CA | ASR | CA | ASR |
No defense | 93.75 | 0 | 89.99 | 100 | 90.03 | 100 | 90.64 | 100 | 90.02 | 98.85 |
FP | 83.21 | 0 | 80.96 | 96.62 | 78.99 | 95.13 | 79.62 | 99.09 | 83.53 | 81.04 |
MCR | 87.02 | 0 | 79.83 | 30.66 | 76.62 | 5.49 | 75.91 | 20.62 | 81.03 | 25.01 |
NAD | 90.33 | 0 | 83.68 | 6.03 | 83.92 | 16.24 | 85.31 | 27.76 | 86.73 | 4.69 |
ABL | 88.37 | 0 | 87.62 | 1.13 | 88.26 | 1.45 | 85.21 | 22.37 | 85.92 | 0.17 |
ANP | 92.83 | 0 | 91.58 | 0.75 | 92.61 | 1.74 | 93.07 | 1.02 | 92.76 | 0.46 |
DLP | 93.27 | 0 | 92.96 | 0.27 | 93.31 | 0.21 | 93.10 | 0 | 93.08 | 0 |