From: DLP: towards active defense against backdoor attacks with decoupled learning process
Poisoning rate | 10% | 20% | 30% | 40% | 50% | |||||
---|---|---|---|---|---|---|---|---|---|---|
Filtering rate | CA | ASR | CA | ASR | CA | ASR | CA | ASR | CA | ASR |
No defense | 91.31 | 100 | 90.22 | 100 | 89.21 | 100 | 77.92 | 99.97 | 71.49 | 100 |
0.10% | 87.25 | 34.26 | 86.94 | 33.08 | 84.27 | 39.37 | 81.99 | 66.9 | 81.58 | 79.23 |
1% | 93.08 | 0.24 | 93.01 | 2.04 | 92.88 | 3.17 | 90.54 | 3.72 | 92.06 | 3.68 |
5% | 91.17 | 0.24 | 93.23 | 2.06 | 92.96 | 3.05 | 91.01 | 3.59 | 90.36 | 4.99 |
10% | 93.88 | 0.28 | 93.59 | 1.89 | 93.61 | 3.19 | 91.32 | 2.80 | 90.81 | 4.55 |