From: DLP: towards active defense against backdoor attacks with decoupled learning process
Attack | BadNets | TrojanNN | Blended | SIG | ||||
---|---|---|---|---|---|---|---|---|
Architecture | CA | ASR | CA | ASR | CA | ASR | CA | ASR |
VGG16 | 92.43 | 0.36 | 92.47 | 0.33 | 92.26 | 0 | 92.53 | 0 |
ResNet18 | 93.14 | 0.25 | 93.22 | 0.27 | 92.87 | 0 | 93.19 | 0 |
InceptionV3 | 93.56 | 0.29 | 93.43 | 0.32 | 93.41 | 0 | 93.61 | 0 |
MobileNetv2 | 93.88 | 0.19 | 93.64 | 0.25 | 93.57 | 0 | 93.92 | 0 |
DenseNet121 | 94.82 | 0.17 | 95.02 | 0.21 | 94.96 | 0 | 95.11 | 0 |