Skip to main content

Table 2 Performance (%) comparison of 6 backdoor defenses against 6 backdoor attacks

From: NBA: defensive distillation for backdoor removal via neural behavior alignment

Attack

Defense

No defense

Fine-tuning

Fine-pruning

MCR

NAD

ARGD

NBA

ASR

BA

ASR

BA

ASR

BA

ASR

BA

ASR

BA

ASR

BA

ASR

BA

BadNets

99.83

80.02

6.46

79.91

82.54

77.65

2.74

78.29

3.55

80.47

1.81

80.35

1.16

81.59

TrojanNN

99.85

79.95

5.61

80.03

52.71

79.96

25.71

78.68

3.26

79.58

2.33

79.97

1.14

80.42

Blend

97.83

82.36

5.23

79.85

89.12

80.07

68.85

79.82

2.77

81.04

1.16

81.13

0.85

80.13

CLA

98.15

81.14

7.32

80.06

35.46

76.88

17.29

80.03

8.55

79.64

5.13

79.96

1.71

80.24

SIG

99.62

82.63

11.29

80.31

65.31

80.15

1.80

79.61

5.69

80.29

2.14

80.25

1.95

81.71

Refool

96.24

80.37

8.78

80.24

59.67

78.22

8.29

78.25

4.27

80.01

4.05

80.04

2.33

82.72

Average

98.57

81.08

7.45

80.07

64.14

78.82

20.78

79.11

4.68

80.17

2.77

80.28

1.52

81.14