From: NBA: defensive distillation for backdoor removal via neural behavior alignment
Settings
ASR
BA
NBA with only \({\mathcal {L}}_{RNB}\)
2.55
83.91
NBA with poisoned samples
1.38
80.89
NBA with pseudo samples
1.52
81.14