Effective Backdoor Defense by Exploiting Sensitivity of Poisoned Samples
–Neural Information Processing Systems
Given a backdoored model, we observe that the feature representations of poisoned samples with trigger are more sensitive to transformations than those of clean samples.
Neural Information Processing Systems
Aug-14-2025, 08:48:25 GMT
- Country:
- Asia > China
- Guangdong Province > Shenzhen (0.05)
- Hong Kong (0.04)
- Asia > China
- Genre:
- Research Report (0.46)
- Industry:
- Information Technology > Security & Privacy (0.32)
- Technology: