Effective Backdoor Defense by Exploiting Sensitivity of Poisoned Samples

Neural Information Processing Systems 

Given a backdoored model, we observe that the feature representations of poisoned samples with trigger are more sensitive to transformations than those of clean samples.

Similar Docs  Excel Report  more

TitleSimilaritySource
None found