Anti-Backdoor Learning: Training Clean Models on Poisoned Data

Neural Information Processing Systems 

ABL introduces a two-stage gradient ascent mechanism for standard training to 1) help isolate backdoor examples at an early training stage, and 2) break the correlation between backdoor examples and the target class at a later training stage.