Breaking the False Sense of Security in Backdoor Defense through Re-Activation Attack

Neural Information Processing Systems 

To further verify this finding, we empirically show that these dormant backdoors can be easily re-activated during inference stage, by manipulating the original trigger with well-designed tiny perturbation using universal adversarial attack.

Similar Docs  Excel Report  more

TitleSimilaritySource
None found