Breaking the False Sense of Security in Backdoor Defense through Re-Activation Attack
–Neural Information Processing Systems
To further verify this finding, we empirically show that these dormant backdoors can be easily re-activated during inference stage, by manipulating the original trigger with well-designed tiny perturbation using universal adversarial attack.
Neural Information Processing Systems
Nov-20-2025, 04:24:06 GMT
- Country:
- Asia
- China
- Guangdong Province > Shenzhen (0.04)
- Hong Kong (0.04)
- Nepal (0.04)
- Singapore > Central Region
- Singapore (0.04)
- China
- Asia
- Genre:
- Research Report > Experimental Study (1.00)
- Industry:
- Government > Military (0.88)
- Information Technology > Security & Privacy (1.00)
- Technology: