Research Article

Natural Backdoor Attacks on Deep Neural Networks via Raindrops

Table 1

Performance of different backdoor methods on ImageNet and GTSRB datasets evaluated using the ATA (%) and ASR (%), where x/y indicates average metrics ATA/ASR and the best results are in bold.

DatasetModelBTABlending [24]BadNets [14]Ours

GTSRBResNet1893.8790.04/99.8093.05/99.1493.52/99.94
GTSRBVGG1692.3192.83/99.9793.22/97.3992.86/100
ImageNetResNet1887.3085.12/99.3284.43/97.2486.70/99.25
ImageNetVGG1686.9085.34/99.4684.13/92.0587.18/99.19