Research Article
DeepDefense: A Steganalysis-Based Backdoor Detecting and Mitigating Protocol in Deep Neural Networks for AI Security
Table 1
The correlation between the intensity of different color bands and those of corresponding triggers.
| Attack | Types | Red vs. green | Red vs. blue | Blue vs. green |
| BadNets [21] | Intensity | 0.9512 | 0.8950 | 0.9737 | Trigger | 0.1781 | 0.1970 | 0.2710 |
| Blend Attack [22] | Intensity | 0.9596 | 0.9121 | 0.9744 | Trigger | 0.6672 | 0.5545 | 0.8046 |
| SSBA [14] | Intensity | 0.9542 | 0.9005 | 0.9695 | Trigger | 0.6424 | 0.5960 | 0.6798 |
|
|