Research Article

DeepDefense: A Steganalysis-Based Backdoor Detecting and Mitigating Protocol in Deep Neural Networks for AI Security

Table 4

Attack success rate (ASR) and clean accuracy (CA) of various backdoor attacks on classification tasks.

TaskBackdoored model (ASR %/CA %)Clean model (CA %)
BadNetsBlend AttackSSBA

CIFAR1099.64/93.02100/93.6799.91/93.0892.40
VGGFace299.40/87.8099.98/87.8499.67/88.5991.31