跳到主要导航 跳到搜索 跳到主要内容

BackdoorBench: A Comprehensive Benchmark of Backdoor Learning

  • Baoyuan Wu
  • , Hongrui Chen
  • , Mingda Zhang
  • , Zihao Zhu
  • , Shaokui Wei
  • , Danni Yuan
  • , Chao Shen
  • The Chinese University of Hong Kong, Shenzhen

科研成果: 书/报告/会议事项章节会议稿件同行评审

111 引用 (Scopus)

摘要

Backdoor learning is an emerging and vital topic for studying deep neural networks' vulnerability (DNNs). Many pioneering backdoor attack and defense methods are being proposed, successively or concurrently, in the status of a rapid arms race. However, we find that the evaluations of new methods are often unthorough to verify their claims and accurate performance, mainly due to the rapid development, diverse settings, and the difficulties of implementation and reproducibility. Without thorough evaluations and comparisons, it is not easy to track the current progress and design the future development roadmap of the literature. To alleviate this dilemma, we build a comprehensive benchmark of backdoor learning called BackdoorBench. It consists of an extensible modular-based codebase (currently including implementations of 8 state-of-the-art (SOTA) attacks and 9 SOTA defense algorithms) and a standardized protocol of complete backdoor learning. We also provide comprehensive evaluations of every pair of 8 attacks against 9 defenses, with 5 poisoning ratios, based on 5 models and 4 datasets, thus 8,000 pairs of evaluations in total. We present abundant analysis from different perspectives about these 8,000 evaluations, studying the effects of different factors in backdoor learning. All codes and evaluations of BackdoorBench are publicly available at https://backdoorbench.github.io.

源语言英语
主期刊名Advances in Neural Information Processing Systems 35 - 36th Conference on Neural Information Processing Systems, NeurIPS 2022
编辑S. Koyejo, S. Mohamed, A. Agarwal, D. Belgrave, K. Cho, A. Oh
出版商Neural information processing systems foundation
ISBN(电子版)9781713871088
出版状态已出版 - 2022
活动36th Conference on Neural Information Processing Systems, NeurIPS 2022 - New Orleans, 美国
期限: 28 11月 20229 12月 2022

出版系列

姓名Advances in Neural Information Processing Systems
35
ISSN(印刷版)1049-5258

会议

会议36th Conference on Neural Information Processing Systems, NeurIPS 2022
国家/地区美国
New Orleans
时期28/11/229/12/22

学术指纹

探究 'BackdoorBench: A Comprehensive Benchmark of Backdoor Learning' 的科研主题。它们共同构成独一无二的指纹。

引用此