bboylyg / ABL

Anti-Backdoor learning (NeurIPS 2021)
78 stars 10 forks source link

Patch size for BadNet and Trojan attacks #2

Closed htwang14 closed 2 years ago

htwang14 commented 2 years ago

Hi, what are the patch sizes you used for BadNet and Trojan attacks on ImageNet? I can see you used 3x3 on CIFAR10 but what about ImageNet? Thank you!

bboylyg commented 2 years ago

Hi, thanks for your interest in our work. The trigger shape used for BadNet and Trojan attacks in our paper is set by 24x24 (about 1\% occupation to the whole area of image).

htwang14 commented 2 years ago

Thanks for the reply. Is the poisoning ratio on ImageNet also 10%?

bboylyg commented 2 years ago

Yes. Hope this response will be helpful for your research.

htwang14 commented 2 years ago

Thank you so much for your reply!

htwang14 commented 2 years ago

Could you please share the four backdoor patterns you used on ImageNet? Thanks!

bboylyg commented 2 years ago

The trigger patterns used on ImageNet have been uploaded to the trigger folder.