bboylyg / ABL

Anti-Backdoor learning (NeurIPS 2021)

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Patch size for BadNet and Trojan attacks

htwang14 opened this issue · comments

Hi, what are the patch sizes you used for BadNet and Trojan attacks on ImageNet? I can see you used 3x3 on CIFAR10 but what about ImageNet? Thank you!

Hi, thanks for your interest in our work. The trigger shape used for BadNet and Trojan attacks in our paper is set by 24x24 (about 1% occupation to the whole area of image).

Thanks for the reply. Is the poisoning ratio on ImageNet also 10%?

Yes. Hope this response will be helpful for your research.

Thank you so much for your reply!

Could you please share the four backdoor patterns you used on ImageNet? Thanks!

The trigger patterns used on ImageNet have been uploaded to the trigger folder.