liuyugeng / baadd

Code for Backdoor Attacks Against Dataset Distillation

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

about the trigger

Guncuke opened this issue · comments

Hello author!
when I run this code, I found that the number of the tigger is out of 0~255, Is this normal? thanks!

It is normal. We didn't do any regularization about the values.

thanks

I found that on the normalized image dataset, the final trigger even reached 1000+, which is high enough to get an accuracy of 100 even without top-k fine-tuning

Yes, maybe this is a reason, but you can regularize the trigger in a range and see the ASR results.