reds-lab / Narcissus

The official implementation of the CCS'23 paper, Narcissus clean-label backdoor attack -- only takes THREE images to poison a face recognition dataset in a clean-label way and achieves a 99.89% attack success rate.

Home Page:https://arxiv.org/pdf/2204.05255.pdf

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

reds-lab/Narcissus Stargazers