Research Article

VarDefense: Variance-Based Defense against Poison Attack

Table 1

The performance of four defense methods against different attack settings in MNIST and Fashion-MNIST. The numbers in italic are the best result.

DatasetTrigger sizePositionBeforeFine-pruningNADGAN-based defenseVarDefense
ASRACCASRACCASRACCASRACCASRACC

MNISTFixed99.0598.6711.4796.701.8698.247.4897.590.5897.25
Random99.5298.8711.5396.422.1498.057.3698.000.5498.52
Fixed99.2498.7410.9597.522.4397.746.7996.080.5797.91
Random99.5398.5911.0297.333.1197.136.6696.311.1097.16
Fixed99.1799.7213.7096.942.2697.3611.7595.540.7198.06
Random99.8799.0013.9897.422.6497.3511.3295.010.8097.60
Global noiseā€”98.7598.8310.3397.192.6598.127.1395.910.9397.79
Fashion-MNISTFixed99.5799.0216.8694.322.8197.7711.6596.410.5798.30
Random99.8699.2516.4295.122.2397.6111.3296.311.2898.08
Fixed99.6899.2314.2595.241.9597.6012.4095.800.3398.19
Random99.1499.4915.1094.671.6997.0612.3596.021.9598.97
Fixed98.9499.8317.8594.303.5395.7814.3295.630.9298.46
Random99.0899.1518.3294.513.5196.3413.5796.520.4198.51
Global noiseā€”99.1299.2318.7994.484.1496.7013.0797.061.1498.36