Research Article

VarDefense: Variance-Based Defense against Poison Attack

Table 2

The performance of four defense methods against different attack settings in CIFAR-10 and CIFAR-100.

DatasetTrigger sizePositionBeforeFine-pruningNADGAN-based defenseVarDefense
ASRACCASRACCASRACCASRACCASRACC

CIFAR-10Fixed98.3683.3332.5178.5411.6569.4810.2178.978.4680.41
Random98.8083.8132.0777.9611.2469.009.5278.958.7080.34
Fixed97.2883.2837.2578.337.9869.589.2978.469.1080.27
Random97.9983.6437.4178.347.6869.259.3278.518.8379.88
Fixed98.9382.9635.1576.328.9270.6310.7978.308.1580.44
Random98.0182.8935.2476.298.9570.4910.7778.328.6881.02
Global noiseā€”98.0884.2733.0878.7612.3370.0010.4278.588.0179.83
CIFAR-100Fixed97.7754.9847.0647.692.5633.5119.8846.932.1446.23
Random98.0654.4047.5848.123.0933.3320.1947.372.7546.45
Fixed97.6554.8751.0744.244.7531.9513.8446.911.9346.83
Random98.4454.7951.2844.644.5631.8913.7546.981.7846.45
Fixed97.6055.6546.9343.515.3634.5218.1346.052.2747.83
Random97.9455.1746.3143.574.7334.2717.7146.111.8146.98
Global noiseā€”97.3854.3447.7948.802.6032.9420.2447.882.6646.02

The numbers in bold mean that this method is the best compared with other methods, under the corresponding experiment settings.