Pith. sign in

REVIEW 3 cited by

BackdoorBench: A Comprehensive Benchmark and Analysis of Backdoor Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.19845 v1 pith:5FOEU5RT submitted 2024-07-29 cs.LG cs.CR

classification cs.LGcs.CR
keywords backdoorlearningalgorithmsbackdoorbenchbenchmarkanalysiscomprehensiveevaluations
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

As an emerging approach to explore the vulnerability of deep neural networks (DNNs), backdoor learning has attracted increasing interest in recent years, and many seminal backdoor attack and defense algorithms are being developed successively or concurrently, in the status of a rapid arms race. However, mainly due to the diverse settings, and the difficulties of implementation and reproducibility of existing works, there is a lack of a unified and standardized benchmark of backdoor learning, causing unfair comparisons or unreliable conclusions (e.g., misleading, biased or even false conclusions). Consequently, it is difficult to evaluate the current progress and design the future development roadmap of this literature. To alleviate this dilemma, we build a comprehensive benchmark of backdoor learning called BackdoorBench. Our benchmark makes three valuable contributions to the research community. 1) We provide an integrated implementation of state-of-the-art (SOTA) backdoor learning algorithms (currently including 20 attack and 32 defense algorithms), based on an extensible modular-based codebase. 2) We conduct comprehensive evaluations with 5 poisoning ratios, based on 4 models and 4 datasets, leading to 11,492 pairs of attack-against-defense evaluations in total. 3) Based on above evaluations, we present abundant analysis from 10 perspectives via 18 useful analysis tools, and provide several inspiring insights about backdoor learning. We hope that our efforts could build a solid foundation of backdoor learning to facilitate researchers to investigate existing algorithms, develop more innovative algorithms, and explore the intrinsic mechanism of backdoor learning. Finally, we have created a user-friendly website at http://backdoorbench.com, which collects all important information of BackdoorBench, including codebase, docs, leaderboard, and model Zoo.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. From Internal Diagnosis to External Auditing: A VLM-Driven Paradigm for Data-Free Online Backdoor Defense

    cs.LG 2026-01 conditional novelty 7.0 of 10

    PRISM uses a frozen VLM as an evolving semantic gatekeeper, reporting average attack success below 1% on CIFAR-10 while preserving clean accuracy.

  2. CLIP-Guided Backdoor Defense through Entropy-Based Poisoned Dataset Separation

    cs.MM 2025-07 conditional novelty 6.0 of 10

    A CLIP-guided entropy split plus guided unlearning removes backdoors from poisoned image datasets, keeping clean accuracy nearly intact.

  3. SifterNet: A Generalized and Model-Agnostic Trigger Purification Approach

    cs.LG 2025-05 conditional novelty 4.0 of 10

    SifterNet uses Hopfield associative memory, trained on clean seed images, to purify backdoor triggers from poisoned inputs without accessing the target model.

Pith tools