Search papers, labs, and topics across Lattice.
University of Bergen
1
0
2
Backdoor defenses focused on removing training triggers are fundamentally flawed, as alternative, perceptually distinct triggers can reliably activate the same backdoor via a latent feature-space direction.