Tiny ImageNet Leaderboard


Targeted Model Defense→ No Defense FT FP NAD NC ANP AC SS ABL DBD CLP D-BR D-ST DDE i-BAU MBNS
Attack↓ CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%)
PreActResNet-18BadNet57.5133.5342.1256.8724.7145.7355.2316.8046.0546.324.6143.9452.4416.1045.9557.4633.5342.1250.440.3150.50N/AN/AN/A50.8611.6946.1447.960.2647.3657.4733.5342.1233.9729.9126.6112.440.0212.2456.2930.0243.3355.3010.6550.7756.2531.9442.15
PreActResNet-18Blended57.5865.1914.6656.9563.9014.9255.2753.3916.6248.1948.6716.2554.0761.9215.0653.9964.0313.8051.1755.7716.38N/AN/AN/A52.7251.4415.6948.330.0734.2057.3965.1714.661.3821.880.8812.530.077.2756.4159.9915.8555.8354.5717.1556.4065.4513.35
PreActResNet-18LC57.315.6151.3856.785.5251.2451.421.8248.4349.731.6346.7253.781.3851.0954.294.7049.1850.720.5848.93N/AN/AN/A52.610.8348.3147.6630.9338.3957.305.6151.3832.132.3129.7711.410.0110.4956.204.3950.9455.847.3949.3957.305.6151.38
PreActResNet-18SIG57.0344.9314.5756.5149.1713.1655.2150.0212.6448.0231.898.4653.8447.6611.7053.1739.7612.0251.3629.9312.88N/AN/AN/A52.279.1317.5847.7250.9718.6757.0944.9414.5739.5318.6211.3612.253.493.0255.7442.3814.2254.4738.4714.0455.4037.5915.10
PreActResNet-18LF56.9719.4938.9556.6919.7338.3454.8512.1438.9447.596.6434.7955.3218.6536.6954.109.2537.0550.8021.4531.80N/AN/AN/A52.429.8535.3047.670.0943.2957.0623.4037.2214.0211.849.9111.560.0011.2656.5919.4237.6055.4017.6337.6757.1322.4837.49
PreActResNet-18SSBA57.2013.2841.5457.069.9241.8755.306.8241.2148.231.9037.7754.6711.2138.9056.8513.2341.3350.525.2438.42N/AN/AN/A51.524.4640.7747.740.0440.3656.8213.3941.0740.3317.6726.3412.340.008.4255.3914.8439.0555.236.7141.5155.7413.3640.17
PreActResNet-18WaNet57.275.3955.3557.261.6854.4155.250.5653.1547.500.7343.2555.811.5052.9055.223.6253.5150.711.8142.89N/AN/AN/A52.671.8043.5147.820.5742.5257.1467.0822.800.6878.610.3313.880.0014.1357.0251.7430.8253.8919.0840.6956.5169.4221.20
PreActResNet-18InputAware57.9663.8020.8357.8756.7423.7556.1426.5529.7846.6621.8525.0854.676.7439.8156.8363.4820.3650.8232.5724.30N/AN/AN/A51.5315.3828.2847.680.2836.3758.2845.555.201.2756.160.3612.430.451.7757.9631.705.7153.2021.954.8958.1737.325.69
PreActResNet-18BPP58.4391.765.7157.5683.8710.8951.9567.6617.2946.642.2842.0853.060.9946.0554.6386.298.7851.250.7846.53N/AN/AN/A52.372.3547.2847.620.3442.9058.4331.4640.2639.405.3734.7418.701.1717.4356.960.0045.9555.6287.338.3757.2087.608.26
PreActResNet-18TrojanNN57.1168.6918.0656.9178.9012.7752.1440.1125.4250.5827.8130.4655.259.3543.2554.3352.4223.6051.4974.5612.40N/AN/AN/A37.6389.654.1847.030.2642.2456.5367.1518.6634.6460.2212.3420.550.0117.5756.6355.2224.5952.8462.8019.3156.9458.5323.22
VGG19_BNBadNet54.1448.8329.5954.0043.0432.2053.2138.9333.6042.947.0537.6553.0546.2030.6551.8726.9539.0343.280.6442.29N/AN/AN/A37.151.7335.2939.500.1439.28N/AN/AN/A54.2449.2529.4229.910.1429.1752.7148.9929.2846.3623.6435.6153.6049.8529.06
VGG19_BNBlended53.1270.2611.6253.3170.4411.4852.3964.2812.8142.8639.5913.4449.7067.3411.2753.1270.2611.6244.4041.9717.33N/AN/AN/AN/AN/AN/A40.540.1132.74N/AN/AN/A0.500.000.5027.8339.688.4552.8471.9310.9444.5453.7311.7951.6868.3311.49
VGG19_BNLC54.0625.9834.3453.9722.8535.6753.2021.3335.1343.585.7035.6551.7014.9637.5453.408.9944.6843.562.9637.95N/AN/AN/A39.974.3230.7237.4257.8915.5854.239.0144.7154.2125.8734.6211.220.5610.1953.6623.7635.6447.648.3635.7054.0025.7234.32
VGG19_BNSIG44.6619.9018.0450.7924.3118.9950.4419.0320.5351.0222.7919.3949.9222.6818.9044.6619.9018.0443.8210.1020.68N/AN/AN/A32.5525.309.7839.7334.5119.6544.8321.4018.330.50100.000.0024.6541.974.0744.0219.3917.9046.7813.9620.5044.3719.8017.85
VGG19_BNLF52.800.1352.6652.750.0752.6252.070.1251.9252.670.0752.5452.800.1352.6651.730.0351.6444.040.2343.84N/AN/AN/A28.980.2028.8741.170.1041.3752.910.1552.7753.030.1452.8623.520.0023.6452.070.0951.9246.460.2146.2652.750.1552.62
VGG19_BNSSBA54.356.9540.7754.125.2341.0353.513.2240.4254.303.7841.6051.872.9439.6052.366.5039.2143.252.4233.40N/AN/AN/A26.580.5021.3636.300.0031.3854.407.0540.6754.367.1740.4822.670.0017.0953.625.6940.2546.691.0439.0653.417.0439.63
VGG19_BNWaNet54.2243.8630.5554.948.9041.6854.383.8942.7554.6917.7838.8853.603.7842.6050.382.2944.4244.281.1437.43N/AN/AN/A23.406.7218.2837.080.7933.3954.5342.8430.9542.3414.0828.5723.210.0324.0854.1735.5934.8947.812.6037.7654.3644.6430.20
VGG19_BNInputAware54.0985.449.2554.3078.0312.6753.3339.7122.4143.3935.3117.1253.7772.2814.9150.0342.3422.7144.2325.6922.89N/AN/AN/A35.9915.2020.8438.360.4530.9254.2282.3610.8454.4479.4012.353.350.002.9753.9383.889.9944.9656.7213.3954.2883.4210.37
VGG19_BNBPP55.3024.2739.7155.642.3945.9054.510.7147.1439.290.1837.7553.130.0349.9550.6211.9845.4844.460.2641.81N/AN/AN/A39.880.2937.9837.760.2336.5155.0116.1845.120.50100.000.0023.983.4122.2754.2625.0638.1447.630.7842.7554.8525.4439.13
VGG19_BNTrojanNN53.7379.8610.5353.9184.678.4652.9371.1513.3253.8481.659.7752.3452.8921.0153.5879.5111.0544.2453.5516.83N/AN/AN/A23.6096.911.2639.440.1032.0353.9683.149.1948.4469.2811.9626.020.0021.5453.5880.2010.1046.5283.777.7453.3071.4614.18
ViT_b_16BadNet76.6754.0338.4375.8335.5951.7366.608.3661.1646.001.2045.4375.1932.0454.3276.6854.0438.4276.5024.1561.86N/AN/AN/A78.4475.0422.9630.840.5430.45N/AN/AN/A75.4044.3845.610.500.000.5076.5450.6041.1450.760.2250.6276.3054.7537.73
ViT_b_16Blended76.7581.9513.6975.4779.5315.1065.2146.8822.3047.2813.4123.6776.7681.9513.6976.7681.9513.6977.6176.9016.74N/AN/AN/A78.8186.2710.91N/AN/AN/AN/AN/AN/A75.9581.6213.720.500.000.5076.4582.0913.4651.0912.7820.3776.3382.3113.46
ViT_b_16LC77.022.8773.1676.252.2972.9366.560.6053.642.526.042.4977.022.8773.1677.022.8773.1676.502.2372.70N/AN/AN/A78.6410.0170.69N/AN/AN/A77.022.8773.1658.782.7754.630.500.000.5076.782.6772.9947.060.8142.1577.023.2372.80
ViT_b_16SIG75.869.1046.6275.1510.0544.4664.802.0728.4842.130.3925.6973.9111.8243.2775.869.1046.6278.018.5249.71N/AN/AN/A78.6112.4248.39N/AN/AN/A75.879.1046.6275.168.5046.100.500.000.5075.498.2246.1855.180.3533.2675.849.5746.47
ViT_b_16LF76.120.0676.0274.830.0674.7265.900.0765.8142.850.1342.7376.120.0676.0275.510.0375.4276.920.0376.83N/AN/AN/A78.560.0978.4637.120.2637.1476.140.0676.041.881.591.800.500.000.5075.820.0975.7253.300.1353.1876.120.0576.02
ViT_b_16SSBA75.7628.2951.5074.7423.5652.5764.775.9247.6041.630.3233.6775.7628.2951.5075.7528.1851.5377.8920.6857.51N/AN/AN/A78.3326.9954.9737.860.1631.5675.7628.3051.491.090.001.110.500.000.5075.6229.7150.5649.190.2341.6675.6728.2951.35
ViT_b_16WaNet61.7051.3334.8362.7718.1451.5854.730.3547.376.871.676.7211.110.369.0256.3823.5645.4575.652.7770.71N/AN/AN/A78.172.5373.235.702.825.6061.7051.3534.832.380.842.360.500.000.5061.6050.8235.095.640.635.5561.4050.1535.40
ViT_b_16InputAware63.9460.2028.8463.7944.3536.8452.934.8240.5618.650.3213.5460.370.3248.2863.7270.4321.9277.9852.2539.07N/AN/AN/A78.3251.3640.38N/AN/AN/A63.7470.3921.932.602.442.60N/AN/AN/A63.5971.5720.9731.780.1124.1463.3770.8321.60
ViT_b_16BPP62.8969.1423.1063.3540.2340.6154.661.5249.796.351.946.2562.650.0859.2262.8969.1423.1076.793.5572.23N/AN/AN/A78.454.3173.7434.640.4831.9562.8969.1423.100.460.000.47N/AN/AN/AN/AN/AN/A5.790.415.48N/AN/AN/A
ViT_b_16TrojanNN76.2788.979.9675.0776.6319.5664.662.5733.0944.350.4627.3875.4678.9518.0476.1488.7010.1776.5985.7012.91N/AN/AN/A78.2891.957.43N/AN/AN/A76.2788.979.9675.8086.1812.290.500.000.5076.0288.7710.0850.515.2527.6376.3089.169.79
ConvNext_tinyBadNet69.184.8966.0265.401.1064.1460.370.2059.4252.900.3752.3969.084.8866.0063.431.9262.2673.370.1672.45N/AN/AN/A77.0335.1953.1338.180.7037.91N/AN/AN/A28.510.6427.275.130.014.9368.924.6665.9566.601.3965.2169.224.8266.02
ConvNext_tinyBlended67.4476.5816.2664.4864.7921.2056.4529.3225.4753.7546.8122.3167.4476.5816.2667.1875.7316.8573.9760.8925.30N/AN/AN/A77.0175.6917.1638.820.0532.59N/AN/AN/A29.2228.8314.525.880.084.3767.2276.1916.3964.4664.7420.5367.4375.7316.61
ConvNext_tinyLC68.722.5962.6965.311.9759.8258.141.2153.4355.692.1651.1460.510.7456.2663.280.7558.5473.430.9867.82N/AN/AN/A76.740.9171.3238.189.6833.3868.722.5962.6947.711.7745.366.790.006.4767.612.1161.7865.741.3261.9968.582.5662.57
ConvNext_tinySIG69.0914.1743.3066.047.2142.0758.244.1034.8064.385.0840.8766.078.2242.5762.9911.1838.4373.228.4246.42N/AN/AN/A69.322.6145.9539.9242.1419.7469.0914.1743.3042.6913.2121.3310.4013.434.1568.0813.2143.1166.4011.8741.3768.8313.9543.57
ConvNext_tinyLF68.130.1768.0364.380.1464.2854.200.1754.0163.130.1463.0165.130.0965.0166.260.1466.1673.910.0273.79N/AN/AN/A69.080.3768.9338.630.1938.6468.130.1768.0342.900.2342.679.190.229.1467.770.1967.6665.190.1365.0967.990.1867.89
ConvNext_tinySSBA67.7927.4848.1264.9316.1550.5958.522.6548.3357.264.8646.0467.7827.4848.1263.1911.4451.8973.684.1462.16N/AN/AN/A76.6618.0759.1140.090.2233.8567.7927.4848.1213.7828.5110.540.560.000.5567.3426.4748.3565.7523.3947.9167.5527.4848.06
ConvNext_tinyWaNet56.9370.4821.152.260.002.3230.851.0828.113.021.373.0610.390.798.4455.0865.7023.9873.900.5969.96N/AN/AN/A67.591.5963.8439.430.8836.9656.9370.4821.1535.2344.3520.959.280.869.9156.1571.5320.6456.6828.1242.9356.8368.7022.33
ConvNext_tinyInputAware57.9385.0311.6015.819.559.393.630.513.3414.870.088.364.730.184.5054.503.0740.6173.8937.9241.05N/AN/AN/A76.8344.9240.2738.250.4330.5456.7575.1817.052.471.862.2610.120.218.7356.4172.3118.4556.5641.9833.0456.8075.3616.99
ConvNext_tinyBPP57.4837.1042.625.332.175.4133.730.7231.502.643.122.626.270.256.0451.983.1948.0772.890.2969.93N/AN/AN/A76.190.3872.9238.930.1638.3257.4837.1042.620.500.000.509.911.139.1157.2736.2142.6456.6612.3050.4457.4637.1742.52
ConvNext_tinyTrojanNN67.0190.997.0864.0780.7213.8557.7524.4231.0363.1179.1714.6352.210.0942.5363.2477.2215.7574.1091.597.40N/AN/AN/A76.7693.555.7738.840.3130.2567.0190.997.080.930.000.927.800.246.0566.9291.646.6065.1583.9711.8566.9690.927.21

Targeted Model Defense→ No Defense FT FP NAD NC ANP AC SS ABL DBD CLP D-BR D-ST DDE i-BAU MBNS
Attack↓ CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%)
PreActResNet-18BadNet57.4991.277.5857.0388.3710.1355.2082.4314.1646.362.9644.7852.360.1951.6452.0388.818.5851.1069.4821.05N/AN/AN/A51.8457.1626.3942.990.1742.4657.3591.747.1811.1169.035.3211.600.0011.4556.472.2154.6654.7676.3718.4857.4991.277.58
PreActResNet-18Blended56.7791.455.3256.2789.975.7054.8886.546.5746.3146.4514.5153.8987.476.6152.1885.796.2251.2087.426.36N/AN/AN/A50.490.4821.5642.7089.796.3356.7891.705.090.710.000.5413.624.716.5256.0586.837.1653.3388.395.7756.7791.445.33
PreActResNet-18LCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
PreActResNet-18SIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
PreActResNet-18LF57.3870.6916.3256.6068.0617.4955.1063.7318.1349.0237.2826.6153.8555.1821.8854.3462.4918.1850.6768.5714.75N/AN/AN/A52.5666.6316.1248.120.1842.6556.7971.2916.4935.0174.817.3412.480.7711.7756.5564.4219.5053.5456.9522.3156.7971.2916.49
PreActResNet-18SSBA57.2562.1421.2756.6851.2726.0355.3437.8828.7147.4111.0635.2255.270.0643.0054.9746.7426.0250.2747.0224.35N/AN/AN/A52.0218.6535.5843.110.0534.8156.1060.5921.5231.4535.7617.7112.570.188.6055.5760.0820.9355.6643.6129.0557.2562.1521.26
PreActResNet-18WaNet56.7056.7530.8056.9929.5642.2054.9235.0934.6247.022.5740.4356.260.3253.6354.3143.3835.7050.7813.5039.27N/AN/AN/A52.086.9241.2947.680.3141.6156.682.7755.280.5931.710.5611.990.3212.6255.9454.7931.2754.797.3950.6156.643.4055.17
PreActResNet-18InputAware57.5693.125.1857.7398.171.4355.6691.326.2550.5088.457.1754.9145.8532.1655.260.3846.1150.7977.5511.96N/AN/AN/A51.7651.6021.7048.590.3344.7956.833.2349.970.9388.800.3612.240.0210.2757.350.1248.7756.2154.5428.0957.9294.204.14
PreActResNet-18BPP58.4698.930.7958.1999.810.1351.7898.171.0748.280.9043.9957.9312.1448.3357.7492.684.7650.8836.6733.42N/AN/AN/A52.3125.1037.9647.850.2343.6558.460.3351.020.610.500.6119.4051.4211.7758.000.2346.3456.8352.1328.8257.7091.735.25
PreActResNet-18TrojanNN56.9794.224.5856.6293.854.9851.8878.0813.5950.7842.6526.2656.9794.224.5854.6093.105.1251.4395.123.39N/AN/AN/A29.5599.990.0146.730.1241.5957.1170.4318.207.6342.743.7421.9790.363.6356.1531.9936.0055.5294.054.6756.5592.955.33
VGG19_BNBadNet53.7398.141.5553.5698.051.6352.6494.594.1443.4864.1218.8653.310.0552.3553.7698.141.5543.6978.4211.92N/AN/AN/AN/AN/AN/A39.690.1739.72N/AN/AN/A53.6498.191.5128.230.0627.7253.1097.681.9746.0092.575.3053.2198.241.48
VGG19_BNBlended54.0091.814.1853.8791.804.0953.1588.764.9840.2247.8710.3054.0091.814.1849.0889.954.5444.0581.966.86N/AN/AN/AN/AN/AN/A40.4391.374.14N/AN/AN/A53.7891.424.3528.1291.041.7553.5491.384.2945.3086.654.4653.3592.073.95
VGG19_BNLCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
VGG19_BNSIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
VGG19_BNLF54.110.2453.9553.660.0453.5753.170.0653.0453.560.0553.4751.180.1251.0652.740.0152.6543.690.3743.52N/AN/AN/A31.420.1831.3138.900.1438.8554.070.3153.9154.110.2253.9621.540.0021.6552.590.1952.4546.560.1446.4352.740.1952.61
VGG19_BNSSBA53.6871.3014.2253.7760.1919.0452.3866.6015.7953.7265.2017.3251.930.0139.4548.9154.5919.9843.7236.7623.17N/AN/AN/A26.7349.6311.1538.300.1633.0553.9046.7024.9053.6772.1513.8421.7465.425.2952.8165.1216.7444.5237.5821.5053.2972.1613.23
VGG19_BNWaNet54.6295.603.1254.4888.227.4154.1911.2130.4739.912.2534.5650.340.2327.7352.1018.5339.8943.789.0334.04N/AN/AN/A30.463.7723.1336.840.0034.7654.8194.853.620.50100.000.0023.430.0024.3154.686.3735.7949.2439.8627.8554.4395.822.97
VGG19_BNInputAware54.0572.9414.7154.5976.8212.6753.342.3441.6341.740.5832.2254.1088.506.7053.810.1043.4444.3346.6418.43N/AN/AN/A41.8127.4720.7037.2293.433.9254.070.5945.5953.4340.9928.5328.485.4615.6054.030.5045.4446.2338.4326.2154.2588.506.70
VGG19_BNBPP54.6586.918.2854.7771.8716.3954.5922.0325.8935.840.8633.7453.8331.1935.8752.720.2149.0943.440.6641.66N/AN/AN/A41.660.5739.7138.210.1536.4753.780.2750.790.490.000.5021.840.0020.5754.320.0646.7848.1933.4429.3854.5315.1522.78
VGG19_BNTrojanNN45.1895.252.4450.7198.121.3251.1795.942.5850.5398.391.1750.0861.3818.0045.2295.242.5243.8395.801.76N/AN/AN/A24.1699.950.0337.3998.871.0545.0873.0511.420.50100.000.0024.350.001.5843.7792.203.7246.0796.761.9243.6778.418.48
ViT_b_16BadNet76.7394.794.5275.5281.5815.3565.8020.2030.8842.250.1241.6975.6185.3112.3576.7294.794.5276.3689.399.21N/AN/AN/A78.5396.293.52N/AN/AN/A76.7294.794.528.7117.647.610.500.000.50N/AN/AN/A14.030.2913.20N/AN/AN/A
ViT_b_16Blended76.1295.683.6074.7393.525.1065.1767.0613.8544.1714.6221.7576.1295.683.6076.1295.683.6077.0295.643.62N/AN/AN/A78.5296.932.5235.410.3227.9076.1295.683.604.5359.752.430.500.000.50N/AN/AN/A50.0812.3325.99N/AN/AN/A
ViT_b_16LCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ViT_b_16SIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ViT_b_16LF76.190.0976.1075.120.0575.0366.330.0766.2343.570.3243.3975.360.0775.2776.190.0976.1077.820.0977.73N/AN/AN/A78.440.0578.3637.430.4337.3376.200.0976.1175.650.2175.560.500.000.5075.910.0775.8250.470.1050.3276.040.0875.95
ViT_b_16SSBA75.2378.1316.5673.9066.8122.9763.6540.6330.7441.441.3232.4273.6273.8418.7373.5771.7720.2676.2171.7221.90N/AN/AN/A78.2863.9027.72N/AN/AN/A75.2378.1316.5574.4875.8617.870.50100.000.0075.1079.0215.8347.854.4738.4675.2478.0716.50
ViT_b_16WaNet62.1295.293.6963.1673.9218.0254.4112.8441.265.282.825.0812.970.6210.1557.3674.2216.9577.0021.8160.95N/AN/AN/A78.2921.2661.99N/AN/AN/A62.1195.303.681.4537.491.200.500.000.5062.0695.473.536.650.646.4661.5895.513.51
ViT_b_16InputAware63.7174.7016.1263.3255.4428.4254.663.1845.4313.471.209.3062.910.1158.8064.6265.7221.9877.5068.5828.27N/AN/AN/A78.3672.9624.83N/AN/AN/A64.6265.7221.981.4615.271.39N/AN/AN/A64.4266.4621.4311.630.367.5064.2265.4921.98
ViT_b_16BPP62.9188.898.161.230.001.2137.510.2634.877.241.816.836.210.486.0462.9188.898.1675.6348.4340.29N/AN/AN/A78.7054.7836.71N/AN/AN/A62.9188.898.161.5733.791.42N/AN/AN/AN/AN/AN/A6.490.836.07N/AN/AN/A
ViT_b_16TrojanNN76.8397.882.0175.6992.896.4065.5415.2418.1145.791.3327.8275.410.3765.6675.8696.962.8177.1698.501.42N/AN/AN/A78.3899.290.63N/AN/AN/A76.8397.882.0176.1297.382.440.500.000.5076.6497.891.9750.3110.8030.5076.8297.832.01
ConvNext_tinyBadNet68.1496.413.2165.1686.3711.5855.861.0854.1355.0737.3739.1354.573.6752.8162.9759.9328.5473.5693.495.89N/AN/AN/AN/AN/AN/A38.260.2638.04N/AN/AN/A1.6611.741.4610.100.769.9067.6796.543.0764.8676.8319.4267.9796.483.14
ConvNext_tinyBlended69.1994.154.7165.4888.458.5458.6964.5317.9156.9780.5911.9865.2690.457.2767.7893.145.4172.8793.914.85N/AN/AN/AN/AN/AN/A38.0996.802.32N/AN/AN/A30.4565.959.079.960.336.8068.8994.314.5765.2188.448.1969.1994.124.74
ConvNext_tinyLCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ConvNext_tinySIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ConvNext_tinyLF67.900.2567.8065.270.1465.1558.290.0958.1655.230.1155.1164.590.0964.4966.470.1966.3773.930.1473.84N/AN/AN/A76.220.1276.1239.020.2439.0667.900.2567.8049.640.7449.4510.000.589.9767.710.2367.6164.320.0964.2267.730.2667.63
ConvNext_tinySSBA69.3780.4314.7665.5657.7328.7461.0830.9340.1655.2937.2534.5769.3780.4314.7662.6345.6633.8874.0970.5522.59N/AN/AN/A76.5674.8719.9639.750.1634.1369.3780.4314.7653.1167.6119.4810.570.087.9368.5278.9115.5965.5665.1624.4369.3080.5614.74
ConvNext_tinyWaNet55.6894.124.676.582.156.2542.8210.3835.012.850.832.856.500.486.2352.8474.9918.4474.2120.4659.78N/AN/AN/A76.4334.5052.0239.221.4336.7355.7094.134.661.373.751.356.991.317.4755.5394.224.5355.9975.3516.1155.7294.374.45
ConvNext_tinyInputAware57.1692.016.2046.1511.1136.622.610.062.5210.780.248.9013.580.0911.3052.2485.4910.2573.1162.2329.21N/AN/AN/A76.9860.4631.5138.180.0933.0456.4999.210.681.600.001.6410.041.158.1756.3499.160.7456.5874.6017.3256.4499.200.69
ConvNext_tinyBPP55.9495.313.556.781.076.9146.091.5442.006.440.436.1311.020.4710.6950.4039.1033.3772.055.9466.93N/AN/AN/A76.4515.3965.1438.070.1736.1355.9495.313.550.710.000.780.500.000.5055.7895.043.7453.7396.392.7555.8395.403.49
ConvNext_tinyTrojanNN68.4998.990.8864.9495.753.5058.6479.8012.6064.1896.642.7650.910.0939.9863.7390.237.0774.0798.461.45N/AN/AN/A76.7899.030.8938.622.9529.2268.4998.990.8843.8781.819.996.530.605.4268.2799.110.7764.6795.953.3568.4698.970.89

Targeted Model Defense→ No Defense FT FP NAD NC ANP AC SS ABL DBD CLP D-BR D-ST DDE i-BAU MBNS
Attack↓ CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%)
PreActResNet-18BadNet57.5133.5342.1257.1492.247.0255.3581.2815.4346.377.3043.3554.3264.8626.8352.3589.778.6050.0890.357.60N/AN/AN/A49.500.0251.6443.050.1142.5157.1995.024.5826.6097.501.2813.101.6013.1555.490.2854.7955.7185.6812.3256.6894.694.83
PreActResNet-18Blended57.5865.1914.6656.8993.734.2554.8391.745.2146.7364.2212.4656.3191.885.0654.8195.153.1050.6491.674.62N/AN/AN/A49.170.0927.5046.9395.353.9157.1795.313.180.560.220.5413.2461.564.3456.6395.782.8454.5294.213.5155.4794.743.21
PreActResNet-18LCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
PreActResNet-18SIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
PreActResNet-18LF56.4783.0310.4556.1880.3511.8654.5075.1413.3346.3648.3720.9152.5866.7917.0550.9977.2612.1650.8182.078.61N/AN/AN/A50.910.2342.7147.170.1841.8157.0383.649.786.3092.860.6912.394.2111.3456.1376.7413.3355.2964.4918.3956.8783.599.77
PreActResNet-18SSBA57.2013.2841.5456.7575.3215.1354.9553.9823.3846.9216.9232.4354.420.1741.1951.9150.6822.6450.4966.4017.09N/AN/AN/A51.4413.8936.5348.340.1140.6756.8080.4312.3238.0674.909.6611.9851.264.8755.8480.8111.8254.6366.6218.8854.7980.6310.97
PreActResNet-18WaNet56.9786.9810.0557.3954.6129.8755.1744.7430.9547.716.9040.5653.921.0650.5852.9025.2239.5150.2330.9833.40N/AN/AN/A50.9617.5638.0947.470.8142.6857.9749.4231.290.6297.500.1412.380.1512.5357.461.8044.3456.1174.9216.5957.350.9643.62
PreActResNet-18InputAware57.7585.1210.5057.8476.1715.1955.7895.762.8748.3561.1919.2755.805.8347.5957.620.0048.0650.3284.739.03N/AN/AN/A50.9625.4131.9047.880.1145.1157.620.1639.650.5080.050.0211.7897.010.2157.440.2228.6655.9613.4434.3557.710.0033.88
PreActResNet-18BPP58.2597.961.3057.9358.9225.3751.5063.1818.6447.030.5244.0055.770.2451.4958.2482.558.6750.7460.9122.20N/AN/AN/A52.140.0148.3747.250.3143.4357.640.2854.770.6417.170.5419.2878.516.3357.280.1548.8756.2552.3127.2157.8496.832.00
PreActResNet-18TrojanNN57.1898.021.8156.8097.931.8651.4387.998.8551.0874.3014.6853.590.0447.6054.0496.533.0250.5696.642.41N/AN/AN/A47.640.0141.8046.8098.721.2057.1740.4632.9532.4098.630.6122.2098.001.0955.931.4946.5954.3496.353.0857.1898.021.81
VGG19_BNBadNet53.9099.040.8353.5699.020.8652.6496.592.7744.225.6638.1851.3930.6338.8253.9799.040.8344.3996.082.67N/AN/AN/AN/AN/AN/A33.6399.980.02N/AN/AN/A47.8697.741.8123.710.0022.9953.5291.716.8446.8198.031.6653.7699.040.85
VGG19_BNBlended53.9995.242.8454.0292.244.2153.0091.934.1844.7472.849.4853.5591.974.4553.0694.842.8643.2490.103.99N/AN/AN/AN/AN/AN/A37.8896.162.03N/AN/AN/A45.8493.412.7029.5994.661.2153.3294.862.8648.4393.563.2753.3495.362.63
VGG19_BNLCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
VGG19_BNSIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
VGG19_BNLF52.400.5052.2652.530.1252.4351.290.0651.1744.780.2044.6152.410.5052.2752.280.0252.2744.310.5444.13N/AN/AN/A38.480.2738.3938.160.2137.9452.340.5152.220.631.080.6323.020.0622.8952.090.5351.9548.320.3348.1751.590.5351.45
VGG19_BNSSBA53.6785.098.3353.6885.588.0652.7378.1910.9243.9257.7417.3452.240.0234.4852.8684.488.3844.0972.2211.02N/AN/AN/A38.1911.5031.5239.2592.623.6853.7784.498.610.520.000.5122.9082.573.4053.6280.3510.5549.8977.0711.1053.4585.148.20
VGG19_BNWaNet55.1291.235.5154.7084.499.1054.250.1525.5438.600.9930.4454.1664.9818.2151.980.5847.9543.6120.3330.55N/AN/AN/A38.2619.8123.5839.991.1436.2255.3044.5428.860.50100.000.0020.931.4520.7553.911.0143.3546.5723.7127.1654.7892.015.04
VGG19_BNInputAware53.9882.6810.7454.070.0647.5053.050.0135.0639.080.2729.9851.810.0345.9253.740.0946.2044.0070.8211.67N/AN/AN/A39.9156.9712.6239.2094.973.6153.860.4643.207.1116.375.5929.4428.267.7852.730.5743.6345.6131.2930.4053.8080.2311.99
VGG19_BNBPP55.3681.0711.6155.1964.4920.5254.500.0223.1539.530.1537.5754.150.3842.4049.850.7931.8244.121.5241.52N/AN/AN/A39.611.9936.9538.530.3737.3254.790.1152.590.50100.000.0023.932.3822.0655.000.3749.0349.5870.0715.4854.950.6336.48
VGG19_BNTrojanNN53.3097.431.8153.0697.591.6452.4192.434.6946.0982.528.4650.655.2737.5453.3097.431.8143.4497.541.39N/AN/AN/A39.640.0028.2140.0899.940.0552.9469.9016.760.520.250.5325.3998.470.4453.1497.531.7846.4693.983.4752.3297.081.99
ViT_b_16BadNet76.9897.452.2775.8094.245.1465.6631.3822.4946.510.1345.8575.7093.076.1676.9797.452.2777.3197.672.09N/AN/AN/A78.5098.451.44N/AN/AN/A76.9797.452.2776.4195.164.240.500.000.50N/AN/AN/A9.500.519.39N/AN/AN/A
ViT_b_16Blended77.3998.031.7376.1096.702.7866.5171.9210.8642.0810.3221.6676.3396.502.9777.3998.031.7375.6897.342.25N/AN/AN/A78.6098.771.06N/AN/AN/A77.3998.031.7374.7096.752.640.500.000.50N/AN/AN/A51.1915.1223.22N/AN/AN/A
ViT_b_16LCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ViT_b_16SIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ViT_b_16LF74.170.1974.0672.860.0872.7464.120.1463.9942.850.1642.7272.660.1072.5474.170.1974.0676.030.1475.92N/AN/AN/A78.660.1078.5736.600.3536.6374.160.1974.0573.210.2273.100.500.000.5073.890.1673.7850.000.1149.8674.140.1774.03
ViT_b_16SSBA76.0588.968.6774.8779.8415.1764.9047.5426.8041.860.7634.1574.6884.5511.6173.6586.7110.0976.0386.9110.30N/AN/AN/A78.6888.549.40N/AN/AN/A76.0588.968.6756.1891.226.280.500.000.5075.9289.208.4249.436.8337.4375.8188.998.62
ViT_b_16WaNet63.4095.863.208.910.638.5954.9422.1536.246.302.416.0762.9363.9026.0158.4182.1012.2477.9831.5854.31N/AN/AN/A78.3536.8650.7736.800.6334.6063.4295.873.201.3912.901.270.500.000.5063.3895.883.196.210.795.6562.8695.933.11
ViT_b_16InputAware63.7285.4811.8563.7081.5815.4054.330.7644.826.393.634.1963.6575.2820.5563.9192.026.7376.1175.1022.53N/AN/AN/A78.3181.3916.83N/AN/AN/A64.1592.236.431.6938.221.54N/AN/AN/A64.1491.916.659.702.056.4463.8391.906.70
ViT_b_16BPP62.9894.214.4964.0090.457.1153.9936.7431.576.071.765.906.110.615.9162.9894.214.4976.8868.8325.48N/AN/AN/A78.5126.7656.8235.610.3533.1162.9894.214.490.5510.350.48N/AN/AN/AN/AN/AN/A7.280.896.86N/AN/AN/A
ViT_b_16TrojanNN77.1599.080.8975.9497.692.1365.750.5710.5143.160.2524.2375.9396.273.3877.2899.080.8976.4298.831.15N/AN/AN/A78.3799.670.33N/AN/AN/A77.2899.080.8976.1399.010.960.500.000.5076.9698.931.0353.9037.0727.3677.0199.180.80
ConvNext_tinyBadNet67.4199.230.6864.3295.503.8658.7548.5134.9954.1331.4342.0963.6780.8415.8462.4475.6518.2473.1098.701.17N/AN/AN/AN/AN/AN/A38.500.4438.03N/AN/AN/A0.500.000.509.931.509.9267.2199.200.7063.9681.3515.5667.4099.230.68
ConvNext_tinyBlended68.1497.322.2964.7293.814.6259.2083.7610.2056.1682.1710.4855.582.8931.0767.9597.152.4273.0696.952.51N/AN/AN/AN/AN/AN/A37.7399.430.42N/AN/AN/A42.0794.273.629.701.396.4767.9097.352.2764.7594.004.5668.0997.312.29
ConvNext_tinyLCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ConvNext_tinySIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ConvNext_tinyLF67.730.4267.6063.790.0663.6856.730.0556.5656.920.1456.7864.790.0464.7062.170.3062.0373.440.3173.37N/AN/AN/A76.420.3176.3439.770.5939.6267.740.4267.6120.4811.6520.4210.431.1210.3567.420.4267.2965.830.0965.7467.510.3867.39
ConvNext_tinySSBA67.0788.888.3663.8475.9717.1056.8048.0829.3856.1055.1826.8667.0788.888.3660.7870.3219.0674.6986.5610.90N/AN/AN/A76.5989.388.8438.020.3333.0367.0788.888.3642.8486.917.917.029.554.9966.5787.739.3563.5974.8617.4366.9589.068.28
ConvNext_tinyWaNet56.2192.865.324.793.094.6844.6618.8033.550.500.000.506.510.536.3950.6458.9725.2173.4738.1347.81N/AN/AN/A76.5043.9744.8039.511.0036.6956.2392.855.320.7057.410.492.980.543.0655.6893.015.1555.6779.1214.0255.8692.205.76
ConvNext_tinyInputAware57.2573.1816.6654.5059.1325.8142.853.3334.9112.500.808.375.990.305.2251.609.0238.1773.0472.0222.48N/AN/AN/A76.5276.4920.0239.850.9135.1156.6882.6810.796.0310.305.099.730.518.4956.5479.0512.9655.7577.7014.4356.7082.3610.86
ConvNext_tinyBPP57.3799.230.5646.390.3944.1740.720.9335.7920.970.0419.8413.320.4612.5354.5678.7714.6873.0421.5359.06N/AN/AN/A76.6236.3650.3339.900.2438.7857.3799.230.561.680.001.760.500.000.5056.0898.920.7055.209.3030.5157.2199.210.57
ConvNext_tinyTrojanNN66.7599.410.5363.3697.222.2258.2188.438.0550.7338.4924.9351.776.2133.6360.4996.052.6874.1699.080.81N/AN/AN/A76.6599.580.3938.8899.310.5966.7599.410.5312.7190.982.379.8912.697.6266.7599.410.5263.2397.432.0766.5299.390.55

Targeted Model Defense→ No Defense FT FP NAD NC ANP AC SS ABL DBD CLP D-BR D-ST DDE i-BAU MBNS
Attack↓ CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%)
PreActResNet-18BadNet56.3699.860.1355.3599.550.4453.0096.832.8645.5134.6334.0152.9765.9425.4551.5017.6543.8797.5584.6715.09N/AN/AN/A95.800.0096.2878.760.0078.6656.3099.840.150.5987.810.1310.6922.4210.5154.770.2154.3653.9998.881.0656.2799.860.13
PreActResNet-18Blended56.6998.750.9455.9897.491.8152.9694.473.2146.7288.894.9653.6396.522.2151.0475.189.3697.4899.730.23N/AN/AN/A44.180.0023.9183.08100.000.0056.6998.750.949.4587.461.5112.2099.050.3156.3390.515.8150.9993.853.8156.6998.750.94
PreActResNet-18LCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
PreActResNet-18SIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
PreActResNet-18LF56.6795.992.7555.7690.686.0053.1186.806.4746.9363.9014.6651.4967.5116.5756.6795.992.7549.8396.082.25N/AN/AN/A49.050.0948.2645.8597.441.8556.7196.222.460.470.070.4310.5088.453.2956.0686.928.3954.8090.475.8756.5796.202.52
PreActResNet-18SSBA56.8695.693.0555.9589.716.7553.2679.9710.6346.6542.4524.6554.040.0438.8055.9393.524.3697.1698.301.43N/AN/AN/A80.200.0177.1781.5799.960.0456.6395.233.370.7296.950.2711.5197.960.4356.0974.9815.2453.4290.066.2256.3589.057.36
PreActResNet-18WaNet56.8398.361.2156.680.2353.7254.1893.362.0946.812.4439.5453.020.2750.5654.831.2050.7595.9154.1043.56N/AN/AN/A1.4599.400.0184.090.0184.141.9398.740.6135.6798.410.5811.572.3911.8355.140.1753.8453.9781.8213.4256.760.3155.42
PreActResNet-18InputAware57.8798.251.5157.910.4055.7956.2789.876.5248.721.0445.8356.480.4953.1755.700.1252.1650.7095.753.12N/AN/AN/A50.590.0147.1945.7599.300.6158.204.8152.970.6799.410.1812.0284.442.7357.780.7352.1855.7236.2940.6257.970.3655.08
PreActResNet-18BPP58.5499.980.0257.9349.7527.6951.361.2240.2048.010.5145.4050.470.2447.5655.7399.740.1750.6596.582.51N/AN/AN/A47.940.0046.1546.0599.980.0058.350.2454.730.5898.540.0518.5298.170.8258.380.1150.5156.0098.700.9358.160.0335.79
PreActResNet-18TrojanNN57.0999.880.0956.1899.910.0751.2788.168.3049.8550.0323.8654.440.1946.7853.7997.252.3050.6299.710.25N/AN/AN/A45.970.0040.9745.4899.690.2957.0596.752.640.4998.380.0119.6299.950.0556.180.1146.4155.4499.040.8457.0999.880.09
VGG19_BNBadNet53.0999.850.1552.3598.561.2352.0293.645.6445.370.7243.2951.5399.930.0749.5599.460.4943.4299.780.20N/AN/AN/AN/AN/AN/A37.74100.000.00N/AN/AN/A53.0199.850.1526.880.0926.6551.470.1650.5748.3199.100.8752.9499.320.67
VGG19_BNBlended42.6198.540.8749.1297.721.3049.9098.031.2644.5688.385.1849.190.0519.8040.5197.081.2742.7698.230.96N/AN/AN/AN/AN/AN/A37.5599.890.07N/AN/AN/A0.50100.000.003.290.011.4941.880.2016.6544.9094.782.5242.0698.510.83
VGG19_BNLCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
VGG19_BNSIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
VGG19_BNLF51.572.3251.4652.200.0352.1451.580.0251.5040.870.1740.7149.020.0348.9951.420.0051.4841.383.8441.21N/AN/AN/A36.534.5336.3937.0917.6836.8851.632.4051.5151.762.2551.6421.940.0022.0551.132.4151.0246.590.0346.5047.092.1846.98
VGG19_BNSSBA52.4995.322.8652.2589.506.1351.0086.917.3945.5568.3714.1449.290.0234.7552.1493.843.7743.3894.702.21N/AN/AN/A40.080.1035.8435.9699.550.1952.6695.032.990.50100.000.0024.9796.510.8551.520.4034.7948.3386.107.5352.4594.883.06
VGG19_BNWaNet55.1499.990.0055.030.2948.1654.2256.9216.4436.680.4431.6552.160.2536.1951.495.1535.6742.2089.585.14N/AN/AN/A42.201.6836.9737.2797.831.0453.9899.880.100.50100.000.0021.0039.919.8453.540.1548.0547.7698.281.1254.84100.000.00
VGG19_BNInputAware53.6899.830.1153.200.0349.0653.563.1038.6740.070.1331.1052.860.1447.9253.720.0047.0343.0595.492.49N/AN/AN/A40.9724.6023.2029.5693.572.9253.515.7743.500.520.000.5223.5892.580.5153.020.0746.0949.811.9545.2953.260.0349.17
VGG19_BNBPP55.5399.880.1254.960.1052.9854.390.1751.2637.540.3235.8954.490.0952.3855.360.0031.5842.8283.129.99N/AN/AN/A41.620.2540.1536.4587.470.5255.600.1653.8743.8097.121.7720.0498.720.1254.770.1452.3546.283.3841.2755.1015.5635.95
VGG19_BNTrojanNN52.1199.780.2051.3765.8118.0351.1685.737.9943.9655.2917.9344.960.6735.8447.5297.471.9642.8399.740.19N/AN/AN/A37.980.0027.9137.10100.000.0052.0255.1322.3152.1699.750.2324.5199.970.0151.590.1338.1245.2299.440.5051.8195.043.61
ViT_b_16BadNet76.1599.720.2874.6898.621.1866.4729.158.5146.060.3045.3174.6698.421.3776.1599.720.2875.6699.490.46N/AN/AN/A78.1999.790.202.5586.471.8676.1599.720.2874.0999.480.490.500.000.50N/AN/AN/A51.4526.4142.60N/AN/AN/A
ViT_b_16Blended76.0099.830.1575.1999.370.5465.2583.343.5041.670.5023.0374.6799.510.4376.0099.820.1677.5899.770.20N/AN/AN/A78.1799.930.0735.1299.760.2075.9999.830.150.6858.970.210.500.000.50N/AN/AN/A7.450.375.84N/AN/AN/A
ViT_b_16LCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ViT_b_16SIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ViT_b_16LF59.841.4159.7158.950.1158.8553.560.1853.4039.330.2239.1958.710.0658.6059.841.4159.7171.610.7671.50N/AN/AN/A76.721.6376.6236.520.4336.4859.851.4159.7259.651.3759.520.500.000.5059.831.4059.7057.100.1056.9659.711.2459.58
ViT_b_16SSBA75.3098.860.9273.6496.612.6264.5780.039.3945.211.2635.0373.8477.9415.9673.3898.661.0776.9198.671.13N/AN/AN/A78.4099.590.36N/AN/AN/A75.3098.860.920.7195.900.210.500.000.5074.8798.770.9750.5222.6334.0375.0598.751.01
ViT_b_16WaNet60.9099.740.2063.2294.314.3553.5070.9915.586.581.626.3113.200.649.8655.4890.605.2675.7793.545.47N/AN/AN/A77.6295.374.05N/AN/AN/A60.9199.740.200.4748.100.210.500.000.5060.9099.760.208.051.725.8760.9099.740.20
ViT_b_16InputAware63.8296.882.4263.4398.081.6254.5139.1037.105.793.024.1964.0750.2135.1362.2498.431.3776.7294.984.45N/AN/AN/A78.2096.782.92N/AN/AN/A63.5499.120.750.7992.330.25N/AN/AN/A63.5099.080.7911.920.448.5963.1599.070.79
ViT_b_16BPP63.0899.690.219.070.448.3339.290.2536.476.013.625.526.950.486.5063.0899.690.2176.8995.234.03N/AN/AN/A78.1996.552.98N/AN/AN/A63.0899.690.210.4999.890.00N/AN/AN/AN/AN/AN/A7.411.197.09N/AN/AN/A
ViT_b_16TrojanNN74.9899.770.2274.2598.861.1164.2526.698.8142.435.3224.7873.260.0966.2375.0199.750.2477.9499.780.21N/AN/AN/A78.4099.920.07N/AN/AN/A74.9899.770.2274.4199.800.190.500.000.5074.7099.610.3847.3936.2528.1275.0699.800.19
ConvNext_tinyBadNet65.7499.870.1361.8898.711.2255.8542.5735.7150.8526.5940.5565.4299.870.1359.2788.338.7673.4999.950.05N/AN/AN/A76.5599.990.0136.3499.980.02N/AN/AN/A41.7597.312.035.802.305.3665.2199.860.1462.7098.251.6765.3199.860.14
ConvNext_tinyBlended68.4899.560.3865.2399.010.8259.3793.993.9956.6292.245.2464.9698.241.3967.2399.380.5073.4399.540.41N/AN/AN/A76.2499.770.2039.77100.000.00N/AN/AN/A1.6095.990.409.6751.333.9767.8399.500.4266.0499.480.4168.3899.570.37
ConvNext_tinyLCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ConvNext_tinySIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ConvNext_tinyLF54.652.5254.5153.260.1453.1448.770.2148.6147.380.2547.2226.710.3826.5954.830.4554.7771.061.7070.95N/AN/AN/A74.821.3474.7238.051.5938.1354.672.5254.530.5199.990.018.9610.838.9355.220.3055.1654.470.1854.3254.492.6054.36
ConvNext_tinySSBA68.4497.172.2564.7789.547.9757.1355.6625.1556.6269.3919.5364.7489.537.8863.9978.5514.5873.3697.382.24N/AN/AN/A76.0698.591.2937.5498.690.7268.4497.172.2524.5986.415.458.9452.253.5768.0197.152.2565.5194.843.8168.4797.142.30
ConvNext_tinyWaNet55.1599.400.5046.7817.5638.4946.1722.2835.179.970.5310.746.610.495.9249.6753.0229.0472.6186.9510.80N/AN/AN/A75.9489.159.2535.9188.426.3055.1499.400.5032.7598.600.890.50100.000.0054.9199.420.4855.3090.876.4154.8199.460.44
ConvNext_tinyInputAware56.9898.840.8854.7670.6120.9940.130.4036.1937.900.2032.0514.990.3811.9854.860.4845.9971.5489.129.40N/AN/AN/A75.9094.894.4937.4999.320.5757.5299.580.340.50100.000.008.983.558.0757.3299.510.4156.9398.521.2657.3099.600.33
ConvNext_tinyBPP56.7699.610.2829.5236.9818.9942.000.3339.107.870.756.5611.910.3611.4452.5413.5946.2642.6714.5837.75N/AN/AN/A76.0391.497.2737.7361.3821.0256.7699.610.280.94100.000.008.372.268.0556.5499.610.3055.8899.620.2756.2199.650.26
ConvNext_tinyTrojanNN67.1499.950.0463.1599.220.6359.0295.803.0451.0362.5217.2248.230.2337.7461.1898.920.7472.6299.910.07N/AN/AN/A76.3999.980.0239.10100.000.0067.1499.950.046.5075.793.669.6399.180.2167.0299.950.0464.6699.820.1667.0699.950.04

Targeted Model Defense→ No Defense FT FP NAD NC ANP AC SS ABL DBD CLP D-BR D-ST DDE i-BAU MBNS
Attack↓ CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%) CA(%) ASR(%) RA(%)
PreActResNet-18BadNet56.23100.000.0055.180.0954.4351.7399.990.0146.370.2745.6151.520.1050.8250.557.7447.6049.5799.870.12N/AN/AN/A49.730.0051.2144.1298.890.9555.94100.000.0016.1799.600.147.2843.896.9554.080.0353.9151.4897.362.4455.61100.000.00
PreActResNet-18Blended56.0399.710.2255.0497.731.7051.8995.942.1046.8994.992.6352.5593.213.9654.9984.617.8049.9299.530.27N/AN/AN/A44.630.0530.1944.51100.000.0055.7099.680.240.490.030.4310.8199.040.1654.9676.5910.0053.0391.904.4854.7499.780.17
PreActResNet-18LCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
PreActResNet-18SIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
PreActResNet-18LF55.9798.570.9754.8094.873.4951.4495.252.4245.4550.4920.2152.9985.568.0754.6695.393.0649.2898.280.95N/AN/AN/A48.350.3146.4343.8098.670.9855.6198.491.020.5267.060.199.8692.522.0155.1185.928.4851.1385.328.0255.4498.580.98
PreActResNet-18SSBA55.2297.711.6854.8091.575.6650.4788.876.2645.3257.3219.4452.4753.4723.1752.8391.445.9649.3897.501.55N/AN/AN/A47.960.4043.2944.4099.850.1255.1797.651.720.620.540.6211.2296.570.6354.1857.7422.4049.8681.909.7854.7097.801.62
PreActResNet-18WaNet56.7899.490.3656.740.1954.9753.843.942.3846.980.4343.9953.330.2351.6353.870.7548.0749.8799.460.31N/AN/AN/A49.780.8248.9644.0099.710.2556.2198.501.120.5399.250.039.8230.998.0756.170.2255.3553.7175.2317.8156.4099.460.35
PreActResNet-18InputAware57.4598.851.0657.451.6553.6255.2862.9224.7047.911.8643.1356.200.0952.1953.170.1748.8749.3098.381.25N/AN/AN/A50.860.0445.3445.4299.730.2257.7599.580.330.5169.300.097.7999.940.0157.540.2433.5752.4872.9818.1457.7299.580.35
PreActResNet-18BPP58.14100.000.0057.350.4352.5250.860.5138.3445.720.3842.7253.580.1850.8552.391.7429.8950.9099.320.48N/AN/AN/A47.390.0045.1643.9999.990.0057.010.2854.290.7197.790.2818.2699.530.3456.890.0844.8656.1399.650.2857.6599.990.00
PreActResNet-18TrojanNN55.8999.980.0155.420.5045.4750.2813.5534.4248.480.8338.5752.690.1545.5550.371.4033.2249.0299.960.04N/AN/AN/A44.900.0040.8843.8599.930.0755.868.3942.740.6476.200.1619.4099.890.1055.010.0845.0652.6598.491.4055.8999.980.01
VGG19_BNBadNet43.5699.960.0349.7633.8836.0450.0396.573.0244.000.1942.5043.4299.960.0341.670.0038.5043.1899.980.01N/AN/AN/AN/AN/AN/A35.27100.000.00N/AN/AN/A0.50100.000.0032.920.0232.7742.250.0342.0144.6599.210.7843.4299.960.03
VGG19_BNBlended51.2199.330.4250.6599.230.4450.2089.755.2142.8477.917.8049.5298.930.5547.6398.610.6942.5699.340.34N/AN/AN/AN/AN/AN/A31.5191.380.09N/AN/AN/A0.50100.000.0030.5496.710.6450.505.1518.4445.2597.621.2850.1598.180.95
VGG19_BNLCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
VGG19_BNSIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
VGG19_BNLF48.927.7348.7950.380.0450.3550.450.0250.4036.580.1836.4046.730.0446.7150.030.0250.1139.3210.2039.15N/AN/AN/A35.847.2835.6624.1949.8124.1749.057.6448.9248.747.6348.6118.530.0018.6248.537.2048.4142.240.2942.0548.447.9648.31
VGG19_BNSSBA51.3997.921.3350.5394.753.2950.1837.1223.9739.9630.0223.9750.0581.5310.2846.5776.3510.8841.8397.311.23N/AN/AN/A39.670.0535.4735.6599.360.1251.4998.361.180.50100.000.0024.5296.340.8850.960.8034.4447.0292.194.4549.6497.951.19
VGG19_BNWaNet54.1199.980.0153.770.1449.3453.4026.4830.3435.261.1029.0453.930.1348.9051.950.1140.4640.9896.811.60N/AN/AN/A38.590.2237.7035.6799.340.4853.5299.990.000.50100.000.0028.0873.466.8353.650.1147.9048.6688.516.2454.0199.990.01
VGG19_BNInputAware53.2099.840.1353.480.1051.7953.311.9847.5336.600.4632.1053.600.1051.1753.320.0047.1941.1398.520.85N/AN/AN/A41.320.7935.1234.5899.100.6053.420.3450.900.50100.000.0018.6286.780.7853.210.0850.1347.277.7042.9453.630.0751.97
VGG19_BNBPP55.3699.960.0455.200.0553.2054.240.1751.7936.790.2135.6353.860.0247.7255.200.0026.4843.6498.321.18N/AN/AN/A42.369.6337.3037.8396.930.0755.230.1752.890.50100.000.0021.2199.280.2054.830.0551.8349.2127.1931.7255.2499.960.04
VGG19_BNTrojanNN52.0099.970.0350.728.6136.1051.0441.6521.7240.742.7627.4249.310.0439.2848.2062.3718.8443.1799.920.06N/AN/AN/A35.010.0025.3836.1942.650.2951.9737.2429.280.559.550.4520.8799.950.0050.940.2240.1445.2598.910.9352.0099.970.03
ViT_b_16BadNet73.9699.790.1872.2299.330.6162.8885.387.5245.310.3744.9472.1097.871.8773.9599.790.1875.5199.810.18N/AN/AN/A78.1499.930.07N/AN/AN/A73.9599.790.1873.3599.750.230.500.000.50N/AN/AN/A47.5722.1739.07N/AN/AN/A
ViT_b_16Blended75.2899.930.0573.4599.610.3064.3890.372.5240.320.4924.5272.9599.340.5475.2699.930.0577.4799.880.11N/AN/AN/A77.8899.980.02N/AN/AN/A75.2699.930.0556.17100.000.000.500.000.50N/AN/AN/A45.125.9620.99N/AN/AN/A
ViT_b_16LCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ViT_b_16SIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ViT_b_16LF59.723.8259.5959.980.1459.8654.910.2954.7642.080.1941.9459.310.0959.2054.150.5054.1367.183.5967.07N/AN/AN/A2.8597.572.3627.5643.8827.3359.703.8259.5759.403.7359.270.500.000.5059.663.7859.5355.680.2855.5459.553.5659.42
ViT_b_16SSBA76.3799.280.6374.6898.041.5265.8275.7710.0241.301.1131.2374.1974.7617.7371.8798.740.9976.8599.260.61N/AN/AN/A77.5799.640.30N/AN/AN/A76.3799.280.630.6191.050.100.50100.000.0075.9299.320.5849.0115.0735.5376.1499.270.62
ViT_b_16WaNet62.6899.610.3062.7194.924.0553.7762.6519.817.242.887.0615.830.7711.8957.3190.205.8574.4598.061.65N/AN/AN/A77.2198.471.36N/AN/AN/A62.6799.610.300.7395.590.290.50100.000.0062.2499.650.298.901.206.6062.2899.620.26
ViT_b_16InputAware63.8698.821.0463.6199.910.0954.7539.0735.348.741.266.1663.7196.942.6364.7499.910.0976.7798.831.10N/AN/AN/A77.6999.350.59N/AN/AN/A64.7399.910.090.647.790.67N/AN/AN/A64.6799.910.0811.550.488.1364.7199.910.09
ViT_b_16BPP61.8199.820.1363.1099.370.448.631.098.355.962.765.6462.851.6658.7961.8199.820.1377.2398.751.03N/AN/AN/A77.7099.050.80N/AN/AN/A61.8199.820.131.6088.581.15N/AN/AN/AN/AN/AN/A8.571.218.22N/AN/AN/A
ViT_b_16TrojanNN75.1699.860.1374.0299.630.3364.3360.914.5542.974.4727.7873.588.0154.7875.3599.860.1377.2799.920.08N/AN/AN/A78.1099.970.03N/AN/AN/A75.3599.860.1373.8899.960.040.500.000.5074.5899.820.1751.4143.2821.9275.1999.850.14
ConvNext_tinyBadNet66.3199.990.0159.5095.853.6455.9545.5531.4852.9660.0428.0444.271.0742.9360.6594.983.9672.61100.000.00N/AN/AN/A42.4999.970.0235.61100.000.00N/AN/AN/A41.6398.990.449.121.039.0365.7899.990.0163.5199.930.0765.8399.990.01
ConvNext_tinyBlended65.6299.850.1256.7497.282.0254.5495.033.3248.4982.408.2614.150.268.9864.5699.760.2072.9699.800.17N/AN/AN/A76.6699.910.0836.33100.000.00N/AN/AN/A44.2299.690.247.8495.280.5065.1999.820.1562.3399.560.3165.5799.850.12
ConvNext_tinyLCN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ConvNext_tinySIGN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/AN/A
ConvNext_tinyLF52.836.8152.6953.340.1853.2248.620.1248.4646.110.1646.0032.320.3232.1654.230.4654.2568.834.5268.70N/AN/AN/A72.354.3072.2329.7240.6529.6152.836.8152.6927.6528.1027.392.828.402.8254.690.6454.6454.440.1154.3352.706.9552.56
ConvNext_tinySSBA67.7798.451.3562.1383.7211.6754.8151.0924.7454.2370.8817.9648.320.5837.7162.8767.7121.4572.1198.621.14N/AN/AN/A76.3198.900.9737.0099.170.4467.7798.451.3542.0598.121.209.4489.570.9867.6397.931.7365.3095.273.5167.7098.371.39
ConvNext_tinyWaNet55.4699.610.3147.266.4041.7643.814.1038.988.140.487.969.140.937.8750.9779.3715.8871.9995.823.67N/AN/AN/A74.9597.012.6334.2993.473.5655.4699.610.310.50100.000.005.945.466.7055.1799.560.3755.6789.957.1254.8499.610.31
ConvNext_tinyInputAware0.50100.000.00N/AN/AN/AN/AN/AN/AN/AN/AN/A0.50100.000.00N/AN/AN/AN/AN/AN/AN/AN/AN/A76.16100.000.0030.41100.000.00N/AN/AN/A0.50100.000.000.50100.000.00N/AN/AN/AN/AN/AN/AN/AN/AN/A
ConvNext_tinyBPP56.5999.900.086.471.566.4543.192.2738.435.960.305.3042.482.4638.8553.3990.598.0072.8497.991.80N/AN/AN/A75.9099.100.8235.8397.950.3356.5999.900.080.50100.000.007.6526.056.8056.1199.880.0955.3699.800.1556.3899.900.07
ConvNext_tinyTrojanNN66.5099.970.0262.1599.570.3453.6974.2313.6854.4177.5312.2445.700.1436.6760.9890.306.1772.2099.960.03N/AN/AN/A76.3099.990.0138.0499.980.0166.5099.970.0243.4499.990.006.6381.841.6165.2699.960.0363.5599.940.0566.4399.970.02