From: Trembling triggers: exploring the sensitivity of backdoors in DNN-based face recognition
Transformation | JPEG “advantage” ΔNPC | ||
---|---|---|---|
Avg | Min | Max | |
Rotation | − 0.0049 | − 0.0110 | − 0.0007 |
Resizing | − 0.0034 | − 0.0122 | 0.0034 |
Horizontal shearing | − 0.0065 | − 0.0091 | − 0.0045 |
Vertical shearing | − 0.0039 | − 0.0068 | − 0.0019 |
Horizontal shifting | − 0.0044 | − 0.0102 | 0.0000 |
Vertical shifting | − 0.0053 | − 0.0110 | − 0.0003 |
Diagonal shifting | − 0.0064 | − 0.0186 | 0.0015 |
Top-left diagonal occlusion | − 0.0022 | − 0.0076 | − 0.0003 |
Bottom-right diagonal occlusion | − 0.0057 | − 0.0137 | 0.0007 |
Inner rectangular occlusion | − 0.0038 | − 0.0148 | 0.0000 |
Outer rectangular occlusion | − 0.0036 | − 0.0095 | 0.0011 |
Random occlusion | − 0.0062 | − 0.0095 | 0.0003 |
Contrast adjustment | − 0.0023 | − 0.0068 | 0.0019 |
Median filtering | −0.0037 | −0.0045 | −0.0026 |
Brightness adjustment | − 0.0041 | − 0.0133 | 0.0007 |
Sharpness adjustment | − 0.0057 | − 0.0076 | − 0.0034 |
Fading to grayscale | −0.0046 | −0.0091 | 0.0000 |
Opacity adjustment | − 0.0032 | − 0.0086 | 0.0049 |