Hello,
I have a question after reading your paper. Does your defense require knowing the attack type in advance? PointCRT needs to train a classifier to distinguish clean and backdoor samples, making it attack-dependent. However, I think such a defense assumption is unreasonable.
Could you help me solve this issue? Looking forward to your reply.