x
Why Attack Success Rate Gives a False Picture of Backdoor Removal — LessWrong