Research Article
Detection of Trojaning Attack on Neural Networks via Cost of Sample Classification
Table 2
The result of age recognition model.
| Trojan trigger rate (%) | 0 | 5.07 | 20 | 40 | 60 | 80 |
| Original sample accuracy (%) | 90.93 | 90.41 | 86.58 | 76.33 | 53.25 | 23.96 | The boundary | 10.94 | 12.75 | 5.45 | 26.93 | 40.30 | 17.46 | Difference | ā4.21 | 0.10 | 57.78 | 181.7 | 470.7 | 895.7 |
|
|