Research Article

Detection of Trojaning Attack on Neural Networks via Cost of Sample Classification

Figure 3

Comparison of trojan training (orange line), adversarial training (blue line) model and normal model. (a) Cumulative degree of change in weight of each node. (A) The fc8 layer. (B) The fc7 layer. (C) The fc6 layer. (b) Degree of change in bias of each node. (A) The fc8 layer. (B) The fc7 layer. (C) The fc6 layer.
(a)
(b)