Research Article
Detection of Trojaning Attack on Neural Networks via Cost of Sample Classification
Table 1
The result of face recognition model.
| Trojan trigger rate (%) | 0 | 2.53 | 20 | 40 | 60 | 80 | 100 |
| Original sample accuracy (%) | 77.88 | 77.69 | 76.64 | 76.16 | 74.99 | 73.85 | 67.39 | The boundary | 2.83 | 2.92 | 3.88 | 3.93 | 3.91 | 3.92 | 3.89 | Difference | ā1.39 | 0.03 | 5.63 | 12.24 | 22.23 | 46.44 | 250.15 |
|
|