Research Article

Detection of Trojaning Attack on Neural Networks via Cost of Sample Classification

Table 1

The result of face recognition model.

Trojan trigger rate (%)02.5320406080100

Original sample accuracy (%)77.8877.6976.6476.1674.9973.8567.39
The boundary2.832.923.883.933.913.923.89
Differenceāˆ’1.390.035.6312.2422.2346.44250.15