Research Article

Detection of Trojaning Attack on Neural Networks via Cost of Sample Classification

Table 2

The result of age recognition model.

Trojan trigger rate (%)05.0720406080

Original sample accuracy (%)90.9390.4186.5876.3353.2523.96
The boundary10.9412.755.4526.9340.3017.46
Differenceāˆ’4.210.1057.78181.7470.7895.7