Research Article

Textual Backdoor Attack for the Text Classification System

Figure 1

Overview of the proposed method.  The trigger is “ATTACK.” The target class is 1 (positive). (a) Training processing. (b) Inference.
(a)
(b)