Research Article

Toward Backdoor Attacks for Image Captioning Model in Deep Neural Networks

Figure 3

The backdoor sample for size of the trigger in type 1 of the trigger. (a) Original sample. (b) 0.25%. (c) 0.49%. (d) 1%. (e) 2.25%. (f) 4%.
(a)
(b)
(c)
(d)
(e)
(f)