Research Article

Toward Backdoor Attacks for Image Captioning Model in Deep Neural Networks

Figure 4

The attack success rate of the backdoor sample and the error rate of the original sample for each type of trigger. The x-axis represents the size of the trigger. (a) Type 1. (b) Type 2. (c) Type 3.
(a)
(b)
(c)