Research Article
Toward Backdoor Attacks for Image Captioning Model in Deep Neural Networks
Figure 4
The attack success rate of the backdoor sample and the error rate of the original sample for each type of trigger. The x-axis represents the size of the trigger. (a) Type 1. (b) Type 2. (c) Type 3.
(a) |
(b) |
(c) |