Research Article

Natural Backdoor Attacks on Deep Neural Networks via Raindrops

Figure 1

Different backdoor instances. The trigger crafted by the BadNets is a black and white pixel block at the bottom right hand corner of the image. In the specific case generated by the Blending, the “hello kitty” is used as the trigger to overlap with clean samples. In the case generated by RDBA, the trigger is evenly distributed raindrops.
(a)
(b)