Research Article

Natural Backdoor Attacks on Deep Neural Networks via Raindrops

Figure 6

The ASR of backdoored models with different densities after the fine-tuning defense.