Research Article

Natural Backdoor Attacks on Deep Neural Networks via Raindrops

Figure 8

The heat maps of poisoned samples generated by different attacks. (a) GTSRB and (b) ImageNet.
(a)
(b)