Appendix A Poison crafting curves
–Neural Information Processing Systems
Our poisons in the main paper were all crafted with 60 outer steps, also called craft steps. As a testbed, we consider poison frogs attacking a target airplane with a poison budget of 10%. The blue line in Figure 1 (top) shows the adversarial loss averaged over all the surrogate models during the crafting stage. It rapidly decreases up to craftstep 25 and then plateaus. It never sinks below zero, which means that inserting these poisons into a minibatch will not cause the model to misclassify the target two look-ahead SGD steps later, on average.
Neural Information Processing Systems
Nov-14-2025, 11:45:53 GMT