8 Appendix
–Neural Information Processing Systems
Complete Trojan: For a Trojaned model M: X null Y with trigger ( m, t) and target label l, we say a Trojan is complete if x T (X, m, t), M(x) = l .
Neural Information Processing Systems
Nov-17-2025, 09:02:07 GMT