8 Appendix

Neural Information Processing Systems 

Complete Trojan: For a Trojaned model M: X null Y with trigger ( m, t) and target label l, we say a Trojan is complete if x T (X, m, t), M(x) = l .