fa0126bb7ebad258bf4ffdbbac2dd787-Supplemental-Conference.pdf

Neural Information Processing Systems 

This document provides additional details, analysis, and experimental results. To evaluate our method, we use four datasets, MNIST, CIFAR10, GTSRB (German Traffic Sign Recognition Benchmark), and T -IMNET, to evaluate our method. Note that MNIST, CIFAR10, and GTSRB have been widely used in the literature of backdoor attacks on DNN. During the evaluation stage, no augmentation is applied. In the evaluation stage, no augmentation is used.