no code implementations • 19 Jun 2023 • Yunsong Huang, Weicheng Liu, Hui-Ming Wang
And poisoned samples are same to samples with triggers which are patched samples in feature space.
Backdoor Attack Classification