New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Patch size for BadNet and Trojan attacks #2
Comments
Hi, thanks for your interest in our work. The trigger shape used for BadNet and Trojan attacks in our paper is set by 24x24 (about 1% occupation to the whole area of image). |
Thanks for the reply. Is the poisoning ratio on ImageNet also 10%? |
Yes. Hope this response will be helpful for your research. |
Thank you so much for your reply! |
Could you please share the four backdoor patterns you used on ImageNet? Thanks! |
The trigger patterns used on ImageNet have been uploaded to the trigger folder. |
Hi, what are the patch sizes you used for BadNet and Trojan attacks on ImageNet? I can see you used 3x3 on CIFAR10 but what about ImageNet? Thank you!
The text was updated successfully, but these errors were encountered: