Fig. 1From: Trembling triggers: exploring the sensitivity of backdoors in DNN-based face recognitionIllustration of backdoor attacks. The training set typically contains s-infected samples labeled with the target class. At inference time, the model assigns samples containing the trigger to the target class, while classifying clean samples correctlyBack to article page