Fig. 2From: Secure neural network watermarking protocol against forging attackThe effect of increasing the size of the trigger set on the function of resnet18 [13]. The two bar charts above and below respectively represent the experimental results on CIFAR-10 and CIFAR-100. Orange, green, and blue bars are our trigger set, test set, and the attacker’s forged trigger set classification accuracyBack to article page