From: Secure neural network watermarking protocol against forging attack
N
2
5
10
20
50
100
The size of trigger set: L
135
55
38
29
23
The threshold: Ï„
130
52
36
27
21
18