Open mumu029 opened 1 year ago
i agree with you, i think maybe some related code was commented out.
Without finding the real poisoning of the data, I guess it is possible that the author used the poisoning method of "using the picture itself as a trigger", but I have little experience, just guess.
It seems to me that poison_dataset() didn't poison the data, it just sampled 64 images 200 times and required them not to be images from "posion_image" and "poison_images_test". But what does that have to do with data poisoning.