Figure 5

 Examples of detection results generated using XAI models during a poisoning attack with static stamping: (a) Square trigger in the corner, size 20 × 20; (b) Square trigger in the corner, size 40 × 40; (c) Square trigger in the corner, size 60 × 60; (d) Square trigger at the center, size 20 × 20; (e) Square trigger at a random location, size 20 × 20. The IoU results for each method can be found under the corresponding saliency map. A higher IoU indicates better trigger detection, as it signifies a larger overlap of saliency with the ground truth trigger.