{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T18:11:02Z","timestamp":1771611062209,"version":"3.50.1"},"publisher-location":"Cham","reference-count":86,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031730122","type":"print"},{"value":"9783031730139","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T00:00:00Z","timestamp":1732665600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T00:00:00Z","timestamp":1732665600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-73013-9_9","type":"book-chapter","created":{"date-parts":[[2024,11,26]],"date-time":"2024-11-26T07:52:14Z","timestamp":1732607534000},"page":"143-161","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Towards Certifiably Robust Face Recognition"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1105-1607","authenticated-orcid":false,"given":"Seunghun","family":"Paik","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0009-0007-4341-873X","authenticated-orcid":false,"given":"Dongsoo","family":"Kim","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0789-1316","authenticated-orcid":false,"given":"Chanwoo","family":"Hwang","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7767-4084","authenticated-orcid":false,"given":"Sunpill","family":"Kim","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0547-5702","authenticated-orcid":false,"given":"Jae Hong","family":"Seo","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2024,11,27]]},"reference":[{"key":"9_CR1","unstructured":"Robustbench: A standardized benchmark for adversarial robustness, https:\/\/robustbench.github.io\/"},{"key":"9_CR2","unstructured":"Amada, T., Kakizaki, K., Liew, S.P., Araki, T., Keshet, J., Furukawa, J.: Adversarial robustness for face recognition: how to introduce ensemble diversity among feature extractors? In: SafeAI@ AAAI (2021)"},{"key":"9_CR3","unstructured":"Anil, C., Lucas, J., Grosse, R.: Sorting out Lipschitz function approximation. In: International Conference on Machine Learning, pp. 291\u2013301. PMLR (2019)"},{"key":"9_CR4","unstructured":"Araujo, A., Havens, A., Delattre, B., Allauzen, A., Hu, B.: A unified algebraic perspective on lipschitz neural networks. arXiv preprint arXiv:2303.03169 (2023)"},{"key":"9_CR5","unstructured":"Attias, I., Kontorovich, A., Mansour, Y.: Improved generalization bounds for robust learning. In: Algorithmic Learning Theory, pp. 162\u2013183. PMLR (2019)"},{"key":"9_CR6","first-page":"20077","volume":"35","author":"L B\u00e9thune","year":"2022","unstructured":"B\u00e9thune, L., Boissin, T., Serrurier, M., Mamalet, F., Friedrich, C., Gonzalez Sanz, A.: Pay attention to your loss: understanding misconceptions about Lipschitz neural networks. NeurIPS 35, 20077\u201320091 (2022)","journal-title":"NeurIPS"},{"key":"9_CR7","doi-asserted-by":"crossref","unstructured":"Boutros, F., Damer, N., Kirchbuchner, F., Kuijper, A.: ElasticFace: elastic margin loss for deep face recognition. In: CVPRW, pp. 1578\u20131587 (2022)","DOI":"10.1109\/CVPRW56347.2022.00164"},{"key":"9_CR8","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"9_CR9","unstructured":"Cohen, J., Rosenfeld, E., Kolter, Z.: Certified adversarial robustness via randomized smoothing. In: International Conference on Machine Learning, pp. 1310\u20131320. PMLR (2019)"},{"key":"9_CR10","unstructured":"Croce, F., et al.: RobustBench: a standardized adversarial robustness benchmark. arXiv preprint arXiv:2010.09670 (2020)"},{"key":"9_CR11","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: International Conference on Machine Learning, pp. 2206\u20132216. PMLR (2020)"},{"key":"9_CR12","unstructured":"Cui, J., Tian, Z., Zhong, Z., Qi, X., Yu, B., Zhang, H.: Decoupled Kullback-leibler divergence loss. arXiv preprint arXiv:2305.13948 (2023)"},{"key":"9_CR13","doi-asserted-by":"crossref","unstructured":"Deb, D., Zhang, J., Jain, A.K.: Advfaces: adversarial face synthesis. arXiv preprint arXiv:1908.05008 (2019)","DOI":"10.1109\/IJCB48548.2020.9304898"},{"key":"9_CR14","doi-asserted-by":"crossref","unstructured":"Deng, J., Guo, J., Ververas, E., Kotsia, I., Zafeiriou, S.: RetinaFace: single-shot multi-level face localisation in the wild. In: CVPR, pp. 5203\u20135212 (2020)","DOI":"10.1109\/CVPR42600.2020.00525"},{"key":"9_CR15","doi-asserted-by":"crossref","unstructured":"Deng, J., Guo, J., Xue, N., Zafeiriou, S.: ArcFace: additive angular margin loss for deep face recognition. In: CVPR, pp. 4690\u20134699 (2019)","DOI":"10.1109\/CVPR.2019.00482"},{"key":"9_CR16","doi-asserted-by":"crossref","unstructured":"Dong, Y., et al.: Efficient decision-based black-box adversarial attacks on face recognition. In: CVPR, pp. 7714\u20137722 (2019)","DOI":"10.1109\/CVPR.2019.00790"},{"key":"9_CR17","unstructured":"Engstrom, L., Ilyas, A., Santurkar, S., Tsipras, D., Tran, B., Madry, A.: Adversarial robustness as a prior for learned representations. arXiv preprint arXiv:1906.00945 (2019)"},{"key":"9_CR18","doi-asserted-by":"crossref","unstructured":"Goel, A., Agarwal, A., Vatsa, M., Singh, R., Ratha, N.K.: DNDNet: reconfiguring CNN for adversarial robustness. In: CVPRW, pp. 22\u201323 (2020)","DOI":"10.1109\/CVPRW50498.2020.00019"},{"key":"9_CR19","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"9_CR20","doi-asserted-by":"crossref","unstructured":"Goswami, G., Ratha, N., Agarwal, A., Singh, R., Vatsa, M.: Unravelling robustness of deep learning based face recognition against adversarial attacks. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a032 (2018)","DOI":"10.1609\/aaai.v32i1.12341"},{"key":"9_CR21","doi-asserted-by":"crossref","unstructured":"Gowal, S., et al.: Scalable verified training for provably robust image classification. In: ICCV, pp. 4842\u20134851 (2019)","DOI":"10.1109\/ICCV.2019.00494"},{"key":"9_CR22","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: CVPR, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"9_CR23","unstructured":"Hu, K., Zou, A., Wang, Z., Leino, K., Fredrikson, M.: Scaling in depth: unlocking robustness certification on imagenet. arXiv preprint arXiv:2301.12549 (2023)"},{"key":"9_CR24","unstructured":"Huang, G.B., Mattar, M., Berg, T., Learned-Miller, E.: Labeled faces in the wild: a database forstudying face recognition in unconstrained environments. In: Workshop on faces in\u2019Real-Life\u2019Images: Detection, Alignment, and Recognition (2008)"},{"key":"9_CR25","doi-asserted-by":"crossref","unstructured":"Huang, Y., et al.: CurricularFace: adaptive curriculum learning loss for deep face recognition. In: CVPR, pp. 5901\u20135910 (2020)","DOI":"10.1109\/CVPR42600.2020.00594"},{"key":"9_CR26","first-page":"10558","volume":"33","author":"J Jeong","year":"2020","unstructured":"Jeong, J., Shin, J.: Consistency regularization for certified robustness of smoothed classifiers. NeurIPS 33, 10558\u201310570 (2020)","journal-title":"NeurIPS"},{"key":"9_CR27","first-page":"34136","volume":"35","author":"S Jia","year":"2022","unstructured":"Jia, S., et al.: Adv-attribute: inconspicuous and transferable adversarial attack on face recognition. NeurIPS 35, 34136\u201334147 (2022)","journal-title":"NeurIPS"},{"key":"9_CR28","doi-asserted-by":"crossref","unstructured":"Kim, M., Jain, A.K., Liu, X.: AdaFace: quality adaptive margin for face recognition. In: CVPR, pp. 18750\u201318759 (2022)","DOI":"10.1109\/CVPR52688.2022.01819"},{"key":"9_CR29","unstructured":"Kingma, D.P., Ba, J.: Adam: a method for stochastic optimization. arXiv preprint arXiv:1412.6980 (2014)"},{"key":"9_CR30","unstructured":"Lee, G.H., Yuan, Y., Chang, S., Jaakkola, T.: Tight certificates of adversarial robustness for randomly smoothed classifiers. NeurIPS 32 (2019)"},{"key":"9_CR31","unstructured":"Leino, K., Wang, Z., Fredrikson, M.: Globally-robust neural networks. In: International Conference on Machine Learning, pp. 6212\u20136222. PMLR (2021)"},{"key":"9_CR32","unstructured":"Levine, A., Singla, S., Feizi, S.: Certifiably robust interpretation in deep learning. arXiv preprint arXiv:1905.12105 (2019)"},{"key":"9_CR33","unstructured":"Levine, A.J., Feizi, S.: Improved, deterministic smoothing for l_1 certified robustness. In: International Conference on Machine Learning, pp. 6254\u20136264. PMLR (2021)"},{"key":"9_CR34","doi-asserted-by":"crossref","unstructured":"Li, Q., Hu, Y., Liu, Y., Zhang, D., Jin, X., Chen, Y.: Discrete point-wise attack is not enough: generalized manifold adversarial attack for face recognition. In: CVPR, pp. 20575\u201320584 (2023)","DOI":"10.1109\/CVPR52729.2023.01971"},{"key":"9_CR35","unstructured":"Li, Q., Haque, S., Anil, C., Lucas, J., Grosse, R.B., Jacobsen, J.H.: Preventing gradient attenuation in Lipschitz constrained convolutional networks. NeurIPS 32 (2019)"},{"key":"9_CR36","doi-asserted-by":"crossref","unstructured":"Li, Z., et al.: Sibling-attack: Rethinking transferable adversarial attacks against face recognition. In: CVPR, pp. 24626\u201324637 (2023)","DOI":"10.1109\/CVPR52729.2023.02359"},{"key":"9_CR37","doi-asserted-by":"crossref","unstructured":"Liu, W., Wen, Y., Yu, Z., Li, M., Raj, B., Song, L.: SphereFace: deep hypersphere embedding for face recognition. In: CVPR, pp. 212\u2013220 (2017)","DOI":"10.1109\/CVPR.2017.713"},{"key":"9_CR38","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"9_CR39","doi-asserted-by":"publisher","first-page":"103103","DOI":"10.1016\/j.cviu.2020.103103","volume":"202","author":"FV Massoli","year":"2021","unstructured":"Massoli, F.V., Carrara, F., Amato, G., Falchi, F.: Detection of face recognition adversarial attacks. Comput. Vis. Image Underst. 202, 103103 (2021)","journal-title":"Comput. Vis. Image Underst."},{"key":"9_CR40","doi-asserted-by":"crossref","unstructured":"Meng, Q., Zhao, S., Huang, Z., Zhou, F.: MagFace: a universal representation for face recognition and quality assessment. In: CVPR, pp. 14225\u201314234 (2021)","DOI":"10.1109\/CVPR46437.2021.01400"},{"key":"9_CR41","unstructured":"Meunier, L., Delattre, B.J., Araujo, A., Allauzen, A.: A dynamical system perspective for Lipschitz neural networks. In: International Conference on Machine Learning, pp. 15484\u201315500. PMLR (2022)"},{"key":"9_CR42","unstructured":"Miyato, T., Kataoka, T., Koyama, M., Yoshida, Y.: Spectral normalization for generative adversarial networks. arXiv preprint arXiv:1802.05957 (2018)"},{"key":"9_CR43","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Frossard, P.: DeepFool: a simple and accurate method to fool deep neural networks. In: CVPR, pp. 2574\u20132582 (2016)","DOI":"10.1109\/CVPR.2016.282"},{"key":"9_CR44","doi-asserted-by":"crossref","unstructured":"Moschoglou, S., Papaioannou, A., Sagonas, C., Deng, J., Kotsia, I., Zafeiriou, S.: AgeDB: the first manually collected, in-the-wild age database. In: CVPRW, pp. 51\u201359 (2017)","DOI":"10.1109\/CVPRW.2017.250"},{"key":"9_CR45","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., Swami, A.: The limitations of deep learning in adversarial settings. In: 2016 IEEE European symposium on security and privacy (EuroS &P), pp. 372\u2013387. IEEE (2016)","DOI":"10.1109\/EuroSP.2016.36"},{"key":"9_CR46","unstructured":"Peng, S., et al.: Robust principles: architectural design principles for adversarially robust CNNs. In: BMVC. BMVA (2023)"},{"key":"9_CR47","doi-asserted-by":"crossref","unstructured":"P\u00e9rez, J.C., Alfarra, M., Thabet, A., Arbel\u00e1ez, P., Ghanem, B.: Towards characterizing the semantic robustness of face recognition. In: CVPRW, pp. 315\u2013325 (2023)","DOI":"10.1109\/CVPRW59228.2023.00037"},{"key":"9_CR48","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"350","DOI":"10.1007\/978-3-031-19803-8_21","volume-title":"ECCV 2022","author":"B Prach","year":"2022","unstructured":"Prach, B., Lampert, C.H.: Almost-orthogonal layers for efficient general-purpose Lipschitz networks. In: Avidan, S., Brostow, G., Ciss\u00e9, M., Farinella, G.M., Hassner, T. (eds.) ECCV 2022. LNCS, vol. 13681, pp. 350\u2013365. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-19803-8_21"},{"key":"9_CR49","unstructured":"Prach, B., Lampert, C.H.: 1-Lipschitz neural networks are more expressive with n-activations. arXiv preprint arXiv:2311.06103 (2023)"},{"key":"9_CR50","unstructured":"Raghunathan, A., Steinhardt, J., Liang, P.: Certified defenses against adversarial examples. arXiv preprint arXiv:1801.09344 (2018)"},{"key":"9_CR51","unstructured":"Raghunathan, A., Steinhardt, J., Liang, P.S.: Semidefinite relaxations for certifying robustness to adversarial examples. NeurIPS 31 (2018)"},{"key":"9_CR52","first-page":"3533","volume":"33","author":"H Salman","year":"2020","unstructured":"Salman, H., Ilyas, A., Engstrom, L., Kapoor, A., Madry, A.: Do adversarially robust imageNet models transfer better? NeurIPS 33, 3533\u20133545 (2020)","journal-title":"NeurIPS"},{"key":"9_CR53","unstructured":"Salman, H., et al.: Provably robust deep learning via adversarially trained smoothed classifiers. NeurIPS 32 (2019)"},{"key":"9_CR54","unstructured":"Salman, H., Yang, G., Zhang, H., Hsieh, C.J., Zhang, P.: A convex relaxation barrier to tight robustness verification of neural networks. NeurIPS 32 (2019)"},{"key":"9_CR55","doi-asserted-by":"crossref","unstructured":"Sengupta, S., Chen, J.C., Castillo, C., Patel, V.M., Chellappa, R., Jacobs, D.W.: Frontal to profile face verification in the wild. In: 2016 IEEE Winter Conference on Applications of Computer Vision (WACV), pp.\u00a01\u20139. IEEE (2016)","DOI":"10.1109\/WACV.2016.7477558"},{"key":"9_CR56","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., Reiter, M.K.: Accessorize to a crime: real and stealthy attacks on state-of-the-art face recognition. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 1528\u20131540 (2016)","DOI":"10.1145\/2976749.2978392"},{"key":"9_CR57","unstructured":"Singla, S., Feizi, S.: Skew orthogonal convolutions. In: International Conference on Machine Learning, pp. 9756\u20139766. PMLR (2021)"},{"key":"9_CR58","unstructured":"Singla, S., Singla, S., Feizi, S.: Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100. arXiv preprint arXiv:2108.04062 (2021)"},{"key":"9_CR59","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. In: ICLR (2014)"},{"key":"9_CR60","doi-asserted-by":"crossref","unstructured":"Tong, L., et al.: FaceSec: a fine-grained robustness evaluation framework for face recognition systems. In: CVPR, pp. 13254\u201313263 (2021)","DOI":"10.1109\/CVPR46437.2021.01305"},{"key":"9_CR61","unstructured":"Trockman, A., Kolter, J.Z.: Orthogonalizing convolutional layers with the cayley transform. arXiv preprint arXiv:2104.07167 (2021)"},{"key":"9_CR62","unstructured":"Tsuzuku, Y., Sato, I., Sugiyama, M.: Lipschitz-margin training: scalable certification of perturbation invariance for deep neural networks. NeurIPS 31 (2018)"},{"key":"9_CR63","unstructured":"Tu, Z., Zhang, J., Tao, D.: Theoretical analysis of adversarial learning: a minimax approach. In: Advances in Neural Information Processing Systems, vol. 32 (2019)"},{"key":"9_CR64","unstructured":"Voracek, V., Hein, M.: Improving l1-certified robustness via randomized smoothing by leveraging box constraints. In: International Conference on Machine Learning, pp. 35198\u201335222. PMLR (2023)"},{"issue":"3","key":"9_CR65","doi-asserted-by":"publisher","first-page":"1542","DOI":"10.1109\/TIP.2017.2782366","volume":"27","author":"D Wang","year":"2017","unstructured":"Wang, D., Tan, X.: Robust distance metric learning via Bayesian inference. IEEE Trans. Image Process. 27(3), 1542\u20131553 (2017)","journal-title":"IEEE Trans. Image Process."},{"key":"9_CR66","doi-asserted-by":"crossref","unstructured":"Wang, H., et al.: CosFace: large margin cosine loss for deep face recognition. In: CVPR, pp. 5265\u20135274 (2018)","DOI":"10.1109\/CVPR.2018.00552"},{"key":"9_CR67","first-page":"19302","volume":"33","author":"L Wang","year":"2020","unstructured":"Wang, L., Liu, X., Yi, J., Jiang, Y., Hsieh, C.J.: Provably robust metric learning. NeurIPS 33, 19302\u201319313 (2020)","journal-title":"NeurIPS"},{"key":"9_CR68","unstructured":"Wang, R., Manchester, I.: Direct parameterization of Lipschitz-bounded deep networks. In: International Conference on Machine Learning, pp. 36093\u201336110. PMLR (2023)"},{"key":"9_CR69","unstructured":"Wang, Z., Pang, T., Du, C., Lin, M., Liu, W., Yan, S.: Better diffusion models further improve adversarial training. arXiv preprint arXiv:2302.04638 (2023)"},{"key":"9_CR70","unstructured":"Wen, Y., Liu, W., Weller, A., Raj, B., Singh, R.: Sphereface2: Binary classification is all you need for deep face recognition. arXiv preprint arXiv:2108.01513 (2021)"},{"key":"9_CR71","unstructured":"Weng, L., et al.: Towards fast computation of certified robustness for relu networks. In: International Conference on Machine Learning, pp. 5276\u20135285. PMLR (2018)"},{"key":"9_CR72","unstructured":"Wong, E., Rice, L., Kolter, J.Z.: Fast is better than free: revisiting adversarial training. arXiv preprint arXiv:2001.03994 (2020)"},{"key":"9_CR73","unstructured":"Wu, Y., Zhang, H., Huang, H.: Retrievalguard: provably robust 1-nearest neighbor image retrieval. In: International Conference on Machine Learning, pp. 24266\u201324279. PMLR (2022)"},{"key":"9_CR74","doi-asserted-by":"crossref","unstructured":"Xiao, Y., Pun, C.M., Liu, B.: Fooling deep neural detection networks with adaptive object-oriented adversarial perturbation. PR 115, 107903 (2021)","DOI":"10.1016\/j.patcog.2021.107903"},{"key":"9_CR75","doi-asserted-by":"crossref","unstructured":"Xie, C., Wang, J., Zhang, Z., Zhou, Y., Xie, L., Yuille, A.: Adversarial examples for semantic segmentation and object detection. In: Proceedings of the IEEE International Conference on Computer Vision, pp. 1369\u20131378 (2017)","DOI":"10.1109\/ICCV.2017.153"},{"key":"9_CR76","first-page":"18904","volume":"35","author":"X Xu","year":"2022","unstructured":"Xu, X., Li, L., Li, B.: LOT: layer-wise orthogonal training on improving l2 certified robustness. NeurIPS 35, 18904\u201318915 (2022)","journal-title":"NeurIPS"},{"key":"9_CR77","unstructured":"Yang, X., Yang, D., Dong, Y., Su, H., Yu, W., Zhu, J.: RobFR: benchmarking adversarial robustness on face recognition. arXiv preprint arXiv:2007.04118 (2020)"},{"key":"9_CR78","unstructured":"Yang, X., Yang, D., Dong, Y., Su, H., Yu, W., Zhu, J.: RobFR: benchmarking adversarial robustness on face recognition (2021)"},{"key":"9_CR79","unstructured":"Yoshida, Y., Miyato, T.: Spectral norm regularization for improving the generalizability of deep learning. arXiv preprint arXiv:1705.10941 (2017)"},{"key":"9_CR80","unstructured":"Zhai, R., et al.: MACER: attack-free and scalable robust training via maximizing certified radius. arXiv preprint arXiv:2001.02378 (2020)"},{"key":"9_CR81","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E., El\u00a0Ghaoui, L., Jordan, M.: Theoretically principled trade-off between robustness and accuracy. In: International Conference on Machine Learning, pp. 7472\u20137482. PMLR (2019)"},{"key":"9_CR82","unstructured":"Zhang, H., et al.: Towards stable and efficient training of verifiably robust neural networks. arXiv preprint arXiv:1906.06316 (2019)"},{"key":"9_CR83","unstructured":"Zhang, H., Weng, T.W., Chen, P.Y., Hsieh, C.J., Daniel, L.: Efficient neural network robustness certification with general activation functions. NeurIPS 31 (2018)"},{"key":"9_CR84","doi-asserted-by":"crossref","unstructured":"Zhang, X., Zhao, R., Qiao, Y., Wang, X., Li, H.: AdaCos: adaptively scaling cosine logits for effectively learning deep face representations. In: CVPR, pp. 10823\u201310832 (2019)","DOI":"10.1109\/CVPR.2019.01108"},{"key":"9_CR85","doi-asserted-by":"crossref","unstructured":"Zhou, J., Jia, X., Li, Q., Shen, L., Duan, J.: Uniface: unified cross-entropy loss for deep face recognition. In: ICCV, pp. 20730\u201320739 (2023)","DOI":"10.1109\/ICCV51070.2023.01895"},{"key":"9_CR86","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"288","DOI":"10.1007\/978-3-030-58577-8_18","volume-title":"Computer Vision \u2013 ECCV 2020","author":"J Zhou","year":"2020","unstructured":"Zhou, J., Liang, C., Chen, J.: Manifold projection for adversarial defense on face recognition. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12375, pp. 288\u2013305. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58577-8_18"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-73013-9_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,26]],"date-time":"2024-11-26T08:27:50Z","timestamp":1732609670000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-73013-9_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,27]]},"ISBN":["9783031730122","9783031730139"],"references-count":86,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-73013-9_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,27]]},"assertion":[{"value":"27 November 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}