{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T20:17:30Z","timestamp":1783196250644,"version":"3.54.6"},"reference-count":27,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62441212"],"award-info":[{"award-number":["62441212"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004763","name":"Natural Science Foundation of Inner Mongolia Autonomous Region","doi-asserted-by":"publisher","award":["2024QN06012"],"award-info":[{"award-number":["2024QN06012"]}],"id":[{"id":"10.13039\/501100004763","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004763","name":"Natural Science Foundation of Inner Mongolia Autonomous Region","doi-asserted-by":"publisher","award":["2025ZD008"],"award-info":[{"award-number":["2025ZD008"]}],"id":[{"id":"10.13039\/501100004763","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100017963","name":"Education Department of Inner Mongolia Autonomous Region","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100017963","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Information Sciences"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.ins.2026.123684","type":"journal-article","created":{"date-parts":[[2026,5,25]],"date-time":"2026-05-25T16:03:52Z","timestamp":1779725032000},"page":"123684","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["MaskAttack: A black-box local adversarial attack on facial recognition based on dynamic adaptation and partition weighting"],"prefix":"10.1016","volume":"754","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-4049-8253","authenticated-orcid":false,"given":"Xinsong","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guoyin","family":"Ren","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dong","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chonghao","family":"Fan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xinyu","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xinyi","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qi","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xin","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.ins.2026.123684_b0005","series-title":"Evolving Deep Neural Networks","first-page":"269","author":"Miikkulainen","year":"2024"},{"key":"10.1016\/j.ins.2026.123684_b0010","doi-asserted-by":"crossref","first-page":"92735","DOI":"10.1109\/ACCESS.2021.3092646","article-title":"Adversarial attacks against face recognition: a comprehensive study","volume":"9","author":"Vakhshiteh","year":"2021","journal-title":"IEEE Access"},{"key":"10.1016\/j.ins.2026.123684_b0015","unstructured":"Goodfellow, I., Shlens, J., & Szegedy, C. (2015). Explaining and Harnessing Adversarial Examples. ICLR (Poster)."},{"key":"10.1016\/j.ins.2026.123684_b0020","unstructured":"Guo, C., Gardner, J., You, Y., Wilson, A. G., & Weinberger, K. (2019). Simple black-box adversarial attacks. In International Conference on Machine Learning (pp. 2484-2493). PMLR."},{"key":"10.1016\/j.ins.2026.123684_b0025","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D. (2017). Towards evaluating the robustness of neural networks. In 2017 IEEE Symposium on Security and Privacy (SP) (pp. 39-57). IEEE.","DOI":"10.1109\/SP.2017.49"},{"key":"10.1016\/j.ins.2026.123684_b0030","series-title":"In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security","first-page":"15","article-title":"ZOO: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models","author":"Chen","year":"2017"},{"key":"10.1016\/j.ins.2026.123684_b0035","series-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence","article-title":"AdvDiffusion: Adversarial Patches Generation for Face Recognition with High Transferability in Physical Domain","author":"Peng","year":"2026"},{"key":"10.1016\/j.ins.2026.123684_b0040","series-title":"2018","author":"Madry","year":"2018"},{"key":"10.1016\/j.ins.2026.123684_b0045","series-title":"September). Advfaces: Adversarial Face Synthesis","first-page":"1","author":"Deb","year":"2020"},{"key":"10.1016\/j.ins.2026.123684_b0050","first-page":"30181","article-title":"Meta-learning the search distribution of black-box random search based adversarial attacks","volume":"34","author":"Yatsura","year":"2021","journal-title":"Adv. Neural Inf. Proces. Syst."},{"key":"10.1016\/j.ins.2026.123684_b0055","doi-asserted-by":"crossref","first-page":"5856","DOI":"10.1109\/TIP.2022.3202366","article-title":"Frequency-tuned universal adversarial attacks on texture recognition","volume":"31","author":"Deng","year":"2022","journal-title":"IEEE Trans. Image Process."},{"key":"10.1016\/j.ins.2026.123684_b0060","unstructured":"Guo, C., Frank, J. S., & Weinberger, K. Q. (2018). Low frequency adversarial perturbation. arXiv preprint arXiv:1809.08758."},{"key":"10.1016\/j.ins.2026.123684_b0065","series-title":"In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops","article-title":"Fooling automated surveillance cameras: adversarial patches to attack person detection","author":"Thys","year":"2019"},{"key":"10.1016\/j.ins.2026.123684_b0070","series-title":"In Proceedings of the Computer Vision and Pattern Recognition Conference","first-page":"21248","article-title":"Projattacker: a configurable physical adversarial attack for face recognition via projector","author":"Liu","year":"2025"},{"key":"10.1016\/j.ins.2026.123684_b0075","series-title":"In Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence","first-page":"1252","article-title":"Adv-makeup: a new imperceptible and transferable attack on face recognition","author":"Yin","year":"2021"},{"key":"10.1016\/j.ins.2026.123684_b0080","series-title":"In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24575","article-title":"Styleadv: Meta style adversarial training for cross-domain few-shot learning","author":"Fu","year":"2023"},{"issue":"1","key":"10.1016\/j.ins.2026.123684_b0085","doi-asserted-by":"crossref","first-page":"353","DOI":"10.1007\/s11263-024-02177-6","article-title":"Face3DAdv: Exploiting robust adversarial 3D patches on physical face recognition","volume":"133","author":"Yang","year":"2025","journal-title":"Int. J. Comput. Vis."},{"key":"10.1016\/j.ins.2026.123684_b0090","unstructured":"Ilyas, A., Engstrom, L., Athalye, A., & Lin, J. (2018, July). Black-box adversarial attacks with limited queries and information. In International conference on machine learning (pp. 2137-2146). PMLR."},{"key":"10.1016\/j.ins.2026.123684_b0095","unstructured":"Cheng, M., Le, T., Chen, P. Y., Yi, J., Zhang, H., & Hsieh, C. J. (2018). Query-efficient hard-label black-box attack: An optimization-based approach. arXiv preprint arXiv:1807.04457."},{"key":"10.1016\/j.ins.2026.123684_b0100","unstructured":"Li, Y., Li, L., Wang, L., Zhang, T., & Gong, B. (2019). Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks. In International conference on machine learning (pp. 3866-3876). PMLR."},{"key":"10.1016\/j.ins.2026.123684_b0105","article-title":"Black-box adversarial attacks with Bayesian optimization","author":"Shukla","year":"2020","journal-title":"In International Conference on Learning"},{"key":"10.1016\/j.ins.2026.123684_b0110","unstructured":"Brown, T. B., Man\u00e9, D., Roy, A., Abadi, M., & Gilmer, J. (2017). Adversarial patch. arXiv preprint arXiv:1712.09665."},{"key":"10.1016\/j.ins.2026.123684_b0115","series-title":"In Proceedings of the 2016 Acm Sigsac Conference on Computer and Communications Security","first-page":"1528","article-title":"Accessorize to a crime: real and stealthy attacks on state-of-the-art face recognition","author":"Sharif","year":"2016"},{"issue":"3","key":"10.1016\/j.ins.2026.123684_b0120","first-page":"2711","article-title":"Adversarial sticker: a stealthy attack method in the physical world","volume":"45","author":"Wei","year":"2022","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.ins.2026.123684_b0125","series-title":"In 32nd USENIX Security Symposium (USENIX Security 23)","first-page":"661","article-title":"TPatch: a triggered physical adversarial patch","author":"Zhu","year":"2023"},{"key":"10.1016\/j.ins.2026.123684_b0130","doi-asserted-by":"crossref","first-page":"5636","DOI":"10.1109\/TIFS.2023.3310352","article-title":"Transferable black-box attack against face recognition with spatial mutable adversarial patch","volume":"18","author":"Ma","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.ins.2026.123684_b0135","doi-asserted-by":"crossref","DOI":"10.1016\/j.neucom.2024.127517","article-title":"EAP: an effective black-box impersonation adversarial patch attack method on face recognition in the physical world","volume":"580","author":"Liu","year":"2024","journal-title":"Neurocomputing"}],"container-title":["Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0020025526006158?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0020025526006158?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T19:41:32Z","timestamp":1783194092000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0020025526006158"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":27,"alternative-id":["S0020025526006158"],"URL":"https:\/\/doi.org\/10.1016\/j.ins.2026.123684","relation":{},"ISSN":["0020-0255"],"issn-type":[{"value":"0020-0255","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"MaskAttack: A black-box local adversarial attack on facial recognition based on dynamic adaptation and partition weighting","name":"articletitle","label":"Article Title"},{"value":"Information Sciences","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.ins.2026.123684","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Inc. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"123684"}}