{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T02:02:16Z","timestamp":1780020136446,"version":"3.53.1"},"reference-count":52,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100007129","name":"Shandong Province Natural Science Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Knowledge-Based Systems"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.knosys.2026.116111","type":"journal-article","created":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T00:46:13Z","timestamp":1777941973000},"page":"116111","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["3D adversarial objects generation for wider-view face recognition attacks"],"prefix":"10.1016","volume":"346","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6549-6989","authenticated-orcid":false,"given":"Lingzhuang","family":"Meng","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7323-5896","authenticated-orcid":false,"given":"Mingwen","family":"Shao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4803-6526","authenticated-orcid":false,"given":"Yuanjian","family":"Qiao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiang","family":"Lv","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yecong","family":"Wan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hang","family":"Su","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.knosys.2026.116111_b1","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2024.112506","article-title":"AGS: Transferable adversarial attack for person re-identification by adaptive gradient similarity attack","volume":"304","author":"Tao","year":"2024","journal-title":"Knowl.-Based Syst."},{"issue":"12","key":"10.1016\/j.knosys.2026.116111_b2","doi-asserted-by":"crossref","first-page":"14248","DOI":"10.1109\/TPAMI.2023.3312123","article-title":"Comprehensive Vulnerability Evaluation of Face Recognition Systems to Template Inversion Attacks via 3D Face Reconstruction","volume":"45","author":"Shahreza","year":"2023","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.knosys.2026.116111_b3","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.113117","article-title":"TF-Attack: Transferable and fast adversarial attacks on large language models","volume":"312","author":"Li","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.knosys.2026.116111_b4","doi-asserted-by":"crossref","unstructured":"Z. Wang, H. Wang, S. Jin, W. Zhang, J. Hu, Y. Wang, P. Sun, W. Yuan, K. Liu, K. Ren, Privacy-Preserving Adversarial Facial Features, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 8212\u20138221.","DOI":"10.1109\/CVPR52729.2023.00794"},{"key":"10.1016\/j.knosys.2026.116111_b5","doi-asserted-by":"crossref","first-page":"6573","DOI":"10.1109\/TIFS.2024.3417266","article-title":"Exploring Bi-Level Inconsistency via Blended Images for Generalizable Face Forgery Detection","volume":"19","author":"Jiang","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"6","key":"10.1016\/j.knosys.2026.116111_b6","doi-asserted-by":"crossref","first-page":"10186","DOI":"10.1109\/TNNLS.2025.3526338","article-title":"Latent Code Augmentation Based on Stable Diffusion for Data-Free Substitute Attacks","volume":"36","author":"Shao","year":"2025","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"10.1016\/j.knosys.2026.116111_b7","series-title":"International Joint Conference on Artificial Intelligence","first-page":"1488","article-title":"Detecting Adversarial Faces Using Only Real Face Self-Perturbations","author":"Wang","year":"2023"},{"key":"10.1016\/j.knosys.2026.116111_b8","first-page":"34136","article-title":"Adv-Attribute: Inconspicuous and Transferable Adversarial Attack on Face Recognition","volume":"vol. 35","author":"Jia","year":"2022"},{"key":"10.1016\/j.knosys.2026.116111_b9","first-page":"3660","article-title":"Attack Can Benefit: An Adversarial Approach to Recognizing Facial Expressions under Noisy Annotations","volume":"vol. 37","author":"Zheng","year":"2023"},{"key":"10.1016\/j.knosys.2026.116111_b10","series-title":"International Joint Conference on Artificial Intelligence","first-page":"1252","article-title":"Adv-Makeup: A New Imperceptible and Transferable Attack on Face Recognition","author":"Yin","year":"2021"},{"key":"10.1016\/j.knosys.2026.116111_b11","doi-asserted-by":"crossref","first-page":"1452","DOI":"10.1109\/TIFS.2020.3036801","article-title":"Towards Transferable Adversarial Attack Against Deep Face Recognition","volume":"16","author":"Zhong","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.knosys.2026.116111_b12","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.113357","article-title":"Subspectrum mixup-based adversarial attack and evading defenses by structure-enhanced gradient purification","volume":"318","author":"Cao","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.knosys.2026.116111_b13","series-title":"ACM Conference on Computer and Communications Security","first-page":"1528","article-title":"Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition","author":"Sharif","year":"2016"},{"key":"10.1016\/j.knosys.2026.116111_b14","series-title":"European Conference on Computer Vision","first-page":"174","article-title":"Design and Interpretation of Universal Adversarial Patches in Face Detection","author":"Yang","year":"2020"},{"key":"10.1016\/j.knosys.2026.116111_b15","series-title":"International Conference on Pattern Recognition","first-page":"819","article-title":"AdvHat: Real-World Adversarial Attack on ArcFace Face ID System","author":"Komkov","year":"2021"},{"key":"10.1016\/j.knosys.2026.116111_b16","series-title":"Robust Physical-World Attacks on Face Recognition","author":"Zheng","year":"2021"},{"key":"10.1016\/j.knosys.2026.116111_b17","doi-asserted-by":"crossref","first-page":"5014","DOI":"10.1109\/TMM.2023.3330089","article-title":"Stealthy Physical Masked Face Recognition Attack via Adversarial Style Optimization","volume":"26","author":"Gong","year":"2024","journal-title":"IEEE Trans. Multimed."},{"key":"10.1016\/j.knosys.2026.116111_b18","series-title":"Delving into the Adversarial Robustness on Face Recognition","author":"Yang","year":"2020"},{"issue":"3","key":"10.1016\/j.knosys.2026.116111_b19","doi-asserted-by":"crossref","first-page":"16:1","DOI":"10.1145\/3317611","article-title":"A General Framework for Adversarial Examples with Objectives","volume":"22","author":"Sharif","year":"2019","journal-title":"ACM Trans. Priv. Secur."},{"key":"10.1016\/j.knosys.2026.116111_b20","article-title":"Gaussian splitting attack: Gaussian splatting-based multi-view 3D adversarial attack","author":"Meng","year":"2025","journal-title":"Pattern Recognit."},{"issue":"11","key":"10.1016\/j.knosys.2026.116111_b21","first-page":"13438","article-title":"3D-Aware Adversarial Makeup Generation for Facial Privacy Protection","volume":"45","author":"Lyu","year":"2023","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.knosys.2026.116111_b22","doi-asserted-by":"crossref","unstructured":"X. Yang, C. Liu, L. Xu, Y. Wang, Y. Dong, N. Chen, H. Su, J. Zhu, Towards Effective Adversarial Textured 3D Meshes on Physical Face Recognition, in: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 4119\u20134128.","DOI":"10.1109\/CVPR52729.2023.00401"},{"key":"10.1016\/j.knosys.2026.116111_b23","article-title":"Face3DAdv: Exploiting Robust Adversarial 3D Patches on Physical Face Recognition","author":"Yang","year":"2024","journal-title":"Int. J. Comput. Vis."},{"key":"10.1016\/j.knosys.2026.116111_b24","series-title":"IEEE Conference on Computer Vision and Pattern Recognition","first-page":"1493","article-title":"Regressing Robust and Discriminative 3D Morphable Models with a Very Deep Neural Network","author":"Tran","year":"2017"},{"key":"10.1016\/j.knosys.2026.116111_b25","series-title":"A Survey on Physical Adversarial Attacks against Face Recognition Systems","author":"Wang","year":"2024"},{"key":"10.1016\/j.knosys.2026.116111_b26","series-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"16469","article-title":"Evading Forensic Classifiers with Attribute-Conditioned Adversarial Faces","author":"Shamshad","year":"2023"},{"issue":"12","key":"10.1016\/j.knosys.2026.116111_b27","doi-asserted-by":"crossref","first-page":"13164","DOI":"10.1109\/TCSVT.2024.3449290","article-title":"Diff-Privacy: Diffusion-based Face Privacy Protection","volume":"34","author":"He","year":"2024","journal-title":"IEEE Trans. Circuits Syst. Video Technol."},{"key":"10.1016\/j.knosys.2026.116111_b28","doi-asserted-by":"crossref","first-page":"5506","DOI":"10.1109\/TIFS.2024.3402167","article-title":"Toward Transferable Attack via Adversarial Diffusion in Face Recognition","volume":"19","author":"Hu","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.knosys.2026.116111_b29","series-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"10.1016\/j.knosys.2026.116111_b30","series-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2018"},{"key":"10.1016\/j.knosys.2026.116111_b31","doi-asserted-by":"crossref","unstructured":"S. Hu, X. Liu, Y. Zhang, M. Li, L.Y. Zhang, H. Jin, L. Wu, Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-Robust Makeup Transfer, in: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2022, pp. 15014\u201315023.","DOI":"10.1109\/CVPR52688.2022.01459"},{"key":"10.1016\/j.knosys.2026.116111_b32","doi-asserted-by":"crossref","unstructured":"Y. Sun, L. Yu, H. Xie, J. Li, Y. Zhang, DiffAM: Diffusion-based Adversarial Makeup Transfer for Facial Privacy Protection, in: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 24584\u201324594.","DOI":"10.1109\/CVPR52733.2024.02321"},{"key":"10.1016\/j.knosys.2026.116111_b33","doi-asserted-by":"crossref","unstructured":"Z. Li, B. Yin, T. Yao, J. Guo, S. Ding, S. Chen, C. Liu, Sibling-Attack: Rethinking Transferable Adversarial Attacks against Face Recognition, in: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 24626\u201324637.","DOI":"10.1109\/CVPR52729.2023.02359"},{"key":"10.1016\/j.knosys.2026.116111_b34","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2024.112241","article-title":"Spatial-frequency gradient fusion based model augmentation for high transferability adversarial attack","volume":"301","author":"Pang","year":"2024","journal-title":"Knowl.-Based Syst."},{"issue":"4","key":"10.1016\/j.knosys.2026.116111_b35","doi-asserted-by":"crossref","first-page":"835","DOI":"10.1007\/s11263-022-01737-y","article-title":"U-Turn: Crafting Adversarial Queries with Opposite-Direction Features","volume":"131","author":"Zheng","year":"2023","journal-title":"Int. J. Comput. Vis."},{"issue":"9","key":"10.1016\/j.knosys.2026.116111_b36","doi-asserted-by":"crossref","first-page":"4373","DOI":"10.1109\/TCYB.2020.2995496","article-title":"Unsupervised Eyeglasses Removal in the Wild","volume":"51","author":"Hu","year":"2021","journal-title":"IEEE Trans. Cybern."},{"key":"10.1016\/j.knosys.2026.116111_b37","first-page":"62510","article-title":"Toward availability attacks in 3D point clouds","volume":"vol. 235","author":"Zhu","year":"2024"},{"key":"10.1016\/j.knosys.2026.116111_b38","doi-asserted-by":"crossref","unstructured":"Y. Huang, Y. Dong, S. Ruan, X. Yang, H. Su, X. Wei, Towards Transferable Targeted 3D Adversarial Attack in the Physical World, in: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 24512\u201324522.","DOI":"10.1109\/CVPR52733.2024.02314"},{"key":"10.1016\/j.knosys.2026.116111_b39","first-page":"21197","article-title":"NeRFail: Neural Radiance Fields-based multiview adversarial attack","volume":"vol. 38","author":"Jiang","year":"2024"},{"key":"10.1016\/j.knosys.2026.116111_b40","unstructured":"L. Meng, M. Shao, Y. Qiao, X. Lv, DEGauss: Defending Against Malicious 3D Editing for Gaussian Splatting, in: The Thirty-Ninth Annual Conference on Neural Information Processing Systems, 2025."},{"key":"10.1016\/j.knosys.2026.116111_b41","first-page":"7990","article-title":"Anti-Avatar: Protect Against Unauthorized 3D Head Avatar Generation via Dual-Space Divergence","volume":"vol. 40","author":"Meng","year":"2026"},{"issue":"4","key":"10.1016\/j.knosys.2026.116111_b42","doi-asserted-by":"crossref","first-page":"139:1","DOI":"10.1145\/3592433","article-title":"3D Gaussian Splatting for Real-Time Radiance Field Rendering","volume":"42","author":"Kerbl","year":"2023","journal-title":"ACM Trans. Graph."},{"key":"10.1016\/j.knosys.2026.116111_b43","unstructured":"J. Kim, S. Lee, J. Shin, J. Choi, H. Shim, DreamCatalyst: Fast and High-Quality 3D Editing via Controlling Editability and Identity Preservation, in: International Conference on Learning Representations, 2025."},{"key":"10.1016\/j.knosys.2026.116111_b44","unstructured":"N. Ravi, V. Gabeur, Y.-T. Hu, R. Hu, C. Ryali, T. Ma, H. Khedr, R. R\u00e4dle, C. Rolland, L. Gustafson, E. Mintun, J. Pan, K.V. Alwala, N. Carion, C.-Y. Wu, R. Girshick, P. Doll\u00e1r, C. Feichtenhofer, SAM 2: Segment Anything in Images and Videos, in: International Conference on Learning Representations, 2025."},{"key":"10.1016\/j.knosys.2026.116111_b45","series-title":"International Conference on Computer Vision","first-page":"19683","article-title":"Instruct-NeRF2NeRF: Editing 3D Scenes with Instructions","author":"Haque","year":"2023"},{"issue":"8","key":"10.1016\/j.knosys.2026.116111_b46","doi-asserted-by":"crossref","first-page":"4983","DOI":"10.1109\/TVCG.2023.3283400","article-title":"NeRF-Art: Text-Driven Neural Radiance Fields Stylization","volume":"30","author":"Wang","year":"2024","journal-title":"IEEE Trans. Vis. Comput. Graphics"},{"key":"10.1016\/j.knosys.2026.116111_b47","doi-asserted-by":"crossref","unstructured":"S. Chen, Y. Liu, X. Gao, Z. Han, MobileFaceNets: Efficient CNNs for Accurate Real-Time Face Verification on Mobile Devices, in: Biometric Recognition, Cham, 2018, pp. 428\u2013438, http:\/\/dx.doi.org\/10.1007\/978-3-319-97909-0_46.","DOI":"10.1007\/978-3-319-97909-0_46"},{"key":"10.1016\/j.knosys.2026.116111_b48","series-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"4685","article-title":"ArcFace: Additive Angular Margin Loss for Deep Face Recognition","author":"Deng","year":"2019"},{"key":"10.1016\/j.knosys.2026.116111_b49","series-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"5265","article-title":"CosFace: Large Margin Cosine Loss for Deep Face Recognition","author":"Wang","year":"2018"},{"key":"10.1016\/j.knosys.2026.116111_b50","doi-asserted-by":"crossref","unstructured":"K. He, X. Zhang, S. Ren, J. Sun, Deep residual learning for image recognition, in: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2016, pp. 770\u2013778.","DOI":"10.1109\/CVPR.2016.90"},{"key":"10.1016\/j.knosys.2026.116111_b51","series-title":"IEEE\/CVF International Conference on Computer Vision Workshops","first-page":"3789","article-title":"3DGS-to-PC: 3D Gaussian Splatting to Dense Point Clouds","author":"Stuart","year":"2025"},{"key":"10.1016\/j.knosys.2026.116111_b52","series-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"5354","article-title":"SuGaR: Surface-Aligned Gaussian Splatting for Efficient 3D Mesh Reconstruction and High-Quality Mesh Rendering","author":"Gu\u00e9don","year":"2024"}],"container-title":["Knowledge-Based Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126008373?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126008373?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T01:09:28Z","timestamp":1780016968000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0950705126008373"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":52,"alternative-id":["S0950705126008373"],"URL":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116111","relation":{},"ISSN":["0950-7051"],"issn-type":[{"value":"0950-7051","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"3D adversarial objects generation for wider-view face recognition attacks","name":"articletitle","label":"Article Title"},{"value":"Knowledge-Based Systems","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116111","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"116111"}}