{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T01:44:18Z","timestamp":1780105458869,"version":"3.54.0"},"reference-count":115,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/access.2021.3092646","type":"journal-article","created":{"date-parts":[[2021,6,28]],"date-time":"2021-06-28T21:20:57Z","timestamp":1624915257000},"page":"92735-92756","source":"Crossref","is-referenced-by-count":72,"title":["Adversarial Attacks Against Face Recognition: A Comprehensive Study"],"prefix":"10.1109","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7935-7090","authenticated-orcid":false,"given":"Fatemeh","family":"Vakhshiteh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3709-1041","authenticated-orcid":false,"given":"Ahmad","family":"Nickabadi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0484-3956","authenticated-orcid":false,"given":"Raghavendra","family":"Ramachandra","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1109\/TPAMI.2013.112","article-title":"Learning discriminant face descriptor","volume":"36","author":"lei","year":"2014","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2015.2475625"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/AFGR.1998.670921"},{"key":"ref32","doi-asserted-by":"crossref","first-page":"328","DOI":"10.1109\/TPAMI.2005.55","article-title":"Face recognition using Laplacianfaces","volume":"27","author":"he","year":"2005","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2012.30"},{"key":"ref30","article-title":"Deep face recognition: A survey","author":"wang","year":"2018","journal-title":"arXiv 1804 06655"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2010.5539992"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2006.244"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2002.999679"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2011.6126277"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2994112"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2920713"},{"key":"ref29","author":"carlini","year":"2019","journal-title":"A Complete List of All Adversarial Example Papers"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.5220\/0006131100390050"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.228"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0173319"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/IWBF.2018.8401555"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-64185-0_9"},{"key":"ref101","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01240-3_47"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2777340"},{"key":"ref100","article-title":"Black-box adversarial attacks with limited queries and information","author":"ilyas","year":"2018","journal-title":"arXiv 1804 08598"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICME.2018.8486607"},{"key":"ref50","article-title":"Learning face representation from scratch","author":"yi","year":"2014","journal-title":"arXiv 1411 7923"},{"key":"ref51","first-page":"87","article-title":"MS-celeb-1M: A dataset and benchmark for large-scale face recognition","author":"guo","year":"2016","journal-title":"Proc Eur Conf Comput Vis"},{"key":"ref59","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref58","first-page":"2","article-title":"Openface: A general-purpose face recognition library with mobile applications","volume":"6","author":"amos","year":"2016","journal-title":"CMU School of Computer Science"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref56","article-title":"AdvFaces: Adversarial face synthesis","author":"deb","year":"2019","journal-title":"arXiv 1908 05008"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00415"},{"key":"ref54","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv 1607 02533"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.527"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/FG.2018.00020"},{"key":"ref40","first-page":"1","article-title":"Labeled faces in the wild: A database forstudying face recognition in unconstrained environments","author":"huang","year":"2008","journal-title":"Proc Workshop Faces Real-Life Images Detection Alignment Recognit"},{"key":"ref4","first-page":"499","article-title":"A discriminative feature learning approach for deep face recognition","author":"wen","year":"2016","journal-title":"Proc Eur Conf Comput Vis"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.220"},{"key":"ref6","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4471-6524-8","author":"marcel","year":"2014","journal-title":"Handbook of Biometric Anti-spoofing"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i09.7085"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3044723"},{"key":"ref49","first-page":"1988","article-title":"Deep learning face representation by joint identification-verification","author":"sun","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref7","first-page":"1","article-title":"Presentation attack detection methods for face recognition systems: A comprehensive survey","volume":"50","author":"raghavendra","year":"2017","journal-title":"ACM Comput Surv"},{"key":"ref9","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00552"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2833032"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.713"},{"key":"ref43","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"arXiv 1409 1556"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1145\/1143997.1144082"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref71","first-page":"1","article-title":"Unravelling robustness of deep learning based face recognition against adversarial attacks","author":"goswami","year":"2018","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7299155"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1162\/106365601750190398"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00665"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1145\/3351261"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/2789168.2790106"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2016.58"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2858821"},{"key":"ref67","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"arXiv 1611 01236"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2010.2059031"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.5244\/C.29.41"},{"key":"ref69","article-title":"Distilling the knowledge in a neural network","author":"hinton","year":"2015","journal-title":"ArXiv 1503 02531"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.1991.139758"},{"key":"ref109","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8683327"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2569436"},{"key":"ref108","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS46853.2019.9185999"},{"key":"ref94","article-title":"Attacks on state-of-the-art face recognition using attentional adversarial attack generative network","author":"song","year":"2018","journal-title":"arXiv 1811 12026"},{"key":"ref107","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.7607"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/SIBIRCON48586.2019.8958134"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-14802-7_57"},{"key":"ref92","article-title":"Invisible mask: Practical attacks on face recognition with infrared","author":"zhou","year":"2018","journal-title":"arXiv 1803 04683"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1145\/2647868.2654889"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1145\/3317611"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1016\/j.imavis.2009.08.002"},{"key":"ref90","article-title":"Advbox: A toolbox to generate adversarial examples that fool neural networks","author":"goodman","year":"2020","journal-title":"arXiv 2001 05574"},{"key":"ref103","article-title":"Fast feature fool: A data independent approach to universal adversarial perturbations","author":"mopuri","year":"2017","journal-title":"arXiv 1707 05572 [cs]"},{"key":"ref102","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2014.7025068"},{"key":"ref111","article-title":"Detection of face recognition adversarial attacks","author":"massoli","year":"2019","journal-title":"arXiv 1912 02918"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1109\/TCSII.2020.2980022"},{"key":"ref110","first-page":"1","article-title":"Adversarial examples detection in features distance spaces","author":"carrara","year":"2018","journal-title":"Proc Eur Conf Comput Vis (ECCV)"},{"key":"ref98","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"brendel","year":"2017","journal-title":"arXiv 1712 04248"},{"key":"ref99","article-title":"Query-efficient hard-label black-box attack:An optimization-based approach","author":"cheng","year":"2018","journal-title":"arXiv 1807 04457"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2013.6712704"},{"key":"ref97","article-title":"NIST special databse 32-multiple encounter dataset II (MEDS-II)","author":"founds","year":"2011"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2014.6996240"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2018.8698548"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-019-01160-w"},{"key":"ref15","first-page":"7717","article-title":"Attacks meet interpretability: Attribute-steered detection of adversarial samples","author":"tao","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3023037"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/ICUFN.2019.8806124"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2889409"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8803803"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2951526"},{"key":"ref84","article-title":"Spatially transformed adversarial examples","author":"xiao","year":"2018","journal-title":"ArXiv 1801 02612"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3045078"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00215"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2018.8698567"},{"key":"ref113","article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","author":"xu","year":"2017","journal-title":"arXiv 1704 01155"},{"key":"ref80","article-title":"AdvHat: Real-world adversarial attack on ArcFace face ID system","author":"komkov","year":"2019","journal-title":"arXiv 1908 08705"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00414"},{"key":"ref89","first-page":"1","article-title":"Fishy faces: Crafting adversarial images to poison face authentication","author":"garofalo","year":"2018","journal-title":"Proc 12th USENIX Workshop Offensive Technol"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3036801"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref87","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2016","journal-title":"arXiv 1611 02770"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/9312710\/09464957.pdf?arnumber=9464957","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,5]],"date-time":"2023-11-05T11:37:34Z","timestamp":1699184254000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9464957\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":115,"URL":"https:\/\/doi.org\/10.1109\/access.2021.3092646","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}