{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T16:50:28Z","timestamp":1775580628896,"version":"3.50.1"},"reference-count":35,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018,10]]},"DOI":"10.1109\/btas.2018.8698548","type":"proceedings-article","created":{"date-parts":[[2019,4,26]],"date-time":"2019-04-26T03:48:37Z","timestamp":1556250517000},"page":"1-7","source":"Crossref","is-referenced-by-count":48,"title":["Are Image-Agnostic Universal Adversarial Perturbations for Face Recognition Difficult to Detect?"],"prefix":"10.1109","author":[{"given":"Akshay","family":"Agarwal","sequence":"first","affiliation":[]},{"given":"Richa","family":"Singh","sequence":"additional","affiliation":[]},{"given":"Mayank","family":"Vatsa","sequence":"additional","affiliation":[]},{"given":"Nalini","family":"Ratha","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref33","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv preprint arXiv 1312 6199"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref31","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"arXiv preprint arXiv 1409 1556"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1162\/jocn.1991.3.1.71"},{"key":"ref34","article-title":"A boundary tilting persepective on the phenomenon of adversarial examples","author":"tanay","year":"2016","journal-title":"arXiv preprint arXiv 1608 07690"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2018.8698567"},{"key":"ref11","article-title":"Adversarial and clean data are not twins","author":"gong","year":"2017","journal-title":"arXiv preprint arXiv 1704 04960"},{"key":"ref12","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv preprint arXiv 1412 6572"},{"key":"ref13","article-title":"Unravelling robustness of deep learning based face recognition against adversarial attacks","author":"goswami","year":"2018","journal-title":"AAAI"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1016\/j.imavis.2009.08.002"},{"key":"ref15","article-title":"On the (statistical) detection of adversarial examples","author":"grosse","year":"2017","journal-title":"arXiv preprint arXiv 1702 06280"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref17","article-title":"Early methods for detecting adversarial images","author":"hendrycks","year":"2016","journal-title":"arXiv preprint arXiv 1608 00530"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/2647868.2654889"},{"key":"ref19","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv preprint arXiv 1607 02533"},{"key":"ref28","article-title":"Fast feature fool: A data independent approach to universal adversarial perturbations","author":"mopuri","year":"2017","journal-title":"BMVC"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/BF00994018"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref5","article-title":"Ead: Elastic-net attacks to deep neural networks via adversarial examples","author":"chen","year":"2017","journal-title":"arXiv preprint arXiv 1709 01922"},{"key":"ref8","article-title":"Detecting adversarial samples from artifacts","author":"feinman","year":"2017","journal-title":"arXiv preprint arXiv 1703 00410"},{"key":"ref7","author":"cox","year":"2008","journal-title":"Digital Watermarking and Steganography"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2013.6712704"},{"key":"ref9","article-title":"Nist special databse 32-multiple encounter dataset ii (meds-ii)","author":"founds","year":"2011","journal-title":"NIST Interagency\/Internal Report (NISTIR)-7807"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00357"},{"key":"ref20","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"arXiv preprint arXiv 1611 01236"},{"key":"ref22","article-title":"Detecting adversarial examples in deep networks with adaptive noise reduction","author":"liang","year":"2017","journal-title":"arXiv preprint arXiv 1705 08378"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.615"},{"key":"ref24","article-title":"Foveation-based mechanisms alleviate adversarial examples","author":"luo","year":"2015","journal-title":"arXiv preprint arXiv 1511 05271"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref25","article-title":"On detecting adversarial perturbations","author":"metzen","year":"2017","journal-title":"arXiv preprint arXiv 1702 08502"}],"event":{"name":"2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems (BTAS)","location":"Redondo Beach, CA, USA","start":{"date-parts":[[2018,10,22]]},"end":{"date-parts":[[2018,10,25]]}},"container-title":["2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems (BTAS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8692576\/8698537\/08698548.pdf?arnumber=8698548","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,13]],"date-time":"2019-05-13T23:09:28Z","timestamp":1557788968000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8698548\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,10]]},"references-count":35,"URL":"https:\/\/doi.org\/10.1109\/btas.2018.8698548","relation":{},"subject":[],"published":{"date-parts":[[2018,10]]}}}