{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T05:27:58Z","timestamp":1730266078496,"version":"3.28.0"},"reference-count":61,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,9,25]],"date-time":"2023-09-25T00:00:00Z","timestamp":1695600000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,9,25]],"date-time":"2023-09-25T00:00:00Z","timestamp":1695600000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,9,25]]},"DOI":"10.1109\/ijcb57857.2023.10449094","type":"proceedings-article","created":{"date-parts":[[2024,3,1]],"date-time":"2024-03-01T18:31:14Z","timestamp":1709317874000},"page":"1-11","source":"Crossref","is-referenced-by-count":0,"title":["Adaptive Adversarial Patch Attack on Face Recognition Models"],"prefix":"10.1109","author":[{"given":"Bei","family":"Yan","sequence":"first","affiliation":[{"name":"Institute of Computing Technology, CAS,Key Lab of Intelligent Information Processing of Chinese Academy of Sciences (CAS),Beijing,China,100190"}]},{"given":"Jie","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS,Key Lab of Intelligent Information Processing of Chinese Academy of Sciences (CAS),Beijing,China,100190"}]},{"given":"Zheng","family":"Yuan","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS,Key Lab of Intelligent Information Processing of Chinese Academy of Sciences (CAS),Beijing,China,100190"}]},{"given":"Shiguang","family":"Shan","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, CAS,Key Lab of Intelligent Information Processing of Chinese Academy of Sciences (CAS),Beijing,China,100190"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref2","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"International conference on machine learning","author":"Athalye"},{"issue":"9","key":"ref3","article-title":"Ebk-means: A clustering technique based on elbow method and k-means in wsn","volume":"105","author":"Bholowalia","year":"2014","journal-title":"International Journal of Computer Applications"},{"key":"ref4","article-title":"Yolov4: Optimal speed and accuracy of object detection","author":"Bochkovskiy","year":"2020","journal-title":"arXiv preprint arXiv:2004.10934"},{"article-title":"Adversarial patch","volume-title":"Proceedings of the NeurIPS Workshop","author":"Brown","key":"ref5"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-97909-0_46"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_31"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref14","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv preprint arXiv:1412.6572"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46487-9_6"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00403"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"},{"article-title":"Labeled faces in the wild: A database forstudying face recognition in unconstrained environments","volume-title":"Workshop on faces in\u2019Real-Life\u2019Images: detection, alignment, and recognition","author":"Huang","key":"ref20"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICME51207.2021.9428443"},{"key":"ref22","article-title":"Certified robustness for top-k predictions against adversarial perturbations via randomized smoothing","author":"Jia","year":"2019","journal-title":"arXiv preprint arXiv:1912.09899"},{"key":"ref23","first-page":"2507","article-title":"Lavan: Localized and visible adversarial noise","volume-title":"International Conference on Machine Learning","author":"Karmon"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63387-9_5"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9412236"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref27","article-title":"On physical adversarial patches for object detection","author":"Lee","year":"2019","journal-title":"arXiv preprint arXiv:1906.11897"},{"key":"ref28","article-title":"Generative dynamic patch attack","author":"Li","year":"2021","journal-title":"arXiv preprint arXiv:2111.04266"},{"key":"ref29","article-title":"Robust adversarial perturbation on deep proposal-based models","author":"Li","year":"2018","journal-title":"arXiv preprint arXiv:1809.05962"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46448-0_2"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.713"},{"key":"ref34","article-title":"Dpatch: An adversarial patch attack on object detectors","author":"Liu","year":"2018","journal-title":"arXiv preprint arXiv:1806.02299"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICB2018.2018.00033"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68238-5_32"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"ref40","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv preprint arXiv:1312.6199"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00552"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3176760"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3231886"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/134"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46478-7_31"},{"key":"ref47","first-page":"5286","article-title":"Provable defenses against adversarial examples via the convex outer adversarial polytope","volume-title":"International conference on machine learning","author":"Wong"},{"key":"ref48","article-title":"Fast is better than free: Revisiting adversarial training","author":"Wong","year":"2020","journal-title":"arXiv preprint arXiv:2001.03994"},{"key":"ref49","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume":"33","author":"Wu","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"article-title":"Defending against physically realizable attacks on image classification","volume-title":"International Conference on Learning Representations","author":"Wu","key":"ref50"},{"key":"ref51","article-title":"Training for faster adversarial robustness verification via inducing relu stability","author":"Xiao","year":"2018","journal-title":"arXiv preprint arXiv:1809.03008"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01167"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-022-03469-5"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-020-09604-z"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/173"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_1"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3036801"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58577-8_18"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01035"}],"event":{"name":"2023 IEEE International Joint Conference on Biometrics (IJCB)","start":{"date-parts":[[2023,9,25]]},"location":"Ljubljana, Slovenia","end":{"date-parts":[[2023,9,28]]}},"container-title":["2023 IEEE International Joint Conference on Biometrics (IJCB)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10447019\/10448524\/10449094.pdf?arnumber=10449094","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,8]],"date-time":"2024-03-08T01:24:30Z","timestamp":1709861070000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10449094\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,25]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/ijcb57857.2023.10449094","relation":{},"subject":[],"published":{"date-parts":[[2023,9,25]]}}}