{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T13:57:18Z","timestamp":1772632638668,"version":"3.50.1"},"reference-count":42,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T00:00:00Z","timestamp":1757289600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T00:00:00Z","timestamp":1757289600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,9,8]]},"DOI":"10.1109\/ijcb65343.2025.11411446","type":"proceedings-article","created":{"date-parts":[[2026,3,3]],"date-time":"2026-03-03T20:50:39Z","timestamp":1772571039000},"page":"1-10","source":"Crossref","is-referenced-by-count":0,"title":["Adversarial Attack Challenge for Secure Face Recognition 2025"],"prefix":"10.1109","author":[{"given":"Jo\u00e3o","family":"Tremo\u00e7o","sequence":"first","affiliation":[{"name":"Youverse,Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Iurii","family":"Medvedev","sequence":"additional","affiliation":[{"name":"University of Coimbra,Institute of Systems and Robotics"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nuno","family":"Freitas","sequence":"additional","affiliation":[{"name":"Youverse,Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andreia","family":"Costa","sequence":"additional","affiliation":[{"name":"Youverse,Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Diogo","family":"Nunes","sequence":"additional","affiliation":[{"name":"University of Coimbra,Institute of Systems and Robotics"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Niklas","family":"Bunzel","sequence":"additional","affiliation":[{"name":"Fraunhofer SIT"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lukas","family":"Graner","sequence":"additional","affiliation":[{"name":"Fraunhofer SIT"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicholas","family":"G\u00f6ller","sequence":"additional","affiliation":[{"name":"Fraunhofer SIT"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lorenzo","family":"Pellegrini","sequence":"additional","affiliation":[{"name":"University of Bologna,Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicol\u00f2","family":"Di Domenico","sequence":"additional","affiliation":[{"name":"University of Bologna,Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guido","family":"Borghi","sequence":"additional","affiliation":[{"name":"University of Modena and Reggio Emilia,Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Monson","family":"Verghese","sequence":"additional","affiliation":[{"name":"Dhirubhai Ambani University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shruti","family":"Bhilare","sequence":"additional","affiliation":[{"name":"Dhirubhai Ambani University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Avik","family":"Hati","sequence":"additional","affiliation":[{"name":"NIT Tiruchirapalli"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Miguel","family":"Louren\u00e7o","sequence":"additional","affiliation":[{"name":"Youverse,Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nuno","family":"Gon\u00e7alves","sequence":"additional","affiliation":[{"name":"University of Coimbra,Institute of Systems and Robotics"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"International conference on machine learning","author":"Athalye"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref6","article-title":"Improving transferability of adversarial examples with translation-invariant attacks","author":"Dong","year":"2019","journal-title":"CVPR"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref11","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015","journal-title":"ICLR"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2016.90"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"},{"key":"ref14","article-title":"Labeled faces in the wild: A database for studying face recognition in unconstrained environments","volume-title":"Workshop on Faces in \u2019Real-Life\u2019 Images (ICCV)","author":"Huang"},{"key":"ref15","article-title":"Pi-fgsm: Patch-wise iterative fast gradient sign method for targeted adversarial attacks","volume-title":"ACM Conference on Multimedia (MM)","author":"Huang"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref17","article-title":"Exploring adversarial example detection in deep face recognition models","volume":"113","author":"Li","year":"2021","journal-title":"Pattern Recognition"},{"key":"ref18","first-page":"593","article-title":"Nesterov accelerated gradient and scale-invariance for adversarial attacks","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","author":"Lin"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref21","article-title":"Detecting adversarial perturbations with pattern recognition","volume-title":"International Conference on Learning Representations (ICLR)","author":"Metzen"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2016.282"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2016.282"},{"key":"ref24","volume-title":"Face recognition vendor test (frvt)","year":"2023"},{"key":"ref25","article-title":"Towards robust detection of adversarial examples","author":"Pang","year":"2018","journal-title":"NeurIPS"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref32","article-title":"Intriguing properties of neural networks","volume-title":"International Conference on Learning Representations (ICLR)","author":"Szegedy"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01305"},{"key":"ref34","first-page":"16336","article-title":"Adaptive attacks to compare the robustness of neural networks","volume":"33","author":"Trame`r","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00564"},{"key":"ref38","article-title":"Robfr: Bench-marking robustness of face recognition models","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Zhang"},{"key":"ref39","article-title":"Adversarial defense through network profiling based path regularization","author":"Zhang","year":"2020","journal-title":"ECCV"},{"key":"ref40","article-title":"Aiot-face: Benchmarking adversarial robustness of face recognition for edge ai","author":"Zhang","year":"2022","journal-title":"NeurIPS"},{"key":"ref41","article-title":"Boosting the adversarial robustness of face recognition via noise-to-semantic adversarial training","author":"Zheng","year":"2022","journal-title":"CVPR"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3036801"}],"event":{"name":"2025 IEEE International Joint Conference on Biometrics (IJCB)","location":"Osaka, Japan","start":{"date-parts":[[2025,9,8]]},"end":{"date-parts":[[2025,9,11]]}},"container-title":["2025 IEEE International Joint Conference on Biometrics (IJCB)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11410556\/11410616\/11411446.pdf?arnumber=11411446","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T07:03:50Z","timestamp":1772607830000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11411446\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,8]]},"references-count":42,"URL":"https:\/\/doi.org\/10.1109\/ijcb65343.2025.11411446","relation":{},"subject":[],"published":{"date-parts":[[2025,9,8]]}}}