{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T17:29:48Z","timestamp":1755797388444,"version":"3.44.0"},"reference-count":26,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,4,24]],"date-time":"2025-04-24T00:00:00Z","timestamp":1745452800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,4,24]],"date-time":"2025-04-24T00:00:00Z","timestamp":1745452800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100003130","name":"Flemish Research Programme Cybersecurity","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003130","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,4,24]]},"DOI":"10.1109\/iwbf63717.2025.11113471","type":"proceedings-article","created":{"date-parts":[[2025,8,15]],"date-time":"2025-08-15T18:11:50Z","timestamp":1755281510000},"page":"01-06","source":"Crossref","is-referenced-by-count":0,"title":["Defying Depth: Exploring the Vulnerability of RGB-D Face Recognition Systems to RGB Attacks"],"prefix":"10.1109","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3836-1840","authenticated-orcid":false,"given":"Verheyen","family":"Willem","sequence":"first","affiliation":[{"name":"KU Leuven,Distrinet,Leuven,Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zafeirakis","family":"Georgios","sequence":"additional","affiliation":[{"name":"KU Leuven,Distrinet,Leuven,Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9292-6449","authenticated-orcid":false,"given":"Joos","family":"Sander","sequence":"additional","affiliation":[{"name":"KU Leuven,Distrinet,Leuven,Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6279-4430","authenticated-orcid":false,"given":"Preuveneers","family":"Davy","sequence":"additional","affiliation":[{"name":"KU Leuven,Distrinet,Leuven,Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7710-5092","authenticated-orcid":false,"given":"Joosen","family":"Wouter","sequence":"additional","affiliation":[{"name":"KU Leuven,Distrinet,Leuven,Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"volume-title":"Faceid: Global facial recognition solutions","year":"2023","key":"ref1"},{"volume-title":"Robust RGB-D Face Recognition Using Attribute-Aware Loss","year":"2018","author":"Jiang","key":"ref2"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-49556-5_14"},{"key":"ref4","doi-asserted-by":"crossref","first-page":"215","DOI":"10.1016\/j.neucom.2020.10.081","article-title":"Deep Face Recognition: A Survey","volume":"429","author":"Wang","year":"2021","journal-title":"Neurocomputing"},{"key":"ref5","article-title":"2018 benchcouncil international symposium on benchmarking, measuring and optimizing (bench18)","volume-title":"Proceedings of the 2018 BenchCouncil International Symposium on Benchmarking, Measuring and Optimizing (Bench18)","author":"Gao","year":"2018"},{"key":"ref6","doi-asserted-by":"crossref","first-page":"119701","DOI":"10.1016\/j.ins.2023.119701","article-title":"Hardening RGB-D object recognition systems against adversarial patch attacks","volume":"651","author":"Zheng","year":"2023","journal-title":"Information Sciences"},{"key":"ref7","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014","journal-title":"arXiv"},{"key":"ref8","article-title":"Explaining and Harnessing Adversarial Examples","author":"Goodfellow","year":"2015","journal-title":"arXiv"},{"journal-title":"Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods","year":"2017","author":"Carlini","key":"ref9"},{"key":"ref10","doi-asserted-by":"crossref","first-page":"819","DOI":"10.1109\/ICPR48806.2021.9412236","article-title":"AdvHat: Real-world adversarial attack on ArcFace face ID system","volume-title":"2020 25th international conference on pattern recognition (ICPR","author":"Komkov","year":"2021"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"journal-title":"PatchZero: Defending against Adversarial Patch Attacks by Detecting and Zeroing the Patch","year":"2022","author":"Xu","key":"ref12"},{"key":"ref13","article-title":"Adversarial Machine Learning at Scale","author":"Kurakin","year":"2017","journal-title":"arXiv"},{"journal-title":"DiffProtect: Generate Adversarial Examples with Diffusion Models for Facial Privacy Protection","year":"2023","author":"Liu","key":"ref14"},{"key":"ref15","first-page":"11845","volume-title":"Improving Transferability of Adversarial Patches on Face Recognition With Generative Models","author":"Xiao","year":"2021"},{"journal-title":"Confidence-Aware RGB-D Face Recognition via Virtual Depth Synthesis","year":"2024","author":"Chen","key":"ref16"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.5220\/0010221700440050"},{"key":"ref18","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1145\/3128572.3140448","article-title":"ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models","volume-title":"Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security","author":"Chen","year":"2017"},{"key":"ref19","article-title":"Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples","author":"Papernot","year":"2016","journal-title":"arXiv"},{"journal-title":"Exploring Adversarial Robustness of Multi-Sensor Perception Systems in Self Driving","year":"2022","author":"Tu","key":"ref20"},{"key":"ref21","doi-asserted-by":"crossref","DOI":"10.1109\/CVPR52729.2023.00401","volume-title":"Towards effective adversarial textured 3d meshes on physical face recognition","author":"Yang","year":"2023"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00420"},{"journal-title":"CASIA-SURF CeFA: A Benchmark for Multi-modal Cross-ethnicity Face Anti-spoofing","year":"2020","author":"Li","key":"ref23"},{"journal-title":"Deep Residual Learning for Image Recognition","year":"2015","author":"He","key":"ref24"},{"key":"ref25","article-title":"Towards Deep Learning Models Resistant to Adversarial Attacks","author":"Madry","year":"2019","journal-title":"arXiv"},{"journal-title":"Adversarial Robustness of Deep Sensor Fusion Models","year":"2022","author":"Wang","key":"ref26"}],"event":{"name":"2025 13th International Workshop on Biometrics and Forensics (IWBF)","start":{"date-parts":[[2025,4,24]]},"location":"Munich, Germany","end":{"date-parts":[[2025,4,25]]}},"container-title":["2025 13th International Workshop on Biometrics and Forensics (IWBF)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11113384\/11113385\/11113471.pdf?arnumber=11113471","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,18]],"date-time":"2025-08-18T19:38:16Z","timestamp":1755545896000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11113471\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,24]]},"references-count":26,"URL":"https:\/\/doi.org\/10.1109\/iwbf63717.2025.11113471","relation":{},"subject":[],"published":{"date-parts":[[2025,4,24]]}}}