{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T15:42:06Z","timestamp":1774539726932,"version":"3.50.1"},"reference-count":47,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,10]]},"DOI":"10.1109\/nas55553.2022.9925338","type":"proceedings-article","created":{"date-parts":[[2022,11,3]],"date-time":"2022-11-03T22:07:41Z","timestamp":1667513261000},"page":"1-8","source":"Crossref","is-referenced-by-count":3,"title":["Transformations as Denoising: A Robust Approach to Weaken Adversarial Facial Images"],"prefix":"10.1109","author":[{"given":"Pu","family":"Tian","sequence":"first","affiliation":[{"name":"Towson University,Dept. of Computer and Information Science,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Turhan","family":"Kimbrough","sequence":"additional","affiliation":[{"name":"Towson University,Dept. of Computer and Information Science,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weixian","family":"Liao","sequence":"additional","affiliation":[{"name":"Towson University,Dept. of Computer and Information Science,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Erik","family":"Blasch","sequence":"additional","affiliation":[{"name":"MOVEJ Analytics,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Yu","sequence":"additional","affiliation":[{"name":"Towson University,Dept. of Computer and Information Science,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref32","doi-asserted-by":"crossref","first-page":"1452","DOI":"10.1109\/TIFS.2020.3036801","article-title":"Towards transferable adversarial attack against deep face recognition","volume":"16","author":"zhong","year":"2020","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/0167-2789(92)90242-F"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref36","first-page":"212","article-title":"Sphereface: Deep hypersphere embedding for face recognition","author":"liu","year":"2017","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"ref35","article-title":"Adversarial examples are not bugs, they are features","volume":"32","author":"ilyas","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2014.7025068"},{"key":"ref10","first-page":"1","author":"browne","year":"2020","journal-title":"Camera Adversaria"},{"key":"ref11","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"International Conference on Learning Representations"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"key":"ref12","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2017","journal-title":"International Conference on Learning Representations"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.3390\/electronics10030236"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2014.6996249"},{"key":"ref15","article-title":"Data poisoning won't save you from facial recognition","author":"radiya-dixit","year":"2022","journal-title":"International Conference on Learning Representations"},{"key":"ref16","article-title":"Data poisoning won't save you from facial recognition","author":"radiya-dixit","year":"0","journal-title":"ICML 2021 Workshop on Adversarial Machine Learning"},{"key":"ref17","first-page":"2574","article-title":"Deepfool: a simple and accurate method to fool deep neural networks","author":"moosavi-dezfooli","year":"2016","journal-title":"IEEE Conf Computer Vision and Pattern Recognition"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref19","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref4","article-title":"Lowkey: leveraging adversarial attacks to protect social media users from facial recognition","author":"cherepanova","year":"2021","journal-title":"International Conference on Learning Representations"},{"key":"ref28","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0006"},{"key":"ref27","article-title":"The limitations of adversarial training and the blind-spot attack","author":"zhang","year":"2019","journal-title":"International Conference on Learning Representations"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0044"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW53098.2021.00105"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/383259.383296"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2830661"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2948912"},{"key":"ref2","first-page":"1589","article-title":"Fawkes: Protecting privacy against unauthorized deep learning models","author":"shan","year":"0","journal-title":"29th USENIX Security Symposium USENIX Security 20"},{"key":"ref9","article-title":"Unlearnable examples: Making personal data unexploitable","author":"huang","year":"2021","journal-title":"International Conference on Learning Representations"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.chb.2021.106894"},{"key":"ref20","article-title":"Mitigating adversarial effects through randomization","author":"xie","year":"2017","journal-title":"International Conference on Learning Representations"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2011.5995566"},{"key":"ref45","article-title":"Learning to align from scratch","author":"huang","year":"2012","journal-title":"NIPS"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5888"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00357"},{"key":"ref47","year":"0","journal-title":"Face Recognition Datasets"},{"key":"ref24","year":"0","journal-title":"Lowkey"},{"key":"ref42","author":"parkhi","year":"2015","journal-title":"Deep face recognition"},{"key":"ref23","year":"0","journal-title":"Image &#x201C;cloaking"},{"key":"ref41","year":"0","journal-title":"Image Processing with Python"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICEET53442.2021.9659697"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ASYU50717.2020.9259802"},{"key":"ref43","doi-asserted-by":"crossref","first-page":"815","DOI":"10.1109\/CVPR.2015.7298682","article-title":"Facenet: A unified embedding for face recognition and clustering","author":"schroff","year":"2015","journal-title":"2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR)"}],"event":{"name":"2022 IEEE International Conference on Networking, Architecture and Storage (NAS)","location":"Philadelphia, PA, USA","start":{"date-parts":[[2022,10,3]]},"end":{"date-parts":[[2022,10,4]]}},"container-title":["2022 IEEE International Conference on Networking, Architecture and Storage (NAS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9925246\/9925275\/09925338.pdf?arnumber=9925338","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,11,28]],"date-time":"2022-11-28T15:23:12Z","timestamp":1669648992000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9925338\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10]]},"references-count":47,"URL":"https:\/\/doi.org\/10.1109\/nas55553.2022.9925338","relation":{},"subject":[],"published":{"date-parts":[[2022,10]]}}}