{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T17:58:32Z","timestamp":1767981512744,"version":"3.49.0"},"reference-count":68,"publisher":"IEEE","license":[{"start":{"date-parts":[[2024,5,19]],"date-time":"2024-05-19T00:00:00Z","timestamp":1716076800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2024,5,19]],"date-time":"2024-05-19T00:00:00Z","timestamp":1716076800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,5,19]]},"DOI":"10.1109\/sp54263.2024.00155","type":"proceedings-article","created":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T17:56:32Z","timestamp":1725558992000},"page":"74-90","source":"Crossref","is-referenced-by-count":5,"title":["AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake Detection"],"prefix":"10.1109","author":[{"given":"Xiangtao","family":"Meng","sequence":"first","affiliation":[{"name":"Shandong University"}]},{"given":"Li","family":"Wang","sequence":"additional","affiliation":[{"name":"Shandong University"}]},{"given":"Shanqing","family":"Guo","sequence":"additional","affiliation":[{"name":"Shandong University"}]},{"given":"Lei","family":"Ju","sequence":"additional","affiliation":[{"name":"Shandong University"}]},{"given":"Qingchuan","family":"Zhao","sequence":"additional","affiliation":[{"name":"City University of Hong Kong"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Baidu deepfake detection services"},{"key":"ref3","volume-title":"Duckduckgoose detection services"},{"key":"ref6","volume-title":"Microsoft video authenticator detection services"},{"key":"ref7","volume-title":"Realai detection services"},{"key":"ref8","volume-title":"Reality defender detection services"},{"key":"ref9","volume-title":"Tencent deepfake detection services"},{"key":"ref10","volume-title":"Virtually Trying on Clothes while Shopping"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00453"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1142\/S0218001496000438"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00337"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58574-7_7"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413630"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00821"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00582"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.3390\/fi13110288"},{"key":"ref21","first-page":"3247","article-title":"Leveraging frequency analysis for deep fake image recognition","volume-title":"International Conference on Machine Learning","author":"Frank"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9207034"},{"key":"ref23","article-title":"Generative adversarial nets","volume":"27","author":"Goodfellow","year":"2014","journal-title":"Advances in neural information processing systems"},{"key":"ref24","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2905689"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413732"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/WACV48630.2021.00339"},{"key":"ref29","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"International conference on machine learning","author":"Ilyas"},{"key":"ref30","article-title":"Progressive growing of gans for improved quality, stability, and variation","author":"Karras","year":"2017"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00453"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00813"},{"key":"ref33","article-title":"Deepfake salvador dal\u00ed takes selfies with museum visitors","author":"Lee","year":"2019","journal-title":"The Verge"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00573"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00512"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00853"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.624"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP42928.2021.9506775"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00808"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref41","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1177\/1365712718807226"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/WACVW.2019.00020"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW53098.2021.00103"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/JSTSP.2020.3007250"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/icassp.2019.8682602"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00728"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.5555\/3327345.3327369"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58610-2_6"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00009"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref52","volume-title":"The state of deepfakes: Landscape, threats, and impact","year":"2019"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2021.3071395"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3306346.3323035"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.262"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3450626.3459838"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/694"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00872"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00991"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.22215\/timreview\/1282"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/cec.2008.4631255"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01267"},{"key":"ref63","article-title":"Improving inversion and generation diversity in stylegan using a gaussianized latent space","author":"Wulff","year":"2020"},{"key":"ref64","article-title":"D-square-b: Deep distribution bound for natural-looking adversarial attack","author":"Xu","year":"2020"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref66","article-title":"Unofficial implementation of f3-net","author":"Yuan","year":"2020"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00384"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46487-9_40"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3037908"},{"key":"ref71","author":"Zhu","year":"2020","journal-title":"Improved stylegan embedding: Where are the good latents?"}],"event":{"name":"2024 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2024,5,19]]},"end":{"date-parts":[[2024,5,23]]}},"container-title":["2024 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10646615\/10646598\/10646754.pdf?arnumber=10646754","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,30]],"date-time":"2025-05-30T05:24:23Z","timestamp":1748582663000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10646754\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,19]]},"references-count":68,"URL":"https:\/\/doi.org\/10.1109\/sp54263.2024.00155","relation":{},"subject":[],"published":{"date-parts":[[2024,5,19]]}}}