{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T18:42:27Z","timestamp":1772822547575,"version":"3.50.1"},"reference-count":63,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2022,7,1]],"date-time":"2022-07-01T00:00:00Z","timestamp":1656633600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,7,1]],"date-time":"2022-07-01T00:00:00Z","timestamp":1656633600000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,7,1]],"date-time":"2022-07-01T00:00:00Z","timestamp":1656633600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,7,1]],"date-time":"2022-07-01T00:00:00Z","timestamp":1656633600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["DGE-1946619"],"award-info":[{"award-number":["DGE-1946619"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2027398"],"award-info":[{"award-number":["CNS-2027398"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2022,7,1]]},"DOI":"10.1109\/tdsc.2021.3067794","type":"journal-article","created":{"date-parts":[[2021,3,22]],"date-time":"2021-03-22T20:24:03Z","timestamp":1616444643000},"page":"2635-2647","source":"Crossref","is-referenced-by-count":10,"title":["A New Facial Authentication Pitfall and Remedy in Web Services"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3935-4749","authenticated-orcid":false,"given":"Dalton","family":"Cole","sequence":"first","affiliation":[{"name":"EECS Department, University of Missouri, Columbia, MO, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5305-7666","authenticated-orcid":false,"given":"Sara","family":"Newman","sequence":"additional","affiliation":[{"name":"EECS Department, University of Missouri, Columbia, MO, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3062-8240","authenticated-orcid":false,"given":"Dan","family":"Lin","sequence":"additional","affiliation":[{"name":"EECS Department, University of Missouri, Columbia, MO, USA"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11672"},{"key":"ref2","first-page":"1467","article-title":"Poisoning attacks against support vector machines","volume-title":"Proc. 29th Int. Conf. Mach. Learn.","author":"Biggio"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/MMSP.2018.8547128"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/FG.2018.00020"},{"key":"ref6","first-page":"6977","article-title":"Houdini: Fooling deep structured visual and speech recognition models with adversarial examples","volume-title":"Proc. 31st Int. Conf. Neural Inf. Process. Syst.","volume":"30","author":"Cisse"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/GlobalSIP.2018.8646335"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01446"},{"key":"ref9","first-page":"1","article-title":"MMA training: Direct input space margin maximization through adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ding"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref12","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.12341"},{"key":"ref14","first-page":"1","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"ref15","first-page":"1","article-title":"Machine learning as an adversarial service: Learning black-box adversarial examples","author":"Hayes","year":"2017"},{"key":"ref16","first-page":"7","article-title":"Labeled faces in the wild: A database for studying face recognition in unconstrained environments","volume-title":"Tech. Rep.","author":"Huang","year":"2007"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00467"},{"key":"ref19","first-page":"219","article-title":"Lessons learned from the chameleon testbed","volume-title":"Proc. USENIX Annu. Techn. Conf.","author":"Keahey"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref21","first-page":"1","article-title":"Adversarial machine learning at scale","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Kurakin"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00020"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.09.016"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081950"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SIBGRAPI.2018.00067"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref31","first-page":"1","article-title":"On detecting adversarial perturbations","author":"Metzen","year":"2017"},{"key":"ref32","article-title":"Face API - v1.0"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref35","first-page":"1","article-title":"Fast feature fool: A data independent approach to universal adversarial perturbations","author":"Mopuri","year":"2017","journal-title":"Proc. Brit. Mach. Vis. Conf."},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140451"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.5555\/3104322.3104425"},{"key":"ref38","article-title":"Exploiting machine learning to subvert your spam filter","volume-title":"Proc. 1st Usenix Workshop Large-Scale Exploits Emergent Threats","author":"Nelson"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-88735-7_2"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref42","article-title":"Acronis reports critical flaws in GeoVision biometric devices, man-in-the-middle attack risks","author":"Pascu","year":"2020","journal-title":"BiometricUpdate"},{"key":"ref43","first-page":"1","article-title":"Detection of adversarial training examples in poisoning attacks through anomaly detection","author":"Paudice","year":"2018"},{"key":"ref44","article-title":"Why do so many wireless routers lack basic security protections?","volume-title":"TechRepublic","author":"Rayome","year":"2019"},{"key":"ref45","first-page":"1","article-title":"UPSET and ANGRI: Breaking high performance image classifiers","author":"Sarkar","year":"2017"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref47","article-title":"ASUS home router bugs open consumers to snooping attacks","author":"Seals","year":"2020","journal-title":"ThreatPost"},{"key":"ref48","first-page":"6106","article-title":"Poison frogs! targeted clean-label poisoning attacks on neural networks","author":"Shafahi","year":"2018","journal-title":"Proc. 32nd Int. Conf. Neural Inform. Process. Syst."},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1948.tb01338.x"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref52","first-page":"1299","article-title":"When does machine learning fail? Generalized transferability for evasion and poisoning attacks","volume-title":"Proc. 27th USENIX Conf. Secur. Symp.","author":"Suciu"},{"key":"ref53","first-page":"1","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014","journal-title":"Proc. 2nd Int. Conf. Learn. Representations"},{"key":"ref54","article-title":"Online fraud: Too many accounts, too few passwords,","author":"Fang"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1016\/j.imavis.2009.11.005"},{"key":"ref56","article-title":"Top 10 facial recognition APIs & software of 2020,","author":"Walling"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref59","first-page":"6586","article-title":"On the convergence and robustness of adversarial training","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","volume":"97","author":"Wang"},{"key":"ref60","first-page":"1","article-title":"On attacking statistical spam filters","author":"Wittel","year":"2004"},{"key":"ref61","article-title":"Evading real-time person detectors by adversarial t-shirt","author":"Xu","year":"2019"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10590-1_53"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2016.2603342"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/8858\/9821019\/9382920-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/9821019\/09382920.pdf?arnumber=9382920","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T22:56:15Z","timestamp":1704840975000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9382920\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,1]]},"references-count":63,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2021.3067794","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,7,1]]}}}