{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T10:13:10Z","timestamp":1785838390696,"version":"3.56.0"},"reference-count":164,"publisher":"Association for Computing Machinery (ACM)","issue":"1","funder":[{"name":"Gates Foundation","award":["INV-001309"],"award-info":[{"award-number":["INV-001309"]}]},{"name":"Baskerville: a national accelerated compute resource under the EPSRC","award":["EP\/T022221\/1"],"award-info":[{"award-number":["EP\/T022221\/1"]}]},{"name":"Alan Turing Institute under EPSRC","award":["EP\/N510129\/1"],"award-info":[{"award-number":["EP\/N510129\/1"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2026,1,31]]},"abstract":"<jats:p>\n            <jats:styled-content style=\"color:#005984\">Face Recognition Systems (FRS)<\/jats:styled-content>\n            are critical and essential components for user authentication via biometrics. To name a few, baking, e-Commerce, and border control are entities propelling their progress. These are of immense importance due to their economic and social relevance.\n            <jats:styled-content style=\"color:#005984\">FRS<\/jats:styled-content>\n            widespread usage leads to security vulnerabilities that need to be identified and mitigated. This article provides a comprehensive review of potential attacks on recently discovered vulnerabilities from 2017\u20132024. Our work is significant regarding\n            <jats:styled-content style=\"color:#005984\">FRS<\/jats:styled-content>\n            development because their impact in terms of security. The novelty is a systematic review to properly categorize threat vectors and their severity toward\n            <jats:styled-content style=\"color:#005984\">FRS<\/jats:styled-content>\n            over the past eight years. We categorize, summarize, and analyze the threat vectors toward\n            <jats:styled-content style=\"color:#005984\">FRS<\/jats:styled-content>\n            to this end. We also elaborate on the threat taxonomy for existing\n            <jats:styled-content style=\"color:#005984\">Architecture Reference Architecture (ARA)<\/jats:styled-content>\n            to identify threats on user-based authentication FRS. Our findings show the most persistent attack vectors, usage trends, severity, functionality, and level of sophistication required to perform them. We present a comprehensive description of each to create more resilient and trustable systems for this fast-growing technology. This article can be used by researchers and practitioners interested in the state-of-the-art\n            <jats:styled-content style=\"color:#005984\">FRS<\/jats:styled-content>\n            attack vectors to develop more secure systems.\n          <\/jats:p>","DOI":"10.1145\/3736753","type":"journal-article","created":{"date-parts":[[2025,5,22]],"date-time":"2025-05-22T07:17:51Z","timestamp":1747898271000},"page":"1-37","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Attack Vectors for Face Recognition Systems: A Comprehensive Review"],"prefix":"10.1145","volume":"58","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4561-8798","authenticated-orcid":false,"given":"Roberto","family":"Leyva","sequence":"first","affiliation":[{"name":"WMG, University of Warwick","place":["Coventry, United Kingdom of Great Britain and Northern Ireland"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1054-6368","authenticated-orcid":false,"given":"Epiphaniou","family":"Gregory","sequence":"additional","affiliation":[{"name":"University of Warwick","place":["Coventry, United Kingdom of Great Britain and Northern Ireland"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4715-212X","authenticated-orcid":false,"given":"Carsten","family":"Maple","sequence":"additional","affiliation":[{"name":"University of Warwick","place":["Coventry, United Kingdom of Great Britain and Northern Ireland"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,9,3]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2021.107094"},{"key":"e_1_3_2_3_2","doi-asserted-by":"crossref","first-page":"94","DOI":"10.1007\/978-3-030-37545-4_7","volume-title":"E-Democracy \u2013 Safeguarding Democracy and Human Rights in the Digital Age","author":"Abomhara Mohamed","year":"2020","unstructured":"Mohamed Abomhara, Sule Yildirim Yayilgan, Anne Hilde Nymoen, Marina Shalaginova, Zolt\u00e1n Sz\u00e9kely, and Ogerta Elezaj. 2020. How to do it right: A framework for biometrics supported border control. In E-Democracy \u2013 Safeguarding Democracy and Human Rights in the Digital Age. Sokratis Katsikas and Vasilios Zorkadis (Eds.), Springer International Publishing, Cham, 94\u2013109."},{"key":"e_1_3_2_4_2","first-page":"1376","volume-title":"Proceedings of the 2023 7th International Conference on Intelligent Computing and Control Systems (ICICCS)","author":"Agrawal Khushabu","year":"2023","unstructured":"Khushabu Agrawal and Charul Bhatnagar. 2023. A black-box based attack generation approach to create the transferable patch attack. In Proceedings of the 2023 7th International Conference on Intelligent Computing and Control Systems (ICICCS). 1376\u20131380. DOI:10.1109\/ICICCS56967.2023.10142656"},{"key":"e_1_3_2_5_2","doi-asserted-by":"crossref","first-page":"3568","DOI":"10.1145\/3394171.3413606","volume-title":"Proceedings of the 28th ACM International Conference on Multimedia (MM\u201920)","author":"Arab Mohammad Amin","year":"2020","unstructured":"Mohammad Amin Arab, Puria Azadi Moghadam, Mohamed Hussein, Wael Abd-Almageed, and Mohamed Hefeeda. 2020. Revealing true identity: Detecting makeup attacks in face-based biometric systems. In Proceedings of the 28th ACM International Conference on Multimedia (MM\u201920). ACM, New York, NY, USA, 3568\u20133576. DOI:10.1145\/3394171.3413606"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2024.129295"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.04.062"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.122821"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBIOM.2024.3349857"},{"key":"e_1_3_2_10_2","doi-asserted-by":"crossref","first-page":"688","DOI":"10.1109\/BTAS.2017.8272758","volume-title":"Proceedings of the 2017 IEEE International Joint Conference on Biometrics (IJCB)","author":"Boulkenafet Z.","year":"2017","unstructured":"Z. Boulkenafet, J. Komulainen, Z. Akhtar, A. Benlamoudi, D. Samai, S. E. Bekhouche, A. Ouafi, F. Dornaika, A. Taleb-Ahmed, L. Qin, et\u00a0al. 2017. A competition on generalized software-based face presentation attack detection in mobile scenarios. In Proceedings of the 2017 IEEE International Joint Conference on Biometrics (IJCB). 688\u2013696. DOI:10.1109\/BTAS.2017.8272758"},{"key":"e_1_3_2_11_2","first-page":"145","volume-title":"Hybrid Artificial Intelligent Systems","author":"Bu Seok-Jun","year":"2019","unstructured":"Seok-Jun Bu and Sung-Bae Cho. 2019. Genetic algorithm-based deep learning ensemble for detecting database intrusion via insider attack. In Hybrid Artificial Intelligent Systems. Hilde P\u00e9rez Garc\u00eda, Lidia S\u00e1nchez Gonz\u00e1lez, Manuel Castej\u00f3n Limas, H\u00e9ctor Quinti\u00e1n Pardo, and Emilio Corchado Rodr\u00edguez (Eds.), Springer International Publishing, Cham, 145\u2013156."},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1038\/s44287-024-00094-x"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-024-02151-2"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3656474"},{"key":"e_1_3_2_15_2","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1007\/978-3-030-58574-7_7","volume-title":"Computer Vision \u2013 ECCV 2020","author":"Chai Lucy","year":"2020","unstructured":"Lucy Chai, David Bau, Ser-Nam Lim, and Phillip Isola. 2020. What makes fake images detectable? Understanding properties that generalize. In Computer Vision \u2013 ECCV 2020. Andrea Vedaldi, Horst Bischof, Thomas Brox, and Jan-Michael Frahm (Eds.), Springer International Publishing, Cham, 103\u2013120."},{"key":"e_1_3_2_16_2","unstructured":"Jiahao Chen Zhiqiang Shen Yuwen Pu Chunyi Zhou Changjiang Li Jiliang Li Ting Wang and Shouling Ji. 2024. Rethinking the vulnerabilities of face recognition systems: From a practical perspective. arXiv:2405.12786. Retrieved from https:\/\/arxiv.org\/abs\/2405.12786"},{"key":"e_1_3_2_17_2","unstructured":"Xinyun Chen Chang Liu Bo Li Kimberly Lu and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv:1712.05526. Retrieved from https:\/\/arxiv.org\/abs\/1712.05526"},{"key":"e_1_3_2_18_2","doi-asserted-by":"crossref","first-page":"233","DOI":"10.1007\/978-3-030-56223-6_13","volume-title":"Advances in Digital Forensics XVI","author":"Chhabra Saheb","year":"2020","unstructured":"Saheb Chhabra, Naman Banati, Gaurav Gupta, and Garima Gupta. 2020. Target identity attacks on facial recognition systems. In Advances in Digital Forensics XVI. Gilbert Peterson and Sujeet Shenoi (Eds.), Springer International Publishing, Cham, 233\u2013252."},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3001730"},{"key":"e_1_3_2_20_2","doi-asserted-by":"crossref","first-page":"518","DOI":"10.1007\/978-3-030-12939-2_36","volume-title":"Pattern Recognition","author":"Damer Naser","year":"2019","unstructured":"Naser Damer, Viola Boller, Yaza Wainakh, Fadi Boutros, Philipp Terh\u00f6rst, Andreas Braun, and Arjan Kuijper. 2019. Detecting face morphing attacks by analyzing the directed distances of facial landmarks shifts. In Pattern Recognition. Thomas Brox, Andr\u00e9s Bruhn, and Mario Fritz (Eds.), Springer International Publishing, Cham, 518\u2013534."},{"key":"e_1_3_2_21_2","first-page":"1","volume-title":"Proceedings of the 2023 11th International Workshop on Biometrics and Forensics (IWBF)","author":"Damer Naser","year":"2023","unstructured":"Naser Damer, Meiling Fang, Patrick Siebke, Jan Niklas Kolf, Marco Huber, and Fadi Boutros. 2023. MorDIFF: Recognition vulnerability and attack detectability of face morphing attacks created by diffusion autoencoders. In Proceedings of the 2023 11th International Workshop on Biometrics and Forensics (IWBF). 1\u20136. DOI:10.1109\/IWBF57495.2023.10157869"},{"key":"e_1_3_2_22_2","first-page":"1","volume-title":"Proceedings of the 2019 22nd International Conference on Information Fusion (FUSION)","author":"Damer Naser","year":"2019","unstructured":"Naser Damer, Steffen Zienert, Yaza Wainakh, Alexandra Mosegu\u00ed Saladi\u00e9, Florian Kirchbuchner, and Arjan Kuijper. 2019. A multi-detector solution towards an accurate and generalized detection of face morphing attacks. In Proceedings of the 2019 22nd International Conference on Information Fusion (FUSION). 1\u20138."},{"key":"e_1_3_2_23_2","first-page":"1","volume-title":"Proceedings of the 2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems (BTAS)","author":"Debiasi Luca","year":"2018","unstructured":"Luca Debiasi, Christian Rathgeb, Ulrich Scherhag, Andreas Uhl, and Christoph Busch. 2018. PRNU variance analysis for morphed face image detection. In Proceedings of the 2018 IEEE 9th International Conference on Biometrics Theory, Applications and Systems (BTAS). 1\u20139. DOI:10.1109\/BTAS.2018.8698576"},{"key":"e_1_3_2_24_2","first-page":"1","volume-title":"Proceedings of the 2020 IEEE International Joint Conference on Biometrics (IJCB)","author":"Dumford Jacob","year":"2020","unstructured":"Jacob Dumford and Walter Scheirer. 2020. Backdooring convolutional neural networks via targeted weight perturbations. In Proceedings of the 2020 IEEE International Joint Conference on Biometrics (IJCB). 1\u20139. DOI:10.1109\/IJCB48548.2020.9304875"},{"key":"e_1_3_2_25_2","first-page":"1","volume-title":"Proceedings of the 2020 IEEE International Joint Conference on Biometrics (IJCB)","author":"Ebihara Akinori F.","year":"2020","unstructured":"Akinori F. Ebihara, Kazuyuki Sakurai, and Hitoshi Imaoka. 2020. Specular- and diffuse-reflection-based face spoofing detection for mobile devices. In Proceedings of the 2020 IEEE International Joint Conference on Biometrics (IJCB). 1\u201310. DOI:10.1109\/IJCB48548.2020.9304862"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.110002"},{"key":"e_1_3_2_27_2","volume-title":"Proceedings of the 26th Annual International Conference on Mobile Computing and Networking (MobiCom\u201920)","author":"Farrukh Habiba","year":"2020","unstructured":"Habiba Farrukh, Reham Mohamed Aburas, Siyuan Cao, and He Wang. 2020. FaceRevelio: A face liveness detection system for smartphones with a single front camera. In Proceedings of the 26th Annual International Conference on Mobile Computing and Networking (MobiCom\u201920). ACM, New York, NY, USA, Article 49, 13 pages. DOI:10.1145\/3372224.3419206"},{"key":"e_1_3_2_28_2","doi-asserted-by":"crossref","first-page":"393","DOI":"10.1007\/978-3-030-37731-1_32","volume-title":"MultiMedia Modeling","author":"Feng Xinjie","year":"2020","unstructured":"Xinjie Feng, Hongxun Yao, Wenbin Che, and Shengping Zhang. 2020. An effective way to boost black-box adversarial attack. In MultiMedia Modeling. Yong Man Ro, Wen-Huang Cheng, Junmo Kim, Wei-Ta Chu, Peng Cui, Jung-Woo Choi, Min-Chun Hu, and Wesley De Neve (Eds.), Springer International Publishing, Cham, 393\u2013404."},{"key":"e_1_3_2_29_2","doi-asserted-by":"crossref","first-page":"1322","DOI":"10.1145\/2810103.2813677","volume-title":"Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security","author":"Fredrikson Matt","year":"2015","unstructured":"Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence information and basic countermeasures. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. 1322\u20131333."},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","unstructured":"Roberto Gallardo-Cava David Ortega-Delcampo Julio Guillen-Garcia Daniel Palacios-Alonso and Cristina Conde. 2023. Creating realistic presentation attacks for facial impersonation step-by-step. IEEE Access 11 (2023) 109257\u2013109266. DOI:10.1109\/ACCESS.2023.3313094","DOI":"10.1109\/ACCESS.2023.3313094"},{"key":"e_1_3_2_31_2","doi-asserted-by":"crossref","first-page":"316","DOI":"10.1109\/CW.2018.00065","volume-title":"Proceedings of the 2018 International Conference on Cyberworlds (CW)","author":"Ghammam Loubna","year":"2018","unstructured":"Loubna Ghammam, Morgan Barbier, and Christophe Rosenberger. 2018. Enhancing the security of transformation based biometric template protection schemes. In Proceedings of the 2018 International Conference on Cyberworlds (CW). 316\u2013323. DOI:10.1109\/CW.2018.00065"},{"key":"e_1_3_2_32_2","first-page":"143","volume-title":"Proceedings of the 2020 3rd International Conference on Information and Communications Technology (ICOIACT)","author":"Hadiprakoso Raden Budiarto","year":"2020","unstructured":"Raden Budiarto Hadiprakoso, Hermawan Setiawan, and Girinoto. 2020. Face anti-spoofing using CNN classifier & face liveness detection. In Proceedings of the 2020 3rd International Conference on Information and Communications Technology (ICOIACT). 143\u2013147. DOI:10.1109\/ICOIACT50329.2020.9331977"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","unstructured":"Xiaoxuan Han Songlin Yang Wei Wang Ziwen He and Jing Dong. 2024. Exploiting backdoors of face synthesis detection with natural triggers. ACM Trans. Multimedia Comput. Commun. Appl. 21 2 (December 2024). DOI:10.1145\/3677380","DOI":"10.1145\/3677380"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3583135"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.06.012"},{"key":"e_1_3_2_36_2","first-page":"231","volume-title":"Proceedings of the ACM Turing Celebration Conference - China (ACM TURC\u201920)","author":"He Can","year":"2020","unstructured":"Can He, Mingfu Xue, Jian Wang, and Weiqiang Liu. 2020. Embedding backdoors as the facial features: Invisible backdoor attacks against face recognition systems. In Proceedings of the ACM Turing Celebration Conference - China (ACM TURC\u201920). ACM, New York, NY, USA, 231\u2013235. DOI:10.1145\/3393527.3393567"},{"key":"e_1_3_2_37_2","first-page":"1","volume-title":"Proceedings of the 2024 IEEE International Conference on Multimedia and Expo (ICME)","author":"He Chaoxiang","year":"2024","unstructured":"Chaoxiang He, Yimiao Zeng, Xiaojing Ma, Bin Benjamin Zhu, Zewei Li, Shixin Li, and Hai Jin. 2024. MysticMask: Adversarial mask for impersonation attack against face recognition systems. In Proceedings of the 2024 IEEE International Conference on Multimedia and Expo (ICME). 1\u20136. DOI:10.1109\/ICME57554.2024.10687792"},{"key":"e_1_3_2_38_2","first-page":"1","volume-title":"Proceedings of the 2024 International Joint Conference on Neural Networks (IJCNN)","author":"He Qiaoyun","year":"2024","unstructured":"Qiaoyun He, Deng Zongyong, Zuyuan He, and Qijun Zhao. 2024. Face morphing via adversarial attack-based adaptive blending. In Proceedings of the 2024 International Joint Conference on Neural Networks (IJCNN). 1\u20138. DOI:10.1109\/IJCNN60899.2024.10650752"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","unstructured":"Yingzhe He Guozhu Meng Kai Chen Xingbo Hu and Jinwen He. 2022. Towards security threats of deep learning systems: A survey. IEEE Transactions on Software Engineering 48 5 (2022) 1743\u20131770. DOI:10.1109\/TSE.2020.3034721","DOI":"10.1109\/TSE.2020.3034721"},{"key":"e_1_3_2_40_2","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1109\/PST.2017.00023","volume-title":"Proceedings of the 2017 15th Annual Conference on Privacy, Security and Trust (PST)","author":"Hidano Seira","year":"2017","unstructured":"Seira Hidano, Takao Murakami, Shuichi Katsumata, Shinsaku Kiyomoto, and Goichiro Hanaoka. 2017. Model inversion attacks for prediction systems: Without knowledge of non-sensitive attributes. In Proceedings of the 2017 15th Annual Conference on Privacy, Security and Trust (PST). 115\u201311509. DOI:10.1109\/PST.2017.00023"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3402167"},{"key":"e_1_3_2_42_2","doi-asserted-by":"crossref","first-page":"326","DOI":"10.1007\/978-3-030-58583-9_20","volume-title":"Computer Vision \u2013 ECCV 2020","author":"Huang Shanjiaoyang","year":"2020","unstructured":"Shanjiaoyang Huang, Weiqi Peng, Zhiwei Jia, and Zhuowen Tu. 2020. One-pixel signature: Characterizing CNN models for backdoor detection. In Computer Vision \u2013 ECCV 2020. Andrea Vedaldi, Horst Bischof, Thomas Brox, and Jan-Michael Frahm (Eds.), Springer International Publishing, Cham, 326\u2013341."},{"key":"e_1_3_2_43_2","doi-asserted-by":"crossref","first-page":"302","DOI":"10.1109\/DSN58367.2023.00038","volume-title":"Proceedings of the 2023 53rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)","author":"Hussain Shehzeen","year":"2023","unstructured":"Shehzeen Hussain, Todd Huster, Chris Mesterharm, Paarth Neekhara, and Farinaz Koushanfar. 2023. ReFace: Adversarial transformation networks for real-time attacks on face recognition systems. In Proceedings of the 2023 53rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). 302\u2013312. DOI:10.1109\/DSN58367.2023.00038"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","unstructured":"Mathias Ibsen Christian Rathgeb Daniel Fischer Pawel Drozdowski and Christoph Busch. 2022. Digital face manipulation in biometric systems. In Handbook of Digital Face Manipulation and Detection: From DeepFakes to Morphing Attacks Christian Rathgeb Ruben Tolosana Ruben Vera-Rodriguez and Christoph Busch (Eds.). Springer International Publishing Cham 27\u201343. DOI:10.1007\/978-3-030-87664-7_2","DOI":"10.1007\/978-3-030-87664-7_2"},{"key":"e_1_3_2_45_2","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1109\/SP.2018.00057","volume-title":"Proceedings of the 2018 IEEE Symposium on Security and Privacy (SP)","author":"Jagielski Matthew","year":"2018","unstructured":"Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li. 2018. Manipulating machine learning: Poisoning attacks and countermeasures for regression learning. In Proceedings of the 2018 IEEE Symposium on Security and Privacy (SP). 19\u201335. DOI:10.1109\/SP.2018.00057"},{"key":"e_1_3_2_46_2","first-page":"4309","volume-title":"Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR)","author":"Ji Qiaobin","year":"2021","unstructured":"Qiaobin Ji, Shugong Xu, Xudong Chen, Shunqing Zhang, and Shan Cao. 2021. A cross domain multi-modal dataset for robust face anti-spoofing. In Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR). 4309\u20134316. DOI:10.1109\/ICPR48806.2021.9413107"},{"key":"e_1_3_2_47_2","first-page":"39","volume-title":"New Trends in Image Analysis and Processing \u2013 ICIAP 2019","author":"Jia Shan","year":"2019","unstructured":"Shan Jia, Chuanbo Hu, Guodong Guo, and Zhengquan Xu. 2019. A database for face presentation attack using wax figure faces. In New Trends in Image Analysis and Processing \u2013 ICIAP 2019. Marco Cristani, Andrea Prati, Oswald Lanz, Stefano Messelodi, and Nicu Sebe (Eds.), Springer International Publishing, Cham, 39\u201347."},{"key":"e_1_3_2_48_2","unstructured":"Shuai Jia Bangjie Yin Taiping Yao Shouhong Ding Chunhua Shen Xiaokang Yang and Chao Ma. 2022. Adv-attribute: Inconspicuous and transferable adversarial attack on face recognition. In Advances in Neural Information Processing Systems Curran Associates S. Koyejo S. Mohamed A. Agarwal D. Belgrave K. Cho and A. Oh (Eds.). Inc. 34136\u201334147. Retrieved from https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2022\/file\/dccbeb7a8df3065c4646928985edf435-Paper-Conference.pdf"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2019.05.078"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","unstructured":"Tero Karras Samuli Laine and Timo Aila. 2021. A style-based generator architecture for generative adversarial networks. IEEE Transactions on Pattern Analysis and Machine Intelligence 43 12 (2021) 4217\u20134228. DOI:10.1109\/TPAMI.2020.2970919","DOI":"10.1109\/TPAMI.2020.2970919"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1016\/S0969-4765(20)30001-1"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2018.02.016"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2019.07.023"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2025.112983"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3140687"},{"key":"e_1_3_2_56_2","doi-asserted-by":"crossref","first-page":"819","DOI":"10.1109\/ICPR48806.2021.9412236","volume-title":"Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR)","author":"Komkov Stepan","year":"2021","unstructured":"Stepan Komkov and Aleksandr Petiushko. 2021. AdvHat: Real-world adversarial attack on arcface face ID system. In Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR). 819\u2013826. DOI:10.1109\/ICPR48806.2021.9412236"},{"key":"e_1_3_2_57_2","first-page":"4830","volume-title":"ICASSP 2024 - Proceedings of the 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Korshunov Pavel","year":"2024","unstructured":"Pavel Korshunov, Anjith George, G\u00f6khan \u00d6zbulak, and S\u00e9bastien Marcel. 2024. Vulnerability of face age verification to replay attacks. In ICASSP 2024 - Proceedings of the 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). 4830\u20134834. DOI:10.1109\/ICASSP48485.2024.10447255"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBIOM.2019.2946175"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","unstructured":"Takaya Kubota Kota Yoshida Mitsuru Shiozaki and Takeshi Fujino. 2021. Deep learning side-channel attack against hardware implementations of AES. Microprocessors and Microsystems 87 (2021) 103383. DOI:10.1016\/j.micpro.2020.103383","DOI":"10.1016\/j.micpro.2020.103383"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1145\/3673224"},{"key":"e_1_3_2_61_2","first-page":"0321","volume-title":"TENCON 2018 - Proceedings of the 2018 IEEE Region 10 Conference","author":"Lee Chien Eao","year":"2018","unstructured":"Chien Eao Lee, Lilei Zheng, Ying Zhang, Vrizlynn L. L. Thing, and Ying Yu Chu. 2018. Towards building a remote anti-spoofing face authentication system. In TENCON 2018 - Proceedings of the 2018 IEEE Region 10 Conference. 0321\u20130326. DOI:10.1109\/TENCON.2018.8650440"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102378"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cad.2020.102948"},{"key":"e_1_3_2_64_2","first-page":"513","volume-title":"Proceedings of the Joint European Conference on Machine Learning and Knowledge Discovery in Databases","author":"Leyva Roberto","year":"2023","unstructured":"Roberto Leyva, Gregory Epiphaniou, Carsten Maple, and Victor Sanchez. 2023. Detecting face synthesis using a concealed fusion model. In Proceedings of the Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 513\u2013524."},{"key":"e_1_3_2_65_2","first-page":"3818","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Leyva Roberto","year":"2024","unstructured":"Roberto Leyva, Victor Sanchez, Gregory Epiphaniou, and Carsten Maple. 2024. Demographic bias effects on face image synthesis. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 3818\u20133826."},{"key":"e_1_3_2_66_2","volume-title":"BMVC-British Machine Vision Conference","author":"Leyva Roberto","year":"2024","unstructured":"Roberto Leyva, Praveen Selvaraj, Andrew Elliott, Gregory Epiphaniou, and Carsten Maple. 2024. Beyond face matching: A facial traits based privacy score for synthetic face datasets. In BMVC-British Machine Vision Conference. BMVA."},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.05.085"},{"key":"e_1_3_2_68_2","first-page":"263","volume-title":"Proceedings of the 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE)","author":"Li Yuanchun","year":"2021","unstructured":"Yuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen, and Yunxin Liu. 2021. DeepPayload: Black-box backdoor attack on deep learning models through neural payload injection. In Proceedings of the 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE). 263\u2013274. DOI:10.1109\/ICSE43902.2021.00035"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2019.07.039"},{"key":"e_1_3_2_70_2","first-page":"24626","volume-title":"Proceedings of the 2023 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Li Zexin","year":"2023","unstructured":"Zexin Li, Bangjie Yin, Taiping Yao, Junfeng Guo, Shouhong Ding, Simin Chen, and Cong Liu. 2023. Sibling-attack: Rethinking transferable adversarial attacks against face recognition. In Proceedings of the 2023 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 24626\u201324637. DOI:10.1109\/CVPR52729.2023.02359"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2016.2521349"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3188149"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2805680"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2024.127517"},{"key":"e_1_3_2_75_2","first-page":"182","volume-title":"Computer Vision \u2013 ECCV 2020","author":"Liu Yunfei","year":"2020","unstructured":"Yunfei Liu, Xingjun Ma, James Bailey, and Feng Lu. 2020. Reflection backdoor: A natural backdoor attack on deep neural networks. In Computer Vision \u2013 ECCV 2020. Andrea Vedaldi, Horst Bischof, Thomas Brox, and Jan-Michael Frahm (Eds.), Springer International Publishing, Cham, 182\u2013199."},{"key":"e_1_3_2_76_2","first-page":"33","volume-title":"Proceedings of the 2020 21st International Symposium on Quality Electronic Design (ISQED)","author":"Liu Yuntao","year":"2020","unstructured":"Yuntao Liu, Ankit Mondal, Abhishek Chakraborty, Michael Zuzak, Nina Jacobsen, Daniel Xing, and Ankur Srivastava. 2020. A survey on neural trojans. In Proceedings of the 2020 21st International Symposium on Quality Electronic Design (ISQED). 33\u201339. DOI:10.1109\/ISQED48828.2020.9137011"},{"key":"e_1_3_2_77_2","first-page":"406","volume-title":"Computer Vision \u2013 ECCV 2020","author":"Liu Yaojie","year":"2020","unstructured":"Yaojie Liu, Joel Stehouwer, and Xiaoming Liu. 2020. On disentangling spoof trace for generic face anti-spoofing. In Computer Vision \u2013 ECCV 2020. Andrea Vedaldi, Horst Bischof, Thomas Brox, and Jan-Michael Frahm (Eds.), Springer International Publishing, Cham, 406\u2013422."},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","unstructured":"Ming Long Song Chen Le-Bing Zhang Fei Peng and Dengyong Zhang. 2024. DFS-Net: StyleGAN2-based dual feature separation for face De-Morphing. Multimedia Tools and Applications (15 Nov 2024). 10.1007\/s11042-024-20445-","DOI":"10.1007\/s11042-024-20445-"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3310352"},{"key":"e_1_3_2_80_2","first-page":"186","volume-title":"Decision and Game Theory for Security","author":"Ma Yuzhe","year":"2018","unstructured":"Yuzhe Ma, Kwang-Sung Jun, Lihong Li, and Xiaojin Zhu. 2018. Data poisoning attacks in contextual bandits. In Decision and Game Theory for Security. Linda Bushnell, Radha Poovendran, and Tamer Ba\u015far (Eds.), Springer International Publishing, Cham, 186\u2013204."},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1145\/3618113"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1145\/3618113"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2676720"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cviu.2020.103103"},{"key":"e_1_3_2_85_2","first-page":"01","volume-title":"Proceedings of the 2024 12th International Workshop on Biometrics and Forensics (IWBF)","author":"Medvedev Iurii","year":"2024","unstructured":"Iurii Medvedev and Nuno Gon\u00e7alves. 2024. Quadruplet loss for improving the robustness to face morphing attacks. In Proceedings of the 2024 12th International Workshop on Biometrics and Forensics (IWBF). 01\u201306. DOI:10.1109\/IWBF62628.2024.10593860"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","unstructured":"Zuheng Ming Muriel Visani Muhammad Muzzamil Luqman and Jean-Christophe Burie. 2020. A survey on anti-spoofing methods for facial recognition with RGB cameras of generic consumer devices. Journal of Imaging 6 12 (2020). DOI:10.3390\/jimaging6120139","DOI":"10.3390\/jimaging6120139"},{"key":"e_1_3_2_87_2","first-page":"3230","volume-title":"Proceedings of the 2024 IEEE International Conference on Image Processing (ICIP)","author":"Mohzary Muhammad","year":"2024","unstructured":"Muhammad Mohzary, Baek-Young Choi, and Sejun Song. 2024. A trustworthy authentication against visual master face dictionary attacks (trauma). In Proceedings of the 2024 IEEE International Conference on Image Processing (ICIP). 3230\u20133235. DOI:10.1109\/ICIP51287.2024.10648241"},{"key":"e_1_3_2_88_2","first-page":"1","volume-title":"Proceedings of the 2019 International Conference on Biometrics (ICB)","author":"Muhammad Usman","year":"2019","unstructured":"Usman Muhammad and Abdenour Hadid. 2019. Face anti-spoofing using hybrid residual learning framework. In Proceedings of the 2019 International Conference on Biometrics (ICB). 1\u20137. DOI:10.1109\/ICB45273.2019.8987283"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-024-02152-1"},{"key":"e_1_3_2_90_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBIOM.2022.3166206"},{"key":"e_1_3_2_91_2","first-page":"1","volume-title":"IEEE INFOCOM 2021 - Proceedings of the IEEE Conference on Computer Communications","author":"Ning Rui","year":"2021","unstructured":"Rui Ning, Jiang Li, Chunsheng Xin, and Hongyi Wu. 2021. Invisible poison: A blackbox clean label backdoor attack to deep neural networks. In IEEE INFOCOM 2021 - Proceedings of the IEEE Conference on Computer Communications. 1\u201310. DOI:10.1109\/INFOCOM42981.2021.9488902"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102492"},{"key":"e_1_3_2_93_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2994112"},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBIOM.2024.3391759"},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBIOM.2024.3391759"},{"key":"e_1_3_2_96_2","doi-asserted-by":"crossref","first-page":"1899","DOI":"10.1145\/3394486.3403241","volume-title":"Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD\u201920)","author":"Pang Ren","year":"2020","unstructured":"Ren Pang, Xinyang Zhang, Shouling Ji, Xiapu Luo, and Ting Wang. 2020. AdvMind: Inferring adversary intent of black-box attacks. In Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD\u201920). ACM, New York, NY, USA, 1899\u20131907. DOI:10.1145\/3394486.3403241"},{"key":"e_1_3_2_97_2","doi-asserted-by":"crossref","first-page":"506","DOI":"10.1145\/3052973.3053009","volume-title":"Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security","author":"Papernot Nicolas","year":"2017","unstructured":"Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. 2017. Practical black-box attacks against machine learning. In Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security. 506\u2013519."},{"key":"e_1_3_2_98_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2938759"},{"key":"e_1_3_2_99_2","first-page":"1060","volume-title":"Proceedings of the 2023 IEEE International Conference on Image Processing (ICIP)","author":"Park Hojin","year":"2023","unstructured":"Hojin Park, Jaewoo Park, Xingbo Dong, and Andrew Beng Jin Teoh. 2023. Towards query efficient and generalizable black-box face reconstruction attack. In Proceedings of the 2023 IEEE International Conference on Image Processing (ICIP). 1060\u20131064. DOI:10.1109\/ICIP49359.2023.10223034"},{"key":"e_1_3_2_100_2","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1007\/978-3-030-13453-2_1","volume-title":"ECML PKDD 2018 Workshops","author":"Paudice Andrea","year":"2019","unstructured":"Andrea Paudice, Luis Mu\u00f1oz-Gonz\u00e1lez, and Emil C. Lupu. 2019. Label sanitization against label flipping poisoning attacks. In ECML PKDD 2018 Workshops. Carlos Alzate, Anna Monreale, Haytham Assem, Albert Bifet, Teodora Sandra Buda, Bora Caglayan, Brett Drury, Eva Garc\u00eda-Mart\u00edn, Ricard Gavald\u00e0, Irena Koprinska, Stefan Kramer, Niklas Lavesson, Michael Madden, Ian Molloy, Maria-Irina Nicolae, and Mathieu Sinn (Eds.), Springer International Publishing, Cham, 5\u201315."},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1145\/3643831"},{"key":"e_1_3_2_102_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3307132"},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.1145\/3687264"},{"key":"e_1_3_2_104_2","first-page":"1","volume-title":"Proceedings of the 2021 IEEE International Joint Conference on Biometrics (IJCB)","author":"Purnapatra Sandip","year":"2021","unstructured":"Sandip Purnapatra, Nic Smalt, Keivan Bahmani, Priyanka Das, David Yambay, Amir Mohammadi, Anjith George, Thirimachos Bourlai, S\u00e9bastien Marcel, Stephanie Schuckers, et\u00a0al. 2021. Face liveness detection competition (livdet-face) - 2021. In Proceedings of the 2021 IEEE International Joint Conference on Biometrics (IJCB). 1\u201310. DOI:10.1109\/IJCB52358.2021.9484359"},{"key":"e_1_3_2_105_2","first-page":"5614","volume-title":"Proceedings of the 31st ACM International Conference on Multimedia (MM\u201923)","author":"Qi Gege","year":"2023","unstructured":"Gege Qi, YueFeng Chen, Xiaofeng Mao, Binyuan Hui, Xiaodan Li, Rong Zhang, and Hui Xue. 2023. Model inversion attack via dynamic memory learning. In Proceedings of the 31st ACM International Conference on Multimedia (MM\u201923). ACM, New York, NY, USA, 5614\u20135622. DOI:10.1145\/3581783.3612072"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.05.005"},{"key":"e_1_3_2_107_2","first-page":"1","volume-title":"Proceedings of the 2019 14th IEEE International Conference on Automatic Face Gesture Recognition (FG 2019)","author":"Qu Xiaofeng","year":"2019","unstructured":"Xiaofeng Qu, Jiwen Dong, and Sijie Niu. 2019. shallowCNN-LE: A shallow CNN with Laplacian embedding for face anti-spoofing. In Proceedings of the 2019 14th IEEE International Conference on Automatic Face Gesture Recognition (FG 2019). 1\u20138. DOI:10.1109\/FG.2019.8756569"},{"key":"e_1_3_2_108_2","doi-asserted-by":"publisher","DOI":"10.1145\/3038924"},{"key":"e_1_3_2_109_2","first-page":"1","volume-title":"Proceedings of the 2024 IEEE 18th International Conference on Automatic Face and Gesture Recognition (FG)","author":"Ramachandra Raghavendra","year":"2024","unstructured":"Raghavendra Ramachandra, Narayan Vetrekar, Sushma Venkatesh, Savita Nageshker, Jag Mohan Singh, and R. S. Gad. 2024. VoxAtnNet: A 3D point clouds convolutional neural network for generalizable face presentation attack detection. In Proceedings of the 2024 IEEE 18th International Conference on Automatic Face and Gesture Recognition (FG). 1\u20139. DOI:10.1109\/FG59268.2024.10582037"},{"key":"e_1_3_2_110_2","first-page":"1","volume-title":"Proceedings of the 2020 8th International Workshop on Biometrics and Forensics (IWBF)","author":"Rathgeb C.","year":"2020","unstructured":"C. Rathgeb, P. Drozdowski, D. Fischer, and C. Busch. 2020. Vulnerability assessment and detection of makeup presentation attacks. In Proceedings of the 2020 8th International Workshop on Biometrics and Forensics (IWBF). 1\u20136. DOI:10.1109\/IWBF49977.2020.9107961"},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jvcir.2019.02.014"},{"key":"e_1_3_2_112_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-024-02153-0"},{"key":"e_1_3_2_113_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3195384"},{"key":"e_1_3_2_114_2","doi-asserted-by":"publisher","DOI":"10.1016\/S0969-4765(21)00023-0"},{"key":"e_1_3_2_115_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3382584"},{"key":"e_1_3_2_116_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-022-13248-6"},{"key":"e_1_3_2_117_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.102769"},{"key":"e_1_3_2_118_2","doi-asserted-by":"crossref","first-page":"6883","DOI":"10.1145\/3503161.3549200","volume-title":"Proceedings of the 30th ACM International Conference on Multimedia (MM\u201922)","author":"Sang Jitao","year":"2022","unstructured":"Jitao Sang, Xian Zhao, Jiaming Zhang, and Zhiyu Lin. 2022. Benign adversarial attack: Tricking models for goodness. In Proceedings of the 30th ACM International Conference on Multimedia (MM\u201922). ACM, New York, NY, USA, 6883\u20136889. DOI:10.1145\/3503161.3549200"},{"key":"e_1_3_2_119_2","first-page":"2959","volume-title":"ICASSP 2022 - Proceedings of the 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Sarkar Eklavya","year":"2022","unstructured":"Eklavya Sarkar, Pavel Korshunov, Laurent Colbois, and S\u00e9bastien Marcel. 2022. Are GAN-based morphs threatening face recognition?. In ICASSP 2022 - Proceedings of the 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). 2959\u20132963. DOI:10.1109\/ICASSP43922.2022.9746477"},{"key":"e_1_3_2_120_2","first-page":"187","volume-title":"Proceedings of the 2018 13th IAPR International Workshop on Document Analysis Systems (DAS)","author":"Scherhag Ulrich","year":"2018","unstructured":"Ulrich Scherhag, Christian Rathgeb, and Christoph Busch. 2018. Towards detection of morphed face images in electronic travel documents. In Proceedings of the 2018 13th IAPR International Workshop on Document Analysis Systems (DAS). 187\u2013192. DOI:10.1109\/DAS.2018.11"},{"key":"e_1_3_2_121_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2899367"},{"key":"e_1_3_2_122_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11760-024-03339-2"},{"key":"e_1_3_2_123_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2799427"},{"key":"e_1_3_2_124_2","first-page":"1852","volume-title":"Proceedings of the 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/ 12th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE)","author":"Shahid Abdur R.","year":"2018","unstructured":"Abdur R. Shahid, Niki Pissinou, S.S. Iyengar, and Kia Makki. 2018. Check-ins and photos: Spatiotemporal correlation-based location inference attack and defense in location-based social networks. In Proceedings of the 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/ 12th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE). 1852\u20131857. DOI:10.1109\/TrustCom\/BigDataSE.2018.00280"},{"key":"e_1_3_2_125_2","first-page":"2435","volume-title":"Proceedings of the 2023 IEEE International Conference on Image Processing (ICIP)","author":"Shahreza Hatef Otroshi","year":"2023","unstructured":"Hatef Otroshi Shahreza and S\u00e9bastien Marcel. 2023. Blackbox face reconstruction from deep facial embeddings using a different face recognition model. In Proceedings of the 2023 IEEE International Conference on Image Processing (ICIP). 2435\u20132439. DOI:10.1109\/ICIP49359.2023.10222312"},{"key":"e_1_3_2_126_2","first-page":"19605","volume-title":"Proceedings of the 2023 IEEE\/CVF International Conference on Computer Vision (ICCV)","author":"Shahreza Hatef Otroshi","year":"2023","unstructured":"Hatef Otroshi Shahreza and S\u00e9bastien Marcel. 2023. Template inversion attack against face recognition systems using 3D face reconstruction. In Proceedings of the 2023 IEEE\/CVF International Conference on Computer Vision (ICCV). 19605\u201319615. DOI:10.1109\/ICCV51070.2023.01801"},{"key":"e_1_3_2_127_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00530-023-01070-5"},{"key":"e_1_3_2_128_2","doi-asserted-by":"publisher","DOI":"10.1145\/3351261"},{"key":"e_1_3_2_129_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBIOM.2023.3324684"},{"key":"e_1_3_2_130_2","first-page":"1","volume-title":"Proceedings of the 2024 IEEE 18th International Conference on Automatic Face and Gesture Recognition (FG)","author":"Singh Jag Mohan","year":"2024","unstructured":"Jag Mohan Singh and Raghavendra Ramachandra. 2024. 3D face morphing attack generation using non-rigid registration. In Proceedings of the 2024 IEEE 18th International Conference on Automatic Face and Gesture Recognition (FG). 1\u20135. DOI:10.1109\/FG59268.2024.10581861"},{"key":"e_1_3_2_131_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-024-09543-y"},{"key":"e_1_3_2_132_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2985453"},{"key":"e_1_3_2_133_2","doi-asserted-by":"crossref","first-page":"512","DOI":"10.1145\/3485447.3512212","volume-title":"Proceedings of the ACM Web Conference 2022 (WWW\u201922)","author":"Tariq Shahroz","year":"2022","unstructured":"Shahroz Tariq, Sowon Jeon, and Simon S. Woo. 2022. Am I a real or fake celebrity? Evaluating face recognition and verification APIs under deepfake impersonation attack. In Proceedings of the ACM Web Conference 2022 (WWW\u201922). ACM, New York, NY, USA, 512\u2013523. DOI:10.1145\/3485447.3512212"},{"key":"e_1_3_2_134_2","first-page":"1471","volume-title":"Proceedings of the 2024 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW)","author":"Tarollo Giuseppe","year":"2024","unstructured":"Giuseppe Tarollo, Tomaso Fontanini, Claudio Ferrari, Guido Borghi, and Andrea Prati. 2024. Adversarial identity injection for semantic face image synthesis. In Proceedings of the 2024 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). 1471\u20131480. DOI:10.1109\/CVPRW63382.2024.00154"},{"key":"e_1_3_2_135_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.imavis.2020.103977"},{"key":"e_1_3_2_136_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3092646"},{"key":"e_1_3_2_137_2","first-page":"16","volume-title":"Information Security","author":"Haar Dustin Terence van der","year":"2019","unstructured":"Dustin Terence van der Haar. 2019. Real-time face antispoofing using shearlets. In Information Security. Hein Venter, Marianne Loock, Marijke Coetzee, Mariki Eloff, and Jan Eloff (Eds.), Springer International Publishing, Cham, 16\u201329."},{"key":"e_1_3_2_138_2","first-page":"986","volume-title":"ICASSP 2020 - Proceedings of the 2020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Vareto Rafael Henrique","year":"2020","unstructured":"Rafael Henrique Vareto, Araceli Marcia Saldanha, and William Robson Schwartz. 2020. The swax benchmark: Attacking biometric systems with wax figures. In ICASSP 2020 - Proceedings of the 2020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). 986\u2013990. DOI:10.1109\/ICASSP40776.2020.9053946"},{"key":"e_1_3_2_139_2","doi-asserted-by":"publisher","unstructured":"Hongjun Wang Guanbin Li Xiaobai Liu and Liang Lin. 2022. A Hamiltonian monte carlo method for probabilistic adversarial attack and learning. IEEE Transactions on Pattern Analysis and Machine Intelligence 44 4 (April 2022) 1725\u20131737. DOI:10.1109\/TPAMI.2020.3032061","DOI":"10.1109\/TPAMI.2020.3032061"},{"key":"e_1_3_2_140_2","doi-asserted-by":"publisher","DOI":"10.1145\/3665496"},{"key":"e_1_3_2_141_2","doi-asserted-by":"publisher","DOI":"10.1145\/3665496"},{"key":"e_1_3_2_142_2","doi-asserted-by":"crossref","first-page":"1376","DOI":"10.1145\/3394171.3413544","volume-title":"Proceedings of the 28th ACM International Conference on Multimedia (MM\u201920)","author":"Wang Run","year":"2020","unstructured":"Run Wang, Felix Juefei-Xu, Qing Guo, Yihao Huang, Xiaofei Xie, Lei Ma, and Yang Liu. 2020. Amora: Black-box adversarial morphing attack. In Proceedings of the 28th ACM International Conference on Multimedia (MM\u201920). ACM, New York, NY, USA, 1376\u20131385. DOI:10.1145\/3394171.3413544"},{"key":"e_1_3_2_143_2","doi-asserted-by":"crossref","first-page":"924","DOI":"10.1109\/CAC51589.2020.9327603","volume-title":"Proceedings of the 2020 Chinese Automation Congress (CAC)","author":"Wang Wanyi","year":"2020","unstructured":"Wanyi Wang, Jian Sun, and Gang Wang. 2020. Visualizing one pixel attack using adversarial maps. In Proceedings of the 2020 Chinese Automation Congress (CAC). 924\u2013929. DOI:10.1109\/CAC51589.2020.9327603"},{"key":"e_1_3_2_144_2","first-page":"2533","article-title":"GAN-generated faces detection: A survey and new perspectives","author":"Wang Xin","year":"2023","unstructured":"Xin Wang, Hui Guo, Shu Hu, Ming-Ching Chang, and Siwei Lyu. 2023. GAN-generated faces detection: A survey and new perspectives. ECAI 2023 (2023), 2533\u20132542.","journal-title":"ECAI 2023"},{"key":"e_1_3_2_145_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3102448"},{"key":"e_1_3_2_146_2","first-page":"355","volume-title":"Proceedings of the 2016 IEEE 29th Computer Security Foundations Symposium (CSF)","author":"Wu Xi","year":"2016","unstructured":"Xi Wu, Matthew Fredrikson, Somesh Jha, and Jeffrey F. Naughton. 2016. A methodology for formalizing model-inversion attacks. In Proceedings of the 2016 IEEE 29th Computer Security Foundations Symposium (CSF). 355\u2013370. DOI:10.1109\/CSF.2016.32"},{"key":"e_1_3_2_147_2","doi-asserted-by":"crossref","first-page":"3502","DOI":"10.1109\/CVPR.2019.00362","volume-title":"Proceedings of the 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Yang Xiao","year":"2019","unstructured":"Xiao Yang, Wenhan Luo, Linchao Bao, Yuan Gao, Dihong Gong, Shibao Zheng, Zhifeng Li, and Wei Liu. 2019. Face anti-spoofing: Model matters, so does data. In Proceedings of the 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 3502\u20133511. DOI:10.1109\/CVPR.2019.00362"},{"key":"e_1_3_2_148_2","first-page":"174","volume-title":"Computer Vision \u2013 ECCV 2020","author":"Yang Xiao","year":"2020","unstructured":"Xiao Yang, Fangyun Wei, Hongyang Zhang, and Jun Zhu. 2020. Design and interpretation of universal adversarial patches in face detection. In Computer Vision \u2013 ECCV 2020. Andrea Vedaldi, Horst Bischof, Thomas Brox, and Jan-Michael Frahm (Eds.), Springer International Publishing, Cham, 174\u2013191."},{"key":"e_1_3_2_149_2","doi-asserted-by":"publisher","unstructured":"Xiao Yang Longlong Xu Tianyu Pang Yinpeng Dong Yikai Wang Hang Su and Jun Zhu. 2024. Face3DAdv: Exploiting robust adversarial 3D patches on physical face recognition. International Journal of Computer Vision (28 Jul 2024). 10.1007\/s11263-024-02177-6","DOI":"10.1007\/s11263-024-02177-6"},{"key":"e_1_3_2_150_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-43567-6_13"},{"key":"e_1_3_2_151_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBIOM.2021.3065526"},{"key":"e_1_3_2_152_2","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2021.3089908"},{"key":"e_1_3_2_153_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3036338"},{"key":"e_1_3_2_154_2","doi-asserted-by":"crossref","first-page":"1423","DOI":"10.1145\/3394171.3413906","volume-title":"Proceedings of the 28th ACM International Conference on Multimedia (MM\u201920)","author":"Zhang Jiaming","year":"2020","unstructured":"Jiaming Zhang, Jitao Sang, Xian Zhao, Xiaowen Huang, Yanfeng Sun, and Yongli Hu. 2020. Adversarial privacy-preserving filter. In Proceedings of the 28th ACM International Conference on Multimedia (MM\u201920). ACM, New York, NY, USA, 1423\u20131431. DOI:10.1145\/3394171.3413906"},{"key":"e_1_3_2_155_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3380848"},{"key":"e_1_3_2_156_2","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2017.2750415"},{"key":"e_1_3_2_157_2","doi-asserted-by":"publisher","unstructured":"Xin Zheng Yanbo Fan Baoyuan Wu Yong Zhang Jue Wang and Shirui Pan. 2023. Robust physical-world attacks on face recognition. Pattern Recognition 133 (2023) 109009. DOI:10.1016\/j.patcog.2022.109009","DOI":"10.1016\/j.patcog.2022.109009"},{"key":"e_1_3_2_158_2","doi-asserted-by":"crossref","first-page":"106","DOI":"10.1145\/3653946.3653962","volume-title":"Proceedings of the 2024 7th International Conference on Machine Vision and Applications (ICMVA\u201924)","author":"Zheng Xuning","year":"2024","unstructured":"Xuning Zheng, Siyu Xia, Ziyiu Yu, and Xiankang Wang. 2024. FAIC-Attack: An adversarial watermarking attack against face age based on identity constraint. In Proceedings of the 2024 7th International Conference on Machine Vision and Applications (ICMVA\u201924). ACM, New York, NY, USA, 106\u2013110. DOI:10.1145\/3653946.3653962"},{"key":"e_1_3_2_159_2","doi-asserted-by":"crossref","first-page":"483","DOI":"10.1007\/978-3-030-41114-5_36","volume-title":"Communications and Networking","author":"Zheng Xiaoyan","year":"2020","unstructured":"Xiaoyan Zheng, Lei Xie, Huifang Chen, and Chao Song. 2020. Performance analysis of consensus-based distributed system under false data injection attacks. In Communications and Networking. Honghao Gao, Zhiyong Feng, Jun Yu, and Jun Wu (Eds.), Springer International Publishing, Cham, 483\u2013497."},{"key":"e_1_3_2_160_2","first-page":"4540","volume-title":"ICASSP 2024 - Proceedings of the 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Zhou Fengfan","year":"2024","unstructured":"Fengfan Zhou, Hefei Ling, Yuxuan Shi, Jiazhong Chen, and Ping Li. 2024. Improving visual quality and transferability of adversarial attacks on face recognition simultaneously with adversarial restoration. In ICASSP 2024 - Proceedings of the 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). 4540\u20134544. DOI:10.1109\/ICASSP48485.2024.10447402"},{"key":"e_1_3_2_161_2","doi-asserted-by":"crossref","first-page":"2487","DOI":"10.1145\/3664647.3681440","volume-title":"Proceedings of the 32nd ACM International Conference on Multimedia (MM\u201924)","author":"Zhou Fengfan","year":"2024","unstructured":"Fengfan Zhou, Qianyu Zhou, Bangjie Yin, Hui Zheng, Xuequan Lu, Lizhuang Ma, and Hefei Ling. 2024. Rethinking impersonation and dodging attacks on face recognition systems. In Proceedings of the 32nd ACM International Conference on Multimedia (MM\u201924). ACM, New York, NY, USA, 2487\u20132496. DOI:10.1145\/3664647.3681440"},{"key":"e_1_3_2_162_2","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2023.3253083"},{"key":"e_1_3_2_163_2","first-page":"225","volume-title":"Proceedings of the 2019 2nd China Symposium on Cognitive Computing and Hybrid Intelligence (CCHI)","author":"Zhou Jie","year":"2019","unstructured":"Jie Zhou, Chenyang Ge, Jiaqi Yang, Huimin Yao, Xin Qiao, and Pengchao Deng. 2019. Research and application of face anti-spoofing based on depth camera. In Proceedings of the 2019 2nd China Symposium on Cognitive Computing and Hybrid Intelligence (CCHI). 225\u2013229. DOI:10.1109\/CCHI.2019.8901932"},{"key":"e_1_3_2_164_2","doi-asserted-by":"crossref","first-page":"4221","DOI":"10.1109\/ICPR48806.2021.9412323","volume-title":"Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR)","author":"Zhou Junwei","year":"2021","unstructured":"Junwei Zhou, Ke Shu, Peng Liu, Jianwen Xiang, and Shengwu Xiong. 2021. Face anti-spoofing based on dynamic color texture analysis using local directional number pattern. In Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR). 4221\u20134228. DOI:10.1109\/ICPR48806.2021.9412323"},{"key":"e_1_3_2_165_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2020.04.109"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3736753","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,3]],"date-time":"2025-09-03T12:49:28Z","timestamp":1756903768000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3736753"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,3]]},"references-count":164,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,1,31]]}},"alternative-id":["10.1145\/3736753"],"URL":"https:\/\/doi.org\/10.1145\/3736753","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,3]]},"assertion":[{"value":"2024-02-17","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-04-27","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-03","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}