{"id":"https://openalex.org/W3090028603","doi":"https://doi.org/10.1109/icip40778.2020.9190678","title":"Security of Facial Forensics Models Against Adversarial Attacks","display_name":"Security of Facial Forensics Models Against Adversarial Attacks","publication_year":2020,"publication_date":"2020-09-30","ids":{"openalex":"https://openalex.org/W3090028603","doi":"https://doi.org/10.1109/icip40778.2020.9190678","mag":"3090028603"},"language":"en","primary_location":{"id":"doi:10.1109/icip40778.2020.9190678","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icip40778.2020.9190678","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE International Conference on Image Processing (ICIP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102978699","display_name":"Rong Huang","orcid":"https://orcid.org/0009-0000-2759-9197"},"institutions":[{"id":"https://openalex.org/I181326427","display_name":"Donghua University","ror":"https://ror.org/035psfh38","country_code":"CN","type":"education","lineage":["https://openalex.org/I181326427"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Rong Huang","raw_affiliation_strings":["College of Information Science and Technology, Donghua University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"College of Information Science and Technology, Donghua University, Shanghai, China","institution_ids":["https://openalex.org/I181326427"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012466506","display_name":"Fuming Fang","orcid":"https://orcid.org/0000-0002-9332-3735"},"institutions":[{"id":"https://openalex.org/I184597095","display_name":"National Institute of Informatics","ror":"https://ror.org/04ksd4g47","country_code":"JP","type":"facility","lineage":["https://openalex.org/I1319490839","https://openalex.org/I184597095","https://openalex.org/I4210158934"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Fuming Fang","raw_affiliation_strings":["National Institute of Informatics, Tokyo, Japan"],"affiliations":[{"raw_affiliation_string":"National Institute of Informatics, Tokyo, Japan","institution_ids":["https://openalex.org/I184597095"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101654553","display_name":"Huy H. Nguyen","orcid":"https://orcid.org/0000-0002-2000-7977"},"institutions":[{"id":"https://openalex.org/I200475212","display_name":"The Graduate University for Advanced Studies, SOKENDAI","ror":"https://ror.org/0516ah480","country_code":"JP","type":"education","lineage":["https://openalex.org/I200475212"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Huy H. Nguyen","raw_affiliation_strings":["SOKENDAI (The Graduate University for Advanced Studies), Kanagawa, Japan"],"affiliations":[{"raw_affiliation_string":"SOKENDAI (The Graduate University for Advanced Studies), Kanagawa, Japan","institution_ids":["https://openalex.org/I200475212"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5007639385","display_name":"Junichi Yamagishi","orcid":"https://orcid.org/0000-0003-2752-3955"},"institutions":[{"id":"https://openalex.org/I184597095","display_name":"National Institute of Informatics","ror":"https://ror.org/04ksd4g47","country_code":"JP","type":"facility","lineage":["https://openalex.org/I1319490839","https://openalex.org/I184597095","https://openalex.org/I4210158934"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Junichi Yamagishi","raw_affiliation_strings":["National Institute of Informatics, Tokyo, Japan"],"affiliations":[{"raw_affiliation_string":"National Institute of Informatics, Tokyo, Japan","institution_ids":["https://openalex.org/I184597095"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5044556342","display_name":"Isao Echizen","orcid":"https://orcid.org/0000-0003-4908-1860"},"institutions":[{"id":"https://openalex.org/I184597095","display_name":"National Institute of Informatics","ror":"https://ror.org/04ksd4g47","country_code":"JP","type":"facility","lineage":["https://openalex.org/I1319490839","https://openalex.org/I184597095","https://openalex.org/I4210158934"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Isao Echizen","raw_affiliation_strings":["National Institute of Informatics, Tokyo, Japan"],"affiliations":[{"raw_affiliation_string":"National Institute of Informatics, Tokyo, Japan","institution_ids":["https://openalex.org/I184597095"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5102978699"],"corresponding_institution_ids":["https://openalex.org/I181326427"],"apc_list":null,"apc_paid":null,"fwci":1.0605,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.82309305,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"2236","last_page":"2240"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.9760000109672546,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8291575908660889},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7877563238143921},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6532085537910461},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.55936199426651},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4981269836425781},{"id":"https://openalex.org/keywords/segmentation","display_name":"Segmentation","score":0.4946593940258026},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.4920799136161804},{"id":"https://openalex.org/keywords/digital-forensics","display_name":"Digital forensics","score":0.4880124628543854},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4331928789615631},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.39477410912513733},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2831822633743286}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8291575908660889},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7877563238143921},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6532085537910461},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.55936199426651},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4981269836425781},{"id":"https://openalex.org/C89600930","wikidata":"https://www.wikidata.org/wiki/Q1423946","display_name":"Segmentation","level":2,"score":0.4946593940258026},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.4920799136161804},{"id":"https://openalex.org/C84418412","wikidata":"https://www.wikidata.org/wiki/Q3246940","display_name":"Digital forensics","level":2,"score":0.4880124628543854},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4331928789615631},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.39477410912513733},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2831822633743286},{"id":"https://openalex.org/C140331021","wikidata":"https://www.wikidata.org/wiki/Q1868104","display_name":"Logit","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icip40778.2020.9190678","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icip40778.2020.9190678","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE International Conference on Image Processing (ICIP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.6800000071525574,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":35,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W2003092530","https://openalex.org/W2243397390","https://openalex.org/W2460937040","https://openalex.org/W2535873859","https://openalex.org/W2543927648","https://openalex.org/W2604505099","https://openalex.org/W2744095836","https://openalex.org/W2806757392","https://openalex.org/W2808763756","https://openalex.org/W2888519208","https://openalex.org/W2891145043","https://openalex.org/W2898877033","https://openalex.org/W2902304528","https://openalex.org/W2903369540","https://openalex.org/W2962700793","https://openalex.org/W2963118571","https://openalex.org/W2963178695","https://openalex.org/W2963207607","https://openalex.org/W2963542245","https://openalex.org/W2963684180","https://openalex.org/W2963969878","https://openalex.org/W2964153729","https://openalex.org/W2964171870","https://openalex.org/W2979980060","https://openalex.org/W2982058372","https://openalex.org/W3083246145","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6719080892","https://openalex.org/W6742823662","https://openalex.org/W6751846511","https://openalex.org/W6756046522","https://openalex.org/W6756925667"],"related_works":["https://openalex.org/W4288055406","https://openalex.org/W4200630034","https://openalex.org/W3137894200","https://openalex.org/W3092178728","https://openalex.org/W4226402597","https://openalex.org/W3132910851","https://openalex.org/W4377864639","https://openalex.org/W4392340763","https://openalex.org/W4283325551","https://openalex.org/W2997056298"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2],"(DNNs)":[3],"have":[4],"been":[5],"used":[6,62,72],"in":[7],"digital":[8],"forensics":[9,20],"to":[10,23,53,63,73,98],"identify":[11],"fake":[12],"facial":[13],"images.":[14],"We":[15,32,89],"investigated":[16],"several":[17],"DNN-based":[18],"forgery":[19],"models":[21],"(FFMs)":[22],"examine":[24],"whether":[25],"they":[26],"are":[27,82,138],"secure":[28],"against":[29],"adversarial":[30,39,44,131,149],"attacks.":[31],"experimentally":[33],"demonstrated":[34,111],"the":[35,85,112,130,135,148],"existence":[36],"of":[37,67,87,114,129,151],"individual":[38],"perturbations":[40,45],"(IAPs)":[41],"and":[42,76,119],"universal":[43],"(UAPs)":[46],"that":[47,69,95,134],"can":[48,70],"lead":[49],"a":[50,91,144],"well-performed":[51],"FFM":[52],"misbehave.":[54],"Based":[55],"on":[56,84],"iterative":[57],"procedure,":[58],"gradient":[59],"information":[60],"is":[61],"generate":[64],"two":[65],"kinds":[66],"IAPs":[68],"be":[71],"fabricate":[74],"classification":[75],"segmentation":[77],"outputs.":[78],"In":[79],"contrast,":[80],"UAPs":[81,115,137],"generated":[83],"basis":[86],"over-firing.":[88],"designed":[90],"new":[92],"objective":[93],"function":[94],"encourages":[96],"neurons":[97],"over-fire,":[99],"which":[100],"makes":[101],"UAP":[102],"generation":[103],"feasible":[104],"even":[105],"without":[106],"using":[107],"training":[108],"data.":[109],"Experiments":[110],"transferability":[113],"across":[116],"unseen":[117,120],"datasets":[118],"FFMs.":[121,152],"Moreover,":[122],"we":[123],"conducted":[124],"subjective":[125],"assessment":[126],"for":[127,146],"imperceptibility":[128],"perturbations,":[132],"revealing":[133],"crafted":[136],"visually":[139],"negligible.":[140],"These":[141],"findings":[142],"provide":[143],"baseline":[145],"evaluating":[147],"security":[150]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":4},{"year":2021,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
