{"id":"https://openalex.org/W3207985630","doi":"https://doi.org/10.1109/mapr53640.2021.9585256","title":"Physical Transferable Attack against Black-box Face Recognition Systems","display_name":"Physical Transferable Attack against Black-box Face Recognition Systems","publication_year":2021,"publication_date":"2021-10-01","ids":{"openalex":"https://openalex.org/W3207985630","doi":"https://doi.org/10.1109/mapr53640.2021.9585256","mag":"3207985630"},"language":"en","primary_location":{"id":"doi:10.1109/mapr53640.2021.9585256","is_oa":false,"landing_page_url":"https://doi.org/10.1109/mapr53640.2021.9585256","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Conference on Multimedia Analysis and Pattern Recognition (MAPR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Dang Minh Nguyen","orcid":null},"institutions":[{"id":"https://openalex.org/I47265099","display_name":"Ho Chi Minh City University of Technology","ror":"https://ror.org/04qva2324","country_code":"VN","type":"education","lineage":["https://openalex.org/I123565023","https://openalex.org/I47265099"]}],"countries":["VN"],"is_corresponding":true,"raw_author_name":"Dang Minh Nguyen","raw_affiliation_strings":["Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering"],"affiliations":[{"raw_affiliation_string":"Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering","institution_ids":["https://openalex.org/I47265099"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Anh Tien Nguyen","orcid":null},"institutions":[{"id":"https://openalex.org/I47265099","display_name":"Ho Chi Minh City University of Technology","ror":"https://ror.org/04qva2324","country_code":"VN","type":"education","lineage":["https://openalex.org/I123565023","https://openalex.org/I47265099"]}],"countries":["VN"],"is_corresponding":false,"raw_author_name":"Anh Tien Nguyen","raw_affiliation_strings":["Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering"],"affiliations":[{"raw_affiliation_string":"Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering","institution_ids":["https://openalex.org/I47265099"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043135326","display_name":"Hieu Minh Tran","orcid":"https://orcid.org/0000-0002-5552-2880"},"institutions":[{"id":"https://openalex.org/I47265099","display_name":"Ho Chi Minh City University of Technology","ror":"https://ror.org/04qva2324","country_code":"VN","type":"education","lineage":["https://openalex.org/I123565023","https://openalex.org/I47265099"]}],"countries":["VN"],"is_corresponding":false,"raw_author_name":"Hieu Minh Tran","raw_affiliation_strings":["Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering"],"affiliations":[{"raw_affiliation_string":"Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering","institution_ids":["https://openalex.org/I47265099"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058523505","display_name":"Nhan Trong Le","orcid":"https://orcid.org/0000-0003-4354-1061"},"institutions":[{"id":"https://openalex.org/I47265099","display_name":"Ho Chi Minh City University of Technology","ror":"https://ror.org/04qva2324","country_code":"VN","type":"education","lineage":["https://openalex.org/I123565023","https://openalex.org/I47265099"]}],"countries":["VN"],"is_corresponding":false,"raw_author_name":"Nhan Trong Le","raw_affiliation_strings":["Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering"],"affiliations":[{"raw_affiliation_string":"Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering","institution_ids":["https://openalex.org/I47265099"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5056767671","display_name":"Tho Quan","orcid":"https://orcid.org/0000-0003-0467-6254"},"institutions":[{"id":"https://openalex.org/I47265099","display_name":"Ho Chi Minh City University of Technology","ror":"https://ror.org/04qva2324","country_code":"VN","type":"education","lineage":["https://openalex.org/I123565023","https://openalex.org/I47265099"]}],"countries":["VN"],"is_corresponding":false,"raw_author_name":"Tho Thanh Quan","raw_affiliation_strings":["Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering"],"affiliations":[{"raw_affiliation_string":"Viet Nam National University Ho Chi Minh City, Ho Chi Minh City University of Technology Faculty of Computer Science and Engineering","institution_ids":["https://openalex.org/I47265099"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I47265099"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.15429358,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"80","issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11448","display_name":"Face recognition and analysis","score":0.9793000221252441,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9761000275611877,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8285987377166748},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7708479166030884},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6592498421669006},{"id":"https://openalex.org/keywords/facial-recognition-system","display_name":"Facial recognition system","score":0.6565694808959961},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.6331635117530823},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6322928071022034},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.6240668892860413},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5062138438224792},{"id":"https://openalex.org/keywords/face","display_name":"Face (sociological concept)","score":0.4996907711029053},{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.4828779995441437},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.45006078481674194},{"id":"https://openalex.org/keywords/transfer-of-learning","display_name":"Transfer of learning","score":0.4439704716205597},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3675021529197693},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.22016572952270508}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8285987377166748},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7708479166030884},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6592498421669006},{"id":"https://openalex.org/C31510193","wikidata":"https://www.wikidata.org/wiki/Q1192553","display_name":"Facial recognition system","level":3,"score":0.6565694808959961},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.6331635117530823},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6322928071022034},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.6240668892860413},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5062138438224792},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.4996907711029053},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.4828779995441437},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.45006078481674194},{"id":"https://openalex.org/C150899416","wikidata":"https://www.wikidata.org/wiki/Q1820378","display_name":"Transfer of learning","level":2,"score":0.4439704716205597},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3675021529197693},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.22016572952270508},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C36289849","wikidata":"https://www.wikidata.org/wiki/Q34749","display_name":"Social science","level":1,"score":0.0},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/mapr53640.2021.9585256","is_oa":false,"landing_page_url":"https://doi.org/10.1109/mapr53640.2021.9585256","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Conference on Multimedia Analysis and Pattern Recognition (MAPR)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.8199999928474426,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":78,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1945616565","https://openalex.org/W1998808035","https://openalex.org/W2145287260","https://openalex.org/W2194775991","https://openalex.org/W2341528187","https://openalex.org/W2460937040","https://openalex.org/W2515770085","https://openalex.org/W2535873859","https://openalex.org/W2609476118","https://openalex.org/W2736899637","https://openalex.org/W2777449390","https://openalex.org/W2784163702","https://openalex.org/W2798952550","https://openalex.org/W2799032899","https://openalex.org/W2890577321","https://openalex.org/W2905311601","https://openalex.org/W2915002466","https://openalex.org/W2930003153","https://openalex.org/W2942526501","https://openalex.org/W2946948417","https://openalex.org/W2949007385","https://openalex.org/W2949650786","https://openalex.org/W2950782995","https://openalex.org/W2955425717","https://openalex.org/W2962972504","https://openalex.org/W2963178695","https://openalex.org/W2963207607","https://openalex.org/W2963420686","https://openalex.org/W2963495494","https://openalex.org/W2963542245","https://openalex.org/W2963557656","https://openalex.org/W2963814162","https://openalex.org/W2963976704","https://openalex.org/W2964153729","https://openalex.org/W2969664989","https://openalex.org/W2969825080","https://openalex.org/W2969985801","https://openalex.org/W2970115835","https://openalex.org/W2972986629","https://openalex.org/W2982648698","https://openalex.org/W2990633046","https://openalex.org/W2998469040","https://openalex.org/W3006076803","https://openalex.org/W3006406099","https://openalex.org/W3008625353","https://openalex.org/W3014641072","https://openalex.org/W3016719260","https://openalex.org/W3033943140","https://openalex.org/W3034303554","https://openalex.org/W3035414587","https://openalex.org/W3035693354","https://openalex.org/W3101998545","https://openalex.org/W3103152812","https://openalex.org/W3108326355","https://openalex.org/W3120119962","https://openalex.org/W3134999934","https://openalex.org/W3163704324","https://openalex.org/W3169129566","https://openalex.org/W3205621936","https://openalex.org/W4288359148","https://openalex.org/W4297665946","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6687483927","https://openalex.org/W6719080892","https://openalex.org/W6741036071","https://openalex.org/W6747385936","https://openalex.org/W6750707585","https://openalex.org/W6759580348","https://openalex.org/W6761839128","https://openalex.org/W6762718338","https://openalex.org/W6767341848","https://openalex.org/W6770761745","https://openalex.org/W6773713311","https://openalex.org/W6775845032","https://openalex.org/W6779419843","https://openalex.org/W6795502672"],"related_works":["https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W4383221314","https://openalex.org/W3093978547","https://openalex.org/W2953536436","https://openalex.org/W3203790781","https://openalex.org/W4313346231","https://openalex.org/W2738001131","https://openalex.org/W4285785480","https://openalex.org/W2997056298"],"abstract_inverted_index":{"Recent":[0],"studies":[1,156],"have":[2,59],"shown":[3],"that":[4,114,150],"machine":[5],"learning":[6,34],"models":[7,132],"in":[8,16,24,71,117],"general":[9],"and":[10,66,136],"deep":[11,33,110,166],"neural":[12],"networks":[13,35],"like":[14],"CNN,":[15],"particular,":[17],"are":[18],"vulnerable":[19],"to":[20,43,93],"adversarial":[21,41,159],"attacks.":[22],"Specifically,":[23],"terms":[25],"of":[26,49,165],"face":[27,111,167],"recognition,":[28],"one":[29],"can":[30,115,153],"easily":[31],"deceive":[32],"by":[36],"adding":[37],"a":[38,78,82,103],"visually":[39],"imperceptible":[40],"perturbation":[42],"the":[44,53,57,63,67,72,94,124,145],"input":[45],"images.":[46],"However,":[47],"most":[48],"these":[50,84],"works":[51],"assume":[52],"ideal":[54],"scenario":[55],"where":[56],"attackers":[58],"perfect":[60],"information":[61],"about":[62,123],"victim":[64,125],"model":[65],"attack":[68,107,141],"is":[69,76],"performed":[70],"digital":[73],"domain,":[74],"which":[75],"not":[77],"realistic":[79],"assumption.":[80],"As":[81],"result,":[83],"methods":[85],"often":[86],"poorly":[87],"(or":[88],"even":[89],"impossible":[90],"to)":[91],"transfer":[92],"real":[95],"world.":[96],"To":[97],"address":[98],"this":[99],"issue,":[100],"we":[101,148],"propose":[102],"novel":[104],"physical":[105],"transferable":[106],"method":[108,152],"on":[109,129,157],"recognition":[112,168],"systems":[113],"work":[116],"real-world":[118],"settings":[119],"without":[120],"any":[121],"knowledge":[122],"model.":[126],"Our":[127],"experiments":[128],"various":[130,134],"state-of-the-art":[131],"with":[133],"architectures":[135],"training":[137],"losses":[138],"show":[139],"non-trivial":[140],"success":[142],"rates.":[143],"With":[144],"observed":[146],"results,":[147],"believe":[149],"our":[151],"enable":[154],"further":[155],"improving":[158],"robustness":[160],"as":[161,163],"well":[162],"security":[164],"systems.":[169]},"counts_by_year":[],"updated_date":"2026-04-23T09:07:50.710637","created_date":"2025-10-10T00:00:00"}
