{"id":"https://openalex.org/W7131134003","doi":"https://doi.org/10.1109/tifs.2026.3666853","title":"PPOM-Attack: A Substitute Model-Free Perturbation Prediction and Optimization Method for Black-Box Adversarial Attack Against Face Recognition","display_name":"PPOM-Attack: A Substitute Model-Free Perturbation Prediction and Optimization Method for Black-Box Adversarial Attack Against Face Recognition","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7131134003","doi":"https://doi.org/10.1109/tifs.2026.3666853"},"language":null,"primary_location":{"id":"doi:10.1109/tifs.2026.3666853","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2026.3666853","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5126603079","display_name":"Ke Cheng","orcid":null},"institutions":[{"id":"https://openalex.org/I74525822","display_name":"Hubei University of Technology","ror":"https://ror.org/02d3fj342","country_code":"CN","type":"education","lineage":["https://openalex.org/I74525822"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Ke Cheng","raw_affiliation_strings":["School of Computer Science, Hubei University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Hubei University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I74525822"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052576161","display_name":"JiXin Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I74525822","display_name":"Hubei University of Technology","ror":"https://ror.org/02d3fj342","country_code":"CN","type":"education","lineage":["https://openalex.org/I74525822"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jixin Zhang","raw_affiliation_strings":["School of Computer Science, Hubei University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Hubei University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I74525822"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126654909","display_name":"Haiyun Li","orcid":null},"institutions":[{"id":"https://openalex.org/I3131625388","display_name":"University Town of Shenzhen","ror":"https://ror.org/05f5j6225","country_code":"CN","type":"education","lineage":["https://openalex.org/I3131625388"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Haiyun Li","raw_affiliation_strings":["Shenzhen International Graduate School, Tsinghua University, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Shenzhen International Graduate School, Tsinghua University, Shenzhen, China","institution_ids":["https://openalex.org/I3131625388","https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126647605","display_name":"Zipeng Zhong","orcid":null},"institutions":[{"id":"https://openalex.org/I74525822","display_name":"Hubei University of Technology","ror":"https://ror.org/02d3fj342","country_code":"CN","type":"education","lineage":["https://openalex.org/I74525822"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zipeng Zhong","raw_affiliation_strings":["School of Computer Science, Hubei University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Hubei University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I74525822"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5117320500","display_name":"Mingwu ZHANG","orcid":null},"institutions":[{"id":"https://openalex.org/I74525822","display_name":"Hubei University of Technology","ror":"https://ror.org/02d3fj342","country_code":"CN","type":"education","lineage":["https://openalex.org/I74525822"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Mingwu Zhang","raw_affiliation_strings":["School of Computer Science, Hubei University of Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science, Hubei University of Technology, Wuhan, China","institution_ids":["https://openalex.org/I74525822"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5126645799","display_name":"Zheng Qin","orcid":null},"institutions":[{"id":"https://openalex.org/I16609230","display_name":"Hunan University","ror":"https://ror.org/05htk5m33","country_code":"CN","type":"education","lineage":["https://openalex.org/I16609230"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zheng Qin","raw_affiliation_strings":["College of Computer Science and Electronic Engineering, Hunan University, Changsha, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Electronic Engineering, Hunan University, Changsha, China","institution_ids":["https://openalex.org/I16609230"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5126603079"],"corresponding_institution_ids":["https://openalex.org/I74525822"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.6680707,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"21","issue":null,"first_page":"2580","last_page":"2595"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9807000160217285,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9807000160217285,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.002199999988079071,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11105","display_name":"Advanced Image Processing Techniques","score":0.0010000000474974513,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8449000120162964},{"id":"https://openalex.org/keywords/facial-recognition-system","display_name":"Facial recognition system","score":0.6008999943733215},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.590399980545044},{"id":"https://openalex.org/keywords/face","display_name":"Face (sociological concept)","score":0.5530999898910522},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.5455999970436096},{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.45739999413490295},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.4546000063419342},{"id":"https://openalex.org/keywords/perturbation","display_name":"Perturbation (astronomy)","score":0.40389999747276306}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8449000120162964},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8140000104904175},{"id":"https://openalex.org/C31510193","wikidata":"https://www.wikidata.org/wiki/Q1192553","display_name":"Facial recognition system","level":3,"score":0.6008999943733215},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.590399980545044},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5677000284194946},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.5530999898910522},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.5455999970436096},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.45739999413490295},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.4546000063419342},{"id":"https://openalex.org/C177918212","wikidata":"https://www.wikidata.org/wiki/Q803623","display_name":"Perturbation (astronomy)","level":2,"score":0.40389999747276306},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3790000081062317},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.34369999170303345},{"id":"https://openalex.org/C184297639","wikidata":"https://www.wikidata.org/wiki/Q177765","display_name":"Biometrics","level":2,"score":0.3391000032424927},{"id":"https://openalex.org/C137836250","wikidata":"https://www.wikidata.org/wiki/Q984063","display_name":"Optimization problem","level":2,"score":0.337799996137619},{"id":"https://openalex.org/C55020928","wikidata":"https://www.wikidata.org/wiki/Q3813865","display_name":"Image quality","level":3,"score":0.32600000500679016},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3127000033855438},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.3095000088214874},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3012000024318695},{"id":"https://openalex.org/C2778355321","wikidata":"https://www.wikidata.org/wiki/Q17079427","display_name":"Identity (music)","level":2,"score":0.2840000092983246},{"id":"https://openalex.org/C191070858","wikidata":"https://www.wikidata.org/wiki/Q5428343","display_name":"Face Recognition Grand Challenge","level":5,"score":0.2815000116825104},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.2806999981403351},{"id":"https://openalex.org/C75294576","wikidata":"https://www.wikidata.org/wiki/Q5165192","display_name":"Contextual image classification","level":3,"score":0.27160000801086426},{"id":"https://openalex.org/C125245961","wikidata":"https://www.wikidata.org/wiki/Q221656","display_name":"Brightness","level":2,"score":0.2639000117778778},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2508000135421753}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2026.3666853","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2026.3666853","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Climate action","id":"https://metadata.un.org/sdg/13","score":0.40757283568382263}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":37,"referenced_works":["https://openalex.org/W2097117768","https://openalex.org/W2341528187","https://openalex.org/W2520774990","https://openalex.org/W2963839617","https://openalex.org/W2963976704","https://openalex.org/W2969985801","https://openalex.org/W2972986629","https://openalex.org/W2989327462","https://openalex.org/W3015646845","https://openalex.org/W3035693354","https://openalex.org/W3036294592","https://openalex.org/W3087801137","https://openalex.org/W3106050153","https://openalex.org/W3189402954","https://openalex.org/W3193394794","https://openalex.org/W3201579356","https://openalex.org/W4281487639","https://openalex.org/W4290996763","https://openalex.org/W4293846201","https://openalex.org/W4312937923","https://openalex.org/W4386066653","https://openalex.org/W4386076306","https://openalex.org/W4386076336","https://openalex.org/W4386090485","https://openalex.org/W4386299120","https://openalex.org/W4390871781","https://openalex.org/W4390872939","https://openalex.org/W4391326512","https://openalex.org/W4391724743","https://openalex.org/W4391725334","https://openalex.org/W4393078693","https://openalex.org/W4393159397","https://openalex.org/W4396982245","https://openalex.org/W4402263970","https://openalex.org/W4406171890","https://openalex.org/W4413145971","https://openalex.org/W4415798822"],"related_works":[],"abstract_inverted_index":{"Face":[0],"recognition":[1],"(FR)":[2],"brings":[3],"convenience":[4],"to":[5,19,42,55,74,143,173],"peoples":[6],"lives":[7],"while":[8,212],"also":[9],"posing":[10],"security":[11,29],"risks.":[12],"Some":[13],"malicious":[14],"users":[15],"employ":[16],"FR":[17,36,78,198,219],"attacks":[18],"impersonate":[20],"the":[21,28,51,56,63,69,89,93,115,128,145,149,155,178,183],"identity":[22],"of":[23,59,119,204,208],"a":[24,75,95,137,166],"target.":[25],"To":[26,87,131,157],"reveal":[27],"risks,":[30],"recent":[31],"work":[32],"has":[33],"attacked":[34],"black-box":[35,104],"models":[37,41,65],"by":[38,201],"utilizing":[39],"substitute":[40,60,64,96,121],"generate":[43,174],"adversarial":[44,83,105,160,184],"face":[45,84,108,150,161,187],"images":[46],"that":[47,72,176,193],"are":[48],"misclassified":[49],"as":[50],"target":[52,70,116],"individual":[53],"due":[54],"attack":[57,79,129,199,209],"transferability":[58],"models.":[61,220],"However,":[62],"cannot":[66],"accurately":[67],"approximate":[68],"model":[71,117],"leads":[73],"decrease":[76],"in":[77,148,206],"success":[80,210],"rate":[81],"and":[82,100,152,185],"image":[85,151,215],"quality.":[86],"address":[88],"issue,":[90],"we":[91,135,163],"propose":[92,165],"PPOM-Attack,":[94],"model-free":[97],"Perturbation":[98],"Prediction":[99],"Optimization":[101],"Method":[102],"for":[103],"Attack":[106],"against":[107],"recognition.":[109],"PPOM-Attack":[110],"directly":[111],"obtains":[112],"feedback":[113],"from":[114],"instead":[118],"using":[120],"models,":[122],"it":[123],"avoids":[124],"any":[125],"discrepancy":[126],"with":[127],"objective.":[130],"achieve":[132],"this":[133],"goal,":[134],"design":[136],"proximal":[138],"policy":[139],"optimization":[140],"(PPO)-based":[141],"agent":[142],"predict":[144],"perturbation":[146],"regions":[147],"self-adaptively":[153],"disturb":[154],"regions.":[156],"maintain":[158],"high-quality":[159],"images,":[162],"further":[164],"minimum":[167],"brightness":[168],"offsets":[169],"method":[170],"specifically":[171],"designed":[172],"perturbations":[175],"minimize":[177],"feature":[179],"embedding":[180],"difference":[181],"between":[182],"targeted":[186],"images.":[188],"The":[189],"experimental":[190],"results":[191],"show":[192],"our":[194],"approach":[195],"outperforms":[196],"state-of-the-art":[197],"methods":[200],"an":[202],"average":[203],"21.7%":[205],"terms":[207],"rate,":[211],"achieving":[213],"better":[214],"quality":[216],"on":[217],"seven":[218]},"counts_by_year":[],"updated_date":"2026-03-13T14:20:09.374765","created_date":"2026-02-24T00:00:00"}
