{"id":"https://openalex.org/W4406089737","doi":"https://doi.org/10.1109/tpami.2025.3526188","title":"Distributionally Location-Aware Transferable Adversarial Patches for Facial Images","display_name":"Distributionally Location-Aware Transferable Adversarial Patches for Facial Images","publication_year":2025,"publication_date":"2025-01-06","ids":{"openalex":"https://openalex.org/W4406089737","doi":"https://doi.org/10.1109/tpami.2025.3526188","pmid":"https://pubmed.ncbi.nlm.nih.gov/40030879"},"language":"en","primary_location":{"id":"doi:10.1109/tpami.2025.3526188","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2025.3526188","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5079657274","display_name":"Xingxing Wei","orcid":"https://orcid.org/0000-0002-0778-8377"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xingxing Wei","raw_affiliation_strings":["Institute of Artificial Intelligence, Beihang University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Artificial Intelligence, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048633696","display_name":"Shouwei Ruan","orcid":"https://orcid.org/0009-0007-0481-5855"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shouwei Ruan","raw_affiliation_strings":["Institute of Artificial Intelligence, Beihang University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Artificial Intelligence, Beihang University, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068755794","display_name":"Yinpeng Dong","orcid":"https://orcid.org/0000-0003-1299-683X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yinpeng Dong","raw_affiliation_strings":["Department of Computer Science and Technology, Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Tsinghua University, Beijing, China","Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Department of Computer Science and Technology, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]},{"raw_affiliation_string":"Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Department of Computer Science and Technology, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100341885","display_name":"Hang Su","orcid":"https://orcid.org/0000-0001-8294-6315"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hang Su","raw_affiliation_strings":["Department of Computer Science and Technology, Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Tsinghua University, Beijing, China","Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Department of Computer Science and Technology, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]},{"raw_affiliation_string":"Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Department of Computer Science and Technology, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5068837264","display_name":"Xiaochun Cao","orcid":"https://orcid.org/0000-0001-7141-708X"},"institutions":[{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaochun Cao","raw_affiliation_strings":["School of Cyber Science and Technology, Shenzhen Campus of Sun Yat-Sen University, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, Shenzhen Campus of Sun Yat-Sen University, Shenzhen, China","institution_ids":["https://openalex.org/I157773358"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5079657274"],"corresponding_institution_ids":["https://openalex.org/I82880672"],"apc_list":null,"apc_paid":null,"fwci":4.7137,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.93437265,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":96},"biblio":{"volume":"47","issue":"4","first_page":"2849","last_page":"2864"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.920199990272522,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}},{"id":"https://openalex.org/T12055","display_name":"Boron Compounds in Chemistry","score":0.901199996471405,"subfield":{"id":"https://openalex.org/subfields/2741","display_name":"Radiology, Nuclear Medicine and Imaging"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7592939138412476},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7430249452590942},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6580008268356323},{"id":"https://openalex.org/keywords/face","display_name":"Face (sociological concept)","score":0.5972225069999695},{"id":"https://openalex.org/keywords/generalization","display_name":"Generalization","score":0.5468409657478333},{"id":"https://openalex.org/keywords/facial-recognition-system","display_name":"Facial recognition system","score":0.5177492499351501},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.503485381603241},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.4621008634567261},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.4516080319881439},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.44475364685058594},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4163750410079956},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.399158239364624},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.15069258213043213}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7592939138412476},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7430249452590942},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6580008268356323},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.5972225069999695},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.5468409657478333},{"id":"https://openalex.org/C31510193","wikidata":"https://www.wikidata.org/wiki/Q1192553","display_name":"Facial recognition system","level":3,"score":0.5177492499351501},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.503485381603241},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.4621008634567261},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.4516080319881439},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.44475364685058594},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4163750410079956},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.399158239364624},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.15069258213043213},{"id":"https://openalex.org/C36289849","wikidata":"https://www.wikidata.org/wiki/Q34749","display_name":"Social science","level":1,"score":0.0},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tpami.2025.3526188","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2025.3526188","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},{"id":"pmid:40030879","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/40030879","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on pattern analysis and machine intelligence","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G4841518984","display_name":null,"funder_award_id":"L247011","funder_id":"https://openalex.org/F4320322919","funder_display_name":"Natural Science Foundation of Beijing Municipality"}],"funders":[{"id":"https://openalex.org/F4320322919","display_name":"Natural Science Foundation of Beijing Municipality","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":50,"referenced_works":["https://openalex.org/W1998808035","https://openalex.org/W2096733369","https://openalex.org/W2145287260","https://openalex.org/W2194775991","https://openalex.org/W2341528187","https://openalex.org/W2774644650","https://openalex.org/W2793350103","https://openalex.org/W2902867332","https://openalex.org/W2905423756","https://openalex.org/W2932026309","https://openalex.org/W2945282335","https://openalex.org/W2962793481","https://openalex.org/W2962898354","https://openalex.org/W2963302614","https://openalex.org/W2963466847","https://openalex.org/W2963542245","https://openalex.org/W2963857521","https://openalex.org/W2963976704","https://openalex.org/W2969664989","https://openalex.org/W2969985801","https://openalex.org/W3036294592","https://openalex.org/W3046768359","https://openalex.org/W3090358134","https://openalex.org/W3107235539","https://openalex.org/W3108072218","https://openalex.org/W3113540817","https://openalex.org/W3119652083","https://openalex.org/W3128390792","https://openalex.org/W3157070795","https://openalex.org/W3189586864","https://openalex.org/W4226232092","https://openalex.org/W4282936640","https://openalex.org/W4312918928","https://openalex.org/W4327652423","https://openalex.org/W4386076048","https://openalex.org/W6618372016","https://openalex.org/W6637162671","https://openalex.org/W6638046521","https://openalex.org/W6640425456","https://openalex.org/W6678911119","https://openalex.org/W6739868092","https://openalex.org/W6741036071","https://openalex.org/W6747706139","https://openalex.org/W6751839145","https://openalex.org/W6765410593","https://openalex.org/W6772291365","https://openalex.org/W6773304887","https://openalex.org/W6793874848","https://openalex.org/W6797731976","https://openalex.org/W6803748346"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W3009622996","https://openalex.org/W2384651879"],"abstract_inverted_index":{"Adversarial":[0,112],"patch":[1],"is":[2,38,49,60],"one":[3],"of":[4,8,22,79,195],"the":[5,13,18,31,35,41,53,58,64,76,88,119,128,157,171,193],"important":[6],"forms":[7],"performing":[9],"adversarial":[10,24,80,196],"attacks":[11,86],"in":[12,122],"physical":[14],"world.":[15],"To":[16],"improve":[17],"naturalness":[19],"and":[20,143,166,179,187],"aggressiveness":[21],"existing":[23],"patches,":[25],"location-aware":[26],"patches":[27,59],"are":[28,92],"proposed,":[29],"where":[30],"patch's":[32,81],"location":[33,55],"on":[34,101,160],"target":[36],"object":[37],"integrated":[39],"into":[40,192],"optimization":[42],"process":[43],"to":[44,83,115,148,175,189],"perform":[45],"attacks.":[46],"Although":[47],"it":[48],"effective,":[50],"efficiently":[51,116],"finding":[52],"optimal":[54],"for":[56,87,118],"placing":[57],"challenging,":[61],"especially":[62],"under":[63],"black-box":[65,136],"attack":[66,137,149],"settings.":[67],"In":[68],"this":[69,102],"paper,":[70],"we":[71,104,131],"first":[72],"empirically":[73],"find":[74],"that":[75],"aggregation":[77,120],"regions":[78,121],"locations":[82],"show":[84],"effective":[85],"same":[89],"facial":[90],"image":[91,167],"pretty":[93],"similar":[94],"across":[95],"different":[96],"face":[97,151,163],"recognition":[98,152,164,168],"models.":[99,153],"Based":[100],"observation,":[103],"then":[105],"propose":[106],"a":[107,123],"novel":[108],"framework":[109],"called":[110],"Distribution-Optimized":[111],"Patch":[113],"(DOPatch)":[114],"search":[117],"distribution":[124,129,194],"modeling":[125],"way.":[126],"Using":[127],"prior,":[130],"further":[132],"design":[133],"two":[134],"query-based":[135],"methods:":[138],"Location":[139],"Optimization":[140],"Attack":[141,146],"(DOP-LOA)":[142],"Distribution":[144],"Transfer":[145],"(DOP-DTA)":[147],"unseen":[150],"We":[154,181],"finally":[155],"evaluate":[156],"proposed":[158],"methods":[159],"various":[161],"SOTA":[162],"models":[165,169],"(including":[170],"popular":[172],"big":[173],"models)":[174],"demonstrate":[176],"our":[177],"effectiveness":[178],"generalization.":[180],"also":[182],"conduct":[183],"extensive":[184],"ablation":[185],"studies":[186],"analyses":[188],"provide":[190],"insights":[191],"locations.":[197]},"counts_by_year":[{"year":2025,"cited_by_count":2}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-10-10T00:00:00"}
