Pith. sign in

REVIEW 4 major objections 4 minor 278 references

A gradient mask and band-aid can hide faces from visible and thermal cameras at once.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-07-31 23:49 UTC pith:WYQMSQO4

load-bearing objection Genuinely new joint visual+thermal patch attack, but the headline claim overreaches: no fused detector is ever tested, so the >90% ASR proves simultaneous single-modality failures, not defeat of a fusion system. the 4 major comments →

arxiv 2607.23292 v1 pith:WYQMSQO4 submitted 2026-07-25 cs.CR cs.CV

Hiding in Plain Sight: An Effective Physical Adversarial Patch Attack against Visual-Infrared Fused Face Detection

classification cs.CR cs.CV
keywords adversarial patchphysical attackvisual-infrared fusionface detectionthermal infraredblack-box attackstealthinessdifferential evolution
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

VIPatch is a physical adversarial patch attack aimed at systems that fuse visible-light and thermal-infrared face detection. It uses two everyday-looking accessories—a gradient-color mask and a band-aid sticker—and optimizes both elements jointly across the two image modalities. The paper reports over 90% attack success in digital simulations and in physical tests across distances, angles, and lighting levels, while the patches stay visually unobtrusive. The authors argue this reveals a practical vulnerability in real-world visual-infrared fused face detection systems.

Core claim

The paper's central claim is that a single physical accessory set—a printed gradient-color mask worn together with a band-aid—can make a person undetectable to visual-infrared fused face detectors. VIPatch optimizes the mask's gradient color combination and the band-aid's position and angle, all under a color-harmonization constraint so the mask blends into the face, with the band-aid restricted to areas away from the eyes. In the infrared image the mask is modeled as a cold block, simulating the thermal insulation of a real mask. After optimization, the digital patches are printed and placed on the face. Across nine visible-light and seven infrared face detectors, the paper reports average

What carries the argument

The load-bearing mechanism is the joint optimization of two physical accessories: a face mask whose colors form a vertical gradient, and a band-aid sticker. Mask colors are chosen by Differential Evolution under a harmonic-template color constraint and applied row-by-row with a gradient formula; the band-aid's location and angle are optimized in the same search. Expectation over Transformation injects realistic noise, brightness, and placement perturbations during optimization, and a 3D face model renders the mask and sticker onto facial images with plausible geometry. These components bridge the digital-to-physical gap, which is why the optimized patterns survive being printed and worn.

Load-bearing premise

The paper never tests a system that truly fuses the two camera types; it attacks each camera's detector separately and assumes that failing both separately fails the fused system, and it does not report keeping the people it tests separate from the ones used to optimize the patches.

What would settle it

Run VIPatch's optimized patches against a deployed fused detector that actually combines the two modalities—for example, by requiring detections from both cameras to overlap, or by averaging their confidence—and test on held-out subjects not used in the optimization. If the fusion layer can still detect the face from either modality alone or uses cross-modal spatial consistency, the reported >90% attack success should drop sharply.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • Thermal screening and surveillance systems relying on fused visible-infrared face detection could be evaded by ordinary-looking accessories, with no special equipment needed.
  • The attack transfers across multiple off-the-shelf face detectors despite black-box query-only access, indicating the vulnerability is not model-specific.
  • Jointly attacking both modalities is essential: optimizing on one modality alone drops success to roughly 61–79%, so defenses must be designed against cross-modal attacks, not per-modality patches.
  • Physical factors such as distance, angle, and lighting that cripple earlier patch attacks have limited effect here, making physical adversarial patches practical outside tightly controlled camera positions.
  • The combination of mask and band-aid is stronger than either alone, suggesting that redundant, mutually supporting physical elements can raise attack reliability.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • Because the paper optimizes each modality's detector separately and never tests a true fusion layer, the strongest unverified implication is that fusion architectures with cross-modal consistency checks would still fall; testing VIPatch against score-level or feature-level fusion models would settle this.
  • The infrared attack's high physical success may owe as much to the cold gel's thermal insulation as to the learned sticker pattern; a controlled ablation that swaps the gel for a non-thermal placeholder would identify which factor matters.
  • The color-harmonization constraint offers a general recipe for stealthy physical patches: restrict adversarial changes to the subspace of natural appearance, which may generalize to other face or person attacks.
  • Since no held-out identity or image split is reported, the practical claim needs replication on subjects and poses never touched by the Differential Evolution search to rule out overfitting to the evaluation set.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. The paper presents VIPatch, a physical adversarial patch attack intended to defeat visual-infrared fused face detection. The patch combines a gradient-color face mask and a band-aid sticker; the mask colors and sticker pose are optimized with differential evolution using only the detector confidence as a black-box signal, under expectation-over-transformation and color-harmonization constraints. The authors report digital attack success rates above 90% for several visible-light and infrared face detectors, and physical ASRs in the same range. An ablation shows that optimizing the two modalities jointly and combining mask plus band-aid improves ASR. The central claim, however, is that one physical accessory defeats visual-infrared fused detection; the evaluation does not include any actual fused detector and does not document a held-out split.

Significance. If confirmed, this is a potentially important security contribution: a natural-looking mask and band-aid would bypass the combined visual/thermal face detectors used in access and temperature-screening systems. Strengths of the paper include its joint visual-infrared patch formulation, the use of physical constraints and EOT, the physical fabrication with a real thermal camera, and the clear ablation evidence that joint optimization matters. The paper is less convincing on its headline claim because no fusion architecture is ever exercised, and no train/test separation is reported. The contribution is publishable in principle, but the evaluation needs substantial additional work before the claimed threat against fused face detection can be accepted.

major comments (4)
  1. [Threat Model, Eq. (1)] Eq. (1) is the core optimization, but it contains no fusion function: it is two independent arg mins over sigma_v and sigma_i with per-modality detectors f_v and f_i. Tables 2 and 3 likewise report visible-only and infrared-only ASRs; Tables 5 and 6 use "Fused" to mean jointly optimized patches evaluated on one modality, not an actual fusion model. The paper therefore does not demonstrate that VIPatch defeats a visual-infrared fused detector. A fusion system using OR/max-score fusion, cross-modal consistency, or a single modality that still detects would invalidate the physical-world claim. Please either implement and attack true early/score/decision fusion models, or reframe the claims to per-modality detectors.
  2. [Experiment Setup / Evaluation Split] The evaluation never states whether the SPEAKINGFACES images used during DE optimization are disjoint from the images used to compute ASR. Without a subject-disjoint split, the reported >90% ASR could be partly an artifact of optimizing and testing on the same data. Please report the split, the number of queries consumed per run, and ASR variability (e.g., over subjects or bootstraps).
  3. [Physical Domain Attack] Fig. 6 reports physical ASR for visual detectors only, and Table 4 reports physical ASR for infrared detectors only. There is no physical experiment in which visible and infrared streams are captured simultaneously and evaluated by a fused detector. Thus the conclusion that "VIPatch reliably bypasses the target models in the physical world" is not supported for the fused system that is the paper's stated target.
  4. [Ablation Study, Tables 5-6] The ablation text states that "jointly optimizing over the visual-infrared fused detectors raises the ASR." Given Eq. (1), these experiments optimize over two separate detectors, not a fused one. The term "fused" is misleading and propagates the unsupported central claim. Rename the columns to "joint two-modality optimization" and treat the absence of a test-time fusion rule as a limitation.
minor comments (4)
  1. [Eq. (4)] The crossover equation and its surrounding text disagree: the prose says the mutation vector replaces the original when rand > gamma_c, while Eq. (4) appears to assign the parent vector in that case. Please align equation and text.
  2. [Physical Domain Attack, Fig. 6] Physical ASRs are quoted to two decimals without confidence intervals, number of subjects, or per-trial variability. A 600-frame video can produce a point estimate, but not the precision claimed. Please report trial counts and variance.
  3. [Abstract / Stealthiness] The paper claims the patches are "unobtrusive to human observers," but no human perceptual study or quantitative stealth metric (e.g., user study, detection-rate test) is reported. Please either add such an evaluation or soften the claim to "visually harmonized by design."
  4. [Throughout] Notation and reference hygiene should be cleaned: e.g., "Mogface" vs "MogFace," "d link" as an author name, duplicated URLs, and the unexpanded table color legend.

Circularity Check

0 steps flagged

No construction-level circularity; the fused-detector concern is an external-validity gap, not a circular derivation.

full rationale

I walked the optimization and evaluation chain. The attack objective Eq. (1) is two independent per-modality arg mins over sigma_v and sigma_i; no fusion function appears, and Tables 2-6 report per-modality ASRs. The 'Fused' columns in Tables 5-6 correspond to the jointly optimized patch evaluated on a single-modality detector, not to a defined fused detector. That is a mismatch between the title/abstract claim and the measurement, i.e., an external-validity/transferability gap, not a circular reduction: the reported ASR is not constructed from the same quantity it is claimed to predict. The DE color optimization uses the detector probability as fitness, and the paper does not state whether the SPEAKINGFACES images used for scoring are disjoint from those used for optimization; if they overlap, digital ASR would partly measure fit. However, I cannot exhibit a quote establishing that overlap, and the physical experiments (participants, printed patches, real cameras) provide an external anchor. No load-bearing self-citation: prior works by the authors are cited as related work or component implementations (FMA-3D, adv-sticker, 3DMM), not as justification for the central effectiveness claim. Therefore, under the hard rule that circularity must be exhibited by quote and specific reduction, I find no significant circularity.

Axiom & Free-Parameter Ledger

6 free parameters · 5 axioms · 0 invented entities

The central claim is empirical, not derived: the numerical inputs are DE hyperparameters, the optimized mask colors/band-aid pose, and the domain assumptions that query feedback is available, that per-modality failures transfer to fused systems, and that the dataset approximates physical deployment.

free parameters (6)
  • DE population size n
    Eq. (2) initializes n color combinations; n is never reported and controls optimization cost/quality.
  • DE mutation rate gamma_m = 0.5
    Set in Experiment Details; chosen by hand and affects convergence.
  • DE crossover rate gamma_c = 0.6
    Set in Experiment Details; chosen by hand and affects exploration.
  • Harmonic template type = type T
    Color harmonization constraint chosen from Fig. 4; the template choice restricts allowed mask colors.
  • Max query budget Q = 10,000
    Threat-model budget bounding the number of queries; no sensitivity analysis is provided.
  • Optimized mask color endpoints and band-aid pose
    DE outputs for each attack; without these values the physical reproduction and audit of reported ASRs are impossible.
axioms (5)
  • domain assumption Attacker has black-box query access to detector confidence scores with fewer than 10,000 queries.
    Threat Model section; this capability enables using the detector probability as the DE fitness score.
  • domain assumption Attacking visible and infrared detectors independently and simultaneously defeats a visual-infrared fused system.
    Eq. (1) optimizes each detector's loss separately, and Tables 2-6 evaluate per-modality detectors rather than a true fusion model.
  • domain assumption The SPEAKINGFACES visual-thermal dataset is representative, and the lack of a stated train/test split does not bias reported ASR.
    Datasets section; no held-out image/subject split is described, so transfer from optimization to evaluation is assumed.
  • domain assumption The digital rendering of the mask, band-aid, and cold block approximates physical printing, 3D face curvature, and thermal insulation.
    VIPatch Design / 3D Transformation and Physical Domain Attack sections; this bridge is asserted via EOT and manual cold gel, not measured in detail.
  • standard math Background algorithms (differential evolution, Reinhard color transfer, 3DMM, FMA-3D, adv-sticker) are correct and applicable as used.
    Used off-the-shelf; the paper provides no proofs or detailed adaptation analysis for this specific use.

pith-pipeline@v1.3.0-alltime-deepseek · 15690 in / 15802 out tokens · 151181 ms · 2026-07-31T23:49:51.370060+00:00 · methodology

0 comments
read the original abstract

Deep learning-based visual-infrared fused face detection models are increasingly deployed across a wide range of applications, yet they remain susceptible to adversarial patch attacks. Most prior attacks target either the visual or the infrared image alone in the digital domain, which renders them ineffective against fused models in the physical world. Moreover, many of these methods are readily noticeable, as their patch patterns deviate substantially from those seen in the real world. In this paper, we introduce VIPatch (Visual-Infrared Patch), a novel physical adversarial patch attack that produces inconspicuous, realistic, and natural-looking patches for facial images. Specifically, VIPatch crafts a gradient-color mask together with a band-aid sticker across both the visual and infrared images, and jointly optimizes these two elements; the resulting digital patches further guide the fabrication of their physical counterparts. Experimental results show that VIPatch achieves competitive attack success rates (over 90%) in both the digital and physical domains, while keeping the patches unobtrusive to human observers.

Figures

Figures reproduced from arXiv: 2607.23292 by Jiayimei Wang, Qingchuan Zhao, Qiucheng Yu, Tao Ni, Yihe Zhou.

Figure 1
Figure 1. Figure 1: An adversary spoofs and bypasses the visual [PITH_FULL_IMAGE:figures/full_fig_p001_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: Overview of VIPatch. Image Harmonization. To minimize the disparity be￾tween the digital and physical domains, we employ actual masks rather than mask patterns and utilize UV mapping to apply them to the human face. UV mapping involves the projection of a 3D model’s surface onto a 2D image for texture mapping, thereby preserving the 3D information of the images. In our approach, the facial landmarks are ex… view at source ↗
Figure 3
Figure 3. Figure 3: Patch images versus Texture Preservation. [PITH_FULL_IMAGE:figures/full_fig_p003_3.png] view at source ↗
Figure 5
Figure 5. Figure 5: Images with visual and infrared patches. [PITH_FULL_IMAGE:figures/full_fig_p004_5.png] view at source ↗
Figure 6
Figure 6. Figure 6: VIPatch’s ASRs at different angles, light conditions and distances [PITH_FULL_IMAGE:figures/full_fig_p007_6.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

278 extracted references · 36 linked inside Pith

  1. [1]

    Abdrakhmanova, M.; Kuzdeuov, A.; Jarju, S.; Khassanov, Y.; Lewis, M.; and Varol, H. A. 2021. Speakingfaces: A large-scale multimodal dataset of voice commands with visual and thermal video streams. Sensors

  2. [2]

    Athalye, A.; Engstrom, L.; Ilyas, A.; and Kwok, K. 2018. Synthesizing robust adversarial examples. In Proceedings of International Conference on Machine Learning (ICML)

  3. [3]

    Barik, S. 2020. COVID-19: Kerala Deploys Thermal Imaging Camera With ‘Face Detection’ Capability. https://www.medianama.com/2020/05/223-kerala-thermal-imaging-camera-face-detection/

  4. [4]

    Blanz, V.; and Vetter, T. 2023. A morphable model for the synthesis of 3D faces. In Seminal Graphics Papers: Pushing the Boundaries

  5. [5]

    Bradski, G. 2000. The openCV library. Dr. Dobb's Journal: Software Tools for the Professional Programmer

  6. [6]

    I.; and Wainwright, M

    Chen, J.; Jordan, M. I.; and Wainwright, M. J. 2020. Hopskipjumpattack: A query-efficient decision-based attack. In Proceedings of IEEE Symposium on Security and Privacy (SP)

  7. [7]

    Chen, P.-Y.; Zhang, H.; Sharma, Y.; Yi, J.; and Hsieh, C.-J. 2017. Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM workshop on Artificial Intelligence and Security (AISec)

  8. [8]

    D.; Flammarion, N.; and Hein, M

    Croce, F.; Andriushchenko, M.; Singh, N. D.; Flammarion, N.; and Hein, M. 2022. Sparse-rs: a versatile framework for query-efficient sparse black-box adversarial attacks. In Proceedings of AAAI Conference on Artificial Intelligence (AAAI)

  9. [9]

    d link. 2020. d-link, human temperature mearsuring and fever warning systems. https://www.dlink.com.au/business-solutions/DCS-9500T-Thermal-Security-Solution-with-Facial-Recognition-Software

  10. [11]

    derronqi . 2023. yolov8-face. https://github.com/derronqi/yolov8-face?tab=readme-ov-file

  11. [12]

    G.; Xue, M.; Ma, S.; Abbasnejad, E.; and Ranasinghe, D

    Doan, B. G.; Xue, M.; Ma, S.; Abbasnejad, E.; and Ranasinghe, D. C. 2022. Tnt attacks! universal naturalistic adversarial patches against deep neural network systems. IEEE Transactions on Information Forensics and Security (TIFS)

  12. [13]

    G.; and Weinberger, K

    Guo, C.; Gardner, J.; You, Y.; Wilson, A. G.; and Weinberger, K. 2019. Simple black-box adversarial attacks. In Proceedings of International Conference on Machine Learning (ICML)

  13. [16]

    Howard. 2020. Enhance Surveillance with Thermal Security Cameras. https://community.fs.com/article/enhance-surveillance-with-thermal-security-cameras.html

  14. [17]

    Hu, C.; Shi, W.; Jiang, T.; Yao, W.; Tian, L.; Chen, X.; Zhou, J.; and Li, W. 2024. Adversarial Infrared Blocks: A Multi-View Black-Box Attack to Thermal Infrared Detectors in Physical World. Neural Networks

  15. [18]

    Hu, Z.; Huang, S.; Zhu, X.; Sun, F.; Zhang, B.; and Hu, X. 2022. Adversarial texture for fooling person detectors in the physical world. In Proceedings of IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

  16. [19]

    King, D. E. 2009. Dlib-ml: A machine learning toolkit. The Journal of Machine Learning Research (JMLR)

  17. [20]

    Komkov, S.; and Petiushko, A. 2021. Advhat: Real-world adversarial attack on arcface face id system. In Proceedings of International Conference on Pattern Recognition (ICPR)

  18. [21]

    Kumar, A.; Kaur, A.; and Kumar, M. 2019. Face detection techniques: a review. Artificial Intelligence Review

  19. [22]

    Kuzdeuov, A.; Aubakirova, D.; Koishigarina, D.; and Varol, H. A. 2022. TFW: Annotated thermal faces in the wild dataset. IEEE Transactions on Information Forensics and Security (TIFS)

  20. [23]

    Li, H. 2019. Guide Sense, human temperature mearsuring and fever warning systems. https://www.guideir.com/products/fever-screeninges/qt/data_152.html

  21. [24]

    Li, H.; Xu, X.; Zhang, X.; Yang, S.; and Li, B. 2020. Qeba: Query-efficient boundary-based blackbox attack. In Proceedings of IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

  22. [25]

    linzai . 2019. Ultra-Light-Fast-Generic-Face-Detector-1MB. https://github.com/Linzaer/Ultra-Light-Fast-Generic-Face-Detector-1MB

  23. [26]

    Liu, Y.; Wang, F.; Deng, J.; Zhou, Z.; Sun, B.; and Li, H. 2022. Mogface: Towards a deeper appreciation on face detection. In Proceedings of IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

  24. [27]

    T.; and Wang, Z

    Liu, Y.; Wei, H.; Jia, C.; Xiao, R.; Ruan, W.; Wei, X.; Zhou, J. T.; and Wang, Z. 2025. ProjAttacker: A Configurable Physical Adversarial Attack for Face Recognition via Projector. In Proceedings of IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

  25. [28]

    Meng, X.; Wang, L.; Guo, S.; Ju, L.; and Zhao, Q. 2024. Ava: Inconspicuous attribute variation-based adversarial attack bypassing deepfake detection. In 2024 IEEE Symposium on Security and Privacy (SP), 74--90. IEEE

  26. [29]

    Mohd, M. N. H.; Kashima, M.; Sato, K.; and Watanabe, M. 2014. Facial visual-infrared stereo vision fusion measurement as an alternative for physiological measurement. J. Biomedical Image Processing (JBIP)

  27. [30]

    S.; Wu, Y.; and Yang, H

    Nguyen, D.-L.; Arora, S. S.; Wu, Y.; and Yang, H. 2020. Adversarial light projection attacks on face recognition systems: A feasibility study. In Proceedings of IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops

  28. [31]

    Ni, T. 2024. Sensor security in virtual reality: Exploration and mitigation. In Proceedings of the 22nd Annual International Conference on Mobile Systems, Applications and Services, 758--759

  29. [32]

    Ni, T.; Chen, Y.; Song, K.; and Xu, W. 2021. A simple and fast human activity recognition system using radio frequency energy harvesting. In Adjunct Proceedings of the 2021 ACM International Joint Conference on Pervasive and Ubiquitous Computing and Proceedings of the 2021 ACM International Symposium on Wearable Computers, 666--671

  30. [33]

    Ni, T.; Chen, Y.; Xu, W.; Xue, L.; and Zhao, Q. 2023 a . Xporter: A study of the multi-port charger security on privacy leakage and voice injection. In Proceedings of the 29th annual international conference on mobile computing and networking, 1--15

  31. [35]

    Ni, T.; Lan, G.; Wang, J.; Zhao, Q.; and Xu, W. 2023 b . Eavesdropping mobile app activity via \ Radio-Frequency \ energy harvesting. In 32nd USENIX Security Symposium (USENIX Security 23), 3511--3528

  32. [36]

    Ni, T.; Li, J.; Zhang, X.; Zuo, C.; Wang, W.; Xu, W.; Luo, X.; and Zhao, Q. 2023 c . Exploiting contactless side channels in wireless charging power banks for user privacy inference via few-shot learning. In Proceedings of the 29th annual international conference on mobile computing and networking, 1--15

  33. [37]

    Ni, T.; Sun, Z.; Chen, Y.; Zhou, Y.; Wang, J.; Xu, W.; Zhao, Q.; and Wang, C. 2025 a . When Good Becomes Evil: Exploring Crosstalk Attack Surfaces on Multi-Port USB Chargers. IEEE Transactions on Mobile Computing

  34. [38]

    Ni, T.; Sun, Z.; Han, M.; Xie, Y.; Lan, G.; Li, Z.; Gu, T.; and Xu, W. 2024 b . Rehsense: Towards battery-free wireless sensing via radio frequency energy harvesting. In Proceedings of the Twenty-Fifth International Symposium on Theory, Algorithmic Foundations, and Protocol Design for Mobile Networks and Mobile Computing, 211--220

  35. [39]

    Ni, T.; Sun, Z.; Zhao, Q.; Lee, W.-B.; and Wang, C. 2026. When VR meets BCI:(Un) observable brainwave-aware privacy reconstruction in the metaverse via unrestricted inbuilt motion sensors. In 2026 IEEE Symposium on Security and Privacy (SP), 961--979. IEEE

  36. [40]

    Ni, T.; Zhang, X.; and Zhao, Q. 2023. Recovering fingerprints from in-display fingerprint sensors via electromagnetic side channel. In Proceedings of the 2023 ACM SIGSAC conference on computer and communications security, 253--267

  37. [41]

    Ni, T.; Zhang, X.; Zuo, C.; Li, J.; Wang, W.; Xu, W.; Luo, X.; and Zhao, Q. 2025 b . Characterizing Contactless Side-channel Eavesdropping on Wireless Chargers. IEEE Transactions on Dependable and Secure Computing

  38. [42]

    Ni, T.; Zhang, X.; Zuo, C.; Li, J.; Yan, Z.; Wang, W.; Xu, W.; Luo, X.; and Zhao, Q. 2023 d . Uncovering user interactions on smartphones via contactless wireless charging side channels. In 2023 IEEE Symposium on Security and Privacy (SP), 3399--3415. IEEE

  39. [43]

    Oh, B.-S.; Oh, K.; Teoh, A. B. J.; Lin, Z.; and Toh, K.-A. 2017. A Gabor-based network for heterogeneous face recognition. Neurocomputing

  40. [44]

    C.; and Wang, X

    Ouyang, S.; Hospedales, T.; Song, Y.-Z.; Li, X.; Loy, C. C.; and Wang, X. 2016. A survey on heterogeneous face recognition: Sketch, infrared, 3D and low-resolution. Image and Vision Computing

  41. [45]

    Pautov, M.; Melnikov, G.; Kaziakhmedov, E.; Kireev, K.; and Petiushko, A. 2019. On adversarial patches: real-world attack on arcface-100 face recognition system. In Proceedings of IEEE International Multi-Conference on Engineering, Computer and Information Sciences (SIBIRCON)

  42. [46]

    Qi, D.; Tan, W.; Yao, Q.; and Liu, J. 2022. YOLO5Face: why reinventing a face detector. In Proceedings of European Conference on Computer Vision (ECCV)

  43. [48]

    Reinhard, E.; Adhikhmin, M.; Gooch, B.; and Shirley, P. 2001. Color transfer between images. IEEE Computer Graphics and Applications

  44. [49]

    Sharif, M.; Bhagavatula, S.; Bauer, L.; and Reiter, M. K. 2016. Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS)

  45. [50]

    Singh, S.; and Prasad, S. 2018. Techniques and challenges of face recognition: A critical review. Procedia Computer Science

  46. [51]

    Storn, R.; and Price, K. 1997. Differential evolution--a simple and efficient heuristic for global optimization over continuous spaces. Journal of Global Optimization

  47. [52]

    Sun, Z.; Ni, T.; Chen, Y.; Duan, D.; Liu, K.; and Xu, W. 2024. Rf-egg: An rf solution for fine-grained multi-target and multi-task egg incubation sensing. In Proceedings of the 30th Annual International Conference on Mobile Computing and Networking, 528--542

  48. [53]

    Sun, Z.; Ni, T.; Hu, P.; Gu, T.; and Xu, W. 2025. SpaceSched: A Constellation-Wide Scheduling System for Resolving Ground Track Congestion in Remote Sensing. In Proceedings of the 31st Annual International Conference on Mobile Computing and Networking, 832--847

  49. [54]

    Surveillance-thermal. 2021. Enhance Surveillance with Thermal Security Cameras. https://www.gst-ir.net/?gad_source=1&gclid=CjwKCAjwuJ2xBhA3EiwAMVjkVI5_TLxF7H6xn7kf8CCU5cb0uHSC04fmwI_Sn2zYYo5tfmOx9u7vChoCHkYQAvD_BwE

  50. [55]

    Tao, G.; An, S.; Cheng, S.; Shen, G.; and Zhang, X. 2023. Hard-label black-box universal adversarial patch attack. In Proceedings of USENIX Security Symposium (USENIX Security)

  51. [56]

    Thys, S.; Van Ranst, W.; and Goedem \'e , T. 2019. Fooling automated surveillance cameras: adversarial patches to attack person detection. In Proceedings of IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops

  52. [57]

    Wang, J.; Liang, J.; Hu, H.; and Li, Y. 2007. Performance evaluation of infrared and visible image fusion algorithms for face recognition. In Proceedings of International Conference on Intelligent Systems and Knowledge Engineering (ISKE)

  53. [58]

    Wang, J.; Liu, Y.; Hu, Y.; Shi, H.; and Mei, T. 2021. Facex-zoo: A pytorch toolbox for face recognition. In Proceedings of ACM International Conference on Multimedia (MM)

  54. [60]

    Wang, J.; Ni, T.; Xu, G.; Zhao, Q.; and Wang, C. 2026. Adversarial patch EXterminator: Zero-shot and patch-agnostic defense framework against adversarial patch attacks. In 35th USENIX Security Symposium (USENIX Security 26)

  55. [61]

    Wang, Y.; Liu, Z.; Luo, B.; Hui, R.; and Li, F. 2024. The Invisible Polyjuice Potion: an Effective Physical Adversarial Attack against Face Recognition. In Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS)

  56. [62]

    Wei, H.; Wang, Z.; Jia, X.; Zheng, Y.; Tang, H.; Satoh, S.; and Wang, Z. 2023. Hotcold block: Fooling thermal infrared detectors with a novel wearable design. In Proceedings of AAAI Conference on Artificial Intelligence (AAAI)

  57. [63]

    Wei, X.; Guo, Y.; and Yu, J. 2022. Adversarial sticker: A stealthy attack method in the physical world. IEEE Transactions on Pattern Analysis and Machine Intelligence (T-PAMI)

  58. [64]

    Wei, X.; Guo, Y.; Yu, J.; and Zhang, B. 2022. Simultaneously optimizing perturbations and positions for black-box adversarial patch attacks. IEEE Transactions on Pattern Analysis and Machine Intelligence (T-PAMI)

  59. [65]

    Wei, X.; Yu, J.; and Huang, Y. 2023. Physically Adversarial Infrared Patches With Learnable Shapes and Locations. In Proceedings of IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

  60. [66]

    Wu, R.; Ni, T.; Sun, Z.; Sun, J.; and Xu, W. 2025. RingByte: Enhancing Text-Entry Practicality via A Singular Wearable Rotating Smart Ring. In Proceedings of the 38th Annual ACM Symposium on User Interface Software and Technology, 1--15

  61. [67]

    S.; and Goldstein, T

    Wu, Z.; Lim, S.-N.; Davis, L. S.; and Goldstein, T. 2020. Making an invisibility cloak: Real world adversarial attacks on object detectors. In Proceedings of European Conference on Computer Vision (ECCV)

  62. [68]

    Yakovleva, O.; Kovtunenko, A.; Liubchenko, V.; Honcharenko, V.; and Kobylin, O. 2023. Face Detection for Video Surveillance-based Security System. In Proceedings of International Conference on Computational Linguistics and Intelligent Systems (COLINS)

  63. [69]

    Yang, X.; Wei, F.; Zhang, H.; and Zhu, J. 2020. Design and interpretation of universal adversarial patches in face detection. In Proceedings of European Conference on Computer Vision (ECCV)

  64. [70]

    Yang, X.; Xu, L.; Pang, T.; Dong, Y.; Wang, Y.; Su, H.; and Zhu, J. 2025. Face3DAdv: Exploiting Robust Adversarial 3D Patches on Physical Face Recognition. International Journal of Computer Vision (IJCV)

  65. [72]

    Yuan, S.; Han, X.; Li, H.; Xu, G.; Jiang, W.; Ni, T.; Zhao, Q.; and Fang, Y. 2026. The fluorescent veil: A stealthy and effective physical adversarial patch against traffic sign recognition. Advances in Neural Information Processing Systems, 38: 98864--98890

  66. [74]

    Yuan, S.; Li, H.; Zhang, R.; Cao, H.; Jiang, W.; Ni, T.; Fan, W.; Zhao, Q.; and Xu, G. 2025 a . Omni-Angle Assault: An Invisible and Powerful Physical Adversarial Attack on Face Recognition. In Proceedings of International Conference on Machine Learning (ICML)

  67. [75]

    Yuan, S.; Xu, G.; Li, H.; Zhang, R.; Cao, H.; Qian, X.; Ni, T.; Zhao, Q.; and Fang, Y. 2025 b . No Trespassing: Ground-view Adversarial Patches for Privacy-aware Management in COTS Robot Vacuum Cleaner. IEEE Transactions on Dependable and Secure Computing

  68. [77]

    Zhang, K.; Zhang, Z.; Li, Z.; and Qiao, Y. 2016. Joint face detection and alignment using multitask cascaded convolutional networks. IEEE Signal Processing Letters (SPL)

  69. [78]

    Zhang, Q.; Guo, Q.; Gao, R.; Juefei-Xu, F.; Yu, H.; and Feng, W. 2024. Adversarial relighting against face recognition. IEEE Transactions on Information Forensics and Security (TIFS)

  70. [80]

    Zhao, Q.; Zuo, C.; Blasco, J.; and Lin, Z. 2022. Periscope: Comprehensive vulnerability analysis of mobile app-defined bluetooth peripherals. In Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security, 521--533

  71. [82]

    Zhu, X.; Hu, Z.; Huang, S.; Li, J.; and Hu, X. 2022. Infrared invisible clothing: Hiding from infrared detectors at multiple angles in real world. In Proceedings of IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)

  72. [83]

    Zolfi, A.; Avidan, S.; Elovici, Y.; and Shabtai, A. 2022. Adversarial Mask: Real-World Universal Adversarial Attack on Face Recognition Models. In Proceedings of Joint European Conference on Machine Learning and Knowledge Discovery in Databases (ECML-PKDD)

  73. [84]

    J.; and Khurshid, K

    Zulfiqar, M.; Syed, F.; Khan, M. J.; and Khurshid, K. 2019. Deep face recognition for biometric authentication. In Proceedings of International Conference on Electrical, Communication, and Computer Engineering (ICECCE)

  74. [85]

    FirstName Alpher , title =

  75. [86]

    Journal of Foo , volume = 13, number = 1, pages =

    FirstName Alpher and FirstName Fotheringham-Smythe , title =. Journal of Foo , volume = 13, number = 1, pages =

  76. [87]

    Journal of Foo , volume = 14, number = 1, pages =

    FirstName Alpher and FirstName Fotheringham-Smythe and FirstName Gamow , title =. Journal of Foo , volume = 14, number = 1, pages =

  77. [88]

    FirstName Alpher and FirstName Gamow , title =

  78. [89]

    Computer Vision -- ECCV 2022 , year =

  79. [90]

    arXiv preprint arXiv:1712.09665 , year=

    Adversarial patch , author=. arXiv preprint arXiv:1712.09665 , year=

  80. [91]

    arXiv preprint arXiv:1910.06261 , year=

    Real-world attack on MTCNN face detection system , author=. arXiv preprint arXiv:1910.06261 , year=

Showing first 80 references.