Table 10. 0.01% FAR threshold: black-box attack success rate comparison on Aliyun, Tencent and Face++.
| Metric | APIs | FGSM | MI-FGSM | C&W | Adv- MakeUP |
AT3D | AdvFace | TIPIM | Sibling attack |
DiffAM | Adv FaceGAN |
|---|---|---|---|---|---|---|---|---|---|---|---|
| ASR 1 | Aliyun | 5.0% | 36.7% | 0% | 0% | 11.2% | 21.6% | 20.1% | 82.0% | 0% | 79.3% |
| Tencent | 21.1% | 51.2% | 1.7% | 4.9% | 41.6% | 41.1% | 46.3% | 85.2% | 11.5% | 76.5% | |
| Face++ | 27.4% | 67.2% | 2.7% | 5.6% | 59.0% | 60.0% | 57.2% | 92.0% | 14.1% | 89.8% | |
| ASR 2 | Aliyun | 5.0% | 34.3% | 0% | 0% | 5.7% | 11.9% | 3.5% | 16.5% | 0% | 62.1% |
| Tencent | 21.1% | 50.1% | 1.7% | 4.9% | 25.2% | 29.3% | 22.8% | 39.5% | 3.6% | 58.4% | |
| Face++ | 27.4% | 65.2% | 2.7% | 5.6% | 30.2% | 39.9% | 15.3% | 51.5% | 2.2% | 68.3% |