Skip to main content
. 2025 Jun 11;11:e2904. doi: 10.7717/peerj-cs.2904

Table 6. Comparison of traditional impersonation attack success rates under white-box and black-box settings.

Method White box attack Black box attack
ArcFace FaceNet ResNet50 MobileFace SphereFace CosFace
FGSM 99.8% 85.4% 96.1% 64.8% 44.3% 40.8%
MI-FGSM 100% 100% 100% 97.6% 86.0% 80.2%
C&W 100% 100% 100% 7.1% 9.1% 8.1%
AdvMakeUP 25.0% 41.9% 31.7% 20.1% 37.1% 28.0%
AT3D 62.5% 84.7% 94.2% 88.6% 41.7% 67.0%
AdvFaces 86.1% 89.9% 78.1% 95.6% 84.5% 73.9%
TIP-IM 100% 99.8% 100% 89.1% 82.4% 91.0%
SiblingAttack 100% 100% 100% 99.2% 83.2% 92.7%
DiffAM 58.1% 36.7% 48.8% 65.6% 52.4% 38.2%
ɛ = 4 w.oζ w.oη 95.7% 93.4% 95.9% 99.2% 79.5% 92.3%
ɛ = 5 w.oζ w.oη 97.7% 97.8% 97.9% 99.3% 87.2% 96.8%
ɛ = 5 ζ = 0.92 η = 0.15 96.6% 94.8% 96.6% 99.2% 83.5% 94.4%