Skip to main content
. 2025 Jun 11;11:e2904. doi: 10.7717/peerj-cs.2904

Table 7. Comparison of dual-identity impersonation attack success rates under white-box and black-box settings.

Method White box attack Black box attack
ArcFace FaceNet ResNet50 MobileFace SphereFace CosFace
FGSM 99.7% 70.6% 96.1% 64.8% 44.3% 40.8%
MI-FGSM 6.3% 1.9% 37.8% 96.6% 84.5% 78.9%
C&W 100% 98.4% 100% 7.1% 9.1% 8.1%
AdvMakeUP 25.0% 41.9% 31.7% 20.1% 37.1% 28.0%
AT3D 60.7% 20.8% 82.1% 85.9% 40.4% 66.9%
AdvFaces 83.5% 58.8% 66.6% 33.7% 25.5% 27.5%
TIP-IM 0% 0% 0% 83.1% 76.7% 87.4%
SiblingAttack 0.9% 2.0% 2.5% 75.4% 72.5% 83.1%
DiffAM 35.9% 11.7% 30.5% 57.2% 42.2% 24.3%
ɛ = 4 w.oζ w.oη 95.2% 73.9% 84.0% 92.7% 78.4% 91.6%
ɛ = 5 w.o.ζ w.oη 94.5% 55.8% 67.1% 79.0% 82.3% 92%
ɛ = 5 ζ = 0.92 η = 0.15 96.2% 76.2% 88.6% 96.0% 81.8% 93.9%