Table 8. Visual quality comparison of adversarial faces generated by different methods (ArcFace White-box, MobileFace Black-box).
| Method | Vision metric | Attack metric | ||||
|---|---|---|---|---|---|---|
| SSIM↑ | PSNR↑ | MSE↓ | ASR 1 | ASR 2 | FSS&FTS | |
| FGSM | 90.2% | 32.3 | 36.0 | 64.8% | 64.8% | 59.1&24.3 |
| MI-FGSM | 89.5% | 32.2 | 36.3 | 97.6% | 96.6% | 43.6&39.7 |
| C&W | 99.5% | 46.7 | 1.4 | 7.1% | 7.1% | 93.2&11.7 |
| AdvMakeUP | 97.4% | 31.6 | 56.7 | 20.1% | 20.1% | 77.4&14.8 |
| AT3D | 89.6% | 23.5 | 348.7 | 84.9% | 82.5% | 37.9&30.5 |
| AdvFaces | 91.6% | 30.4 | 59.6 | 89.1% | 83.1% | 38.7&34.6 |
| TIP-IM | 85.3% | 31.0 | 47.8 | 95.6% | 21.5% | 13.3&35.0 |
| SiblingAttack | 59.5% | 24.9 | 205.2 | 99.1% | 71.3% | 27.7&50.5 |
| DiffAM | 82.4% | 16.9 | 1367.0 | 65.6% | 57.2% | 32.3&24.9 |
| ɛ = 4 w.o. ζ w.o. η | 93.8% | 33.3 | 28.1 | 99.2% | 92.7% | 38.3&49.6 |
| ɛ = 5 w.o. ζ w.o. η | 91.0% | 31.3 | 43.9 | 99.3% | 79.0% | 30.2&54.3 |
| ɛ = 5 ζ = 0.92 η = 0.15 | 94.0% | 32.0 | 37.4 | 99.2% | 96.0% | 40.9&52.1 |