Table 9. Comparison of visual quality of adversarial faces generated by different methods (FaceNet White-box, CosFace Black-box).
| Method | Vision metric | Attack metric | ||||
|---|---|---|---|---|---|---|
| SSIM↑ | PSNR↑ | MSE↓ | ASR 1 | ASR 2 | FSS&FTS | |
| FGSM | 88.4% | 32.4 | 35.9 | 29.3% | 29.3% | 64.6&18.0 |
| MI-FGSM | 87.0% | 32.3 | 36.3 | 69.5% | 69.2% | 53.5&31.2 |
| C&W | 99.4% | 47.3 | 1.2 | 4.2% | 4.2% | 97.0&8.3 |
| AdvMakeUP | 97.4% | 31.6 | 56.7 | 28.0% | 28.0% | 84.1&18.4 |
| AT3D | 88.4% | 22.8 | 386.8 | 60.6% | 60.2% | 37.9&30.5 |
| AdvFaces | 91.6% | 30.5 | 59.6 | 91.0% | 87.4% | 47.8&40.3 |
| TIP-IM | 83.7% | 31.4 | 43.9 | 66.7% | 27.5% | 23.2&29.6 |
| SiblingAttack | 60.8% | 25.1 | 196.4 | 92.7% | 83.1% | 40.3&42.5 |
| DiffAM | 82.4% | 16.9 | 1367.0 | 38.2% | 24.3% | 31.5&22.3 |
| ɛ = 4 w.o. ζ w.o. η | 93.8% | 33.3 | 28.1 | 92.3% | 91.6% | 54.8&40.6 |
| ɛ = 5 w.o. ζ w.o. η | 91.0% | 31.3 | 43.9 | 96.8% | 92.0% | 46.1&46.4 |
| ɛ = 5 ζ = 0.92 η = 0.15 | 94.0% | 32.0 | 37.4 | 94.4% | 93.9% | 55.29&43.4 |