Abstract: Classical adversarial attacks for Face Recognition (FR) models typically generate discrete examples for target identity with a single state image. However, such paradigm of point-wise attack ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results