Skip to main content

Table 6 Black-box attacks with adversarial samples generated from different models by MI-FGSM and TRA

From: Adversarial attacks on fingerprint liveness detection

Generation model

Target model&Datasets

VGG19 Bio2013 (%)

Alexnet Bio2013 (%)

MobilenetV1 Bio2013 (%)

VGG19 Bio2015 (%)

Alexnet Bio2015 (%)

MobilenetV1

Bio2015 (%)

MI-FGSM

ShollowCNN

5.6

7.5

4.2

4.7

6.9

3.7

DeepCNN

8.9

10.4

6.5

7.1

11.2

5.4

ShallowEnsemble

21.3

26.1

7.3

19.4

27.3

5.2

DeepEnsemble

21.9

27.0

8.9

22.4

25.1

7.6

 

TRA

ShollowCNN

6.6

8.3

5.2

5.6

6.6

3.4

DeepCNN

9.0

12.7

6.4

8.1

12.3

5.6

ShallowEnsemble

23.3

27.9

8.5

22.1

27.4

6.7

DeepEnsemble

20.5

27.1

10.2

21.4

24.2

7.7