Research Article
Research on Multimodality Face Antispoofing Model Based on Adversarial Attacks
Figure 8
RGB, Depth, and IR images formed under the FGSM attack with perturbations of 0.1 and 0.2, respectively. The first line represents the original image patches, and the second line represents the FGSM attacks with perturbation of 0.1. The third line represents the FGSM attacks with perturbation of 0.2.