Abstract: Highlights•Address privacy concerns with unauthorized facial recognition systems (FRS).•Propose low frequency adversarial perturbation (LFAP) and low-mid frequency adversarial perturbation (LMFAP).•LFAP and LMFAP exhibit enhanced transferability and compatibility with various attack algorithms.•Comprehensive evaluation on black-box configurations and commercial API, Face++, demonstrates effectiveness.
Loading