1 Introduction
In recent years, the vulnerability of face biometric systems has been widely recognized and increasingly brought attention to the computer vision community. The attacks attempt to deceive the systems to make wrong identity recognition: either recognize the attackers as a target person (i.e., impersonation), or cover up the original identity (i.e., obfuscation).