Abstract: Face recognition systems based on deep neural networks remain susceptible to adversarial samples. Input reconstruction is a widely adopted defense due to its independence from the target ...