Compact Vision Models for Iris Presentation Attack Detection under Presentation Attack Instrument Shift and Environmental Degradation Athanasios Angelakis∗1,2 and Marta Gomez-Barrero†1 1
arXiv:2609.20386v1 [cs.CV] 17 Sep 2026
2
BioML Lab, RI CODE, UniBw, Munich, Germany EDS, Amsterdam UMC, University of Amsterdam, Amsterdam, Netherlands [email protected] [email protected]
Accepted at BIOSIG 2026. This preprint includes minor nomenclature and editorial corrections.
Abstract Iris presentation attack detection (PAD) is security-critical when a subsystem that appears reliable during development encounters presentation attack instruments (PAIs) or acquisition conditions absent from validation data. We benchmark three compact scratchtrained computer-vision models, each with at most approximately 0.26 million trainable parameters, on the Notre Dame subset of LivDet-Iris 2017 under PAI-driven domain shift and environmental degradation. All models are trained without external pretraining or data augmentation and evaluated over five seeds. A validation-selected threshold is transferred unchanged to the known-attack, unknown-attack, corrupted, and pooled test partitions. From known to unknown attack presentations, Attack Presentation Classification Error Rate (APCER) increases by 17.11-30.47 percentage points and Detection Equal Error Rate (D-EER) increases by 7.38-12.73 percentage points. At the validation-selected threshold, ZACH-ViT obtains the lowest unknown-attack APCER (47.69 ± 4.84%) and D-EER (38.87 ± 0.93%), while Compact-TransMIL obtains the lowest Bona Fide Presentation Classification Error Rate (BPCER). ZACH-ViT also gives the lowest unknown-attack BPCER at an APCER limit of 10% (81.29 ± 1.95%). The high absolute errors show that the comparative advantage of the best compact model does not constitute deployment readiness under unknown PAIs.
Keywords: Iris presentation attack detection; biometric recognition security; compact vision transformers; ZACH-ViT; PAI shift; operational degradation; APCER; BPCER; D-EER.
1
Introduction
Iris recognition is widely used in biometric recognition because iris texture is distinctive and comparatively stable. However, iris recognition systems remain vulnerable to presentation attacks, including textured contact lenses and other artefacts designed to imitate bona-fide presentations. Presentation attack detection (PAD) is therefore a security-critical subsystem for person authentication rather than an auxiliary image-classification task [1, 2, 3]. This paper studies a deployment-relevant challenge: a PAD model can appear adequate during development, yet degrade when the presentation attack instrument (PAI), sensor condition, or ∗ †
ORCID: 0000-0003-1226-9560 ORCID: 0000-0003-4581-5353
1
acquisition pipeline changes. A high Attack Presentation Classification Error Rate (APCER) under unknown attack presentations is a security-side error because attack presentations are classified as bona-fide presentations and may pass the PAD subsystem. A high Bona Fide Presentation Classification Error Rate (BPCER) affects availability and usability. Thus, the relevant question is not only which compact model obtains the best average result, but how the PAD error trade-off changes when the PAI, capture conditions, or operational scenario changes. The LivDet-Iris 2017 Notre Dame subset supports this analysis through separate knownattack and unknown-attack test partitions [3]. We interpret the known-to-unknown transition as PAI-driven domain shift. We additionally use light image corruptions as controlled proxies for sensor noise, focus degradation, optical contamination, compression, and low-quality capture pipelines. The evaluation therefore links compact model design, validation-driven threshold selection, and PAD security margins under shifted conditions. We frame the study as a compact computer-vision benchmark rather than a single-architecture demonstration. Patch-ABMIL, Compact-TransMIL, and ZACH-ViT are evaluated under the same scratch-trained protocol, with every model containing at most approximately 0.26 million trainable parameters. Patch-ABMIL and Compact-TransMIL are project-specific compact variants inspired by attention-based deep multiple instance learning and TransMIL, respectively. ZACH-ViT is included as a zero-token compact vision transformer designed to reduce fixed spatial assumptions in data regimes where spatial organization is not uniformly informative [4, 5].
1.1
Contributions
This paper makes four contributions: 1. We present a compact iris PAD benchmark of scratch-trained computer-vision models containing at most approximately 0.26 million trainable parameters on LivDet-Iris 2017 Notre Dame. 2. We quantify known-to-unknown security degradation, showing APCER increases of 17.11-30.47 percentage points and D-EER increases of 7.38-12.73 percentage points. 3. We show that ZACH-ViT obtains the lowest unknown-attack and pooled-test APCER and D-EER at the validation-selected threshold, together with the lowest BPCER at an APCER limit of 10%. 4. We analyze architectural sensitivity and operational robustness through a ZACH-ViT ablation and controlled Gaussian-noise, blur, and Joint Photographic Experts Group (JPEG) compression stress tests.
2
Related Work
Iris PAD spans textured contact lenses, printed or artificial eyes, and synthetic iris imagery, and generalization across PAIs remains open [6]. Doyle and Bowyer showed that robust textured contact lens detection can be achieved using Binarized Statistical Image Features (BSIF) descriptors without highly accurate iris segmentation [7], while LivDet-Iris established known-attack and unknown-attack protocols [3]. Generative iris research has progressed from iDCGAN and RaSGAN to multi-domain CIT-GAN and diffusion-GAN synthesis, supporting both new PAIs and data augmentation [8, 9, 10, 11]; LivDet-Iris 2023 further emphasizes synthetic PAIs [12]. Deep iris PAD increasingly uses learned representations, including larger backbones, transfer learning, periocular information, and foundation models [13]; privacy-preserving synthetic training is another emerging direction [14]. Segmentation-aware methods have incorporated 2
masks or joint iris localization [15, 16]. Compact ocular recognition has also been evaluated on mobile hardware, while tiny-ML research highlights memory- and latency-aware architecture design [17, 18]. In contrast, we study compact scratch-trained models under PAI shift. ZACHViT first appeared in lung ultrasound [4], was formalized as a regime-dependent inductive-bias study [5], and was subsequently evaluated under corruption and adversarial stress [19].
3
Experimental Protocol
3.1
Dataset and Evaluation Protocol
We evaluate the Notre Dame subset of LivDet-Iris 2017, which contains an official training partition and two official test partitions: known attack presentations and unknown attack presentations [3]. The data comprise near-infrared iris images with bona-fide presentations and textured contact lens attacks derived from the Notre Dame Contact Lenses Dataset 2015 lineage [7]. The local manifest contains 1,200 training images, 1,800 known-attack test images, and 1,800 unknown-attack test images. The official training set is split into 960 training and 240 validation images using a stratified 80/20 split. All models are trained from scratch on the same split and evaluated over seeds {3, 5, 7, 11, 13}. Repeated seeds quantify stochastic optimization variability rather than classsubsampling variability. Each Tagged Image File Format (TIFF) image is converted to grayscale, center-cropped, resized to 224 × 224, and replicated to three channels. Center cropping avoids a separate segmentation model but retains non-iris context. No external pretraining or data augmentation is used. Terminology follows ISO/IEC 2382-37:2022 [1]: we use bona-fide presentation, biometric presentation attack, presentation attack detection (PAD), and presentation attack instrument (PAI), avoiding legacy terms such as “live”, “fake”, or “spoof”. Reporting follows ISO/IEC 30107-style terminology [2] and biometric performance-testing practice [20]. We report Attack Presentation Classification Error Rate (APCER), Bona Fide Presentation Classification Error Rate (BPCER), Detection Equal Error Rate (D-EER), Detection Error Trade-off (DET) curves, and BPCER at a fixed APCER limit. For the primary APCER and BPCER evaluation, the threshold is selected on validation data using the APCER-BPCER balance criterion implemented in the evaluation scripts. It is then transferred unchanged to the known-attack, unknown-attack, corrupted, and pooled test partitions, avoiding oracle tuning of the primary test operating point. D-EER and DET curves are computed by sweeping the threshold separately on each evaluation partition. To characterize security-constrained operation, we additionally report BPCER at APCER ≤ 10%, obtained from each test DET curve. This curve-derived operating point characterizes the security-usability trade-off and does not replace or retune the validation-selected threshold.
3.2
Compact Baselines
The benchmark contains three compact scratch-trained models. Patch-ABMIL (∼0.09 million parameters) is our patch-level compact variant inspired by attention-based deep multiple instance learning [21]: non-overlapping image patches are treated as instances and aggregated with learned attention weights. Compact-TransMIL (∼0.26 million) is our reduced transformer-MIL variant inspired by TransMIL [22]; unlike canonical TransMIL, it omits PPEG and Nyström attention and uses a compact transformer stack followed by global average pooling. ZACH-ViT (∼0.25 million) follows the previously introduced compact architecture [4, 5]. All models are trained for 23 epochs with batch size 16, the Adam optimizer, learning rate 10−4 , and identical input size. The training schedule is fixed a priori across models to isolate architectural and threshold-transfer behavior rather than tune each model separately. 3
4
Results
4.1
Main test performance
Table 1 summarizes performance at the validation-selected threshold and at the curve-derived APCER limit. On known attack presentations, ZACH-ViT obtains the lowest APCER and D-EER, while Compact-TransMIL has the lowest BPCER. Under unknown PAIs, ZACH-ViT gives the lowest APCER (47.69 ± 4.84%) and D-EER (38.87 ± 0.93%), while Compact-TransMIL has the lowest BPCER at the transferred threshold. ZACH-ViT also gives the lowest BPCER at APCER ≤ 10% on the known-attack (63.29 ± 7.32%), unknown-attack (81.29 ± 1.95%), and pooled (74.83 ± 3.42%) partitions. Nevertheless, the unknown-attack result means that more than four-fifths of bona-fide presentations would be rejected when APCER is constrained to 10%, indicating comparative advantage rather than operational acceptability. Figure 1 shows representative DET curves for seed 3 and visualizes the BPCER-APCER trade-off across all test partitions.
4.2
Known-to-unknown degradation
Table 2 quantifies degradation from known to unknown attack presentations. APCER increases by 17.11-30.47 percentage points and D-EER increases by 7.38-12.73 percentage points. ZACHViT has the smallest increase in both metrics and the lowest absolute unknown-attack APCER and D-EER. Its APCER rises from 30.58% to 47.69%, meaning that nearly half of unknown attack presentations are classified as bona-fide presentations at the validation-selected threshold. Compact-TransMIL has the lowest BPCER at that threshold.
4.3
Ablation and corruption stress
The ablation in Table 3 tests positional embeddings, a classification (CLS) token, and patch size 8 × 8. The patch-size-8 variant gives the lowest known-attack APCER, BPCER, and D-EER, but generalizes poorly to unknown attack presentations, where APCER rises to 68.49 ± 3.56% and D-EER to 41.29 ± 3.00%. On unknown attack presentations, the positional-embedding variant gives the lowest APCER, the patch-size-8 variant gives the lowest BPCER, and the default configuration gives the lowest D-EER. Strong performance on familiar PAIs therefore does not guarantee generalization to unseen PAIs. Table 4 reports corruption-averaged results under Gaussian noise, Gaussian blur, and JPEG compression at two severities each. ZACH-ViT gives the lowest APCER, BPCER, and D-EER across the known-attack, unknown-attack, and pooled partitions. Nevertheless, its corrupted unknown-attack APCER remains 48.51±8.13%, representing a comparative robustness advantage rather than deployment certification.
4.4
Efficiency
Table 5 reports parameter count, training time, inference latency, throughput, and pooled-test PAD performance measured in the same local environment; these are comparative workstation measurements, not an on-device benchmark. Patch-ABMIL is the smallest and fastest model but has the weakest pooled-test performance. ZACH-ViT gives the lowest pooled-test BPCER at APCER ≤ 10% and the lowest D-EER among models containing at most approximately 0.26 million trainable parameters.
4
Table 1: Main PAD results on LivDet-Iris 2017 Notre Dame (mean ± standard deviation over five seeds). APCER and BPCER use the validation-selected threshold. D-EER and BPCER at APCER ≤ 10% are derived by threshold sweeping. All values are percentages; lowest values per block and metric are bold. Model
APCER
BPCER
D-EER
BPCER@APCER≤ 10%
Known attack presentations Patch-ABMIL 36.04 ± 5.46 Compact-TransMIL 34.82 ± 4.38 ZACH-ViT 30.58 ± 3.06
36.09 ± 3.83 30.91 ± 2.44 32.36 ± 2.19
35.98 ± 1.11 32.67 ± 2.82 31.49 ± 2.05
72.02 ± 4.95 67.16 ± 6.47 63.29 ± 7.32
Unknown attack presentations Patch-ABMIL 66.51 ± 3.74 Compact-TransMIL 53.62 ± 3.62 ZACH-ViT 47.69 ± 4.84
34.49 ± 3.64 30.89 ± 1.86 31.84 ± 2.59
48.71 ± 2.33 40.87 ± 1.83 38.87 ± 0.93
86.67 ± 1.71 81.96 ± 3.32 81.29 ± 1.95
Pooled test presentations Patch-ABMIL 51.28 ± 4.07 Compact-TransMIL 44.22 ± 2.83 ZACH-ViT 39.13 ± 2.78
35.29 ± 3.72 30.90 ± 2.11 32.10 ± 2.07
43.02 ± 1.26 36.74 ± 1.70 35.21 ± 0.41
81.18 ± 1.60 76.90 ± 3.98 74.83 ± 3.42
Table 2: Known-to-unknown PAD degradation. Changes are unknown minus known in percentage points. Lowest absolute APCER and D-EER values and their smallest increases are bold. BPCER changes are descriptive because a lower BPCER under shift may coincide with a higher APCER. Metric
Model
Known
Unknown
Change
APCER
Patch-ABMIL Compact-TransMIL ZACH-ViT
36.04 34.82 30.58
66.51 53.62 47.69
30.47 18.80 17.11
BPCER
Patch-ABMIL Compact-TransMIL ZACH-ViT
36.09 30.91 32.36
34.49 30.89 31.84
-1.60 -0.02 -0.51
D-EER
Patch-ABMIL Compact-TransMIL ZACH-ViT
35.98 32.67 31.49
48.71 40.87 38.87
12.73 8.20 7.38
Table 3: PAD ablation of ZACH-ViT (mean ± standard deviation over five seeds, in percent). PosEmb denotes positional embeddings and PS8 denotes patch size 8 × 8. Lowest values per block and metric are bold. Variant
APCER
BPCER
D-EER
Known attack presentations Default 30.58 ± 3.06 32.36 ± 2.19 + PosEmb 29.11 ± 2.46 36.64 ± 1.47 + CLS 35.13 ± 4.90 32.87 ± 4.22 PS8 25.07 ± 3.38 24.40 ± 2.80
31.49 ± 2.05 33.11 ± 0.86 33.69 ± 1.15 24.87 ± 3.00
Unknown attack presentations Default 47.69 ± 4.84 31.84 ± 2.59 + PosEmb 43.58 ± 3.02 35.33 ± 0.94 + CLS 50.71 ± 6.26 33.69 ± 4.12 PS8 68.49 ± 3.56 23.22 ± 3.16
38.87 ± 0.93 39.16 ± 1.06 41.49 ± 1.31 41.29 ± 3.00
Pooled test presentations Default 39.13 ± 2.78 + PosEmb 36.34 ± 1.30 + CLS 42.92 ± 5.40 PS8 46.78 ± 3.02
35.21 ± 0.41 36.22 ± 0.62 37.43 ± 0.39 33.72 ± 2.79
32.10 ± 2.07 35.99 ± 1.02 33.28 ± 4.08 23.81 ± 2.97
5
Table 4: Corruption-averaged robustness under Gaussian noise, Gaussian blur, and JPEG compression (mean ± standard deviation over corruption, severity, and seed evaluations, in percent). Lowest values per block and metric are bold. Model
APCER
BPCER
D-EER
Known attack presentations Patch-ABMIL 37.19 ± 5.53 Compact-TransMIL 33.93 ± 5.75 ZACH-ViT 32.10 ± 7.71
35.66 ± 3.82 34.37 ± 5.68 32.96 ± 4.80
36.29 ± 1.03 34.20 ± 2.94 32.48 ± 2.00
Unknown attack presentations Patch-ABMIL 67.50 ± 3.87 Compact-TransMIL 52.08 ± 6.47 ZACH-ViT 48.51 ± 8.13
33.82 ± 3.27 33.88 ± 5.58 32.76 ± 4.49
48.54 ± 2.25 42.09 ± 1.99 39.84 ± 1.71
Pooled test presentations Patch-ABMIL 52.38 ± 4.30 Compact-TransMIL 43.01 ± 5.52 ZACH-ViT 40.20 ± 7.32
34.72 ± 3.48 34.19 ± 5.68 32.86 ± 4.63
42.98 ± 1.12 38.25 ± 2.34 36.25 ± 1.46
Table 5: Efficiency and deployment-oriented summary. FPS denotes frames per second. BPCER at APCER ≤ 10% is derived from the pooled-test DET curve. Lowest BPCER and D-EER are bold. Model
Par. (M)
ZACH-ViT Compact-TransMIL Patch-ABMIL
0.25 0.26 0.09
(a) Known attacks
Train (s)
Lat. (ms)
FPS
82.11 ± 1.36 1.123 ± 0.028 890.33 81.80 ± 3.08 1.085 ± 0.115 921.47 72.15 ± 0.79 0.276 ± 0.012 3623.89
(b) Unknown attacks
BPCER@10% APCER
D-EER
74.83 ± 3.42 76.90 ± 3.98 81.18 ± 1.60
35.21 ± 0.41 36.74 ± 1.70 43.02 ± 1.26
(c) Pooled test
Figure 1: Representative DET curves for seed 3. The horizontal axis is BPCER and the vertical axis is APCER.
6
5
Discussion
Compact computer-vision models show substantial degradation when the PAI changes. From known to unknown attack presentations, APCER increases by 17.11–30.47 percentage points and D-EER by 7.38–12.73 percentage points. ZACH-ViT gives the lowest unknown-attack APCER and D-EER, whereas Compact-TransMIL gives the lowest BPCER at the validation-selected threshold. The threshold protocol is central to this interpretation. APCER and BPCER at the transferred threshold describe a fixed decision rule, whereas D-EER, DET curves, and BPCER at a fixed APCER describe the score-distribution trade-off. At APCER ≤ 10%, unknown-attack BPCER remains 81.29%–86.67%; at APCER limits of 1% and 0.10%, it rises above 96.5% and 99.7%, respectively. Thus, none of the evaluated models provides an acceptable security-usability operating point under unknown PAIs. The ablation results further show that stronger known-attack performance does not guarantee generalization. Reducing patch size improves results for familiar PAIs but weakens unknownattack performance, suggesting over-reliance on local texture. Similarly, noise, blur, and compression should be evaluated using the threshold selected on clean validation data rather than by retuning on corrupted test samples. Center cropping avoids iris-segmentation latency and failures but retains sclera, eyelids, periocular texture, and acquisition background. Because ZACH-ViT uses global average pooling, this additional context may contain useful PAI evidence or dataset-specific shortcuts. Comparing center-cropped, iris-masked, and segmentation-aware inputs is therefore an important next step [15, 16]. Compactness must also be evaluated together with security behavior: PatchABMIL is the smallest and fastest model but has the highest unknown-attack APCER. Actual edge deployment should additionally measure memory, energy, and latency on target hardware [17, 18].
6
Conclusion
We evaluated compact scratch-trained models for iris PAD under PAI-driven domain shift and environmental degradation. ZACH-ViT gives the lowest unknown-attack and pooled-test APCER and D-EER, as well as the lowest unknown-attack BPCER at APCER ≤ 10% (81.29 ± 1.95%). It is therefore the strongest comparative compact model in this benchmark, but the absolute error rates do not support deployment under unknown PAIs. The study is limited to one benchmark, center-crop preprocessing, workstation-level efficiency measurements, and simple corruption tests. Future work should compare segmentation strategies, evaluate recent synthetic PAIs, cross-sensor and temporal conditions, adaptive threats, and ondevice performance, while reporting known and unknown PAIs separately under both transferred and security-constrained operating points.
References [1] Information technology, Vocabulary, Part 37: Biometrics. ISO/IEC 2382-37:2022. International Organization for Standardization and International Electrotechnical Commission. Geneva, Switzerland, 2022. [2] Information technology, Biometric presentation attack detection, Part 1: Framework. ISO/IEC 30107-1:2016. International Organization for Standardization. Geneva, Switzerland, 2016.
7
[3] David Yambay, Brian Becker, Naman Kohli, Adam Czajka, Kevin W. Bowyer, Stephanie Schuckers, Richa Singh, Mayank Vatsa, Afzel Noore, and Tieniu Tan. “LivDet Iris 2017 Iris Liveness Detection Competition 2017”. In: Proceedings of the IEEE International Joint Conference on Biometrics (IJCB). 2017, pp. 733–741. doi: 10.1109/BTAS.2017.8272763. [4] Athanasios Angelakis et al. ZACH-ViT: A Zero-Token Vision Transformer with ShuffleStrides Data Augmentation for Robust Lung Ultrasound Classification. arXiv preprint arXiv:2510.17650. 2025. [5] Athanasios Angelakis. ZACH-ViT: Regime-Dependent Inductive Bias in Compact Vision Transformers for Medical Imaging. arXiv preprint arXiv:2602.17929. 2026. doi: 10.48550/ arXiv.2602.17929. [6] Adam Czajka and Kevin W. Bowyer. “Presentation Attack Detection for Iris Recognition: An Assessment of the State-of-the-Art”. In: ACM Computing Surveys 51.4 (2018), 86:1– 86:35. doi: 10.1145/3232849. [7] James S. Doyle and Kevin W. Bowyer. “Robust Detection of Textured Contact Lenses in Iris Recognition Using BSIF”. In: IEEE Access 3 (2015), pp. 1672–1683. doi: 10.1109/ ACCESS.2015.2477470. [8] Naman Kohli, Daksha Yadav, Mayank Vatsa, Richa Singh, and Afzel Noore. “Synthetic Iris Presentation Attack Using iDCGAN”. In: Proceedings of the IEEE International Joint Conference on Biometrics (IJCB). 2017, pp. 674–680. doi: 10.1109/BTAS.2017.8272756. [9] Shivangi Yadav, Cunjian Chen, and Arun Ross. “Synthesizing Iris Images Using RaSGAN With Application in Presentation Attack Detection”. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). 2019, pp. 2422–2430. doi: 10.1109/CVPRW.2019.00297. [10] Shivangi Yadav and Arun Ross. “CIT-GAN: Cyclic Image Translation Generative Adversarial Network With Application in Iris Presentation Attack Detection”. In: Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision (WACV). 2021, pp. 2412–2421. [11] Shivangi Yadav and Arun Ross. “A Multi-domain Image Translative Diffusion StyleGAN for Iris Presentation Attack Detection”. In: Proceedings of the IEEE/CVF International Conference on Computer Vision Workshops (ICCVW). 2025, pp. 3747–3756. [12] Patrick Tinsley, Sourav Purnapatra, Mary Mitcheff, Andrew Boyd, Claire Crum, Kevin W. Bowyer, Patrick Flynn, Stephanie Schuckers, Adam Czajka, Meiling Fang, Naser Damer, Xin Liu, Cunjian Wang, Xintao Sun, Zhenan Chang, Xiaoming Li, Guodong Zhao, Juan E. Tapia, Christoph Busch, Claudio Aravena, and Daniel Schulz. Iris Liveness Detection Competition (LivDet-Iris). arXiv preprint arXiv:2310.04541. 2023. [13] Juan E. Tapia, L. J. González-Soler, and Christoph Busch. Towards Iris Presentation Attack Detection with Foundation Models. arXiv preprint arXiv:2501.06312. 2025. [14] Mary Mitcheff, Andrew Boyd, Patrick Tinsley, Adam Czajka, Kevin W. Bowyer, and Patrick J. Flynn. “Privacy-Safe Iris Presentation Attack Detection”. In: Proceedings of the IEEE International Joint Conference on Biometrics (IJCB). 2024. [15] Steven Hoffman, Renu Sharma, and Arun Ross. “Convolutional Neural Networks for Iris Presentation Attack Detection: Toward Cross-Dataset and Cross-Sensor Generalization”. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). 2018, pp. 1620–1628. doi: 10.1109/CVPRW.2018.00213. [16] Cunjian Chen and Arun Ross. “A Multi-task Convolutional Neural Network for Joint Iris Detection and Presentation Attack Detection”. In: Proceedings of the IEEE Winter Conference on Applications of Computer Vision Workshops (WACVW). 2018, pp. 44–51. doi: 10.1109/WACVW.2018.00011. 8
[17] Ali Almadan and Ajita Rattani. “Compact CNN Models for On-device Ocular-based User Recognition in Mobile Devices”. In: Proceedings of the IEEE Symposium Series on Computational Intelligence (SSCI). 2021, pp. 1–7. doi: 10.1109/SSCI50451.2021. 9660033. [18] Ji Lin, Wei-Ming Chen, Yujun Lin, John Cohn, Chuang Gan, and Song Han. “MCUNet: Tiny Deep Learning on IoT Devices”. In: Advances in Neural Information Processing Systems 33 (NeurIPS). 2020. [19] Athanasios Angelakis and Marta Gomez-Barrero. “Extending ZACH-ViT to Robust Medical Imaging: Corruption and Adversarial Stress Testing in Low-Data Regimes”. In: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). 2026, pp. 6114–6122. [20] Information technology, Biometric performance testing and reporting, Part 1: Principles and framework. ISO/IEC 19795-1:2021. International Organization for Standardization and International Electrotechnical Commission. Geneva, Switzerland, 2021. [21] Maximilian Ilse, Jakub M. Tomczak, and Max Welling. “Attention-based Deep Multiple Instance Learning”. In: Proceedings of the 35th International Conference on Machine Learning (ICML). Vol. 80. 2018, pp. 2127–2136. doi: 10.48550/arXiv.1802.04712. [22] Zhuchen Shao, Hao Bian, Yang Chen, Yifeng Wang, Jian Zhang, Xiangyang Ji, and Yongbing Zhang. “TransMIL: Transformer Based Correlated Multiple Instance Learning for Whole Slide Image Classification”. In: Advances in Neural Information Processing Systems 34 (NeurIPS). 2021, pp. 2136–2147. doi: 10.48550/arXiv.2106.00908.
9