Mauro Barni

dblp:06/4558 · DBLP profile ↗
← Back
158ranked-venue papers
51as first author
33since 2021 · last 2026
0000-0002-7368-0866ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 82 · 32 first-author · 8 since 2021Security and privacy · 53 · 9 first-author · 19 since 2021Artificial intelligence and machine learning · 15 · 4 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 first-authorTheory of computation · 3 · 2 first-authorSystems, architecture and hardware · 1 · 1 first-authorComputer networks · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Comparative Study of Adversarial Training and Randomized Smoothing for Robust AI-Generated Image Attribution
abstract
In this paper we explore two different approaches for designing AI-generated image attribution methods that are robust in adversarial settings, namely adversarial training (AT) and randomized smoothing (RS). While AT has been widely adopted in machine learning to improve the adversarial robustness of classifiers, its application to source image attribution is still unexplored. RS, on the other hand, has emerged as a method for developing deep learning classifiers with certified robustness, i.e., for which a certified level of robustness can be theoretically guaranteed, regardless of the specific manipulation causing the distortion. With the exception of a single prior study, its application to forensic tasks has not been previously explored. Experiments conducted on two datasets of AI-generated images show that both approaches achieve substantial adversarial robustness and exhibit a general resistance to common image manipulations. In particular, adversarial training provides stronger robustness against a broad range of post-processing operations, whereas randomized smoothing yields higher practical robustness against adversarial attacks.
Niccolò Pancino, Nasrin Malekzadeh Goradel, Mauro Barni, Benedetta Tondi
IH&MMSec4
2026 An efficient watermarking method for latent diffusion models via low-rank adaptation and dynamic loss weighting
Dongdong Lin, Yue Li 0041, Benedetta Tondi, Kaiqing Lin, Bin Li 0011, Mauro Barni
Expert Syst. Appl.6
2025 Colorization Network Watermarking in the CIE-Lab Domain
abstract
A possible solution to protect the copyright of generative models is to watermark the models so that any image generated by the models contain an invisible watermark, whose presence can be checked at a later stage for ownership verification or to trace back the image to the generator which produced it. In general, a Generative Adversarial Network (GAN) or a diffusion model can be watermarked by applying a frozen pretrained watermark decoder on top of the generator, and adding the watermark decoding loss term to the generator loss. In this paper, we propose a method to watermark image colorization models, that is models whose goal is to introduce plausible colors in grey-level images. The particular color domain wherein colorization models operate requires that the watermark is embedded in the image components that are actually affected by the colorization, avoiding to embed the watermark in the luminance channel, which is usually left unchanged by the colorization process. In particular, we show that the domain the watermark decoder is trained on impacts the performance of the network and better performance in terms of watermark accuracy and robustness can be achieved by training the decoder to extract the watermark bits from the chrominance components in the CIE-Lab space and use the decoder trained in this way to watermark the GAN model.
Alessio Chiovelli, Nischay Purnekar, Benedetta Tondi, Mauro Barni
ICASSP4
2025 WILD: a new in-the-Wild Image Linkage Dataset for synthetic image attribution
abstract
Synthetic image source attribution is an open challenge, with an increasing number of image generators being released yearly. The complexity and the sheer number of available generative techniques, as well as the scarcity of high-quality open source datasets of diverse nature for this task, make training and benchmarking synthetic image source attribution models very challenging. WILD1is a new in-the-Wild Image Linkage Dataset designed to provide a powerful training and benchmarking tool for synthetic image attribution models. The dataset is built out of a closed set of 10 popular commercial generators, which constitutes the training base of attribution models, and an open set of 10 additional generators, simulating a real-world in-the-wild scenario. Each generator is represented by 1,000 images, for a total of 10,000 images in the closed set and 10,000 images in the open set. Half of the images are post-processed with a wide range of operators. WILD allows benchmarking attribution models in a wide range of tasks, including closed and open set identification and verification, and robust attribution with respect to post-processing and adversarial attacks. Models trained on WILD are expected to benefit from the challenging scenario represented by the dataset itself. Moreover, an assessment of seven baseline methodologies on closed and open set attribution is presented, including robustness tests with respect to post-processing.
Pietro Bongini, Sara Mandelli, Andrea Montibeller, Mirko Casu, Orazio Pontorno, Claudio Vittorio Ragaglia, Luca Zanchetta, Mattia Aquilina, Taiba Majid Wani, Luca Guarnera, Benedetta Tondi, Giulia Boato, Paolo Bestagini, Irene Amerini, Francesco G. B. De Natale, Sebastiano Battiato, Mauro Barni
IJCNN17
2025 Semiotic-Based Construction of a Large Emotional Image Dataset with Neutral Samples
abstract
Image Visual Sentiment Analysis (VSA) requires the availability of large annotated datasets, whose construction presents many challenges. The necessity of gathering a large amount of labeled images contrasts with the rigorous, but lengthy, process required for manual annotation based on psychovisual experiments, and with the automatic gathering of large amounts of data roughly labeled based on the sentiment analysis of the text accompanying the images, like captions, tweets and tags. An additional limitation is the scarcity of high-quality datasets with a neutral class, which forces the images to be classified into emotions even when the observers show no emotional activation. In this work, we present a scalable methodology rooted in semiotics and art theory for the construction of a 3-class (positive, negative and neutral) VSA dataset, enabling the downloading of a desired quantity of images while maintaining labeling coherence and accuracy. Based on the proposed methodology, we introduce and make publicly available a VSA dataset of over 100,000 images. To validate the quality of the dataset, we used it to train several classifiers and compared their performance with those of classifiers trained on other datasets. The results, we got, show that the classifiers trained on the new dataset provide better performance when tested on independent datasets, including those commonly used for psycho-visual experiments.
Marco Blanchini, Giovanna Maria Dimitri, Lydia Abady, Benedetta Tondi, Tarcisio Lancioni, Mauro Barni
WACV6
2025 A CycleGAN Watermarking Method for Ownership Verification
abstract
Due to the widespread use and proliferation of Deep Neural Networks (DNNs), safeguarding their Intellectual Property Rights (IPR) has become increasingly important. This article proposes a method for watermarking a cyclic Generative Adversarial Network (GAN), specifically CycleGAN, to address the gap between the watermarking of conventional GAN models and cyclic GAN watermarking. The proposed method involves training a watermark decoder, which is then frozen and used to extract the watermark bits during the training of the CycleGAN model. The model is trained using specific loss functions that are optimized to achieve excellent performance on both the Image-to-Image Translation (I2IT) task and watermark embedding. Besides, a comprehensive theoretical and practical statistical analysis to verify the ownership of the model from the extracted watermark bits is given. At last, the model's robustness is evaluated against image post-processing, and further improved by fine-tuning the watermark decoder by applying data augmentation to the generated images before extracting the watermark bits. We also verify the robustness of the watermark to surrogate model attacks, carried out by accessing the watermarked model in a black-box modality. The experimental results demonstrate that the proposed method is effective and robust against image post-processing and can resist surrogate model attacks.
Dongdong Lin, Benedetta Tondi, Bin Li 0011, Mauro Barni
IEEE Trans. Dependable Secur. Comput.4
2025 Robust and Large-Payload DNN Watermarking via Fixed, Distribution-Optimized, Weights
abstract
The design of an effective multi-bit watermarking algorithm hinges upon finding a good trade-off between the three fundamental requirements forming the watermarking trade-off triangle, namely, robustness against network modifications, payload, and unobtrusiveness, ensuring minimal impact on the performance of the watermarked network. In this paper, we first revisit the nature of the watermarking trade-off triangle for the DNN case, then we exploit our findings to propose a white-box, multi-bit watermarking method achieving very large payload and strong robustness against network modification. In the proposed system, the weights hosting the watermark are set prior to training, making sure that their amplitude is large enough to bear the target payload and survive network modifications, notably retraining, and are left unchanged throughout the training process. The distribution of the weights carrying the watermark is theoretically optimised to ensure the secrecy of the watermark and make sure that the watermarked weights are indistinguishable from the non-watermarked ones. The proposed method can achieve outstanding performance, with no significant impact on network accuracy, including robustness against network modifications, retraining and transfer learning, while ensuring a payload which is out of reach of state of the art methods achieving a lower - or at most comparable - robustness.
Benedetta Tondi, Andrea Costanzo, Mauro Barni
IEEE Trans. Dependable Secur. Comput.3
2025 JMA: A General Algorithm to Craft Nearly Optimal Targeted Adversarial Examples
Benedetta Tondi, Wei Guo 0012, Niccolò Pancino, Mauro Barni
IEEE Trans. Inf. Forensics Secur.4
2025 BOSC: A Backdoor-Based Framework for Open Set Synthetic Image Attribution
abstract
With the continuous progress of AI technology, new generative architectures continuously appear, thus driving the attention of researchers towards the development of synthetic image attribution methods capable of working in open-set scenarios. Existing approaches focus on extracting highly discriminative features for closed-set architectures, increasing the confidence of the prediction when the samples come from closed-set models/architectures, or estimating the distribution of unknown samples, i.e., samples from unknown architectures. In this paper, we propose a novel framework for open set attribution of synthetic images, named BOSC (Backdoor-based Open Set Classification), that relies on backdoor injection to design a classifier with rejection option. BOSC works by deliberately including class-specific triggers inside a portion of the images in the training set to induce the network to establish a matching between in-set class features and trigger features. The behavior of the trained model with respect to samples containing a trigger is then exploited at inference time to perform sample rejection using an ad-hoc score. Experiments show that the proposed method has good performance, always surpassing the state-of-the-art. Robustness against image processing is also very good. Although we designed our method for the task of synthetic image attribution, the proposed framework is a general one and can be used for other image forensic applications.
Jun Wang 0061, Benedetta Tondi, Mauro Barni
IEEE Trans. Inf. Forensics Secur.3
2024 Improving the Robustness of Synthetic Images Detection by Means of Print and Scan Augmentation
abstract
A common approach to improve the robustness of synthetic image detectors against image post-processing is to augment the dataset the detectors are trained on by applying a selected pool of image processing operators. A list of commonly adopted image processing augmentations includes JPEG compression, geometric transformations, color adjustment, noise addition, and filtering. Robustness against image processing operators that are not included in the augmentation pool, however, is problematic since the detectors tend to overfit to the image operators used during training, without generalizing to other kinds of processing. In this paper, we introduce a new form of data augmentation based on the simulation of the Print & Scan (P&S) process. We argue that asking the synthetic image detector to still work after that an image has been printed and scanned, forces the detector to rely on robust features that can be detected even after other forms of processing. Given the impossibility of creating a large enough dataset of P&S images, we trained a CycleGAN network to simulate the P&S process and used it for data augmentation. The results we got by applying the above procedure to a detector trained to distinguish real and synthetic images in different domains show that P&S augmentation improves the robustness of the detectors even on images processed by operators that have not been used during training.
Nischay Purnekar, Lydia Abady, Benedetta Tondi, Mauro Barni
IH&MMSec4
2024 A siamese-based verification system for open-set architecture attribution of synthetic images
abstract
Despite the wide variety of methods developed for synthetic image attribution, most of them can only attribute images generated by models or architectures included in the training set and do not work with unknown architectures, hindering their applicability in real-world scenarios. In this paper, we propose a verification framework that relies on a Siamese Network to address the problem of open-set attribution of synthetic images to the architecture that generated them. We consider two different settings. In the first setting, the system determines whether two images have been produced by the same generative architecture or not. In the second setting, the system verifies a claim about the architecture used to generate a synthetic image, utilizing one or multiple reference images generated by the claimed architecture. The main strength of the proposed system is its ability to operate in both closed and open-set scenarios so that the input images, either the query and reference images, can belong to the architectures considered during training or not. Experimental evaluations encompassing various generative architectures such as GANs, diffusion models, and transformers, focusing on synthetic face image generation, confirm the excellent performance of our method in both closed and open-set settings, as well as its strong generalization capabilities.
Lydia Abady, Jun Wang 0061, Benedetta Tondi, Mauro Barni
Pattern Recognit. Lett.4
2024 Wide Flat Minimum Watermarking for Robust Ownership Verification of GANs
abstract
We propose a novel multi-bit box-free watermarking method for the protection of Intellectual Property Rights (IPR) of GANs with improved robustness against white-box model-level attacks like fine-tuning, pruning, quantization, and surrogate model attacks. The watermark is embedded by adding an extra watermarking loss term during GAN training, ensuring that the images generated by the GAN contain an invisible watermark that can be retrieved by a pre-trained watermark decoder. In order to improve the robustness against white-box model-level attacks, we make sure that the model converges to a wide flat minimum of the watermarking loss term, in such a way that any modification of the model parameters does not erase the watermark. To do so, we add random noise vectors to the parameters of the generator and require that the watermarking loss term is as invariant as possible with respect to the presence of noise. This procedure forces the generator to converge to a wide flat minimum of the watermarking loss. The proposed method is architecture- and dataset-agnostic, thus being applicable to many different generation tasks and models, as well as to CNN-based image processing architectures. We present the results of extensive experiments showing that the presence of the watermark has a negligible impact on the quality of the generated images, and proving the superior robustness of the watermark against model modification and surrogate model attacks.
Jianwei Fei, Zhihua Xia, Benedetta Tondi, Mauro Barni
IEEE Trans. Inf. Forensics Secur.4
2024 Universal Detection of Backdoor Attacks via Density-Based Clustering and Centroids Analysis
abstract
We propose a Universal Defence against backdoor attacks based on Clustering and Centroids Analysis (CCA-UD). The goal of the defence is to reveal whether a Deep Neural Network model is subject to a backdoor attack by inspecting the training dataset. CCA-UD first clusters the samples of the training set by means of density-based clustering. Then, it applies a novel strategy to detect the presence of poisoned clusters. The proposed strategy is based on a general misclassification behaviour observed when the features of a representative example of the analysed cluster are added to benign samples. The capability of inducing a misclassification error is a general characteristic of poisoned samples, hence the proposed defence is attack-agnostic. This marks a significant difference with respect to existing defences, that, either can defend against only some types of backdoor attacks, or are effective only when some conditions on the poisoning ratio or the kind of triggering signal used by the attacker are satisfied. Experiments carried out on several classification tasks and network architectures, considering different types of backdoor attacks (with either clean or corrupted labels), and triggering signals, including both global and local triggering signals, as well as sample-specific and source-specific triggers, reveal that the proposed method is very effective to defend against backdoor attacks in all the cases, always outperforming the state of the art techniques.
Wei Guo 0012, Benedetta Tondi, Mauro Barni
IEEE Trans. Inf. Forensics Secur.3
2024 Constructing an Intrinsically Robust Steganalyzer via Learning Neighboring Feature Relationships and Self-Adversarial Adjustment
abstract
The effectiveness of deep learning-based steganalyzers is significantly compromised by adversarial steganography. In response to this challenge, recent efforts have been devoted to identifying distinct traces of adversarial perturbations, yet they have overlooked the inherently adversarial robustness required in steganalyzers. This paper aims to develop a steganalytic model that defends against adversarial steganography by increasing the difficulty of generating adversarial stego images. To achieve this objective, the techniques of learning neighboring feature relationships and self-adversarial adjustment are proposed with three essential modules. The first one, named K-times Dropout Neighboring Feature Transformer (KDNFT), is designed to accept a set of neighboring features obtained by dropout as input. Based on the finding that K-times dropout neighboring features have different distributions for covers and adversarial stegos, KDNFT effectively learns to exploit the relationships among these features for adversarial steganalysis. To facilitate adversarial training, which is an effective way to improve intrinsic robustness, the second module called Pseudo Adversarial Stego Generator (PASG) is proposed to synthesize samples for training. The third module is a Test-time Active Perturbation (TAP) module that adjusts the results of adversarial stego samples close to the decision boundary in a self-adversarial way. Extensive experiments demonstrate that our method achieves improvements in steganalyzing various kinds of adversarial steganographic methods.
Kaiqing Lin, Bin Li 0011, Weixiang Li, Mauro Barni, Benedetta Tondi, Xulong Liu
IEEE Trans. Inf. Forensics Secur.4
2024 Covert Task Embedding: Turning a DNN Into an Insider Agent Leaking Out Private Information
abstract
We present the covert task embedding (CTE) attack, a new general threat affecting deep neural networks (DNNs). The new attack consists in hiding a malicious privacy-sensitive task within a seemingly innocuous network, in such a way that the result of the malicious task is delivered together with the legitimate output in a stealthy way. The result of the covert task is further protected by requiring that its extraction depends on a secret key shared by the embedder and the detector. We demonstrate the feasibility of the CTE attack in various settings, wherein a face-based age estimation DNN is trained in such a way as to also detect the gender (binary classification task) or ethnicity (multiclassification task) of the framed individual and stealthily pass along such information together with the estimated age. The results of the experiments we carried out show that, in all cases, the gender and ethnicity information can be reliably extracted without impairing the accuracy of the age estimation functionality. Despite the simplicity of the estting considered in the brief, our experiments show the feasibility of the CTE attack, thus calling for the development of suitable remedies against it.
Li Li 0103, Weiming Zhang 0001, Mauro Barni
IEEE Trans. Neural Networks Learn. Syst.3
2023 A Siamese Based System for City Verification
abstract
Image geolocalization is receiving increasing attention due to its importance in several applications, such as image retrieval, criminal investigations and fact-checking. Previous works focused on several instances of image geolocalization including place recognition, GPS coordinates estimation and country recognition. In this paper, we tackle an even more challenging problem, which is recognizing the city where an image has been taken. Due to the vast number of cities in the world, we cast the problem as a verification problem, whereby the system has to decide whether a certain image has been taken in a given city or not. In particular, we present a system that given a query image and a small set of images taken in a target city, decides if the query image has been shot in the target city or not. To allow the system to handle the case of images, taken in cities that have not been used during training, we use a Siamese network based on Vision Transformer as a backbone. The experiments we run prove the validity of the proposed system which outperforms solutions based on state-of-the-art techniques, even in the challenging case of images shot in different cities of the same country.
Omran Alamayreh, Jun Wang 0061, Giovanna Maria Dimitri, Benedetta Tondi, Mauro Barni
ECAI5
2023 Which Country is This Picture From? New Data and Methods For Dnn-Based Country Recognition
abstract
Recognizing the country where a picture has been taken has many potential applications, such as identification of fake news and prevention of disinformation campaigns. Previous works focused on the estimation of the geo-coordinates where a picture has been taken. Yet, recognizing in which country an image was taken could be more critical, from a semantic and forensic point of view, than estimating its spatial coordinates. In the above framework, this paper provides two contributions. First, we introduce the VIPPGeo dataset, containing 3.8 million geo-tagged images. Secondly, we used the dataset to train a model casting the country recognition problem as a classification problem. The experiments show that our model provides better results than the current state of the art. Notably, we found that asking the network to identify the country provides better results than estimating the geo-coordinates and then tracing them back to the country where the picture was taken.
Omran Alamayreh, Giovanna Maria Dimitri, Jun Wang 0061, Benedetta Tondi, Mauro Barni
ICASSP5
2023 Classification of Synthetic Facial Attributes by Means of Hybrid Classification/Localization Patch-Based Analysis
abstract
Facial attributes editing, that is the manipulation of some specific attributes of a face image, is a new trend in the generation of synthetic images by GANs. Several recent studies have shown the possibility to detect the synthetic nature of such images by training a DL-based binary classifier. At the same time, the question about the specific face attributes that have been altered is typically disregarded, yet this may be a crucial information for forensic analysts. In this paper, we propose a new architecture whose objective is to identify the altered facial attributes of synthetic face images. To do so, we developed a hybrid classification-and-localization architecture. The local and global features are first extracted from the full image and from specific image patches, and then merged by using an attentional feature fusion module. The extensive experiments we have carried out involving 19 different facial attributes, manipulated by a StyleGAN2 network, show the good accuracy of the proposed method and its robustness against several image post-processing operators.
Jun Wang 0061, Benedetta Tondi, Mauro Barni
ICASSP3
2023 Universal BlackMarks: Key-Image-Free Blackbox Multi-Bit Watermarking of Deep Neural Networks
abstract
Existing methods for Deep Neural Networks (DNN) watermarking either require accessing the internal parameters of the DNN models (white-box watermarking), or rely on backdooring to enforce a desired behavior of the model when the DNN is fed with a specific set of key input images (black-box watermarking). In this letter, we propose a black-box multi-bit DNN watermarking algorithm, suitable for multiclass classification networks, whereby the presence of the watermark can be retrieved from the output of the network in correspondence toanyinput. To read the watermark, we first apply a power function to the softmax output of the DNN model to map it from an impulse-like to a smooth distibution. Then, we extract the watermark bits by projecting the output of the DNN onto a pseudorandom key vector. Watermark embedding is achieved by adding a proper regularizer term to the training loss. The effectiveness of the proposed method is demonstrated by applying it to various network architectures working on different datasets. The experimental results demonstrate the possibility to embed a robust watermark into the output of the host DNN with a negligible impact on the accuracy of the original task.
Li Li 0103, Weiming Zhang 0001, Mauro Barni
IEEE Signal Process. Lett.3
2023 A Temporal Chrominance Trigger for Clean-Label Backdoor Attack Against Anti-Spoof Rebroadcast Detection
abstract
We propose a stealthy clean-label video backdoor attack against Deep Learning (DL)-based models aiming at detecting a particular class of spoofing attacks, namely video rebroadcast attacks. The injected backdoor does not affect spoofing detection in normal conditions, but induces a misclassification in the presence of a specific triggering signal. The proposed backdoor relies on a temporal trigger altering the average chrominance of the video sequence. The backdoor signal is designed by taking into account the peculiarities of the Human Visual System (HVS) to reduce the visibility of the trigger, thus increasing the stealthiness of the backdoor. To force the network to look at the presence of the trigger in the challenging clean-label scenario, we choose the poisoned samples used for the injection of the backdoor following a so-called Outlier Poisoning Strategy (OPS). According to OPS, the triggering signal is inserted in the training samples that the network finds more difficult to classify. The effectiveness of the proposed backdoor attack and its generality are validated experimentally on different datasets and anti-spoofing rebroadcast detection architectures.
Wei Guo 0012, Benedetta Tondi, Mauro Barni
IEEE Trans. Dependable Secur. Comput.3
2022 Detection and Localization of GAN Manipulated Multi-spectral Satellite Images
abstract
Owing to their realistic features and continuous improvements, images manipulated by Generative Adversarial Network (GAN) have become a compelling research topic.In this paper, we apply detection and localization to GAN manipulated images by means of models, based on EfficientNet-B4 architectures.Detection is tested on multiple generated multi-spectral datasets from several world regions and different GAN architectures, whereas localization is tested on an inpainted images dataset of sizes 2048×2048×13.The results obtained for both detection and localization are shown to be promising.
Lydia Abady, Giovanna Maria Dimitri, Mauro Barni
ESANN3
2022 Exploiting temporal information to prevent the transferability of adversarial examples against deep fake detectors
abstract
The diffusion of AI tools capable of generating realistic DeepFakes (DF) videos raises serious threats to face-based biometric recognition systems. For this reason, several detectors based on Deep Neural Networks (DNNs) have been developed to distinguish between real and DF videos. Despite their good performance, these methods suffer from vulnerability to adversarial attacks. In this paper, we argue that it is possible to increase the resilience of DNN-based DF detectors against black-box adversarial attacks by exploiting the temporal information contained in the video. By using such information, in fact, the transferability of adversarial examples from a source to a target model is significantly decreased, making it difficult to launch an attack without accessing the target network. To back this claim, we trained two convolutional neural networks (CNNs) to detect DF videos, and measured their robustness against black-box, transfer-based, attacks. We also trained two detectors by adding to the CNNs a long short-term memory (LSTM) layer to extract temporal information. Then, we measured the transferability of adversarial examples to-wards the LSTM-networks. The results we got suggest that the methods based on temporal information are less prone to black-box attacks.
Dongdong Lin, Benedetta Tondi, Bin Li 0011, Mauro Barni
IJCB4
2022 Improving Cost Learning for JPEG Steganography by Exploiting JPEG Domain Knowledge
abstract
Although significant progress has been achieved recently in automatic learning of steganographic cost, the existing methods designed for spatial images cannot be directly applied to JPEG images which are more common media in daily life. The difficulties of migration are mainly caused by the characteristics of the$8\times 8$DCT mode structure. To address the issue, in this paper we extend an existing automatic cost learning scheme to JPEG, where the proposed scheme called JEC-RL (JPEG Embedding Cost with Reinforcement Learning) is explicitly designed to tailor the JPEG DCT structure. It works with the embedding action sampling mechanism under reinforcement learning, where a policy network learns the optimal embedding policies via maximizing the rewards provided by an environment network. Following a domain-transition design paradigm, the policy network is composed of three modules, i.e., pixel-level texture complexity evaluation module, DCT feature extraction module, and mode-wise rearrangement module. These modules operate in serial, gradually extracting useful features from a decompressed JPEG image and converting them into embedding policies for DCT elements, while considering JPEG characteristics including inter-block and intra-block correlations simultaneously. The environment network is designed in a gradient-oriented way to provide stable reward values by using a wide architecture equipped with a fixed preprocessing layer with$8\times 8$DCT basis filters. Extensive experiments and ablation studies demonstrate that the proposed method can achieve good security performance for JPEG images against both advanced feature-based and modern CNN-based steganalyzers.
Weixuan Tang 0004, Bin Li 0011, Mauro Barni, Jin Li 0002, Jiwu Huang
IEEE Trans. Circuits Syst. Video Technol.3
2021 DNN Watermarking: Four Challenges and a Funeral
abstract
The demand for methods to protect the Intellectual Property Rights (IPR) associated to Deep Neural Networks (DNNs) is rising. Watermarking has been recently proposed as a way to protect the IPR of DNNs and track their usages. Although a number of techniques for media watermarking have been proposed and developed over the past decades, their direct translation to DNN watermarking faces the problem of the embedding being carried out on functionals instead of signals. This originates differences not only in the way performance, robustness and unobtrusiveness are measured, but also on the embedding domain, since there is the possibility of hiding information in the model behavior. In this paper, we discuss these dissimilarities that lead to a DNN-specific taxonomy of watermarking techniques. Then, we present four challenges specific to DNN watermarking that, for their practical importance and theoretical interest, should occupy the agenda of researchers in the next years. Finally, we discuss some bad practices that negatively affected research in media watermarking and that should not be repeated in the case of DNNs.
Mauro Barni, Fernando Pérez-González, Benedetta Tondi
IH&MMSec1
2021 MasterFace Watermarking for IPR Protection of Siamese Network for Face Verification
Wei Guo 0012, Benedetta Tondi, Mauro Barni
IWDW3
2021 A Feature-Map-Based Large-Payload DNN Watermarking Algorithm
Yue Li 0041, Lydia Abady, Hongxia Wang 0001, Mauro Barni
IWDW4
2021 A survey of Deep Neural Network watermarking techniques
Yue Li 0041, Hongxia Wang 0001, Mauro Barni
Neurocomputing3
2021 Spread-Transform Dither Modulation Watermarking of Deep Neural Network
Yue Li 0041, Benedetta Tondi, Mauro Barni
J. Inf. Secur. Appl.3
2021 A Master Key backdoor for universal impersonation attack against DNN-based face verification
Wei Guo 0012, Benedetta Tondi, Mauro Barni
Pattern Recognit. Lett.3
2021 Adversarial Kendall's Model Towards Containment of Distributed Cyber-Threats
abstract
This work examines propagation of cyber-threats over networks under an adversarial formulation. Exploiting Kendall's birth-death-immigration model, we propose an analytical framework to describe the stochastic dynamics of cyber-threat propagation in a collection of heterogeneous sub-networks characterized by different attributes. We propose two formalisations of the problem as zero-sum games involving two adversaries: an attacker, who launches cyber-threats across the distinct sub-networks; and a defender, who tries to mitigate the threats by delivering suitable countermeasures. According to the first formalisation, the interplay between the defender and the attacker is modelled as a Stackelberg leader-follower game, while the second formalisation considers a strategic game wherein the two contenders play simultaneously without knowing the choice of the other player. We derive the equilibrium strategies for both versions of the game, and discuss a number of insightful interplays and ramifications of the different equilibrium points for the problem at hand. The equilibrium strategies depend on three fundamental attributes: i) the available resource budget of the attacker and the defender; ii) the capacity of the legitimate nodes to (unintentionally) forward the threat across the network, after they have been compromised during the propagation of the threat; iii) the intrinsic characteristics of the sub-networks, namely, their immunity to the attacks, their inertia in responding to the countermeasures, and the importance of the individual sub-networks. The relevance of the proposed solution is illustrated through a series of examples and numerical simulations.
Paolo Addesso, Mauro Barni, Mario Di Mauro, Vincenzo Matta
IEEE Trans. Inf. Forensics Secur.2
2021 Copy Move Source-Target Disambiguation Through Multi-Branch CNNs
abstract
We propose a method to identify the source and target regions of a copy-move forgery so allow a correct localisation of the tampered area. First, we cast the problem into a hypothesis testing framework whose goal is to decide which region between the two nearly-duplicate regions detected by a generic copy-move detector is the original one. Then we design a multi-branch CNN architecture that solves the hypothesis testing problem by learning a set of features capable to reveal the presence of interpolation artefacts and boundary inconsistencies in the copy-moved area. The proposed architecture, trained on a synthetic dataset explicitly built for this purpose, achieves good results on copy-move forgeries from both synthetic and realistic datasets. Based on our tests, the proposed disambiguation method can reliably reveal the target region even in realistic cases where an approximate version of the copy-move localization mask is provided by a state-of-the-art copy-move detection algorithm.
Mauro Barni, Quoc-Tin Phan, Benedetta Tondi
IEEE Trans. Inf. Forensics Secur.1
2021 Image Splicing Detection, Localization and Attribution via JPEG Primary Quantization Matrix Estimation and Clustering
abstract
Detection of inconsistencies of double JPEG artifacts across different image regions is often used to detect local image manipulations, like image splicing, and to localize them. In this paper, we move one step further, proposing an end-to-end system that, in addition to detecting and localizing spliced regions, can also distinguish regions coming from different donor images. We assume that both the spliced regions and the background image have undergone a double JPEG compression, and use a local estimate of the primary quantization matrix to distinguish between spliced regions taken from different sources. To do so, we cluster the image blocks according to the estimated primary quantization matrix and refine the result by means of morphological reconstruction. The proposed method can work in a wide variety of settings including aligned and non-aligned double JPEG compression, and regardless of whether the second compression is stronger or weaker than the first one. We validated the proposed approach by means of extensive experiments showing its superior performance with respect to baseline methods working in similar conditions.
Yakun Niu, Benedetta Tondi, Yao Zhao 0001, Mauro Barni
IEEE Trans. Inf. Forensics Secur.5
2021 An Automatic Cost Learning Framework for Image Steganography Using Deep Reinforcement Learning
abstract
Automatic cost learning for steganography based on deep neural networks is receiving increasing attention. Steganographic methods under such a framework have been shown to achieve better security performance than methods adopting hand-crafted costs. However, they still exhibit some limitations that prevent a full exploitation of their potentiality, including using a function-approximated neural-network-based embedding simulator and a coarse-grained optimization objective without explicitly using pixel-wise information. In this article, we propose a new embedding cost learning framework called SPAR-RL (Steganographic Pixel-wise Actions and Rewards with Reinforcement Learning) that overcomes the above limitations. In SPAR-RL, an agent utilizes a policy network which decomposes the embedding process into pixel-wise actions and aims at maximizing the total rewards from a simulated steganalytic environment, while the environment employs an environment network for pixel-wise reward assignment. A sampling process is utilized to emulate the message embedding of an optimal embedding simulator. Through the iterative interactions between the agent and the environment, the policy network learns a secure embedding policy which can be converted into pixel-wise embedding costs for practical message embedding. Experimental results demonstrate that the proposed framework achieves state-of-the-art security performance against various modern steganalyzers, and outperforms existing cost learning frameworks with regard to learning stability and efficiency.
Weixuan Tang 0004, Bin Li 0011, Mauro Barni, Jin Li 0002, Jiwu Huang
IEEE Trans. Inf. Forensics Secur.3
2020 Effectiveness of Random Deep Feature Selection for Securing Image Manipulation Detectors Against Adversarial Examples
abstract
We investigate if the random feature selection approach proposed in [1] to improve the robustness of forensic detectors to targeted attacks, can be extended to detectors based on deep learning features. In particular, we study the transferability of adversarial examples targeting an original CNN image manipulation detector to other detectors (a fully connected neural network and a linear SVM) that rely on a random subset of the features extracted from the flatten layer of the original network. The results we got by considering three image manipulation detection tasks (resizing, median filtering and adaptive histogram equalization), two original network architectures and three classes of attacks, show that feature randomization helps to hinder attack transferability, even if, in some cases, simply changing the architecture of the detector, or even retraining the detector is enough to prevent the transferability of the attacks.
Mauro Barni, Ehsan Nowroozi, Benedetta Tondi
ICASSP1
2020 Backdooring Deep Learning Architectures: Threats and (some) Opportunities
Mauro Barni
ICISSP1
2020 Adversarial examples for replay attacks against CNN-based face recognition with anti-spoofing capability
Benedetta Tondi, Mauro Barni
Comput. Vis. Image Underst.3
2020 Improving the security of image manipulation detection through one-and-a-half-class multiple classification
Mauro Barni, Ehsan Nowroozi, Benedetta Tondi
Multim. Tools Appl.1
2020 Challenging the Adversarial Robustness of DNNs Based on Error-Correcting Output Codes
abstract
The existence of adversarial examples and the easiness with which they can be generated raise several security concerns with regard to deep learning systems, pushing researchers to develop suitable defence mechanisms. The use of networks adopting error-correcting output codes (ECOC) has recently been proposed to counter the creation of adversarial examples in a white-box setting. In this paper, we carry out an in-depth investigation of the adversarial robustness achieved by the ECOC approach. We do so by proposing a new adversarial attack specifically designed for multilabel classification architectures, like the ECOC-based one, and by applying two existing attacks. In contrast to previous findings, our analysis reveals that ECOC-based networks can be attacked quite easily by introducing a small adversarial perturbation. Moreover, the adversarial examples can be generated in such a way to achieve high probabilities for the predicted target class, hence making it difficult to use the prediction confidence to detect them. Our findings are proven by means of experimental results obtained on MNIST, CIFAR-10, and GTSRB classification tasks.
Benedetta Tondi, Xixiang Lv, Mauro Barni
Secur. Commun. Networks4
2020 CNN-based steganalysis and parametric adversarial embedding: A game-theoretic framework
Benedetta Tondi, Bin Li 0011, Mauro Barni
Signal Process. Image Commun.4
2020 Primary Quantization Matrix Estimation of Double Compressed JPEG Images via CNN
abstract
Available model-based techniques for the estimation of the primary quantization matrix in double-compressed JPEG images work only under specific conditions regarding the relationship between the first and second compression quality factors, and the alignment of the first and second JPEG compression grids. In this paper, we propose a single CNN-based estimation technique that can work under a wide range of settings. We do so, by adapting a dense CNN network to the problem at hand. Particular attention is paid to the choice of the loss function. Experimental results highlight several advantages of the new method, including: i) capability of working under very general conditions, ii) improved performance in terms of MSE and Accuracy, especially in the non-aligned case, iii) better spatial resolution due to the ability of providing good results also on small image patches.
Yakun Niu, Benedetta Tondi, Yao Zhao 0001, Mauro Barni
IEEE Signal Process. Lett.4
2020 Identification of VoIP Speech With Multiple Domain Deep Features
abstract
Identifying whether a phone call comes from VoIP (Voice over Internet Protocol) is a challenging but less-investigated audio forensic issue. As shown in a previous study, existing feature based methods do not work well. In this paper, we propose a robust data-driven approach, called CNN-MLS (convolutional neural network based multi-domain learning scheme), to distinguish VoIP calls from mobile phone calls. To better explore the differences between VoIP and mobile phone calls, we first process data with high-pass filtering, and then extract deep features from both temporal domain and spectral domain. Two CNN architectures are designed for accepting data from respective domains, and some tricks such as auxiliary classifiers and individual subnet training are used for accelerating network convergence. The deep features are finally fused in a classification module for identifying the phone call type. The proposed method is evaluated on VPCID (VoIP Phone Call Identification Database) dataset, under various testing conditions. We pay particular attention to tests on data belonging to a source mismatched with the training sources. Experimental results show that, compared with existing methods, our method can achieve satisfactory and better accuracy on two-second-long inputs, implying that an alert may be activated shortly after a VoIP call is made.
Yuankun Huang, Bin Li 0011, Mauro Barni, Jiwu Huang
IEEE Trans. Inf. Forensics Secur.3
2020 Video Integrity Verification and GOP Size Estimation Via Generalized Variation of Prediction Footprint
abstract
The Variation of Prediction Footprint (VPF), formerly used in video forensics for double compression detection and GOP size estimation, is comprehensively investigated to improve its acquisition capabilities and extend its use to video sequences that contain bi-directional frames (B-frames). By relying on a universal rate-distortion analysis applied to a generic double compression scheme, we first explain the rationale behind the presence of the VPF in double compressed videos and then justify the need of exploiting a new source of information such as the motion vectors, to enhance the VPF acquisition process. Finally, we describe the shifted VPF induced by the presence of B-frames and detail how to compensate the shift to avoid misguided GOP size estimations. The experimental results show that the proposed Generalized VPF (G-VPF) technique outperforms the state of the art, not only in terms of double compression detection and GOP size estimation, but also in reducing computational time.
David Vazquez-Padin, Marco Fontani, Dasara Shullani, Fernando Pérez-González, Alessandro Piva, Mauro Barni
IEEE Trans. Inf. Forensics Secur.6
2019 On the Transferability of Adversarial Examples against CNN-based Image Forensics
abstract
Recent studies have shown that Convolutional Neural Networks (CNN) are relatively easy to attack through the generation of so called adversarial examples. Such vulnerability also affects CNN-based image forensic tools. Research in deep learning has shown that adversarial examples exhibit a certain degree of transferability, i.e., they maintain part of their effectiveness even against CNN models other than the one targeted by the attack. This is a very strong property undermining the usability of CNN's in security-oriented applications. In this paper, we investigate if attack transferability also holds in image forensics applications. With specific reference to the case of manipulation detection, we analyse the results of several experiments considering different sources of mismatch between the CNN used to build the adversarial examples and the one adopted by the forensic analyst. The analysis ranges from cases in which the mismatch involves only the training dataset, to cases in which the attacker and the forensic analyst adopt different architectures. The results of our experiments show that, in the majority of the cases, the attacks are not transferable, thus easing the design of proper countermeasures at least when the attacker does not have a perfect knowledge of the target detector.
Mauro Barni, Kassem Kallas, Ehsan Nowroozi, Benedetta Tondi
ICASSP1
2019 A New Backdoor Attack in CNNS by Training Set Corruption Without Label Poisoning
abstract
Backdoor attacks against CNNs represent a new threat against deep learning systems, due to the possibility of corrupting the training set so to induce an incorrect behaviour at test time. To avoid that the trainer recognises the presence of the corrupted samples, the corruption of the training set must be as stealthy as possible. Previous works have focused on the stealthiness of the perturbation injected into the training samples, however they all assume that the labels of the corrupted samples are also poisoned. This greatly reduces the stealthiness of the attack, since samples whose content does not agree with the label can be identified by visual inspection of the training set or by running a pre-classification step. In this paper we present a new backdoor attack without label poisoning Since the attack works by corrupting only samples of the target class, it has the additional advantage that it does not need to identify beforehand the class of the samples to be attacked at test time. Results obtained on the MNIST digits recognition task and the traffic signs classification task show that backdoor attacks without label poisoning are indeed possible, thus raising a new alarm regarding the use of deep learning in security-critical applications.
Mauro Barni, Kassem Kallas, Benedetta Tondi
ICIP1
2019 Luminance-based video backdoor attack against anti-spoofing rebroadcast detection
abstract
We introduce a new backdoor attack against a deep-learning video rebroadcast detection network. In addition to the difficulties of working with video signals rather than still images, injecting a backdoor into a deep learning model for rebroadcast detection presents the additional problem that the backdoor must survive the digital-to-analog and analog-to-digital conversion associated to video rebroadcast. To cope with this problem, we have built a backdoor attack that works by varying the average luminance of video frames according to a predesigned sinusoidal function. In this way, robustness against geometric transformation is automatically achieved, together with a good robustness against luminance transformations associated to display and recapture, like Gamma correction and white balance. Our experiments demonstrate the effectiveness of the proposed backdoor attack, especially when the attack is carried out by also corrupting the labels of the attacked training samples.
Abhir Bhalerao, Kassem Kallas, Benedetta Tondi, Mauro Barni
MMSP4
2019 Secure Detection of Image Manipulation by Means of Random Feature Selection
abstract
We address the problem of data-driven image manipulation detection in the presence of an attacker with limited knowledge about the detector. Specifically, we assume that the attacker knows the architecture of the detector, the training data, and the class of features V the detector can rely on. In order to get an advantage in his race of arms with the attacker, the analyst designs the detector by relying on a subset of features chosen at random in V. Given its ignorance about the exact feature set, the adversary attacks a version of the detector based on the entire feature set. In this way, the effectiveness of the attack diminishes since there is no guarantee that attacking a detector working in the full feature space will result in a successful attack against the reduced-feature detector. We theoretically prove that, thanks to random feature selection, the security of the detector significantly increases at the expense of a negligible loss of performance in the absence of attacks. We also provide an experimental validation of the proposed procedure by focusing on the detection of two specific kinds of image manipulations, namely adaptive histogram equalization and median filtering. The experiments confirm the gain in security at the expense of a negligible loss of performance in the absence of attacks.
Benedetta Tondi, Xiaolong Li 0001, Yao Zhao 0001, Mauro Barni
IEEE Trans. Inf. Forensics Secur.6
2019 CNN-Based Adversarial Embedding for Image Steganography
abstract
Steganographic schemes are commonly designed in a way to preserve image statistics or steganalytic features. Since most of the state-of-the-art steganalytic methods employ a machine learning (ML)-based classifier, it is reasonable to consider countering steganalysis by trying to fool the ML classifiers. However, simply applying perturbations on stego images as adversarial examples may lead to the failure of data extraction and introduce unexpected artifacts detectable by other classifiers. In this paper, we present a steganographic scheme with a novel operation called adversarial embedding (ADV-EMB), which achieves the goal of hiding a stego message while at the same time fooling a convolutional neural network (CNN)-based steganalyzer. The proposed method works under the conventional framework of distortion minimization. In particular, ADV-EMB adjusts the costs of image elements modifications according to the gradients back propagated from the target CNN steganalyzer. Therefore, modification direction has a higher probability to be the same as the inverse sign of the gradient. In this way, the so-called adversarial stego images are generated. Experiments demonstrate that the proposed steganographic scheme achieves better security performance against the target adversary-unaware steganalyzer by increasing its missed detection rate. In addition, it deteriorates the performance of other adversary-aware steganalyzers, opening the way to a new class of modern steganographic schemes capable of overcoming powerful CNN-based steganalysis.
Weixuan Tang 0004, Bin Li 0011, Shunquan Tan, Mauro Barni, Jiwu Huang
IEEE Trans. Inf. Forensics Secur.4
2018 Cnn-Based Detection of Generic Contrast Adjustment with Jpeg Post-Processing
abstract
Detection of contrast adjustments in the presence of JPEG post processing is known to be a challenging task. JPEG post processing is often applied innocently, as JPEG is the most common image format, or it may correspond to a laundering attack, when it is purposely applied to erase the traces of manipulation. In this paper, we propose a CNN-based detector for generic contrast adjustment, which is robust to JPEG compression. The proposed system relies on a patch-based Convolutional Neural Network (CNN), trained to distinguish pristine images from contrast adjusted images, for some selected adjustment operators of different nature. Robustness to JPEG compression is achieved by training the CNN with JPEG examples, compressed over a range of Quality Factors (QFs). Experimental results show that the detector works very well and scales well with respect to the adjustment type, yielding very good performance under a large variety of unseen tonal adjustments.
Mauro Barni, Andrea Costanzo, Ehsan Nowroozi, Benedetta Tondi
ICIP1
2018 An Improved Statistic for the Pooled Triangle Test Against PRNU-Copy Attack
abstract
We propose a new statistic to improve the pooled version of the triangle test used to combat the fingerprint-copy counter-forensic attack against PRNU-based camera identification [1]. As opposed to the original version of the test, the new statistic exploits the one-tail nature of the test, weighting differently positive and negative deviations from the expected value of the correlation between the image under analysis and the candidate images, i.e., those image suspected to have been used during the attack. The experimental results confirm the superior performance of the new test, especially when the conditions of the test are challenging ones, that is when the number of images used for the fingerprint-copy attack is large and the size of the image under test is small.
Mauro Barni, Hector Santoyo-Garcia, Benedetta Tondi
IEEE Signal Process. Lett.1
2018 Adversarial Source Identification Game With Corrupted Training
abstract
We study a variant of the source identification game with training data in which part of the training data is corrupted by an attacker. In the addressed scenario, the defender aims at deciding whether a test sequence has been drawn according to a discrete memoryless source X ~ PX, whose statistics are known to him through the observation of a training sequence generated by X. In order to undermine the correct decision under the alternative hypothesis that the test sequence has not been drawn from X, the attacker can modify a sequence produced by a source Y ~ PYup to a certain distortion and corrupt the training sequence either by adding some fake samples or by replacing some samples with fake ones. We derive the unique rationalizable equilibrium of the two versions of the game in the asymptotic regime and by assuming that the defender makes his decision by relying only on the first order statistics of the test and the training sequences. By mimicking Stein's lemma, we derive the best achievable performance for the defender when the first type error probability is required to tend to zero exponentially fast with an arbitrarily small, yet positive, error exponent. We then use such a result to analyze the ultimate distinguishability of any two sources as a function of the allowed distortion and the fraction of corrupted samples injected into the training sequence.
Mauro Barni, Benedetta Tondi
IEEE Trans. Inf. Theory1
2017 Aligned and non-aligned double JPEG detection using convolutional neural networks
Mauro Barni, Luca Bondi, Nicolò Bonettini, Paolo Bestagini, Andrea Costanzo, Marco Maggini, Benedetta Tondi, Stefano Tubaro
J. Vis. Commun. Image Represent.1
2017 Farewell Message
abstract
Three years have gone since I started my term as Editor-in-Chief (EiC) of the IEEE Transactions on Information Forensics and Security (T-IFS). These have been tough but exciting years. Tough because taking care of a journal like T-IFS requires great dedication and time availability. Exciting because in these years the popularity of the journal has continued to increase and the topics falling under the wide umbrella of Information Forensics and Security (IFS) have been receiving an increasing attention by our society and now are constantly sitting on top of the agenda of governments, public and private companies, research institutions, etc. Most of all, these have been exciting years because I got in touch with a huge number of scholars, researchers, and practitioners throughout the world, belonging to a large number of different communities dealing with disciplines far away from my expertise. Serving the IFS community as EiC of T-IFS enriched me beyond any expectations I had.
Mauro Barni
IEEE Trans. Inf. Forensics Secur.1
2017 Smart Detection of Line-Search Oracle Attacks
Benedetta Tondi, Pedro Comesaña Alfaro, Fernando Pérez-González, Mauro Barni
IEEE Trans. Inf. Forensics Secur.4
2016 A Game-Theoretic Framework for Optimum Decision Fusion in the Presence of Byzantines
abstract
Optimum decision fusion in the presence of malicious nodes - often referred to as Byzantines - is hindered by the necessity of exactly knowing the statistical behavior of Byzantines. In this paper, we focus on a simple, yet widely adopted, setup in which a fusion center (FC) is asked to make a binary decision about a sequence of system states by relying on the possibly corrupted decisions provided by local nodes. We propose a game-theoretic framework, which permits to exploit the superior performance provided by optimum decision fusion, while limiting the amount of a priori knowledge required. We use numerical simulations to derive the optimum behavior of the FC and the Byzantines in a game-theoretic sense, and to evaluate the achievable performance at the equilibrium point of the game. We analyze several different setups, showing that in all cases, the proposed solution permits to improve the accuracy of data fusion. We also show that, in some cases, it is preferable for the Byzantines to minimize the mutual information between the status of the observed system and the reports submitted to the FC, rather than always flipping the decision made by the local nodes.
Andrea Abrardo, Mauro Barni, Kassem Kallas, Benedetta Tondi
IEEE Trans. Inf. Forensics Secur.2
2016 Source Distinguishability Under Distortion-Limited Attack: An Optimal Transport Perspective
abstract
We analyze the distinguishability of two sources in a Neyman-Pearson setup when an attacker is allowed to modify the output of one of the two sources subject to an additive distortion constraint. By casting the problem in a game-theoretic framework and by exploiting the parallelism between the attacker's goal and optimal transport theory, we introduce the concept of security margin defined as the maximum average per-sample distortion introduced by the attacker for which the two sources can be distinguished ensuring arbitrarily small, yet positive, error exponents for type I and type II error probabilities. Several versions of the problem are considered according to the available knowledge about the sources. We compute the security margin for some classes of sources and derive general bounds assuming that the distortion is measured in terms of the mean square error between the original and the attacked sequence. The analysis of the game and the study of the distinguishability of the sources are extended to the case in which the distortion constraint is defined in terms of the maximum distance.
Mauro Barni, Benedetta Tondi
IEEE Trans. Inf. Forensics Secur.1
2016 Piecewise Function Approximation With Private Data
abstract
We present two secure two party computation (STPC) protocols for piecewise function approximation on private data. The protocols rely on a piecewise approximation of the to-be-computed function easing the implementation in an STPC setting. The first protocol relies entirely on garbled circuits (GCs), while the second one exploits a hybrid construction where GC and homomorphic encryption are used together. In addition to piecewise constant and linear approximation, polynomial interpolation is also considered. From a communication complexity perspective, the full-GC implementation is preferable when the input and output variables can be represented with a small number of bits, while the hybrid solution is preferable otherwise. With regard to computational complexity, the full-GC solution is generally more convenient.
Riccardo Lazzeretti, Tommaso Pignata, Mauro Barni
IEEE Trans. Inf. Forensics Secur.3
2016 Multiple Parenting Phylogeny Relationships in Digital Images
abstract
Recently, several studies have been concerned with modeling the parenthood relationships between near duplicates in a set of images. Two images share a parenthood relationship if one is obtained by applying transformations to the other. However, this is not the only form of parenting that can exist among images. An image might be a composition created through the combination of the semantic information existent in two or more source images, establishing a relationship between the sources and the composite. The problem of identifying these relations in a set containing near-duplicate subsets of source and composition images is referred to as multiple parenting phylogeny. Thus far, researchers tackled this problem with a three-step solution: 1) separation of near-duplicate groups; 2) classification of the relations between the groups; and 3) identification of the images used to create the original composition. In this work, we extend upon this framework by introducing key improvements, such as better identification of when two images share content, and improved ways to compare this content. In addition, we also introduce a new realistic professionally created data set of compositions involving multiple parenting relationships. The method we present in this paper is properly evaluated through quantitative metrics, established for assessing the accuracy in finding multiple parenting relationships. Finally, we discuss some particularities of the framework, such as the importance of an accurate reconstruction of phylogenies and the method's behavior when dealing with more complex compositions.
Alberto A. de Oliveira, Pasquale Ferrara, Alessia De Rosa, Alessandro Piva, Mauro Barni, Siome Goldenstein, Zanoni Dias, Anderson Rocha 0001
IEEE Trans. Inf. Forensics Secur.5
2015 Optimum decision fusion in cognitive wireless sensor networks with unknown users location
abstract
We consider a cooperative cognitive wireless network scenario where a primary wireless network is co-located with a cognitive (or secondary) network. In the considered scenario, the nodes of the secondary network make local binary decisions about the presence of a signal emitted by a primary node. Then, they transmit their decisions to a fusion center (FC). The final decision about the channel state is up to the FC by means of a proper fusion rule. In this scenario, we derive the optimum decision strategy for the FC and the optimum local decision thresholds of the secondary nodes in a Neyman-Pearson setup. In particular, the overall system performance are derived by making the realistic assumption that the position of the primary user is completely unknown to the FC.
Andrea Abrardo, Mauro Barni
ICASSP2
2015 Second-Order Statistics Analysis to Cope With Contrast Enhancement Counter-Forensics
abstract
Image forensic analysis for the detection of contrast enhancement and other histogram-based processing, usually relies on the study of first-order statistics derived from image histogram. Methods based on such an approach, though, are easily circumvented by adopting some counter-forensic attacks. To overcome such a problem, we propose a novel forensic technique based on the study of second-order statistics derived from the co-occurrence matrix. The experiments we carried out demonstrate that the proposed approach is very effective even in the presence of counter-forensic attacks, while it retains the good performance of histogram-based methods when no attack is present.
Alessia De Rosa, Marco Fontani, Matteo Massai, Alessandro Piva, Mauro Barni
IEEE Signal Process. Lett.5
2014 A video forensic technique for detecting frame deletion and insertion
abstract
We propose a method for detecting insertion and deletion of whole frames in digital videos. We start by strengthening and extending a state of the art method for double encoding detection, and propose a system that is able to locate the point in time where frames have been deleted or inserted, discerning between the two cases. The proposed method is applicable even when different codecs are used for the first and second compression, and performs well even when the second encoding is as strong as the first one.
Alessandra Gironi, Marco Fontani, Tiziano Bianchi, Alessandro Piva, Mauro Barni
ICASSP5
2014 Compressive hyperspectral imaging using progressive total variation
abstract
Compressed Sensing (CS) is suitable for remote acquisition of hyperspectral images for earth observation, since it could exploit the strong spatial and spectral correlations, allowing to simplify the architecture of the onboard sensors. Solutions proposed so far tend to decouple spatial and spectral dimensions to reduce the complexity of the reconstruction, not taking into account that onboard sensors progressively acquire spectral rows rather than acquiring spectral channels. For this reason, we propose a novel progressive CS architecture based on separate sensing of spectral rows and joint reconstruction employing Total Variation. Experimental results run on raw AVIRIS and AIRS images confirm the validity of the proposed system.
Simeon Kamdem Kuiteing, Giulio Coluccia, Alessandro Barducci, Mauro Barni, Enrico Magli
ICASSP4
2014 Multiple parenting identification in image phylogeny
abstract
Image phylogeny deals with tracing back parent-child relationships among near duplicates, images that share the same semantic content. This approach results in a visual structure showing the inheritance of semantic content among images, called phylogeny tree. In this paper, we extend upon the image phylogeny's original formulation, which considers that an image may inherit content from only a single parent, to deal with situations whereby an image may inherit it from multiple different parents. Our objective is to find the multiple parenting relationships in a set of images, a problem which we refer to as multiple parenting phylogeny. The proposed solution works by first identifying near-duplicate groups and reconstructing their phylogenies; then among the found groups we determine the one(s) representing the composition images; finally, we detect the parenting relations between those compositions and the source images used to create them.
Alberto A. de Oliveira, Pasquale Ferrara, Alessia De Rosa, Alessandro Piva, Mauro Barni, Siome Goldenstein, Zanoni Dias, Anderson Rocha 0001
ICIP5
2014 Universal Counterforensics of Multiple Compressed JPEG Images
Mauro Barni, Marco Fontani, Benedetta Tondi
IWDW1
2014 A New Watermarking Scheme Based on Antipodal Binary Dirty Paper Coding
abstract
We investigate the performance of a watermarking system in which the encoder is forced to use a binning strategy based on antipodal binary-valued sequences. The use of antipodal binary random binning has several advantages, including the possibility of relying on simple and effective binary code constructions and the ease with which this kind of schemes can cope with amplitude scaling. By relying on a novel binning strategy, we derive a lower bound of the Gelfand-Pinsker capacity of the watermark channel when the encoder is forced to use an antipodal binary auxiliary random variable, showing that for low to moderate bit-rates, the bound coincides with Costa's capacity. We exploit the properties of the new binning strategy, to develop a practical watermarking system and show that the new scheme outperforms previous constructions, exhibiting very good performance also in the presence of gain attack. Preliminary results on audio signals show that the new scheme retains its good performance also when used for the watermarking of real multimedia data.
Andrea Abrardo, Mauro Barni
IEEE Trans. Inf. Forensics Secur.2
2014 Forensic Analysis of SIFT Keypoint Removal and Injection
abstract
Attacks capable of removing SIFT keypoints from images have been recently devised with the intention of compromising the correct functioning of SIFT-based copy-move forgery detection. To tackle with these attacks, we propose three novel forensic detectors for the identification of images whose SIFT keypoints have been globally or locally removed. The detectors look for inconsistencies like the absence or anomalous distribution of keypoints within textured image regions. We first validate the methods on state-of-the-art keypoint removal techniques, then we further assess their robustness by devising a counter-forensic attack injecting fake SIFT keypoints in the attempt to cover the traces of removal. We apply the detectors to a practical image forensic scenario of SIFT-based copy-move forgery detection, assuming the presence of a counterfeiter who resorts to keypoint removal and injection to create copy-move forgeries that successfully elude SIFT-based detectors but are in turn exposed by the newly proposed tools.
Andrea Costanzo, Irene Amerini, Roberto Caldelli, Mauro Barni
IEEE Trans. Inf. Forensics Secur.4
2014 Binary Hypothesis Testing Game With Training Data
abstract
We introduce a game-theoretic framework to study the hypothesis testing problem in the presence of an adversary aiming to prevent a correct decision. Specifically, this paper considers a scenario in which an analyst has to accept or reject the null hypothesis H0characterized by a probability mass function (pmf) PXbased on the evidence provided by a test sequence. In turn, the goal of the adversary is to take a sequence generated according to a different pmf and modify it in such a way to induce a decision error. PXis known only through one or more training sequences. We derive the asymptotic equilibrium of the game under the assumption that the analyst relies only on first order statistics of the test and training sequences, and compute the asymptotic payoff of the game when the length of the sequences tends to infinity. We introduce the concept of indistinguishability region, defined as the set of pmfs that can not be distinguished reliably from PXin the presence of attacks. Two different scenarios are considered: in the first one the analyst and the adversary share the same training sequence, in the second scenario, they rely on independent sequences. The obtained results are compared with a version of the game in which the pmf PXis perfectly known to both the analyst and the adversary.
Mauro Barni, Benedetta Tondi
IEEE Trans. Inf. Theory1
2013 Coping with the enemy: Advances in adversary-aware signal processing
abstract
This paper is a first attempt to provide a unified framework for studying signal processing problems where designers have to cope with the presence of an adversary, including media forensics, watermarking, adversarial machine learning, biometric spoofing, etc. We focus on the binary decision problem and discuss which strategies the adversary can use to flip the decision output at minimal cost, including blind sensitivity attacks and hill-climbing attacks. As the defender can also play smarter by considering the presence of a rational adversary, we introduce a game-theoretic approach where some advances have been recently made. We conclude by discussing some trends raised by this game-theoretic formulation.
Mauro Barni, Fernando Pérez-González
ICASSP1
2013 SIFT keypoint removal and injection for countering matching-based image forensics
abstract
Scale Invariant Feature Transform (SIFT) has been widely employed in several image application domains, including Image Forensics (e.g. detection of copy-move forgery or near duplicates). Until now, the research community has focused on studying the robustness of SIFT against legitimate image processing, but rarely concerned itself with the problem of SIFT security against malicious procedures. Recently, a number of methods allowing to remove SIFT keypoints from an original image have been devised. Although quite effective, such methods produce an attacked image with very few (or no) keypoints, thus leaving cues that can be easily exploited by a forensic analyst to reveal the occurred manipulation. In this paper, we explore the topic of reintroducing fake SIFT keypoints into a previously cleaned image in order to address the main weakness of the existing removal attacks. In particular, we evaluate the fitness of locally adaptive contrast enhancement methods to the task of injecting new keypoints. The results we obtained are encouraging: (i) it is possible to effectively introduce new keypoints whose descriptors do not match with those of the original image, thus concealing the removal forgery; (ii) the perceptual quality of the image following the removal and injection attacks is comparable to the one of the original image.
Irene Amerini, Mauro Barni, Roberto Caldelli, Andrea Costanzo
IH&MMSec2
2013 Localization of forgeries in MPEG-2 video through GOP size and DQ analysis
abstract
This work addresses forgery localization in MPEG-2 compressed videos. The proposed method is based on the analysis of Double Quantization (DQ) traces in frames that were encoded twice as intra (i.e., I-frames). Employing a state-of-the-art method, such frames are located in the video under analysis by estimating the size of the Group Of Pictures (GOP) that was used in the first compression; then, the DQ analysis is devised for the MPEG-2 encoding scheme and applied to frames that were intra-coded in both the first and second compression. In such a way, regions that were manipulated between the two encodings are detected. Compared to existing methods based on double quantization analysis, the proposed scheme makes forgery localization possible on a wider range of settings.
D. Labartino, Tiziano Bianchi, Alessia De Rosa, Marco Fontani, David Vazquez-Padin, Alessandro Piva, Mauro Barni
MMSP7
2013 Removal and injection of keypoints for SIFT-based copy-move counter-forensics
abstract
Abstract Recent studies exposed the weaknesses of scale-invariant feature transform (SIFT)-based analysis by removing keypoints without significantly deteriorating the visual quality of the counterfeited image. As a consequence, an attacker can leverage on such weaknesses to impair or directly bypass with alarming efficacy some applications that rely on SIFT. In this paper, we further investigate this topic by addressing the dual problem of keypoint removal, i.e., the injection of fake SIFT keypoints in an image whose authentic keypoints have been previously deleted. Our interest stemmed from the consideration that an image with too few keypoints is per se a clue of counterfeit, which can be used by the forensic analyst to reveal the removal attack. Therefore, we analyse five injection tools reducing the perceptibility of keypoint removal and compare them experimentally. The results are encouraging and show that injection is feasible without causing a successive detection at SIFT matching level. To demonstrate the practical effectiveness of our procedure, we apply the best performing tool to create a forensically undetectable copy-move forgery, whereby traces of keypoint removal are hidden by means of keypoint injection.
Irene Amerini, Mauro Barni, Roberto Caldelli, Andrea Costanzo
EURASIP J. Inf. Secur.2
2013 The Source Identification Game: An Information-Theoretic Perspective
abstract
We introduce a theoretical framework in which to cast the source identification problem. Thanks to the adoption of a game-theoretic approach, the proposed framework permits us to derive the ultimate achievable performance of the forensic analysis in the presence of an adversary aiming at deceiving it. The asymptotic Nash equilibrium of the source identification game is derived under an assumption on the resources on which the forensic analyst may rely. The payoff at the equilibrium is analyzed, deriving the conditions under which a successful forensic analysis is possible and the error exponent of the false-negative error probability in such a case. The difficulty of deriving a closed-form solution for general instances of the game is alleviated by the introduction of an efficient numerical procedure for the derivation of the optimum attacking strategy. The numerical analysis is applied to a case study to show the kind of information it can provide.
Mauro Barni, Benedetta Tondi
IEEE Trans. Inf. Forensics Secur.1
2013 A Framework for Decision Fusion in Image Forensics Based on Dempster-Shafer Theory of Evidence
abstract
In this work, we present a decision fusion strategy for image forensics. We define a framework that exploits information provided by available forensic tools to yield a global judgment about the authenticity of an image. Sources of information are modeled and fused using Dempster-Shafer Theory of Evidence, since this theory allows us to handle uncertain answers from tools and lack of knowledge about prior probabilities better than the classical Bayesian approach. The proposed framework permits us to exploit any available information about tools reliability and about the compatibility between the traces the forensic tools look for. The framework is easily extendable: new tools can be added incrementally with a little effort. Comparison with logical disjunction- and SVM-based fusion approaches shows an improvement in classification accuracy, particularly when strong generalization capabilities are needed.
Marco Fontani, Tiziano Bianchi, Alessia De Rosa, Alessandro Piva, Mauro Barni
IEEE Trans. Inf. Forensics Secur.5
2012 A game theoretic approach to source identification with known statistics
abstract
In the attempt to lay the basis for the construction of a theoretical framework to cast forensics and anti-forensics techniques in, we introduce a game-theoretic model for the source-identification problem with known statistics. The framework is used to derive the Nash equilibrium for an asymptotic version of the game, in which the players' strategies and the payoff are defined in terms of the error exponents of the false positive and false negative probabilities. The payoff at the equilibrium is evaluated and the conditions under which the false negative error probability tends to zero derived.
Mauro Barni
ICASSP1
2012 Dealing with uncertainty in image forensics: A fuzzy approach
abstract
Image forensics research has mainly focused on the detection of artifacts introduced by a single processing tool. In tamper detection applications, however, the kind of artifacts the forensic analyst should look for is not known beforehand, hence making it necessary that several tools developed for different scenarios are applied. The problem, then, is twofold: i) devise a sound strategy to elaborate the information provided by the different tools into a single output, and ii) deal with the uncertainty introduced by error-prone tools. In this paper, we introduce a framework based on Fuzzy Theory to overcome these problems. We describe a practical implementation of the proposed framework putting the theoretical principles in practice. To validate the proposed approach, we carried out some experiments addressing a simple realistic scenario in which three forensic tools exploit artifacts introduced by JPEG compression to detect cut&paste tampering within a specified region of an image. The results are encouraging, especially when compared with those obtained by simply XOR-ing the output of the the single detection tools.
Mauro Barni, Andrea Costanzo
ICASSP1
2012 An efficient protocol for private iris-code matching by means of garbled circuits
abstract
Biometric-based access control is receiving increasing attention due to its security and ease-of-use. However, concerns are often raised regarding the protection of the privacy of enrolled users. Signal processing in the encrypted domain has been proposed as a viable solution to protect biometric templates and the privacy of the users. In particular, several solutions have been proposed to protect the privacy of the biometric probe during the authentication process. In this paper we focus on privacy-preserving iris-based authentication. The main innovations compared to the prior art include: i) an iris masking technique that simplifies the operations on the encrypted data without sacrificing the recognition rate; ii) the adoption of a matching protocol based only on garbled circuits which offers longer term security over existing solutions based on homomorphic encryption or hybrid techniques. The computational and communication complexity of the on-line phase of the proposed protocol is extremely low, thus opening the way to its exploitation in practical applications.
Ying Luo 0008, Sen-Ching S. Cheung, Tommaso Pignata, Riccardo Lazzeretti, Mauro Barni
ICIP5
2012 Emerging cryptographic challenges in image and video processing
abstract
In an increasing number of image and video processing problems, cryptographic techniques are used to enforce content access control, identity verification and authentication, and privacy protection. The combination of cryptography and signal processing is an exciting emerging field. This introductory paper gives an overview of approaches and challenges that exist in applying cryptographic primitives to important image and video processing problems, including (partial) content encryption, secure face recognition, and secure biometrics. This paper aims to help the community in appreciating the utility and challenges of cryptographic techniques in image and video processing.
William Puech, Zekeriya Erkin, Mauro Barni, Shantanu Rane, Reginald L. Lagendijk
ICIP3
2012 A fuzzy approach to deal with uncertainty in image forensics
Mauro Barni, Andrea Costanzo
Signal Process. Image Commun.1
2011 Low-complexity predictive lossy compression of hyperspectral and ultraspectral images
abstract
Lossy compression of hyperspectral and ultraspectral images is traditionally performed using 3D transform coding. This approach yields good performance, but its complexity and memory requirements are unsuitable for onboard compression. In this paper we propose a low-complexity lossy compression scheme based on prediction, uniform threshold quantization, and rate-distortion optimization. Its performance is competitive with that of state-of-the-art 3D transform coding schemes, but the complexity is immensely lower. The algorithm is able to limit the scope of errors, and is amenable to parallel implementation, making it suitable for onboard compression at high throughputs.
Andrea Abrardo, Mauro Barni, Enrico Magli
ICASSP2
2011 Analysis of the security of linear blinding techniques from an information theoretical point of view
abstract
We propose a novel model to characterize the security of linear blinding techniques. The proposed model relates the security of blinding to the possibility of estimating the blinded signals up to a certain signal-to-noise ratio (SNR). Practical upper bounds on the SNR are derived by relying on rate-distortion theory and evaluating the mutual information between the blinded and the plaintext signals. The proposed bounds allow to characterize the security of different blinding techniques, showing that multiplicative blinding techniques can not achieve the same level of security as additive ones. The proposed model provides a rigorous measure for evaluating the tradeoff between security and efficiency in practical secure signal processing algorithms.
Tiziano Bianchi, Alessandro Piva, Mauro Barni
ICASSP3
2011 Privacy-Preserving ECG Classification With Branching Programs and Neural Networks
abstract
Privacy protection is a crucial problem in many biomedical signal processing applications. For this reason, particular attention has been given to the use of secure multiparty computation techniques for processing biomedical signals, whereby nontrusted parties are able to manipulate the signals although they are encrypted. This paper focuses on the development of a privacy preserving automatic diagnosis system whereby a remote server classifies a biomedical signal provided by the client without getting any information about the signal itself and the final result of the classification. Specifically, we present and compare two methods for the secure classification of electrocardiogram (ECG) signals: the former based on linear branching programs (a particular kind of decision tree) and the latter relying on neural networks. The paper deals with all the requirements and difficulties related to working with data that must stay encrypted during all the computation steps, including the necessity of working with fixed point arithmetic with no truncation while guaranteeing the same performance of a floating point implementation in the plain domain. A highly efficient version of the underlying cryptographic primitives is used, ensuring a good efficiency of the two proposed methods, from both a communication and computational complexity perspectives. The proposed systems prove that carrying out complex tasks like ECG classification in the encrypted domain efficiently is indeed possible in the semihonest model, paving the way to interesting future applications wherein privacy of signal owners is protected by applying high security standards.
Mauro Barni, Pierluigi Failla, Riccardo Lazzeretti, Ahmad-Reza Sadeghi, Thomas Schneider 0003
IEEE Trans. Inf. Forensics Secur.1
2010 Forensics aided steganalysis of heterogeneous images
abstract
We tackle the problem of the steganalysis of images produced by different sources. We first use a classifier to try to understand the image source and then use a version of the steganalyzer that has been explicitly trained to work with images belonging to the correct class. These classifiers are widely available from the image forensics literature and have reached a good level of maturity hence making the proposed approach feasible. We tested the goodness of our approach on a case study in which a steganalyzer is asked to analyze both computer generated and camera images. The results we obtained are promising encouraging further research in this direction.
Mauro Barni, Giacomo Cancelli, Annalisa Esposito
ICASSP1
2010 Low-complexity lossy compression of hyperspectral images via informed quantization
abstract
Lossy compression of hyperspectral and ultraspectral images is traditionally performed using 3D transform coding. This approach yields good performance, but the complexity and memory requirements make it unsuitable for onboard compression. In this paper we propose a low-complexity lossy compression scheme based on prediction, quantization and rate-distortion optimization. The scheme employs coset codes coupled with the newconcept of “informed quantization”, and requires no entropy coding. The performance of the resulting algorithm is competitive with that of state-of-the-art 3D transform coding schemes, but the complexity is immensely lower, making it suitable for onboard compression at high throughputs.
Andrea Abrardo, Mauro Barni, Enrico Magli
ICIP2
2010 Identification of cut & paste tampering by means of double-JPEG detection and image segmentation
abstract
This paper focuses on images whose content has been modified by means of a cut & paste operation. By relying on an existing scheme for the detection of double JPEG compressed images with desynchronized grids, we propose two algorithms for the detection of image regions that have been transplanted from another image. The proposed methods work whenever the pasted region is extracted from a JPEG compressed image and inserted in a target image that is subsequently compressed with a quality factor larger than that used to compress the source image. The new methods are intended as a complement to previous works relying on the detection of artifacts introduced by double JPEG compression with aligned compression grids. The experiments we carried out show the good performance of the novel schemes, the second one providing better results at a lower complexity thanks to the incorporation within the detection process of some information regarding the actual image content.
Mauro Barni, Andrea Costanzo, Lara Sabatini
ISCAS1
2010 Error-Resilient and Low-Complexity Onboard Lossless Compression of Hyperspectral Images by Means of Distributed Source Coding
abstract
In this paper, we propose a lossless compression algorithm for hyperspectral images inspired by the distributed-source-coding (DSC) principle. DSC refers to separate compression and joint decoding of correlated sources, which are taken as adjacent bands of a hyperspectral image. This concept is used to design a compression scheme that provides error resilience, very low complexity, and good compression performance. These features are obtained employing scalar coset codes to encode the current band at a rate that depends on its correlation with the previous band, without encoding the prediction error. Iterative decoding employs the decoded version of the previous band as side information and uses a cyclic redundancy code to verify correct reconstruction. We develop three algorithms based on this paradigm, which provide different tradeoffs between compression performance, error resilience, and complexity. Their performance is evaluated on raw and calibrated AVIRIS images and compared with several existing algorithms. Preliminary results of a field-programmable gate array implementation are also provided, which show that the proposed algorithms can sustain an extremely high throughput.
Andrea Abrardo, Mauro Barni, Enrico Magli, Filippo Nencini
IEEE Trans. Geosci. Remote. Sens.2
2010 Composite signal representation for fast and storage-efficient processing of encrypted signals
abstract
Signal processing tools working directly on encrypted data could provide an efficient solution to application scenarios where sensitive signals must be protected from an untrusted processing device. In this paper, we consider the data expansion required to pass from the plaintext to the encrypted representation of signals, due to the use of cryptosystems operating on very large algebraic structures. A general composite signal representation allowing us to pack together a number of signal samples and process them as a unique sample is proposed. The proposed representation permits us to speed up linear operations on encrypted signals via parallel processing and to reduce the size of the encrypted signal. A case study-1-D linear filtering-shows the merits of the proposed representation and provides some insights regarding the signal processing algorithms more suited to work on the composite representation.
Tiziano Bianchi, Alessandro Piva, Mauro Barni
IEEE Trans. Inf. Forensics Secur.3
2010 Roughness-Adaptive 3-D Watermarking Based on Masking Effect of Surface Roughness
abstract
We present a method to improve watermark robustness by exploiting the masking effect of surface roughness on watermark visibility. Our idea is to adapt watermark strength to local surface roughness based on the knowledge that human eyes are less sensitive to changes on a rougher surface patch than those on a smoother surface. In order to quantify human sensitivity to surface roughness of polygonal meshes, we conducted a rigorous psychovisual experiment to obtain human watermark detection thresholds as a function of surface roughness. The results can be used to adaptively select watermark strength according to local surface roughness during the watermark embedding process. To test our idea, we applied it to the modified versions of two popular 3-D watermarking methods, one proposed by Benedens and one by Cayre and Macq. Experimental results showed that our approach improves watermark robustness as compared to the original algorithms. Further analyses indicated that the average watermark strength allowed by our roughness-adaptive method was larger than that by the original Benedens's and Cayre and Macq's methods while ensuring watermark imperceptibility. This was the main reason for the improved robustness observed in our experiments. We conclude that exploiting the masking property of human vision is a viable way to improve the robustness of 3-D watermarks, and can potentially be applied to other 3-D digital watermarking techniques.
Kwangtaek Kim, Mauro Barni, Hong Z. Tan
IEEE Trans. Inf. Forensics Secur.2
2010 A Full-Reference Quality Metric for Geometrically Distorted Images
abstract
In multimedia applications, there has been an increasing interest in the use of quality measures based on human perception; however, research has not dealt with distortions due to geometric transformations. In this paper, we propose a method to objectively assess the perceptual quality of geometrically distorted images, based on image features processed by human vision. The proposed approach is a full-reference image quality metric focusing on the problem of local geometric distortions and is based on the use of Gabor filters that have received considerable attention because the characteristics of certain cells in the visual cortex of some mammals can be approximated by these filters. The novelty of the proposed technique is that it considers both the displacement field describing the distortion and the structure of the image. The experimental results show the good performances of the proposed metric.
Angela D'Angelo, Zhaoping Li 0001, Mauro Barni
IEEE Trans. Image Process.3
2010 Asymptotically optimum universal watermark embedding and detection in the high-SNR regime
abstract
The problem of optimum watermark embedding and detection was addressed in a recent paper by Merhav and Sabbag, where the optimality criterion was the maximum false-negative error exponent subject to a guaranteed false-positive error exponent. In particular, Merhav and Sabbag derived universal asymptotically optimum embedding and detection rules under the assumption that the detector relies solely on second-order joint empirical statistics of the received signal and the watermark. In the case of a Gaussian host signal and a Gaussian attack, however, closed-form expressions for the optimum embedding strategy and the false-negative error exponent were not obtained in that work. In this paper, we derive the false-negative error exponent for any given embedding strategy and use such a result to show that in general the optimum embedding rule depends on the variance of the host sequence and the variance of the attack noise. We then focus on high signal-to-noise ratio (SNR) regime, deriving the optimum embedding strategy for such a setup. In this case, a universally optimum embedding rule turns out to exist and to be very simple with an intuitively appealing geometrical interpretation. The effectiveness of the newly proposed embedding strategy is evaluated numerically.
Pedro Comesaña Alfaro, Neri Merhav, Mauro Barni
IEEE Trans. Inf. Theory3
2009 Secure Evaluation of Private Linear Branching Programs with Medical Applications
Mauro Barni, Pierluigi Failla, Vladimir Kolesnikov, Riccardo Lazzeretti, Ahmad-Reza Sadeghi, Thomas Schneider 0003
ESORICS1
2009 A compressive-sensing based watermarking scheme for sparse image tampering identification
abstract
In this paper we describe a robust watermarking scheme for image tampering identification and localization. A compact representation of the image is first produced by assembling a feature vector consisting of pseudo-random projections of the decimated image. Then, the quantized projections are encoded to form a hash, which is robustly embedded as a watermark in the image. By recovering the watermark the random projections are obtained, and then used to estimate the distortion of the received image. If tampering is sufficiently sparse or compressible in some basis description, a map of the introduced modification is recovered. The system relies on compressive sensing and distributed source coding principles to reduce the size of the hash of a 1024 × 1024 image, to about 4,000 bits. With this hash length, tampering sparse up to 20% and with a tampering energy around a PSNR of 15 dB can be successfully localized.
Giuseppe Valenzise, Marco Tagliasacchi, Stefano Tubaro, Giacomo Cancelli, Mauro Barni
ICIP5
2009 Watermark Embedding and Recovery in the Presence of C-LPCD De-synchronization Attacks
Andrea Abrardo, Mauro Barni, Cesare Maria Carretti
IWDW2
2009 Quality evaluation of motion estimation algorithms based on structural distortions
abstract
In this paper a methodology for understanding the effectiveness of motion estimation techniques is presented. Unlike other performances evaluation systems, that are based on measuring the errors between the actual and the predicted displacements, the proposed technique is inspired to the Human Visual System. More in detail, the perceptual impact of geometric distortions induced by non accurate motion estimation is considered by means of an objective measure of the perceived distortion impact. Some of the most common block-based motion estimation algorithms have been tested. For each of them the performances have been evaluated by comparing the proposed metric with the state of the art metrics. A subjective experiment has been performed to assess the effectiveness of the estimation algorithms from a perceptual point of view. The obtained results show that the scores obtained with the tested metrics generally do not match with the perceived quality, while the proposed methodology does. Therefore, the presented tool can be used in the design and in the verification of a generic motion estimation algorithm.
Angela D'Angelo, Marco Carli, Mauro Barni
MMSP3
2009 Encrypted Domain DCT Based on Homomorphic Cryptosystems
abstract
Signal processing in the encrypted domain (s.p.e.d.) appears an elegant solution in application scenarios, where valuable signals must be protected from a possibly malicious processing device. In this paper, we consider the application of the Discrete Cosine Transform (DCT) to images encrypted by using an appropriate homomorphic cryptosystem. An s.p.e.d. 1-dimensional DCT is obtained by defining a convenient signal model and is extended to the 2-dimensional case by using separable processing of rows and columns. The bounds imposed by the cryptosystem on the size of the DCT and the arithmetic precision are derived, considering both the direct DCT algorithm and its fast version. Particular attention is given to block-based DCT (BDCT), with emphasis on the possibility of lowering the computational burden by parallel application of the s.p.e.d. DCT to different image blocks. The application of the s.p.e.d. 2D-DCT and 2D-BDCT to 8-bit greyscale images is analyzed; whereas a case study demonstrates the feasibility of the s.p.e.d. DCT in a practical scenario.
Tiziano Bianchi, Alessandro Piva, Mauro Barni
EURASIP J. Inf. Secur.3
2009 On the implementation of the discrete Fourier transform in the encrypted domain
abstract
Signal-processing modules working directly on encrypted data provide an elegant solution to application scenarios where valuable signals must be protected from a malicious processing device. In this paper, we investigate the implementation of the discrete Fourier transform (DFT) in the encrypted domain by using the homomorphic properties of the underlying cryptosystem. Several important issues are considered for the direct DFT: the radix-2 and the radix-4 fast Fourier algorithms, including the error analysis and the maximum size of the sequence that can be transformed. We also provide computational complexity analyses and comparisons. The results show that the radix-4 fast Fourier transform is best suited for an encrypted domain implementation in the proposed scenarios.
Tiziano Bianchi, Alessandro Piva, Mauro Barni
IEEE Trans. Inf. Forensics Secur.3
2009 MPSteg-color: data hiding through redundant basis decomposition
abstract
The possibility of using redundant basis expansion to securely hide a message within a cover color image is explored by improving previous attempts in this sense in terms of security and payload. The stability and computational complexity problems of previous works are solved by introducing new selection and update rules working entirely in the integer domain, and by fully exploiting the availability of three color bands in such a way that all the available atoms in the three color bands are used to convey the stego-message. Image decomposition is randomized in several ways thus improving the stego-message undetectability, and making the hidden message undetectable by targeted steganalyzers explicitly developed to exploit the weaknesses of the MPSteg algorithm. The security of the new scheme is also evaluated by testing it against blind steganalyzers and compared to that of plusmn1 embedding algorithm applied in the pixel domain.
Giacomo Cancelli, Mauro Barni
IEEE Trans. Inf. Forensics Secur.2
2008 Implementing the discrete Fourier transform in the encrypted domain
abstract
Signal processing modules working directly on the encrypted data could provide an elegant solution to application scenarios where valuable signals should be protected from a malicious processing device. In this paper, we investigate the implementation of the discrete Fourier transform (DFT) in the encrypted domain, by using the homomorphic properties of the underlying cryptosystem. Several important issues are considered for both the DFT and radix-2 fast Fourier transform, including the error analysis and the maximum size of the sequence that can be transformed.
Tiziano Bianchi, Alessandro Piva, Mauro Barni
ICASSP3
2008 Discrete cosine transform of encrypted images
abstract
Processing a signal directly in the encrypted domain provides an elegant solution in application scenarios where valuable signals must be protected from a malicious processing device. In a previous paper we considered the implementation of the ID discrete fourier transform (DFT) in the encrypted domain, by using the homomorphic properties of the underlying cryptosystem. In this paper we extend our previous results by considering the application of the 2-dimensional DCT to encrypted images. The effect of the consecutive application of the DCT algorithm first by rows then by columns is considered, as well as the differences between the implementation of the direct DCT algorithm and its fast version. Particular attention is given to block-based DCT, with emphasis on the possibility of lowering the computational burden by parallel application of the encrypted domain DCT algorithm to different image blocks.
Tiziano Bianchi, Alessandro Piva, Mauro Barni
ICIP3
2008 Detection of +/-1 LSB steganography based on the amplitude of histogram local extrema
abstract
Recently Zhang et al described an algorithm for the detection of plusmn1 LSB steganography based on the statistics of the amplitudes of local extrema in the greylevel histogram. Experimental results demonstrated performance comparable or superior to other state-of-the-art algorithms. In this paper, we describe improvements to this algorithm to (i) reduce the noise associated with border effects in the histogram, and (ii) extend the analysis to amplitudes of local extrema in the 2D adjacency histogram. Experimental results on a composite database of 7125 images, averaged over a 20-fold cross validation, with classification based on Fisher linear discriminant analysis, demonstrate that the improved algorithm exhibits significantly better performance. The experimetal results are reported in the form of receiver operating characteristic (ROC) curves and summarized by computing the area under the ROC curve (AUC). The new algorithm, using 10 features derived from the ID and 2D histograms, has an AUC value of 0.77 compared to 0.57 for the original algorithm. It also significantly outperforms other state-of-the-art steganalysers.
Giacomo Cancelli, Gwenaël J. Doërr, Ingemar J. Cox, Mauro Barni
ICIP4
2008 A comparative study of +/- steganalyzers
abstract
We compare the performance of three steganalysis system for detection of plusmn1 steganography. We examine the relative performance of each system on three commonly used image databases. Experimental results clearly demonstrate that both absolute and relative performance of all three algorithms vary considerably across databases. This sensitivity suggests that considerably more work is needed to develop databases that are more representative of diverse imagery. In addition, we investigate how performance varies based on a variety of training and testing assumptions, specifically (i) that training and testing are performed for a fixed and known embedding rate, (ii) training is performed at one embedding rate, but testing is over a range of embedding rates, (iii) training and testing are performed over a range of embedding rates. As expected, experimental results show that performance under (ii) and (iii) is inferior to (i). The experimental results also suggest that test results for different embedding rates should not be consolidated into a single score, but rather reported separately. Otherwise, good performance at high embedding rates may mask poor performance at low embedding rates.
Giacomo Cancelli, Gwenaël J. Doërr, Mauro Barni, Ingemar J. Cox
MMSP3
2008 A structural method for quality evaluation of desynchronization attacks in image watermarking
abstract
Geometric transformations are known to be one of the most serious threats against any digital watermarking scheme. The goal of this work is to design an objective measurement scheme for geometric distortions in order to investigate the perceptual quality impact of geometric attacks on the watermarked images. The proposed approach is a full-reference image quality metric focusing on the problem of local geometric attacks and it is based on the use of Gabor filters. The novelty of the proposed metric is that it considers both the displacement field describing the distortion and the structure of the image.The experimental results show the good performances of the metric.
Angela D'Angelo, Mauro Barni
MMSP2
2008 Enhancing Privacy in Remote Data Classification
Alessandro Piva, Claudio Orlandi, Michele Caini, Tiziano Bianchi, Mauro Barni
SEC5
2008 Stochastic Image Warping for Improved Watermark Desynchronization
abstract
The use of digital watermarking in real applications is impeded by the weakness of current available algorithms against signal processing manipulations leading to the desynchronization of the watermark embedder and detector. For this reason, the problem of watermarking under geometric attacks has received considerable attention throughout recent years. Despite their importance, only few classes of geometric attacks are considered in the literature, most of which consist of global geometric attacks. The random bending attack contained in the Stirmark benchmark software is the most popular example of a local geometric transformation. In this paper, we introduce two new classes of local desynchronization attacks (DAs). The effectiveness of the new classes of DAs is evaluated from different perspectives including perceptual intrusiveness and desynchronization efficacy. This can be seen as an initial effort towards the characterization of the whole class of perceptually admissible DAs, a necessary step for the theoretical analysis of the ultimate performance reachable in the presence of watermark desynchronization and for the development of a new class of watermarking algorithms that can efficiently cope with them.
Angela D'Angelo, Mauro Barni, Neri Merhav
EURASIP J. Inf. Secur.2
2007 Putting Reproducible Signal Processing into Practice: A Case Study in Watermarking
abstract
In this paper the authors analyze how the description and presentation of results about an algorithm proposed in the literature should be modified in order to comply with the reproducible signal processing paradigm. We describe the problems one is faced with, by specifically focusing on how the description of the algorithm should be improved with respect to the classical approach.
Mauro Barni, Fernando Pérez-González, Pedro Comesaña Alfaro, Guido Bartoli
ICASSP (4)1
2007 Protection and Retrieval of Encrypted Multimedia Content: When Cryptography Meets Signal Processing
abstract
The processing and encryption of multimedia content are generally considered sequential and independent operations. In certain multimedia content processing scenarios, it is, however, desirable to carry out processing directly on encrypted signals. The field of secure signal processing poses significant challenges for both signal processing and cryptography research; only few ready-to-go fully integrated solutions are available. This study first concisely summarizes cryptographic primitives used in existing solutions to processing of encrypted signals, and discusses implications of the security requirements on these solutions. The study then continues to describe two domains in which secure signal processing has been taken up as a challenge, namely, analysis and retrieval of multimedia content, as well as multimedia content protection. In each domain, state-of-the-art algorithms are described. Finally, the study discusses the challenges and open issues in the field of secure signal processing.
Zekeriya Erkin, Alessandro Piva, Stefan Katzenbeisser 0001, Reginald L. Lagendijk, Jamshid Shokrollahi, Gregory Neven, Mauro Barni
EURASIP J. Inf. Secur.7
2007 Oblivious Neural Network Computing via Homomorphic Encryption
abstract
The problem of secure data processing by means of a neural network (NN) is addressed. Secure processing refers to the possibility that the NN owner does not get any knowledge about the processed data since they are provided to him in encrypted format. At the same time, the NN itself is protected, given that its owner may not be willing to disclose the knowledge embedded within it. The considered level of protection ensures that the data provided to the network and the network weights and activation functions are kept secret. Particular attention is given to prevent any disclosure of information that could bring a malevolent user to get access to the NN secrets by properly inputting fake data to any point of the proposed protocol.With respect to previous works in this field, the interaction between the user and the NN owner is kept to a minimum with no resort to multiparty computation protocols.
Claudio Orlandi, Alessandro Piva, Mauro Barni
EURASIP J. Inf. Secur.3
2007 Design and Analysis of the First BOWS Contest
abstract
The break our watermarking system (BOWS) contest was launched in the framework of the activities carried out by the European Network of Excellence for Cryptology ECRYPT. The aim of the contest was to investigate how and when an image watermarking system can be broken while preserving the highest possible quality of the content, in the case the watermarking system is subject to a massive worldwide attack. The great number of participants and the echo that the contest has had in the watermarking community contributed to make BOWS a great success. From a scientific point of view, many insights into the problems attackers have to face with when operating in a practical scenario have been obtained, confirming the threat posed by the sensitivity attack, which turned out to be the most successful attack. At the same time, several interesting modifications of such an attack have been proposed to make it work in a real scenario under limited communication and time resources. This paper describes how the contest has been designed and analyzes the general progress of the attacks during the contest.
Alessandro Piva, Mauro Barni
EURASIP J. Inf. Secur.2
2007 Watermarked 3-D Mesh Quality Assessment
abstract
This paper addresses the problem of assessing distortions produced by watermarking 3D meshes. In particular, a new methodology for subjective evaluation of the quality of 3D objects is proposed and implemented. Two objective metrics derived from measures of surface roughness are then proposed and their efficiency to predict the perceptual impact of 3D watermarking is assessed and compared with the state of the art. Results obtained show good correlations between the proposed objective metrics and subjective assessments by human observers
Massimiliano Corsini, Elisa Drelie Gelasca, Touradj Ebrahimi, Mauro Barni
IEEE Trans. Multim.4
2006 Image Watermarking Robust Against Non-Linear Value-Metric Scaling Based on Higher Order Statistics
abstract
A new QIM-based image watermarking system for still images is proposed. The new system is expressly designed to cope with non-linear value-metric scaling attacks such as histogram stretching and gamma correction. By recognizing that any value-metric scaling attack must not change the global appearance of the image, we argue that the watermark should be inserted into high level visual features. We move a first step into this direction by proposing a system embedding the watermark into the kurtosis of selected image blocks. Though the kurtosis is not strictly invariant against non-linear gain, its value tends to remain constant whenever the image content is not altered significantly. The experiments we carried out confirm the validity of the new system, though some problems still need to be solved to make it suitable for real applications
Fabrizio Guerrini, Riccardo Leonardi, Mauro Barni
ICASSP (5)3
2006 Joint near-lossless compression and watermarking of still images for authentication and tamper localization
Roberto Caldelli, Francesco Filippini, Mauro Barni
Signal Process. Image Commun.3
2005 Objective evaluation of the perceptual quality of 3D watermarking
abstract
In this paper an objective metric to measure the perceptual quality of watermarked 3D meshes is presented. The metric, which is based on a black-box approach, relies on the measurement of the roughness of 3D meshes before and after the insertion of the watermark. To calibrate the metric and to validate it, a set of psychovisual experiments has been carried out. Due to the lack of prior work in this field, a new methodology for the subjective evaluation of the quality of watermarked 3D objects is introduced. The validity of the proposed metric has been tested against a number of different 3D watermarking algorithms, showing an excellent match with the subjective evaluation of the quality stemming from the psychovisual experiments.
Elisa Drelie Gelasca, Touradj Ebrahimi, Massimiliano Corsini, Mauro Barni
ICIP (1)4
2005 Improved low-complexity intraband lossless compression of hyperspectral images by means of Slepian-Wolf coding
abstract
In remote sensing systems, on-board data compression is a crucial task that has to be carried out with limited computational resources. In this paper we propose a novel lossless compression scheme for multispectral and hyperspectral images, which combines low encoding complexity and high-performance. The encoder is based on distributed source coding concepts, and employs Slepian-Wolf coding of the bitplanes of the CALIC prediction errors to achieve improved performance. Experimental results on AVIRIS data show that the proposed scheme exhibits performance similar to CALIC, and significantly better than JPEG 2000.
Antonello Nonnis, Marco Grangetto, Enrico Magli, Gabriella Olmo, Mauro Barni
ICIP (1)5
2005 Distributed source coding of hyperspectral images
abstract
A first attempt to exploit distributed source coding (DSC) principles for the lossless compression of hyperspectral images is presented. The DSC paradigm is exploited to design a very light coder which minimizes the exploitation of the correlation between the image bands. In this way we managed to move the computational complexity from the encoder to the decoder, thus matching the needs of classical acquisition system where compression is achieved on board of the aerial platform and decoding at the ground station. Though the encoder does not explicitly exploit inter-band correlation, the achieved bit rate is about 1 bit/pixel lower than classical 2D schemes such as JPEG-LS or CALID 2D, and only about 1 b/p higher than the best performing, and much more complex, 3D schemes.
Mauro Barni, David Papini, Andrea Abrardo, Enrico Magli
IGARSS1
2005 Trellis-Coded Rational Dither Modulation for Digital Watermarking
Andrea Abrardo, Mauro Barni, Fernando Pérez-González, Carlos Mosquera
IWDW2
2005 Effectiveness of ST-DM Watermarking Against Intra-video Collusion
Roberto Caldelli, Alessandro Piva, Mauro Barni, Andrea Carboni
IWDW3
2005 Effectiveness of exhaustive search and template matching against watermark desynchronization
abstract
By focusing on a simple example, we investigate the effectiveness of exhaustive watermark detection and resynchronization through template matching against watermark desynchronization. We find that if the size of the search space does not increase exponentially, both methods provide asymptotically good results. We also show that the exhaustive search approach outperforms template matching from the point of view of reliable detection.
Mauro Barni
IEEE Signal Process. Lett.1
2005 Watermarking of MPEG-4 video objects
abstract
The recent finalization of MPEG-4 will make this standard very attractive for a large range of applications such as video editing, Internet video distribution, wireless video communications. Some of these applications are likely to get great benefit from watermarking technology, since it can enable a number of innovative services, such as conditional access policies, data annotation, data labeling, content authentication, to be implemented at a low price. One of the key points of the MPEG-4 standard is the possibility to access and manipulate objects within a video sequence. Thus object watermarking has to be achieved in such a way that, while a video object is transferred from a sequence to another, it is still possible to correctly access the data embedded within the object itself. The algorithm proposed in this paper embeds a watermark in each video object by imposing a particular relationship between some predefined pairs of quantized discrete cosine transform (DCT) coefficients in the luminance blocks of pseudo-randomly selected macroblocks (MBs). Watermarks are equally embedded into intra and inter MBs. Experimental results are presented validating the effectiveness of the proposed approach.
Mauro Barni, Franco Bartolini, Nicola Checcacci
IEEE Trans. Multim.1
2004 Minimum-Impact-on-Classifier (MIC) watermarking for protection of remote sensing imagery
abstract
The application of digital watermarking to remote sensing images requires a careful quality assessment in order to understand how the data quality is affected by the watermark. We propose a watermarking approach that minimizes the watermark impact on image classification, based on the idea of modulating the insertion coefficient in each channel so as to preserve to a larger extent the channels which classification is most sensitive to; we also propose a simplified procedure for estimating cluster displacement due to watermarking, leading to a low-complexity insertion approach. Experimental results on Landsat 7 ETM+ and IKONOS images show that the proposed MIC approach is able to significantly reduce classification errors, and to keep them within the intrinsic classification error
Mauro Barni, Enrico Magli, R. Troia
IGARSS1
2004 Joint near-lossless watermarking and compression for the authentication of remote sensing images
abstract
In this paper we present a new watermarking algorithm for joint near-lossless compression and authentication of remote sensing images. The adopted compression algorithm is the standard JPEG-LS algorithm. Our methodology has been designed by integrating into the standard JPEG-LS compression algorithm, by means of a stripe approach, a known authentication technique derived from Fridrich. This procedure points out two advantages: firstly, the produced bit-stream is perfectly compliant with the JPEG-LS standard, secondly, when the image has been decoded, it is always authenticated because information has been embedded in the reconstructed values. Near-lossless coding does not harm authentication procedure and robustness against different attacks is preserved
Roberto Caldelli, Giovanni Macaluso, Mauro Barni, Enrico Magli
IGARSS3
2004 Rational dither modulation: a novel data-hiding method robust to value-metric scaling attacks
abstract
A novel quantization-based data-hiding method, named rational dither modulation (RDM), is presented. This method amounts to simple modifications of the well-known dither modulation (DM) scheme, which is largely vulnerable to scaling attacks. With such modifications, RDM becomes invariant to those attacks. Since RDM does not work by trying to estimate the step-size of the quantizers, it does not need any pilot-sequence. Moreover, RDM is suitable for a scalar operation, thus avoiding the cumbersome constructions of spherical codes. It is also shown that RDM approaches the performance of DM asymptotically with the size of the memory needed for the method to operate. Simulation results show the accuracy of our theoretical analysis and the superiority of RDM compared to the improved spread spectrum method.
Fernando Pérez-González, Mauro Barni, Andrea Abrardo, Carlos Mosquera
MMSP2
2003 ArtShop: an art-oriented image-processing tool for cultural heritage applications
abstract
Abstract Advances in electronic imaging over recent years have encouraged the development of new tools for cultural heritage applications. In this paper a software application called ArtShop is described, containing some tools for artwork image restoration, developed during several years of research at the Image and Communications Laboratory of the University of Florence. Copyright © 2003 John Wiley & Sons, Ltd.
Vito Cappellini, Mauro Barni, Massimiliano Corsini, Alessia De Rosa, Alessandro Piva
Comput. Animat. Virtual Worlds2
2003 A general framework for robust watermarking security
Mauro Barni, Franco Bartolini, Teddy Furon
Signal Process.1
2002 Near-lossless digital watermarking for copyright protection of remote sensing images
abstract
We propose near-lossless digital watermarking for copyright protection of remote sensing images. In particular, we show that, by forcing a maximum absolute difference between the original and watermarked scene, the near-lossless paradigm makes it possible to decrease the effect of watermarking on remote sensing applications to be carried out on the images. As an example, the effect of near-lossless watermarking on image classification is analyzed.
Mauro Barni, Franco Bartolini, Vito Cappellini, Enrico Magli, Gabriella Olmo
IGARSS1
2002 Multichannel watermarking of color images
abstract
In the field of image watermarking, research has been mainly focused on grayscale image watermarking, whereas the extension to the color case is usually accomplished by marking the image luminance, or by processing each color channel separately. A DCT domain watermarking technique expressly designed to exploit the peculiarities of color images is presented. The watermark is hidden within the data by modifying a subset of full-frame DCT coefficients of each color channel. Detection is based on a global correlation measure which is computed by taking into account the information conveyed by the three color channels as well as their interdependency. To ultimately decide whether or not the image contains the watermark, the correlation value is compared to a threshold. With respect to existing grayscale algorithms, a new approach to threshold selection is proposed, which permits reducing the probability of missed detection to a minimum, while ensuring a given false detection probability. Experimental results, as well as theoretical analysis, are presented to demonstrate the validity of the new approach with respect to algorithms operating on image luminance only.
Mauro Barni, Franco Bartolini, Alessandro Piva
IEEE Trans. Circuits Syst. Video Technol.1
2001 Text based geometric normalization for robust watermarking of digital maps
abstract
The peculiarities of digital map images are exploited to develop a watermarking algorithm which is robust against geometric distortions. Robustness against geometric attacks is achieved through text-based image normalization. First, text is extracted from the to-be-marked map, then text orientation and size are exploited to normalize the image geometry prior to watermark insertion. Watermarking is performed by means of any of the existing algorithms ensuring good robustness against image processing tools. At the decoder side, text is extracted again from the map and used to normalize image geometry. Owing to the robustness of text features with respect to common image manipulations, and to the likely spreading of text all across the digital map, the proposed system exhibits an excellent robustness, as is witnessed by the experimental results reported.
Mauro Barni, Franco Bartolini, Vito Cappellini, Alessandro Piva, Filippo Salucco
ICIP (1)1
2001 Image segmentation and region filling for virtual restoration of artworks
abstract
Progress in electronic imaging over the last years has encouraged the development of new tools for cultural heritage applications. In particular, the areas of painting preservation and restoration have attracted the interest of researchers working in the field of image processing. A virtual tool for painting restoration, which simulates the actual restoration carried out in the restoration laboratory, is presented; in particular, the proposed techniques allow the virtual recovery and filling of the areas of a painting which are damaged by lacunas.
Alessia De Rosa, A. M. Bonacchi, Vito Cappellini, Mauro Barni
ICIP (1)4
2001 Cartographic image watermarking using text-based normalization
abstract
This paper deals with robust watermarking of cartographic images. We present a method (text-based geometric normalization-TBGN) which, by exploiting the particular content of cartographic images, namely text content, permits one to cope with global geometric transformations. The validity of the method is validated by experimental results.
Mauro Barni, Franco Bartolini, Alessandro Piva, Filippo Salucco
MMSP1
2001 A data hiding approach for correcting errors in H.263 video transmitted over a noisy channel
abstract
The performance of syntax-based error detection in the framework of H.263 video transmission is not sufficient to detect errors reliably, calling for the adoption of more effective error detection techniques. A new technique, based on data hiding concepts, is proposed here to increase the error detection rate in H.263 video sequences transmitted over error-prone communication channels. Some information is embedded into the compressed H.263 video stream aimed at highlighting the regions of the frame corrupted by transmission errors. The method preserves the image quality and maintains the original bit rate, without any modifications of the H.263 standard. The proposed approach allows one to avoid the transmission overhead typical of FEC-based or header-based error detection algorithms, and the extra computational burden peculiar to image analysis-based techniques, achieving better results with respect to syntax-based error detection, thanks to the use of side information at the decoder.
Franco Bartolini, A. Manetti, Alessandro Piva, Mauro Barni
MMSP4
2001 Image authentication techniques for surveillance applications
abstract
In automatic video surveillance (VS) systems, the issue of authenticating the video content is of primary importance. Given the ease with which digital images and videos can be manipulated, practically they do not have any value as legal proof, if the possibility of authenticating their content is not provided. In this paper, the problem of authenticating video surveillance image sequences is considered. After an introduction motivating the need for a watermarking-based authentication of VS sequences, a brief survey of the main watermarking-based authentication techniques is presented and the requirements that an authentication algorithm should satisfy for VS applications, are discussed. A novel algorithm which is suitable for VS visual data authentication is also presented and the results obtained by applying it to test data are discussed.
Franco Bartolini, Anastasios Tefas, Mauro Barni, Ioannis Pitas
Proc. IEEE3
2001 From watermark detection to watermark decoding: a PPM approach
Riccardo Baitello, Mauro Barni, Franco Bartolini, Vito Cappellini
Signal Process.2
2001 Information theoretic aspects in digital watermarking
Vito Cappellini, Franco Bartolini, Mauro Barni
Signal Process.3
2001 An improved H.263 video coder relying on weighted median filtering of motion vectors
abstract
The impact of a regularization of motion vectors (MVs) on the performance of a block-DCT based video coder (H.263) is addressed. Postprocessing is accomplished by exploiting both the spatial correlation of the vector field and the confidence of the estimated block vectors. A previously proposed adaptive scheme for MV smoothing, based on the theory of vector median filters, is adjusted and embedded into an H.263 coder. With a bit stream that is perfectly H.263-compatible, results are improved, especially for very low bit rates and complex motion of the scene.
Luciano Alparone, Mauro Barni, Franco Bartolini, Leonardo Santurri
IEEE Trans. Circuits Syst. Video Technol.2
2001 Improved wavelet-based watermarking through pixel-wise masking
abstract
A watermarking algorithm operating in the wavelet domain is presented. Performance improvement with respect to existing algorithms is obtained by means of a new approach to mask the watermark according to the characteristics of the human visual system (HVS). In contrast to conventional methods operating in the wavelet domain, masking is accomplished pixel by pixel by taking into account the texture and the luminance content of all the image subbands. The watermark consists of a pseudorandom sequence which is adaptively added to the largest detail bands. As usual, the watermark is detected by computing the correlation between the watermarked coefficients and the watermarking code, and the detection threshold is chosen in such a way that the knowledge of the watermark energy used in the embedding phase is not needed, thus permitting one to adapt it to the image at hand. Experimental results and comparisons with other techniques operating in the wavelet domain prove the effectiveness of the new algorithm.
Mauro Barni, Franco Bartolini, Alessandro Piva
IEEE Trans. Image Process.1
2001 A new decoder for the optimum recovery of nonadditive watermarks
abstract
Watermark detection, i.e., the detection of an invisible signal hidden within an image for copyright protection or data authentication, has classically been tackled by means of correlation-based techniques. Nevertheless, when watermark embedding does not obey an additive rule, or when the features the watermark is superimposed on do not follow a Gaussian pdf, correlation-based decoding is not the optimum choice. A new decoding algorithm is presented here which is optimum for nonadditive watermarks embedded in the magnitude of a set of full-frame DFT coefficients of the host image. By relying on statistical decision theory, the structure of the optimum is derived according to the Neyman-Pearson criterion, thus permitting to minimize the missed detection probability subject to a given false detection rate. The validity of the optimum decoder has been tested thoroughly to assess the improvement it permits to achieve from a robustness perspective. The results we obtained confirm the superiority of the novel algorithm with respect to classical correlation-based decoding.
Mauro Barni, Franco Bartolini, Alessia De Rosa, Alessandro Piva
IEEE Trans. Image Process.1
2000 Multichannel M-Filtering for Color Image Restoration
abstract
A new multichannel filter, the vector Huber filter (VHF) is proposed which, by relying on multivariate estimation theory permits to simultaneously remove impulsive and Gaussian noise from color images, while preserving edges and other fine image details. The new filter is obtained by extending the classical gray-scale Huber filter to the multichannel case. By relying on robust estimation theory, the rationale behind the development of the new filter is discussed. An approximated version of the vector Huber filter (the A-VHF filter), is also introduced to reduce the computational burden and making filtering practical. The validity of the A-VHF filter is confirmed by the preliminary experimental results shown in the paper.
Mauro Barni, Vito Cappellini, L. Mirri
ICIP1
2000 Craters Detection via Possibilistic Shell Clustering
abstract
A new circle extraction algorithm based on possibilistic clustering is presented along with its application to automatic crater detection in remote sensing images. With respect to classical algorithms based on fuzzy shell-clustering, solutions are proposed to make circle extraction robust against noise and non-circular structures. The proposed algorithm operates by grouping edge pixels into connected subgroups, and by fitting a circle to each group through possibilistic clustering. Circles are refined through PCS clustering, and validated by means of geometrical considerations. The effectiveness of the proposed approach for crater detection is confirmed by experimental results.
Mauro Barni, Alessandro Mecocci, L. Perugini
ICIP1
2000 Geometric-Invariant Robust Watermarking through Constellation Matching in the Frequency Domain
abstract
So far digital watermarking has been indicated as the most feasible answer for multimedia copyright protection issues, though many problems, especially regarding aspects of robustness against geometrical attacks, have not been completely and adequately solved yet. Robustness against geometric manipulations has been dealt with by inserting, together with the watermark, a synchronization template to be used later in the detection phase, to determine if a geometric distortion occurred and invert it before looking for the mark. A novel technique is presented, which, by exploiting the theory of geometric invariants, inserts a watermark intrinsically resistant to this sort of manipulations, thus avoiding the need of a synchronization pattern. Preliminary experimental results proving the goodness of the methodology are discussed along with some implementation problems due to the computational complexity.
Roberto Caldelli, Mauro Barni, Franco Bartolini, Alessandro Piva
ICIP2
2000 Robust video watermarking for wireless multimedia communications
abstract
Digital watermarking involves embedding copyright marks (watermarks), often imperceptibly, in multimedia objects to enhance or protect their value. In this paper we describe a novel watermarking algorithm suitable for video coding techniques such as MPEG-4 and H.263/H.324 and we test it in a wireless environment. The proposed algorithm satisfies critical properties not all of which are available in previous solutions. These properties include: resistance (robustness) of the embedded watermark to the error-prone nature of wireless channels as well as to video frame loss or misplacement, negligible probability of reading a non-embedded watermark, non-degradation of the marked video sequence and the possibility to mark video objects (e.g., MPEG-4 objects) in a single frame separately. Experimental results are given that show how these and other properties are achieved when video sequences are corrupted with errors that are typical of a wireless channel.
Nicola Checcacci, Mauro Barni, Franco Bartolini, Stefano Basagni
WCNC2
2000 A quasi-Euclidean norm to speed up vector median filtering
abstract
For reducing impulsive noise without degrading image contours, median filtering is a powerful tool. In multiband images, as for example color images or vector fields obtained by optic flow computation, a vector median filter can be used. Vector median filters are defined on the basis of a suitable distance, the best performing distance being the Euclidean. Euclidean distance is evaluated by using the Euclidean norm which is quite demanding from the point of view of computation given that a square root is required. In this paper an optimal piece-wise linear approximation of the Euclidean norm is presented which is applied to vector median filtering.
Mauro Barni, Fabio Buti, Franco Bartolini, Vito Cappellini
IEEE Trans. Image Process.1
2000 Capacity of full frame DCT image watermarks
abstract
The evaluation of the number of bits that can be hidden within an image through digital watermarking is a crucial topic, which has been addressed only for additive watermarks. The evaluation of watermark capacity is very important because it allows to put a theoretical upper bound on the amount of information that can be hidden into an image by a given watermarking procedure, regardless of the watermark extraction technique. It is the purpose of this work to suggest a methodology for the evaluation of the watermark capacity in a nonadditive, non-Gaussian framework, and to discuss the results we obtained by applying it to a set of standard images.
Mauro Barni, Franco Bartolini, Alessia De Rosa, Alessandro Piva
IEEE Trans. Image Process.1
1999 Exploiting the Cross-Correlation of RGB-Channels for Robust Watermarking of Color Images
abstract
In the last few years, digital watermarking has been proposed as a solution to the problem of copyright protection of multimedia data against unauthorized uses. In the field of image watermarking, research has been mainly focused on grey-scale image watermarking, whereas the extension to the color case is usually accomplished by marking the image luminance, or by processing each color channel separately. In this paper, a DCT domain technique expressly devised for watermarking of color images is presented, which exploits the characteristics of the human visual system and the correlation between the RGB image channels. Experimental results are presented to demonstrate the validity of the new approach with respect to algorithms operating on image luminance only.
Alessandro Piva, Mauro Barni, Franco Bartolini, Vito Cappellini
ICIP (1)2
1999 A Java-based system for remote correction of CRT color distortion
abstract
Calibration of the output device used for the reproduction of digital colour images (a color CRT in most cases) can either be achieved through conventional techniques involving mathematical modeling of the CRT, or through a novel neural-network-based scheme, introduced in this work. A Java-based system for CRT remote calibration is also presented, which allows the user to get rid of the computational burden necessary to train the neural network, or to estimate the parameters of the CRT model by relying on a set of measurements of the colours displayed by the CRT. Measurements can be avoided as well, by storing calibration data relative to a wide variety of CRTs and by using them to calibrate monitors with similar characteristics.
Andrea Abrardo, Mauro Barni, Vito Cappellini, M. Zappalorti, L. Fabiani
MMSP2
1999 A new possibilistic clustering algorithm for line detection in real world imagery
Mauro Barni, Rossana Gualtieri
Pattern Recognit.1
1999 Regularization of optic flow estimates by means of weighted vector median filtering
abstract
Vector median filtering has been recently proposed as an effective method to refine estimated velocity fields. Here, the use of a weighted vector median filtering is suggested to improve the regularization of the optic flow field across motion boundaries. Information about the confidence of the estimated pixel velocities is exploited for the choice of the filter weights. Experimental results, on both synthetic and real-world sequences, show the effectiveness of the proposed procedure.
Luciano Alparone, Mauro Barni, Franco Bartolini, Roberto Caldelli
IEEE Trans. Image Process.2
1998 Mask Building for Perceptually Hiding Frequency Embedded Watermarks
abstract
The interest in image watermarking techniques has rapidly grown during the years. Two requirements needed to be satisfied to use watermarking techniques for copyright protection are: unperceivability and robustness against image processing algorithms and forgery attacks. In particular, it is widely accepted that the exploitation of the characteristics of the human visual system should greatly help in satisfying both these requirements. Some solutions to the problem of building some perceptual masks for better hiding watermarks embedded in the full-frame DCT domain are presented. The results support the validity of the approach.
Franco Bartolini, Mauro Barni, Vito Cappellini, Alessandro Piva
ICIP (1)2
1998 Copyright protection of digital images by embedded unperceivable marks
Mauro Barni, Franco Bartolini, Vito Cappellini, Alessandro Piva
Image Vis. Comput.1
1998 A DCT-domain system for robust image watermarking
Mauro Barni, Franco Bartolini, Vito Cappellini, Alessandro Piva
Signal Process.1
1998 On the computational complexity of multivariate median filters
Mauro Barni, Vito Cappellini
Signal Process.1
1997 Using A Wavelet-Based Fractal Feature to Improve Texture Discrimination on SAR Images
abstract
Clustering is commonly used in remote sensing image segmentation. Among the clustering techniques, pyramid-based methods generally provide better performance in discriminating among different cover classes if compared to global algorithms. When applied to single polarization synthetic aperture radar (SAR) data, though, such algorithms suffer from misinterpretation problems due to the mono-band nature of the images produced by these sensors. In this case an important feature to improve the segmentation is texture. This paper describes a wavelet-based fuzzy clustering algorithm which receives as input both the remotely sensed image and a texture image based on a fractal model, derived from the wavelet representation itself. The algorithm has been tested on X-SAR images, and the results demonstrate its potential usefulness.
A. Betti, Mauro Barni, Alessandro Mecocci
ICIP (1)2
1997 DCT-Based Watermark Recovering Without Resorting to the Uncorrupted Original Image
abstract
Digital watermarking has been proposed as a viable solution to the need of copyright protection and authentication of multimedia data in a networked environment, since it makes it possible to identify the author, owner, distributor or authorized consumer of a document. In this paper a new watermarking technique to add a code to digital images is presented; the method operates in the frequency domain embedding a pseudo-random sequence of real numbers in a selected set of DCT coefficients. Watermark casting is performed by exploiting the masking characteristics of the human visual system, to ensure watermark invisibility. The embedded sequence is extracted without resorting to the original image, so that the proposed technique represents a major improvement to methods relying on the comparison between the watermarked and original images. Experimental results demonstrate that the watermark is robust to most of the signal processing techniques and geometric distortions.
Alessandro Piva, Mauro Barni, Franco Bartolini, Vito Cappellini
ICIP (1)2
1997 Colour-based detection of defects on chicken meat
Mauro Barni, Vito Cappellini, Alessandro Mecocci
Image Vis. Comput.1
1997 A fast algorithm for 1-norm vector median filtering
abstract
A major drawback with vector median filters is their high computational complexity. A fast algorithm is presented for the computation of the vector median operator based on 1-norm. The algorithm complexity is investigated both from a theoretical and an experimental point of view. Simulation results are shown proving the complexity reduction achieved by the novel algorithm.
Mauro Barni
IEEE Trans. Image Process.1
1996 Adaptively weighted vector-median filters for motion-fields smoothing
abstract
In the field of video coding the issues of backward prediction and standards conversion have focused an increasing attention towards techniques for an effective estimation of the true interframe motion. The problem of restoration of motion vector-fields computed by means of a standard block matching algorithm is addressed. The restoration must be carried out carefully by exploiting both the spatial correlation of the vector-field, and the significance of the obtained vectors as measures of the reliability of the previous estimation step. A novel approach matching both the above requirements is presented. Based on the theory of vector-median filters an adaptive scheme is developed and results are discussed.
Luciano Alparone, Mauro Barni, Franco Bartolini, Vito Cappellini
ICASSP2
1996 Unsupervised detection of straight lines through possibilistic clustering
abstract
The unsupervised detection of an unknown number of straight lines in digital imagery is addressed. Based on possibilistic clustering an algorithm is proposed which does not require any assumption about the number of straight lines present in the edge map. Three major modifications are introduced with respect to existing clustering-based algorithms: the use of possibilistic clustering; a more sophisticated analysis of the clusters, including the possibility of rejecting non linear clusters; a bottom up strategy to evaluate how many straight lines the image contains. The effectiveness of the proposed scheme is proved by validating it against real world imagery.
Mauro Barni, Vito Cappellini, A. Paoli, Alessandro Mecocci
ICIP (2)1
1996 Comments on "A possibilistic approach to clustering"
abstract
In this comment, we report a difficulty with the-application of the possibilistic approach to fuzzy clustering (PCM) proposed by Keller and Krishnapuram (1993). In applying this algorithm we found that it has the undesirable tendency to produce coincidental clusters. Results illustrating this tendency are reported and a possible explanation for the PCM behavior is suggested.
Mauro Barni, Vito Cappellini, Alessandro Mecocci
IEEE Trans. Fuzzy Syst.1
1995 Optimum linear approximation of the Euclidean norm to speed up vector median filtering
abstract
For reducing impulsive noise without degrading image contours, median filtering is a powerful tool. In multiband images, as for example color images or vector field obtained by optic flow computation, a vector median filter can be used. Vector median filters are defined on the basis of a suitable distance, the best performing distance being the Euclidean. The Euclidean distance is computed by using the Euclidean norm which is quite demanding from the point of view of computation given that a square root is required. An optimal piecewise linear approximation of the Euclidean norm is presented which is applied to vector median filtering.
Mauro Barni, Franco Bartolini, Fabio Buti, Vito Cappellini
ICIP1
1995 An intelligent perception system for food quality inspection using color analysis
abstract
Modern manufacturing systems call for full-rate automated inspection of produced samples. A vision-based intelligent perception system (IPS) is presented making automated inspection of chicken meat feasible. The IPS analyzes RGB images framing the chickens after the slaughtering and plucking process and detects defects such as burns, hematomas and blisters, along with other relevant features. The vision module, which is the core of the system, operates by first extracting the chicken body from the background, then it segments the body into its anatomic subparts. Defective areas are identified by means of morphological reconstruction. Finally, defects are classified by comparing their features against the defect description contained in a reference database.
Mauro Barni, A. W. Mussa, Alessandro Mecocci, Vito Cappellini, Tariq S. Durrani
ICIP1
1994 Dual-channel iterative even-median filter
Luciano Alparone, Mauro Barni
Pattern Recognit. Lett.2
1994 Fast vector median filter based on Euclidean norm approximation
abstract
The vector median filter has good filtering capabilities; nevertheless, its huge computational complexity significantly limits its practical usability. A vector median filter based on a fast approximation of the Euclidean norm is presented. The proposed algorithm couples computational and filtering effectiveness, and it is well suited for hardware implementation. Theoretical and experimental results regarding both approximation error and speed improvement prove the validity of the proposed algorithm.>
Mauro Barni, Vito Cappellini, Alessandro Mecocci
IEEE Signal Process. Lett.1