VLDB 2026 Research / reviewers in the wild / expert
Benedetta Tondi
dblp:124/8382
· DBLP profile ↗
46ranked-venue papers
4as first author
26since 2021 · last 2026
0000-0002-7518-046XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 4 first-author · 17 since 2021Graphics, computer vision, multimedia, augmented reality and games · 16 · 6 since 2021Artificial intelligence and machine learning · 7 · 6 since 2021Theory of computation · 2Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Comparative Study of Adversarial Training and Randomized Smoothing for Robust AI-Generated Image AttributionabstractIn this paper we explore two different approaches for designing AI-generated image attribution methods that are robust in adversarial settings, namely adversarial training (AT) and randomized smoothing (RS). While AT has been widely adopted in machine learning to improve the adversarial robustness of classifiers, its application to source image attribution is still unexplored. RS, on the other hand, has emerged as a method for developing deep learning classifiers with certified robustness, i.e., for which a certified level of robustness can be theoretically guaranteed, regardless of the specific manipulation causing the distortion. With the exception of a single prior study, its application to forensic tasks has not been previously explored. Experiments conducted on two datasets of AI-generated images show that both approaches achieve substantial adversarial robustness and exhibit a general resistance to common image manipulations. In particular, adversarial training provides stronger robustness against a broad range of post-processing operations, whereas randomized smoothing yields higher practical robustness against adversarial attacks. Niccolò Pancino, Nasrin Malekzadeh Goradel, Mauro Barni, Benedetta Tondi |
IH&MMSec | 5 |
| 2026 | An efficient watermarking method for latent diffusion models via low-rank adaptation and dynamic loss weighting
Dongdong Lin, Yue Li 0041, Benedetta Tondi, Kaiqing Lin, Bin Li 0011, Mauro Barni |
Expert Syst. Appl. | 3 |
| 2025 | Colorization Network Watermarking in the CIE-Lab DomainabstractA possible solution to protect the copyright of generative models is to watermark the models so that any image generated by the models contain an invisible watermark, whose presence can be checked at a later stage for ownership verification or to trace back the image to the generator which produced it. In general, a Generative Adversarial Network (GAN) or a diffusion model can be watermarked by applying a frozen pretrained watermark decoder on top of the generator, and adding the watermark decoding loss term to the generator loss. In this paper, we propose a method to watermark image colorization models, that is models whose goal is to introduce plausible colors in grey-level images. The particular color domain wherein colorization models operate requires that the watermark is embedded in the image components that are actually affected by the colorization, avoiding to embed the watermark in the luminance channel, which is usually left unchanged by the colorization process. In particular, we show that the domain the watermark decoder is trained on impacts the performance of the network and better performance in terms of watermark accuracy and robustness can be achieved by training the decoder to extract the watermark bits from the chrominance components in the CIE-Lab space and use the decoder trained in this way to watermark the GAN model. Alessio Chiovelli, Nischay Purnekar, Benedetta Tondi, Mauro Barni |
ICASSP | 3 |
| 2025 | WILD: a new in-the-Wild Image Linkage Dataset for synthetic image attributionabstractSynthetic image source attribution is an open challenge, with an increasing number of image generators being released yearly. The complexity and the sheer number of available generative techniques, as well as the scarcity of high-quality open source datasets of diverse nature for this task, make training and benchmarking synthetic image source attribution models very challenging. WILD1is a new in-the-Wild Image Linkage Dataset designed to provide a powerful training and benchmarking tool for synthetic image attribution models. The dataset is built out of a closed set of 10 popular commercial generators, which constitutes the training base of attribution models, and an open set of 10 additional generators, simulating a real-world in-the-wild scenario. Each generator is represented by 1,000 images, for a total of 10,000 images in the closed set and 10,000 images in the open set. Half of the images are post-processed with a wide range of operators. WILD allows benchmarking attribution models in a wide range of tasks, including closed and open set identification and verification, and robust attribution with respect to post-processing and adversarial attacks. Models trained on WILD are expected to benefit from the challenging scenario represented by the dataset itself. Moreover, an assessment of seven baseline methodologies on closed and open set attribution is presented, including robustness tests with respect to post-processing. Pietro Bongini, Sara Mandelli, Andrea Montibeller, Mirko Casu, Orazio Pontorno, Claudio Vittorio Ragaglia, Luca Zanchetta, Mattia Aquilina, Taiba Majid Wani, Luca Guarnera, Benedetta Tondi, Giulia Boato, Paolo Bestagini, Irene Amerini, Francesco G. B. De Natale, Sebastiano Battiato, Mauro Barni |
IJCNN | 11 |
| 2025 | Semiotic-Based Construction of a Large Emotional Image Dataset with Neutral SamplesabstractImage Visual Sentiment Analysis (VSA) requires the availability of large annotated datasets, whose construction presents many challenges. The necessity of gathering a large amount of labeled images contrasts with the rigorous, but lengthy, process required for manual annotation based on psychovisual experiments, and with the automatic gathering of large amounts of data roughly labeled based on the sentiment analysis of the text accompanying the images, like captions, tweets and tags. An additional limitation is the scarcity of high-quality datasets with a neutral class, which forces the images to be classified into emotions even when the observers show no emotional activation. In this work, we present a scalable methodology rooted in semiotics and art theory for the construction of a 3-class (positive, negative and neutral) VSA dataset, enabling the downloading of a desired quantity of images while maintaining labeling coherence and accuracy. Based on the proposed methodology, we introduce and make publicly available a VSA dataset of over 100,000 images. To validate the quality of the dataset, we used it to train several classifiers and compared their performance with those of classifiers trained on other datasets. The results, we got, show that the classifiers trained on the new dataset provide better performance when tested on independent datasets, including those commonly used for psycho-visual experiments. Marco Blanchini, Giovanna Maria Dimitri, Lydia Abady, Benedetta Tondi, Tarcisio Lancioni, Mauro Barni |
WACV | 4 |
| 2025 | A CycleGAN Watermarking Method for Ownership VerificationabstractDue to the widespread use and proliferation of Deep Neural Networks (DNNs), safeguarding their Intellectual Property Rights (IPR) has become increasingly important. This article proposes a method for watermarking a cyclic Generative Adversarial Network (GAN), specifically CycleGAN, to address the gap between the watermarking of conventional GAN models and cyclic GAN watermarking. The proposed method involves training a watermark decoder, which is then frozen and used to extract the watermark bits during the training of the CycleGAN model. The model is trained using specific loss functions that are optimized to achieve excellent performance on both the Image-to-Image Translation (I2IT) task and watermark embedding. Besides, a comprehensive theoretical and practical statistical analysis to verify the ownership of the model from the extracted watermark bits is given. At last, the model's robustness is evaluated against image post-processing, and further improved by fine-tuning the watermark decoder by applying data augmentation to the generated images before extracting the watermark bits. We also verify the robustness of the watermark to surrogate model attacks, carried out by accessing the watermarked model in a black-box modality. The experimental results demonstrate that the proposed method is effective and robust against image post-processing and can resist surrogate model attacks. Dongdong Lin, Benedetta Tondi, Bin Li 0011, Mauro Barni |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Robust and Large-Payload DNN Watermarking via Fixed, Distribution-Optimized, WeightsabstractThe design of an effective multi-bit watermarking algorithm hinges upon finding a good trade-off between the three fundamental requirements forming the watermarking trade-off triangle, namely, robustness against network modifications, payload, and unobtrusiveness, ensuring minimal impact on the performance of the watermarked network. In this paper, we first revisit the nature of the watermarking trade-off triangle for the DNN case, then we exploit our findings to propose a white-box, multi-bit watermarking method achieving very large payload and strong robustness against network modification. In the proposed system, the weights hosting the watermark are set prior to training, making sure that their amplitude is large enough to bear the target payload and survive network modifications, notably retraining, and are left unchanged throughout the training process. The distribution of the weights carrying the watermark is theoretically optimised to ensure the secrecy of the watermark and make sure that the watermarked weights are indistinguishable from the non-watermarked ones. The proposed method can achieve outstanding performance, with no significant impact on network accuracy, including robustness against network modifications, retraining and transfer learning, while ensuring a payload which is out of reach of state of the art methods achieving a lower - or at most comparable - robustness. Benedetta Tondi, Andrea Costanzo, Mauro Barni |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | JMA: A General Algorithm to Craft Nearly Optimal Targeted Adversarial Examples
Benedetta Tondi, Wei Guo 0012, Niccolò Pancino, Mauro Barni |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | BOSC: A Backdoor-Based Framework for Open Set Synthetic Image AttributionabstractWith the continuous progress of AI technology, new generative architectures continuously appear, thus driving the attention of researchers towards the development of synthetic image attribution methods capable of working in open-set scenarios. Existing approaches focus on extracting highly discriminative features for closed-set architectures, increasing the confidence of the prediction when the samples come from closed-set models/architectures, or estimating the distribution of unknown samples, i.e., samples from unknown architectures. In this paper, we propose a novel framework for open set attribution of synthetic images, named BOSC (Backdoor-based Open Set Classification), that relies on backdoor injection to design a classifier with rejection option. BOSC works by deliberately including class-specific triggers inside a portion of the images in the training set to induce the network to establish a matching between in-set class features and trigger features. The behavior of the trained model with respect to samples containing a trigger is then exploited at inference time to perform sample rejection using an ad-hoc score. Experiments show that the proposed method has good performance, always surpassing the state-of-the-art. Robustness against image processing is also very good. Although we designed our method for the task of synthetic image attribution, the proposed framework is a general one and can be used for other image forensic applications. Jun Wang 0061, Benedetta Tondi, Mauro Barni |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Improving the Robustness of Synthetic Images Detection by Means of Print and Scan AugmentationabstractA common approach to improve the robustness of synthetic image detectors against image post-processing is to augment the dataset the detectors are trained on by applying a selected pool of image processing operators. A list of commonly adopted image processing augmentations includes JPEG compression, geometric transformations, color adjustment, noise addition, and filtering. Robustness against image processing operators that are not included in the augmentation pool, however, is problematic since the detectors tend to overfit to the image operators used during training, without generalizing to other kinds of processing. In this paper, we introduce a new form of data augmentation based on the simulation of the Print & Scan (P&S) process. We argue that asking the synthetic image detector to still work after that an image has been printed and scanned, forces the detector to rely on robust features that can be detected even after other forms of processing. Given the impossibility of creating a large enough dataset of P&S images, we trained a CycleGAN network to simulate the P&S process and used it for data augmentation. The results we got by applying the above procedure to a detector trained to distinguish real and synthetic images in different domains show that P&S augmentation improves the robustness of the detectors even on images processed by operators that have not been used during training. Nischay Purnekar, Lydia Abady, Benedetta Tondi, Mauro Barni |
IH&MMSec | 3 |
| 2024 | A siamese-based verification system for open-set architecture attribution of synthetic imagesabstractDespite the wide variety of methods developed for synthetic image attribution, most of them can only attribute images generated by models or architectures included in the training set and do not work with unknown architectures, hindering their applicability in real-world scenarios. In this paper, we propose a verification framework that relies on a Siamese Network to address the problem of open-set attribution of synthetic images to the architecture that generated them. We consider two different settings. In the first setting, the system determines whether two images have been produced by the same generative architecture or not. In the second setting, the system verifies a claim about the architecture used to generate a synthetic image, utilizing one or multiple reference images generated by the claimed architecture. The main strength of the proposed system is its ability to operate in both closed and open-set scenarios so that the input images, either the query and reference images, can belong to the architectures considered during training or not. Experimental evaluations encompassing various generative architectures such as GANs, diffusion models, and transformers, focusing on synthetic face image generation, confirm the excellent performance of our method in both closed and open-set settings, as well as its strong generalization capabilities. Lydia Abady, Jun Wang 0061, Benedetta Tondi, Mauro Barni |
Pattern Recognit. Lett. | 3 |
| 2024 | Wide Flat Minimum Watermarking for Robust Ownership Verification of GANsabstractWe propose a novel multi-bit box-free watermarking method for the protection of Intellectual Property Rights (IPR) of GANs with improved robustness against white-box model-level attacks like fine-tuning, pruning, quantization, and surrogate model attacks. The watermark is embedded by adding an extra watermarking loss term during GAN training, ensuring that the images generated by the GAN contain an invisible watermark that can be retrieved by a pre-trained watermark decoder. In order to improve the robustness against white-box model-level attacks, we make sure that the model converges to a wide flat minimum of the watermarking loss term, in such a way that any modification of the model parameters does not erase the watermark. To do so, we add random noise vectors to the parameters of the generator and require that the watermarking loss term is as invariant as possible with respect to the presence of noise. This procedure forces the generator to converge to a wide flat minimum of the watermarking loss. The proposed method is architecture- and dataset-agnostic, thus being applicable to many different generation tasks and models, as well as to CNN-based image processing architectures. We present the results of extensive experiments showing that the presence of the watermark has a negligible impact on the quality of the generated images, and proving the superior robustness of the watermark against model modification and surrogate model attacks. Jianwei Fei, Zhihua Xia, Benedetta Tondi, Mauro Barni |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Universal Detection of Backdoor Attacks via Density-Based Clustering and Centroids AnalysisabstractWe propose a Universal Defence against backdoor attacks based on Clustering and Centroids Analysis (CCA-UD). The goal of the defence is to reveal whether a Deep Neural Network model is subject to a backdoor attack by inspecting the training dataset. CCA-UD first clusters the samples of the training set by means of density-based clustering. Then, it applies a novel strategy to detect the presence of poisoned clusters. The proposed strategy is based on a general misclassification behaviour observed when the features of a representative example of the analysed cluster are added to benign samples. The capability of inducing a misclassification error is a general characteristic of poisoned samples, hence the proposed defence is attack-agnostic. This marks a significant difference with respect to existing defences, that, either can defend against only some types of backdoor attacks, or are effective only when some conditions on the poisoning ratio or the kind of triggering signal used by the attacker are satisfied. Experiments carried out on several classification tasks and network architectures, considering different types of backdoor attacks (with either clean or corrupted labels), and triggering signals, including both global and local triggering signals, as well as sample-specific and source-specific triggers, reveal that the proposed method is very effective to defend against backdoor attacks in all the cases, always outperforming the state of the art techniques. Wei Guo 0012, Benedetta Tondi, Mauro Barni |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Constructing an Intrinsically Robust Steganalyzer via Learning Neighboring Feature Relationships and Self-Adversarial AdjustmentabstractThe effectiveness of deep learning-based steganalyzers is significantly compromised by adversarial steganography. In response to this challenge, recent efforts have been devoted to identifying distinct traces of adversarial perturbations, yet they have overlooked the inherently adversarial robustness required in steganalyzers. This paper aims to develop a steganalytic model that defends against adversarial steganography by increasing the difficulty of generating adversarial stego images. To achieve this objective, the techniques of learning neighboring feature relationships and self-adversarial adjustment are proposed with three essential modules. The first one, named K-times Dropout Neighboring Feature Transformer (KDNFT), is designed to accept a set of neighboring features obtained by dropout as input. Based on the finding that K-times dropout neighboring features have different distributions for covers and adversarial stegos, KDNFT effectively learns to exploit the relationships among these features for adversarial steganalysis. To facilitate adversarial training, which is an effective way to improve intrinsic robustness, the second module called Pseudo Adversarial Stego Generator (PASG) is proposed to synthesize samples for training. The third module is a Test-time Active Perturbation (TAP) module that adjusts the results of adversarial stego samples close to the decision boundary in a self-adversarial way. Extensive experiments demonstrate that our method achieves improvements in steganalyzing various kinds of adversarial steganographic methods. Kaiqing Lin, Bin Li 0011, Weixiang Li, Mauro Barni, Benedetta Tondi, Xulong Liu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | A Siamese Based System for City VerificationabstractImage geolocalization is receiving increasing attention due to its importance in several applications, such as image retrieval, criminal investigations and fact-checking. Previous works focused on several instances of image geolocalization including place recognition, GPS coordinates estimation and country recognition. In this paper, we tackle an even more challenging problem, which is recognizing the city where an image has been taken. Due to the vast number of cities in the world, we cast the problem as a verification problem, whereby the system has to decide whether a certain image has been taken in a given city or not. In particular, we present a system that given a query image and a small set of images taken in a target city, decides if the query image has been shot in the target city or not. To allow the system to handle the case of images, taken in cities that have not been used during training, we use a Siamese network based on Vision Transformer as a backbone. The experiments we run prove the validity of the proposed system which outperforms solutions based on state-of-the-art techniques, even in the challenging case of images shot in different cities of the same country. Omran Alamayreh, Jun Wang 0061, Giovanna Maria Dimitri, Benedetta Tondi, Mauro Barni |
ECAI | 4 |
| 2023 | Which Country is This Picture From? New Data and Methods For Dnn-Based Country RecognitionabstractRecognizing the country where a picture has been taken has many potential applications, such as identification of fake news and prevention of disinformation campaigns. Previous works focused on the estimation of the geo-coordinates where a picture has been taken. Yet, recognizing in which country an image was taken could be more critical, from a semantic and forensic point of view, than estimating its spatial coordinates. In the above framework, this paper provides two contributions. First, we introduce the VIPPGeo dataset, containing 3.8 million geo-tagged images. Secondly, we used the dataset to train a model casting the country recognition problem as a classification problem. The experiments show that our model provides better results than the current state of the art. Notably, we found that asking the network to identify the country provides better results than estimating the geo-coordinates and then tracing them back to the country where the picture was taken. Omran Alamayreh, Giovanna Maria Dimitri, Jun Wang 0061, Benedetta Tondi, Mauro Barni |
ICASSP | 4 |
| 2023 | Classification of Synthetic Facial Attributes by Means of Hybrid Classification/Localization Patch-Based AnalysisabstractFacial attributes editing, that is the manipulation of some specific attributes of a face image, is a new trend in the generation of synthetic images by GANs. Several recent studies have shown the possibility to detect the synthetic nature of such images by training a DL-based binary classifier. At the same time, the question about the specific face attributes that have been altered is typically disregarded, yet this may be a crucial information for forensic analysts. In this paper, we propose a new architecture whose objective is to identify the altered facial attributes of synthetic face images. To do so, we developed a hybrid classification-and-localization architecture. The local and global features are first extracted from the full image and from specific image patches, and then merged by using an attentional feature fusion module. The extensive experiments we have carried out involving 19 different facial attributes, manipulated by a StyleGAN2 network, show the good accuracy of the proposed method and its robustness against several image post-processing operators. Jun Wang 0061, Benedetta Tondi, Mauro Barni |
ICASSP | 2 |
| 2023 | A Temporal Chrominance Trigger for Clean-Label Backdoor Attack Against Anti-Spoof Rebroadcast DetectionabstractWe propose a stealthy clean-label video backdoor attack against Deep Learning (DL)-based models aiming at detecting a particular class of spoofing attacks, namely video rebroadcast attacks. The injected backdoor does not affect spoofing detection in normal conditions, but induces a misclassification in the presence of a specific triggering signal. The proposed backdoor relies on a temporal trigger altering the average chrominance of the video sequence. The backdoor signal is designed by taking into account the peculiarities of the Human Visual System (HVS) to reduce the visibility of the trigger, thus increasing the stealthiness of the backdoor. To force the network to look at the presence of the trigger in the challenging clean-label scenario, we choose the poisoned samples used for the injection of the backdoor following a so-called Outlier Poisoning Strategy (OPS). According to OPS, the triggering signal is inserted in the training samples that the network finds more difficult to classify. The effectiveness of the proposed backdoor attack and its generality are validated experimentally on different datasets and anti-spoofing rebroadcast detection architectures. Wei Guo 0012, Benedetta Tondi, Mauro Barni |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Exploiting temporal information to prevent the transferability of adversarial examples against deep fake detectorsabstractThe diffusion of AI tools capable of generating realistic DeepFakes (DF) videos raises serious threats to face-based biometric recognition systems. For this reason, several detectors based on Deep Neural Networks (DNNs) have been developed to distinguish between real and DF videos. Despite their good performance, these methods suffer from vulnerability to adversarial attacks. In this paper, we argue that it is possible to increase the resilience of DNN-based DF detectors against black-box adversarial attacks by exploiting the temporal information contained in the video. By using such information, in fact, the transferability of adversarial examples from a source to a target model is significantly decreased, making it difficult to launch an attack without accessing the target network. To back this claim, we trained two convolutional neural networks (CNNs) to detect DF videos, and measured their robustness against black-box, transfer-based, attacks. We also trained two detectors by adding to the CNNs a long short-term memory (LSTM) layer to extract temporal information. Then, we measured the transferability of adversarial examples to-wards the LSTM-networks. The results we got suggest that the methods based on temporal information are less prone to black-box attacks. Dongdong Lin, Benedetta Tondi, Bin Li 0011, Mauro Barni |
IJCB | 2 |
| 2021 | DNN Watermarking: Four Challenges and a FuneralabstractThe demand for methods to protect the Intellectual Property Rights (IPR) associated to Deep Neural Networks (DNNs) is rising. Watermarking has been recently proposed as a way to protect the IPR of DNNs and track their usages. Although a number of techniques for media watermarking have been proposed and developed over the past decades, their direct translation to DNN watermarking faces the problem of the embedding being carried out on functionals instead of signals. This originates differences not only in the way performance, robustness and unobtrusiveness are measured, but also on the embedding domain, since there is the possibility of hiding information in the model behavior. In this paper, we discuss these dissimilarities that lead to a DNN-specific taxonomy of watermarking techniques. Then, we present four challenges specific to DNN watermarking that, for their practical importance and theoretical interest, should occupy the agenda of researchers in the next years. Finally, we discuss some bad practices that negatively affected research in media watermarking and that should not be repeated in the case of DNNs. Mauro Barni, Fernando Pérez-González, Benedetta Tondi |
IH&MMSec | 3 |
| 2021 | MasterFace Watermarking for IPR Protection of Siamese Network for Face Verification
Wei Guo 0012, Benedetta Tondi, Mauro Barni |
IWDW | 2 |
| 2021 | Boosting CNN-based primary quantization matrix estimation of double JPEG images via a classification-like architectureabstractAbstract Estimating the primary quantization matrix of double JPEG compressed images is a problem of relevant importance in image forensics since it allows to infer important information about the past history of an image. In addition, the inconsistencies of the primary quantization matrices across different image regions can be used to localize splicing in double JPEG tampered images. Traditional model-based approaches work under specific assumptions on the relationship between the first and second compression qualities and on the alignment of the JPEG grid. Recently, a deep learning-based estimator capable to work under a wide variety of conditions has been proposed that outperforms tailored existing methods in most of the cases. The method is based on a convolutional neural network (CNN) that is trained to solve the estimation as a standard regression problem. By exploiting the integer nature of the quantization coefficients, in this paper, we propose a deep learning technique that performs the estimation by resorting to a simil-classification architecture. The CNN is trained with a loss function that takes into account both the accuracy and the mean square error (MSE) of the estimation. Results confirm the superior performance of the proposed technique, compared to the state-of-the art methods based on statistical analysis and, in particular, deep learning regression. Moreover, the capability of the method to work under general operative conditions, regarding the alignment of the second compression grid with the one of first compression and the combinations of the JPEG qualities of former and second compression, is very relevant in practical applications, where these information are unknown a priori. Benedetta Tondi, Andrea Costanzo, Dequ Huang, Bin Li 0011 |
EURASIP J. Inf. Secur. | 1 |
| 2021 | Spread-Transform Dither Modulation Watermarking of Deep Neural Network
Yue Li 0041, Benedetta Tondi, Mauro Barni |
J. Inf. Secur. Appl. | 2 |
| 2021 | A Master Key backdoor for universal impersonation attack against DNN-based face verification
Wei Guo 0012, Benedetta Tondi, Mauro Barni |
Pattern Recognit. Lett. | 2 |
| 2021 | Copy Move Source-Target Disambiguation Through Multi-Branch CNNsabstractWe propose a method to identify the source and target regions of a copy-move forgery so allow a correct localisation of the tampered area. First, we cast the problem into a hypothesis testing framework whose goal is to decide which region between the two nearly-duplicate regions detected by a generic copy-move detector is the original one. Then we design a multi-branch CNN architecture that solves the hypothesis testing problem by learning a set of features capable to reveal the presence of interpolation artefacts and boundary inconsistencies in the copy-moved area. The proposed architecture, trained on a synthetic dataset explicitly built for this purpose, achieves good results on copy-move forgeries from both synthetic and realistic datasets. Based on our tests, the proposed disambiguation method can reliably reveal the target region even in realistic cases where an approximate version of the copy-move localization mask is provided by a state-of-the-art copy-move detection algorithm. Mauro Barni, Quoc-Tin Phan, Benedetta Tondi |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Image Splicing Detection, Localization and Attribution via JPEG Primary Quantization Matrix Estimation and ClusteringabstractDetection of inconsistencies of double JPEG artifacts across different image regions is often used to detect local image manipulations, like image splicing, and to localize them. In this paper, we move one step further, proposing an end-to-end system that, in addition to detecting and localizing spliced regions, can also distinguish regions coming from different donor images. We assume that both the spliced regions and the background image have undergone a double JPEG compression, and use a local estimate of the primary quantization matrix to distinguish between spliced regions taken from different sources. To do so, we cluster the image blocks according to the estimated primary quantization matrix and refine the result by means of morphological reconstruction. The proposed method can work in a wide variety of settings including aligned and non-aligned double JPEG compression, and regardless of whether the second compression is stronger or weaker than the first one. We validated the proposed approach by means of extensive experiments showing its superior performance with respect to baseline methods working in similar conditions. Yakun Niu, Benedetta Tondi, Yao Zhao 0001, Mauro Barni |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | Effectiveness of Random Deep Feature Selection for Securing Image Manipulation Detectors Against Adversarial ExamplesabstractWe investigate if the random feature selection approach proposed in [1] to improve the robustness of forensic detectors to targeted attacks, can be extended to detectors based on deep learning features. In particular, we study the transferability of adversarial examples targeting an original CNN image manipulation detector to other detectors (a fully connected neural network and a linear SVM) that rely on a random subset of the features extracted from the flatten layer of the original network. The results we got by considering three image manipulation detection tasks (resizing, median filtering and adaptive histogram equalization), two original network architectures and three classes of attacks, show that feature randomization helps to hinder attack transferability, even if, in some cases, simply changing the architecture of the detector, or even retraining the detector is enough to prevent the transferability of the attacks. Mauro Barni, Ehsan Nowroozi, Benedetta Tondi |
ICASSP | 3 |
| 2020 | Adversarial examples for replay attacks against CNN-based face recognition with anti-spoofing capability
Benedetta Tondi, Mauro Barni |
Comput. Vis. Image Underst. | 2 |
| 2020 | Improving the security of image manipulation detection through one-and-a-half-class multiple classification
Mauro Barni, Ehsan Nowroozi, Benedetta Tondi |
Multim. Tools Appl. | 3 |
| 2020 | Challenging the Adversarial Robustness of DNNs Based on Error-Correcting Output CodesabstractThe existence of adversarial examples and the easiness with which they can be generated raise several security concerns with regard to deep learning systems, pushing researchers to develop suitable defence mechanisms. The use of networks adopting error-correcting output codes (ECOC) has recently been proposed to counter the creation of adversarial examples in a white-box setting. In this paper, we carry out an in-depth investigation of the adversarial robustness achieved by the ECOC approach. We do so by proposing a new adversarial attack specifically designed for multilabel classification architectures, like the ECOC-based one, and by applying two existing attacks. In contrast to previous findings, our analysis reveals that ECOC-based networks can be attacked quite easily by introducing a small adversarial perturbation. Moreover, the adversarial examples can be generated in such a way to achieve high probabilities for the predicted target class, hence making it difficult to use the prediction confidence to detect them. Our findings are proven by means of experimental results obtained on MNIST, CIFAR-10, and GTSRB classification tasks. Benedetta Tondi, Xixiang Lv, Mauro Barni |
Secur. Commun. Networks | 2 |
| 2020 | CNN-based steganalysis and parametric adversarial embedding: A game-theoretic framework
Benedetta Tondi, Bin Li 0011, Mauro Barni |
Signal Process. Image Commun. | 2 |
| 2020 | Primary Quantization Matrix Estimation of Double Compressed JPEG Images via CNNabstractAvailable model-based techniques for the estimation of the primary quantization matrix in double-compressed JPEG images work only under specific conditions regarding the relationship between the first and second compression quality factors, and the alignment of the first and second JPEG compression grids. In this paper, we propose a single CNN-based estimation technique that can work under a wide range of settings. We do so, by adapting a dense CNN network to the problem at hand. Particular attention is paid to the choice of the loss function. Experimental results highlight several advantages of the new method, including: i) capability of working under very general conditions, ii) improved performance in terms of MSE and Accuracy, especially in the non-aligned case, iii) better spatial resolution due to the ability of providing good results also on small image patches. Yakun Niu, Benedetta Tondi, Yao Zhao 0001, Mauro Barni |
IEEE Signal Process. Lett. | 2 |
| 2019 | On the Transferability of Adversarial Examples against CNN-based Image ForensicsabstractRecent studies have shown that Convolutional Neural Networks (CNN) are relatively easy to attack through the generation of so called adversarial examples. Such vulnerability also affects CNN-based image forensic tools. Research in deep learning has shown that adversarial examples exhibit a certain degree of transferability, i.e., they maintain part of their effectiveness even against CNN models other than the one targeted by the attack. This is a very strong property undermining the usability of CNN's in security-oriented applications. In this paper, we investigate if attack transferability also holds in image forensics applications. With specific reference to the case of manipulation detection, we analyse the results of several experiments considering different sources of mismatch between the CNN used to build the adversarial examples and the one adopted by the forensic analyst. The analysis ranges from cases in which the mismatch involves only the training dataset, to cases in which the attacker and the forensic analyst adopt different architectures. The results of our experiments show that, in the majority of the cases, the attacks are not transferable, thus easing the design of proper countermeasures at least when the attacker does not have a perfect knowledge of the target detector. Mauro Barni, Kassem Kallas, Ehsan Nowroozi, Benedetta Tondi |
ICASSP | 4 |
| 2019 | A New Backdoor Attack in CNNS by Training Set Corruption Without Label PoisoningabstractBackdoor attacks against CNNs represent a new threat against deep learning systems, due to the possibility of corrupting the training set so to induce an incorrect behaviour at test time. To avoid that the trainer recognises the presence of the corrupted samples, the corruption of the training set must be as stealthy as possible. Previous works have focused on the stealthiness of the perturbation injected into the training samples, however they all assume that the labels of the corrupted samples are also poisoned. This greatly reduces the stealthiness of the attack, since samples whose content does not agree with the label can be identified by visual inspection of the training set or by running a pre-classification step. In this paper we present a new backdoor attack without label poisoning Since the attack works by corrupting only samples of the target class, it has the additional advantage that it does not need to identify beforehand the class of the samples to be attacked at test time. Results obtained on the MNIST digits recognition task and the traffic signs classification task show that backdoor attacks without label poisoning are indeed possible, thus raising a new alarm regarding the use of deep learning in security-critical applications. Mauro Barni, Kassem Kallas, Benedetta Tondi |
ICIP | 3 |
| 2019 | Luminance-based video backdoor attack against anti-spoofing rebroadcast detectionabstractWe introduce a new backdoor attack against a deep-learning video rebroadcast detection network. In addition to the difficulties of working with video signals rather than still images, injecting a backdoor into a deep learning model for rebroadcast detection presents the additional problem that the backdoor must survive the digital-to-analog and analog-to-digital conversion associated to video rebroadcast. To cope with this problem, we have built a backdoor attack that works by varying the average luminance of video frames according to a predesigned sinusoidal function. In this way, robustness against geometric transformation is automatically achieved, together with a good robustness against luminance transformations associated to display and recapture, like Gamma correction and white balance. Our experiments demonstrate the effectiveness of the proposed backdoor attack, especially when the attack is carried out by also corrupting the labels of the attacked training samples. Abhir Bhalerao, Kassem Kallas, Benedetta Tondi, Mauro Barni |
MMSP | 3 |
| 2019 | Secure Detection of Image Manipulation by Means of Random Feature SelectionabstractWe address the problem of data-driven image manipulation detection in the presence of an attacker with limited knowledge about the detector. Specifically, we assume that the attacker knows the architecture of the detector, the training data, and the class of features V the detector can rely on. In order to get an advantage in his race of arms with the attacker, the analyst designs the detector by relying on a subset of features chosen at random in V. Given its ignorance about the exact feature set, the adversary attacks a version of the detector based on the entire feature set. In this way, the effectiveness of the attack diminishes since there is no guarantee that attacking a detector working in the full feature space will result in a successful attack against the reduced-feature detector. We theoretically prove that, thanks to random feature selection, the security of the detector significantly increases at the expense of a negligible loss of performance in the absence of attacks. We also provide an experimental validation of the proposed procedure by focusing on the detection of two specific kinds of image manipulations, namely adaptive histogram equalization and median filtering. The experiments confirm the gain in security at the expense of a negligible loss of performance in the absence of attacks. Benedetta Tondi, Xiaolong Li 0001, Yao Zhao 0001, Mauro Barni |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | Cnn-Based Detection of Generic Contrast Adjustment with Jpeg Post-ProcessingabstractDetection of contrast adjustments in the presence of JPEG post processing is known to be a challenging task. JPEG post processing is often applied innocently, as JPEG is the most common image format, or it may correspond to a laundering attack, when it is purposely applied to erase the traces of manipulation. In this paper, we propose a CNN-based detector for generic contrast adjustment, which is robust to JPEG compression. The proposed system relies on a patch-based Convolutional Neural Network (CNN), trained to distinguish pristine images from contrast adjusted images, for some selected adjustment operators of different nature. Robustness to JPEG compression is achieved by training the CNN with JPEG examples, compressed over a range of Quality Factors (QFs). Experimental results show that the detector works very well and scales well with respect to the adjustment type, yielding very good performance under a large variety of unseen tonal adjustments. Mauro Barni, Andrea Costanzo, Ehsan Nowroozi, Benedetta Tondi |
ICIP | 4 |
| 2018 | An Improved Statistic for the Pooled Triangle Test Against PRNU-Copy AttackabstractWe propose a new statistic to improve the pooled version of the triangle test used to combat the fingerprint-copy counter-forensic attack against PRNU-based camera identification [1]. As opposed to the original version of the test, the new statistic exploits the one-tail nature of the test, weighting differently positive and negative deviations from the expected value of the correlation between the image under analysis and the candidate images, i.e., those image suspected to have been used during the attack. The experimental results confirm the superior performance of the new test, especially when the conditions of the test are challenging ones, that is when the number of images used for the fingerprint-copy attack is large and the size of the image under test is small. Mauro Barni, Hector Santoyo-Garcia, Benedetta Tondi |
IEEE Signal Process. Lett. | 3 |
| 2018 | Adversarial Source Identification Game With Corrupted TrainingabstractWe study a variant of the source identification game with training data in which part of the training data is corrupted by an attacker. In the addressed scenario, the defender aims at deciding whether a test sequence has been drawn according to a discrete memoryless source X ~ PX, whose statistics are known to him through the observation of a training sequence generated by X. In order to undermine the correct decision under the alternative hypothesis that the test sequence has not been drawn from X, the attacker can modify a sequence produced by a source Y ~ PYup to a certain distortion and corrupt the training sequence either by adding some fake samples or by replacing some samples with fake ones. We derive the unique rationalizable equilibrium of the two versions of the game in the asymptotic regime and by assuming that the defender makes his decision by relying only on the first order statistics of the test and the training sequences. By mimicking Stein's lemma, we derive the best achievable performance for the defender when the first type error probability is required to tend to zero exponentially fast with an arbitrarily small, yet positive, error exponent. We then use such a result to analyze the ultimate distinguishability of any two sources as a function of the allowed distortion and the fraction of corrupted samples injected into the training sequence. Mauro Barni, Benedetta Tondi |
IEEE Trans. Inf. Theory | 2 |
| 2017 | Aligned and non-aligned double JPEG detection using convolutional neural networks
Mauro Barni, Luca Bondi, Nicolò Bonettini, Paolo Bestagini, Andrea Costanzo, Marco Maggini, Benedetta Tondi, Stefano Tubaro |
J. Vis. Commun. Image Represent. | 7 |
| 2017 | Smart Detection of Line-Search Oracle Attacks
Benedetta Tondi, Pedro Comesaña Alfaro, Fernando Pérez-González, Mauro Barni |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | A Game-Theoretic Framework for Optimum Decision Fusion in the Presence of ByzantinesabstractOptimum decision fusion in the presence of malicious nodes - often referred to as Byzantines - is hindered by the necessity of exactly knowing the statistical behavior of Byzantines. In this paper, we focus on a simple, yet widely adopted, setup in which a fusion center (FC) is asked to make a binary decision about a sequence of system states by relying on the possibly corrupted decisions provided by local nodes. We propose a game-theoretic framework, which permits to exploit the superior performance provided by optimum decision fusion, while limiting the amount of a priori knowledge required. We use numerical simulations to derive the optimum behavior of the FC and the Byzantines in a game-theoretic sense, and to evaluate the achievable performance at the equilibrium point of the game. We analyze several different setups, showing that in all cases, the proposed solution permits to improve the accuracy of data fusion. We also show that, in some cases, it is preferable for the Byzantines to minimize the mutual information between the status of the observed system and the reports submitted to the FC, rather than always flipping the decision made by the local nodes. Andrea Abrardo, Mauro Barni, Kassem Kallas, Benedetta Tondi |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | Source Distinguishability Under Distortion-Limited Attack: An Optimal Transport PerspectiveabstractWe analyze the distinguishability of two sources in a Neyman-Pearson setup when an attacker is allowed to modify the output of one of the two sources subject to an additive distortion constraint. By casting the problem in a game-theoretic framework and by exploiting the parallelism between the attacker's goal and optimal transport theory, we introduce the concept of security margin defined as the maximum average per-sample distortion introduced by the attacker for which the two sources can be distinguished ensuring arbitrarily small, yet positive, error exponents for type I and type II error probabilities. Several versions of the problem are considered according to the available knowledge about the sources. We compute the security margin for some classes of sources and derive general bounds assuming that the distortion is measured in terms of the mean square error between the original and the attacked sequence. The analysis of the game and the study of the distinguishability of the sources are extended to the case in which the distortion constraint is defined in terms of the maximum distance. Mauro Barni, Benedetta Tondi |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | Universal Counterforensics of Multiple Compressed JPEG Images
Mauro Barni, Marco Fontani, Benedetta Tondi |
IWDW | 3 |
| 2014 | Binary Hypothesis Testing Game With Training DataabstractWe introduce a game-theoretic framework to study the hypothesis testing problem in the presence of an adversary aiming to prevent a correct decision. Specifically, this paper considers a scenario in which an analyst has to accept or reject the null hypothesis H0characterized by a probability mass function (pmf) PXbased on the evidence provided by a test sequence. In turn, the goal of the adversary is to take a sequence generated according to a different pmf and modify it in such a way to induce a decision error. PXis known only through one or more training sequences. We derive the asymptotic equilibrium of the game under the assumption that the analyst relies only on first order statistics of the test and training sequences, and compute the asymptotic payoff of the game when the length of the sequences tends to infinity. We introduce the concept of indistinguishability region, defined as the set of pmfs that can not be distinguished reliably from PXin the presence of attacks. Two different scenarios are considered: in the first one the analyst and the adversary share the same training sequence, in the second scenario, they rely on independent sequences. The obtained results are compared with a version of the game in which the pmf PXis perfectly known to both the analyst and the adversary. Mauro Barni, Benedetta Tondi |
IEEE Trans. Inf. Theory | 2 |
| 2013 | The Source Identification Game: An Information-Theoretic PerspectiveabstractWe introduce a theoretical framework in which to cast the source identification problem. Thanks to the adoption of a game-theoretic approach, the proposed framework permits us to derive the ultimate achievable performance of the forensic analysis in the presence of an adversary aiming at deceiving it. The asymptotic Nash equilibrium of the source identification game is derived under an assumption on the resources on which the forensic analyst may rely. The payoff at the equilibrium is analyzed, deriving the conditions under which a successful forensic analysis is possible and the error exponent of the false-negative error probability in such a case. The difficulty of deriving a closed-form solution for general instances of the game is alleviated by the introduction of an efficient numerical procedure for the derivation of the optimum attacking strategy. The numerical analysis is applied to a case study to show the kind of information it can provide. Mauro Barni, Benedetta Tondi |
IEEE Trans. Inf. Forensics Secur. | 2 |