Giulia Orrù

dblp:217/2354 · DBLP profile ↗
← Back
20ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0002-7802-2483ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 16 · 6 first-author · 11 since 2021Graphics, computer vision, multimedia, augmented reality and games · 12 · 5 first-author · 7 since 2021Security and privacy · 6 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2026 3D differential decomposition for video deepfake detection with identity suppression
abstract
Detecting deepfake videos remains a challenging task, especially in scenarios involving unknown manipulation methods or unseen data distributions. Most existing video deepfake detection methods rely on high-level semantic features, which often lead to overfitting of facial identity information and poor transferability. In this work, we explore a novel perspective by modeling videos through 3D differential operations along temporal and spatial dimensions. To exploit the spatial–temporal variation information of the video content, the proposed approach decomposes videos into single-axis 1D differential signals, which are then transformed into 2D representations for efficient learning. This procedure enables the use of lightweight 2D CNNs while retaining directional forgery cues. Our experiments, aimed at analyzing whether these differential signals capture discriminative patterns useful for distinguishing real from fake content, show that the proposed method achieves strong intra-dataset performance and reveals complementary information across dimensions. These findings suggest that differential signals could potentially support generalization when integrated into broader detection frameworks. • We propose 3D Differential Decomposition modeling for deepfake video detection. • Multi-directional and multi-order differential operation are considered. • Optimization for differential order selection and fusion strategy are explored.
Marco Micheletto, Giulia Orrù, Xiaoyi Feng, Gian Luca Marcialis
Signal Process. Image Commun.3
2025 Deep Data Hiding for ICAO-Compliant Face Images: A Survey
abstract
ICAO-compliant facial images, initially designed for secure biometric passports, are increasingly becoming central to identity verification in a wide range of application contexts, including border control, digital travel credentials, and financial services. While their standardization enables global interoperability, it also facilitates practices such as morphing and deepfakes, which can be exploited for harmful purposes like identity theft and illegal sharing of identity documents. Traditional countermeasures like Presentation Attack Detection (PAD) are limited to real-time capture and offer no post-capture protection. This survey paper investigates digital watermarking and steganography as complementary solutions that embed tamper-evident signals directly into the image, enabling persistent verification without compromising ICAO compliance. We provide the first comprehensive analysis of state-of-the-art techniques to evaluate the potential and drawbacks of the underlying approaches concerning the applications involving ICAO-compliant images and their suitability under standard constraints. We highlight key trade-offs, offering guidance for secure deployment in real-world identity systems.
Jefferson David Rodriguez Chivata, Davide Ghiani, Simone Maurizio La Cava, Marco Micheletto, Giulia Orrù, Federico Lama, Gian Luca Marcialis
IJCB5
2025 LivDet2025: Toward Robust and Generalizable Fingerprint Presentation Attack Detection
abstract
The Fingerprint Liveness Detection Competition (LivDet) is a recurring benchmark series that evaluates the effectiveness of software-based Presentation Attack Detection (PAD) algorithms in fingerprint recognition. LivDet2025 presents three challenges: (1) "Liveness Detection in Action", requiring the integration of PAD with user-specific recognition; (2) "Fingerprint Representation", evaluating the compactness and discriminability of feature vectors; and (3) "Adversarial Robustness", assessing the resilience of PADs to adversarially-crafted presentation attack instruments. This edition marks a significant milestone with the inclusion of contactless fingerprint data, promoting interoperability and robustness across acquisition technologies. Furthermore, no training data was provided; participants must select and declare external datasets for model development. The competition was open to academic and industrial research groups, with all submitted algorithms evaluated on common datasets and under standardized protocols. LivDet2025 aims to provide a comprehensive assessment of PAD performance under realistic, multi-sensor, and multi-attack scenarios. Results reveal important trade-offs between PAD accuracy, usability, and computational efficiency. For instance, some systems achieved high presentation attack rejection at the cost of extremely high false rejection rates, while others optimised speed and generalizability but exhibited limited attack resilience.
Giulia Orrù, Marco Micheletto, Roberto Casula, Simone Zedda, Daniele Fenu, Lambert Igene, Jannis Priesnitz, Christoph Busch 0001, Christian Rathgeb, Stephanie Schuckers, Gian Luca Marcialis
IJCB1
2025 Fragile Watermarking for Image Certification Using Deep Steganographic Embedding
abstract
Modern identity verification systems increasingly rely on facial images embedded in biometric documents such as electronic passports. To ensure global interoperability and security, these images must comply with strict standards defined by the International Civil Aviation Organization (ICAO), which specify acquisition, quality, and format requirements. However, once issued, these images may undergo unintentional degradations (e.g., compression, resizing) or malicious manipulations (e.g., morphing) and deceive facial recognition systems. In this study, we explore fragile watermarking, based on deep steganographic embedding as a proactive mechanism to certify the authenticity of ICAO-compliant facial images. By embedding a hidden image within the official photo at the time of issuance, we establish an integrity marker that becomes sensitive to any post-issuance modification. We assess how a range of image manipulations affects the recovered hidden image and show that degradation artifacts can serve as robust forensic cues. Furthermore, we propose a classification framework that analyzes the revealed content to detect and categorize the type of manipulation applied. Our experiments demonstrate high detection accuracy, including cross-method scenarios with multiple deep steganography-based models. These findings support the viability of fragile watermarking via steganographic embedding as a valuable tool for biometric document integrity verification.
Davide Ghiani, Jefferson David Rodriguez Chivata, Stefano Lilliu, Simone Maurizio La Cava, Marco Micheletto, Giulia Orrù, Federico Lama, Gian Luca Marcialis
IJCNN6
2025 Interpretability of fingerprint presentation attack detection systems: a look at the "representativeness" of samples against never-seen-before attacks
abstract
Abstract Nowadays, fingerprint Presentation Attack Detection systems (PADs) are primarily based on deep learning architectures subjected to massive training. However, their performance decreases to never-seen-before attacks. With the goal of contributing to explaining this issue, we hypothesized that this limited ability to generalize is due to the lack of "representativeness" of the samples available for the PAD training. "Representativeness" is treated here from a geometrical perspective: the spread of samples into the feature space, especially near the decision boundaries. In particular, we explored the possibility of adopting three-dimensionality reduction methods to make the problem affordable through visual inspection. These methods enable visual inspection and interpretation by projecting data into two-dimensional spaces, facilitating the identification of weak areas in the decision regions estimated after the training phase. Our analysis delineates the benefits and drawbacks of each dimensionality reduction method and leads us to make substantial recommendations in the crucial phase of the training design.
Simone Carta, Roberto Casula, Giulia Orrù, Marco Micheletto, Gian Luca Marcialis
Mach. Vis. Appl.3
2024 SDFR: Synthetic Data for Face Recognition Competition
abstract
Large-scale face recognition datasets are collected by crawling the Internet and without individuals' consent, raising legal, ethical, and privacy concerns. With the recent advances in generative models, recently several works proposed generating synthetic face recognition datasets to mitigate concerns in web-crawled face recognition datasets. This paper presents the summary of the Synthetic Data for Face Recognition (SDFR) Competition held in conjunction with the 18th IEEE International Conference on Automatic Face and Gesture Recognition (FG 2024) and established to investigate the use of synthetic data for training face recognition models. The SDFR competition was split into two tasks, allowing participants to train face recognition systems using new synthetic datasets and/or existing ones. In the first task, the face recognition backbone was fixed and the dataset size was limited, while the second task provided almost complete freedom on the model backbone, the dataset, and the training pipeline. The submitted models were trained on existing and also new synthetic datasets and used clever methods to improve training with synthetic data. The submissions were evaluated and ranked on a diverse set of seven benchmarking datasets. The paper gives an overview of the submitted face recognition models and reports achieved performance compared to baseline models trained on real and synthetic datasets. Furthermore, the evaluation of submissions is extended to bias assessment across different demography groups. Lastly, an outlook on the current state of the research in training face recognition models using synthetic data is presented, and existing problems as well as potential future directions are also discussed.
Hatef Otroshi-Shahreza, Christophe Ecabert, Anjith George, Alexander Unnervik, Sébastien Marcel, Nicolò Di Domenico, Guido Borghi, Davide Maltoni, Fadi Boutros, Julia Vogel, Naser Damer, Ángela Sánchez-Pérez, Enrique Mas-Candela, Jorge Calvo-Zaragoza, Bernardo Biesseck, Pedro Vidal 0001, Roger Granada, David Menotti, Ivan DeAndres-Tame, Simone Maurizio La Cava, Sara Concas, Pietro Melzi, Ruben Tolosana, Rubén Vera-Rodríguez, Gianpaolo Perelli, Giulia Orrù, Gian Luca Marcialis, Julian Fierrez
FG26
2024 Texture and artifact decomposition for improving generalization in deep-learning-based deepfake detection
abstract
The harmful utilization of DeepFake technology poses a significant threat to public welfare, precipitating a crisis in public opinion. Existing detection methodologies, predominantly relying on convolutional neural networks and deep learning paradigms, focus on achieving high in-domain recognition accuracy amidst many forgery techniques. However, overseeing the intricate interplay between textures and artifacts results in compromised performance across diverse forgery scenarios. This paper introduces a groundbreaking framework, denoted as Texture and Artifact Detector (TAD), to mitigate the challenge posed by the limited generalization ability stemming from the mutual neglect of textures and artifacts. Specifically, our approach delves into the similarities among disparate forged datasets, discerning synthetic content based on the consistency of textures and the presence of artifacts. Furthermore, we use a model ensemble learning strategy to judiciously aggregate texture disparities and artifact patterns inherent in various forgery types, thereby enabling the model’s generalization ability. Our comprehensive experimental analysis, encompassing extensive intra-dataset and cross-dataset validations along with evaluations on both video sequences and individual frames, confirms the effectiveness of TAD. The results from four benchmark datasets highlight the significant impact of the synergistic consideration of texture and artifact information, leading to a marked improvement in detection capabilities.
Marco Micheletto, Giulia Orrù, Sara Concas, Xiaoyi Feng, Gian Luca Marcialis, Fabio Roli
Eng. Appl. Artif. Intell.3
2024 Recent advances in behavioral and hidden biometrics for personal identification
Giulia Orrù, Ajita Rattani, Imad Rida, Sébastien Marcel
Pattern Recognit. Lett.1
2024 Realistic Fingerprint Presentation Attacks Based on an Adversarial Approach
abstract
Modern Fingerprint Presentation Attack Detection (FPAD) modules have been particularly successful in avoiding attacks exploiting artificial fingerprint replicas against Automated Fingerprint Identification Systems (AFISs). As for several other domains, Machine and Deep Learning strongly contributed to this success, with all recent state-of-the-art detectors leveraging learning-based approaches. An insidious flip side is represented by adversarial attacks, namely, procedures intended to mislead a target detector. Indeed, despite this type of attack has been considered unrealistic, as it presupposes access to the communication channel between the sensor and the detector, in a recent work, we have highlighted the possibility of transferring a fingerprint adversarial attack from the digital domain to the physical one. In this work, we take a step further by introducing a new procedure designed to make the physical adversarial presentation attack i) more robust to the physical crafting of the PAI by exploiting explainability techniques, ii) easier to adapt to different fingerprint scanners and adversarial algorithms, and iii) usable in a black-box scenario. To quantify the impact of these novel adversarial presentation attacks family, designed to be robust to the physical crafting process, we assess the performance of both state-of-the-art PAD modules alone and integrated AFISs. Results highlight the approach’s feasibility, opening a new series of threats in the context of fingerprint PAD.
Roberto Casula, Giulia Orrù, Stefano Marrone 0002, Umberto Gagliardini, Gian Luca Marcialis, Carlo Sansone
IEEE Trans. Inf. Forensics Secur.2
2023 LivDet2023 - Fingerprint Liveness Detection Competition: Advancing Generalization
abstract
The International Fingerprint Liveness Detection Competition (LivDet) is a biennial event that invites academic and industry participants to prove their advancements in Fingerprint Presentation Attack Detection (PAD). This edition, LivDet2023, proposed two challenges, “Liveness Detection in Action” and “Fingerprint Representation”, to evaluate the efficacy of PAD embedded in verification systems and the effectiveness and compactness of feature sets. A third, “hidden” challenge is the inclusion of two subsets in the training set whose sensor information is unknown, testing participants’ ability to generalize their models. Only bona fide fingerprint samples were provided to participants, and the competition reports and assesses the performance of their algorithms suffering from this limitation in data availability.
Marco Micheletto, Roberto Casula, Giulia Orrù, Simone Carta, Sara Concas, Simone Maurizio La Cava, Julian Fierrez, Gian Luca Marcialis
IJCB3
2023 Towards realistic fingerprint presentation attacks: The ScreenSpoof method
Roberto Casula, Marco Micheletto, Giulia Orrù, Gian Luca Marcialis, Fabio Roli
Pattern Recognit. Lett.3
2022 3D Face Reconstruction for Forensic Recognition - A Survey
abstract
3D face reconstruction algorithms from images and videos are applied to many fields, from plastic surgery to the entertainment sector, thanks to their advantageous features. However, when looking at forensic applications, 3D face reconstruction must observe strict requirements that still make unclear its possible role in bringing evidence to a lawsuit. Shedding some light on this matter is the goal of the present survey, where we start by clarifying the relation between forensic applications and biometrics. To our knowledge, no previous work adopted this relation to make the point on the state of the art. Therefore, we analyzed the achievements of 3D face reconstruction algorithms from surveillance videos and mugshot images and discussed the current obstacles that separate 3D face reconstruction from an active role in forensic applications.
Simone Maurizio La Cava, Giulia Orrù, Tomás Goldmann, Martin Drahanský, Gian Luca Marcialis
ICPR2
2021 LivDet 2021 Fingerprint Liveness Detection Competition - Into the unknown
abstract
The International Fingerprint Liveness Detection Competition is an international biennial competition open to academia and industry with the aim to assess and report advances in Fingerprint Presentation Attack Detection. The proposed "Liveness Detection in Action" and "Fingerprint representation" challenges were aimed to evaluate the impact of a PAD embedded into a verification system, and the effectiveness and compactness of feature sets for mobile applications. Furthermore, we experimented a new spoof fabrication method that has particularly affected the final results. Twenty-three algorithms were submitted to the competition, the maximum number ever achieved by LivDet.
Roberto Casula, Marco Micheletto, Giulia Orrù, Rita Delussu, Sara Concas, Andrea Panzino, Gian Luca Marcialis
IJCB3
2021 Fingerprint Recognition With Embedded Presentation Attacks Detection: Are We Ready?
abstract
The diffusion of fingerprint verification systems for security applications makes it urgent to investigate the embedding of software-based presentation attack detection algorithms (PAD) into such systems. Companies and institutions need to know whether such integration would make the system more “secure” and whether the technology available is ready, and, if so, at what operational working conditions. Despite significant improvements, especially by adopting deep learning approaches to fingerprint PAD, current research did not state much about their effectiveness when embedded in fingerprint verification systems. We believe that the lack of works is explained by the lack of instruments to investigate the problem, that is, modeling the cause-effect relationships when two non-zero error-free systems work together. Accordingly, this paper explores the fusion of PAD into verification systems by proposing a novel investigation instrument: a performance simulator based on the probabilistic modeling of the relationships among the Receiver Operating Characteristics (ROC) of the two individual systems when PAD and verification stages are implemented sequentially. As a matter of fact, this is the most straightforward, flexible, and widespread approach. We carry out simulations on the PAD algorithms’ ROCs submitted to the most recent editions of LivDet (2017-2019), the state-of-the-art NIST Bozorth3, and the top-level Veryfinger 12 matchers. Reported experiments explore significant scenarios to get the conditions under which fingerprint matching with embedded PAD can improve, rather than degrade, the overall personal verification performance.
Marco Micheletto, Gian Luca Marcialis, Giulia Orrù, Fabio Roli
IEEE Trans. Inf. Forensics Secur.3
2020 Are spoofs from latent fingerprints a real threat for the best state-of-art liveness detectors?
abstract
We investigated the threat level of realistic attacks using latent fingerprints against sensors equipped with state-of-art liveness detectors and fingerprint verification systems which integrate such liveness algorithms. To the best of our knowledge, only a previous investigation was done with spoofs from latent prints. In this paper, we focus on using snapshot pictures of latent fingerprints. These pictures provide molds, that allows, after some digital processing, to fabricate high-quality spoofs. Taking a snapshot picture is much simpler than developing fingerprints left on a surface by magnetic powders and lifting the trace by a tape. What we are interested here is to evaluate preliminary at which extent attacks of the kind can be considered a real threat for state-of-art fingerprint liveness detectors and verification systems. To this aim, we collected a novel data set of live and spoof images fabricated with snapshot pictures of latent fingerprints. This data set provide a set of attacks at the most favourable conditions. We refer to this method and the related data set as “ScreenSpoof”. Then, we tested with it the performances of the best liveness detection algorithms, namely, the three winners of the LivDet competition. Reported results point out that the ScreenSpoof method is a threat of the same level, in terms of detection and verification errors, than that of attacks using spoofs fabricated with the full consensus of the victim. We think that this is a notable result, never reported in previous work.
Roberto Casula, Giulia Orrù, Daniele Angioni, Xiaoyi Feng, Gian Luca Marcialis, Fabio Roli
ICPR2
2020 Detecting Anomalies from Video-Sequences: a Novel Descriptor
abstract
We present a novel descriptor for crowd behavior analysis and anomaly detection. The goal is to measure by appropriate patterns the speed of formation and disintegration of groups in the crowd. This descriptor is inspired by the concept of one-dimensional local binary patterns: in our case, such patterns depend on the number of group observed in a time window. An appropriate measurement unit, named “trit” (trinary digit), represents three possible dynamic states of groups on a certain frame. Our hypothesis is that abrupt variations of the groups' number may be due to an anomalous event that can be accordingly detected, by translating these variations on temporal trit-based sequence of strings which are significantly different from the one describing the “no-anomaly” one. Due to the peculiarity of the rationale behind this work, relying on the number of groups, three different methods of people group's extraction are compared. Experiments are carried out on the Motion-Emotion benchmark data set. Reported results point out in which cases the trit-based measurement of group dynamics allows us to detect the anomaly. Besides the promising performance of our approach, we show how it is correlated with the anomaly typology and the camera's perspective to the crowd's flow (frontal, lateral).
Giulia Orrù, Davide Ghiani, Maura Pintor, Gian Luca Marcialis, Fabio Roli
ICPR1
2020 Electroencephalography signal processing based on textural features for monitoring the driver's state by a Brain-Computer Interface
abstract
In this study we investigate a textural processing method of electroencephalography (EEG) signal as an indicator to estimate the driver's vigilance in a hypothetical Brain-Computer Interface (BCI) system. The novelty of the solution proposed relies on employing the one-dimensional Local Binary Pattern (1D-LBP) algorithm for feature extraction from pre-processed EEG data. From the resulting feature vector, the classification is done according to three vigilance classes: awake, tired and drowsy. The claim is that the class transitions can be detected by describing the variations of the micro-patterns' occurrences along the EEG signal. The 1D-LBP is able to describe them by detecting mutual variations of the signal temporarily “close” as a short bit-code. Our analysis allows to conclude that the 1D-LBP adoption has led to significant performance improvement. Moreover, capturing the class transitions from the EEG signal is effective, although the overall performance is not yet good enough to develop a BCI for assessing the driver's vigilance in real environments.
Giulia Orrù, Marco Micheletto, Fabio Terranova, Gian Luca Marcialis
ICPR1
2020 Are Adaptive Face Recognition Systems still Necessary? Experiments on the APE Dataset
abstract
In the last five years, deep learning methods, in particular CNN, have attracted considerable attention in the field of face-based recognition, achieving impressive results. Despite this progress, it is not yet clear precisely to what extent deep features are able to follow all the intra-class variations that the face can present over time. In this paper we investigate the performance the performance improvement of face recognition systems by adopting self updating strategies of the face templates. For that purpose, we evaluate the performance of a well-known deep-learning face representation, namely, FaceNet, on a dataset that we generated explicitly conceived to embed intra-class variations of users on a large time span of captures: the APhotoEveryday (APE) dataset11https://github.com/PRALabBiometrics/APhotoEverydayDB. Moreover, we compare these deep features with handcrafted features extracted using the BSIF algorithm. In both cases, we evaluate various template update strategies, in order to detect the most useful for such kind of features. Experimental results show the effectiveness of “optimized” self-update methods with respect to systems without update or random selection of templates.
Giulia Orrù, Marco Micheletto, Julian Fierrez, Gian Luca Marcialis
IPAS1
2020 A novel classification-selection approach for the self updating of template-based face recognition systems
Giulia Orrù, Gian Luca Marcialis, Fabio Roli
Pattern Recognit.1
2019 Personal Identity Verification by EEG-Based Network Representation on a Portable Device
Giulia Orrù, Marco Garau, Matteo Fraschini, Javier Acedo, Luca Didaci, David Ibáñez, Aureli Soria-Frisch, Gian Luca Marcialis
CAIP (2)1