EDBT 2026 Demo / reviewers in the wild / expert
Andrea Costanzo
dblp:318/5015
· DBLP profile ↗
11ranked-venue papers
1as first author
2since 2021 · last 2025
0009-0007-1659-5722ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Robust and Large-Payload DNN Watermarking via Fixed, Distribution-Optimized, WeightsabstractThe design of an effective multi-bit watermarking algorithm hinges upon finding a good trade-off between the three fundamental requirements forming the watermarking trade-off triangle, namely, robustness against network modifications, payload, and unobtrusiveness, ensuring minimal impact on the performance of the watermarked network. In this paper, we first revisit the nature of the watermarking trade-off triangle for the DNN case, then we exploit our findings to propose a white-box, multi-bit watermarking method achieving very large payload and strong robustness against network modification. In the proposed system, the weights hosting the watermark are set prior to training, making sure that their amplitude is large enough to bear the target payload and survive network modifications, notably retraining, and are left unchanged throughout the training process. The distribution of the weights carrying the watermark is theoretically optimised to ensure the secrecy of the watermark and make sure that the watermarked weights are indistinguishable from the non-watermarked ones. The proposed method can achieve outstanding performance, with no significant impact on network accuracy, including robustness against network modifications, retraining and transfer learning, while ensuring a payload which is out of reach of state of the art methods achieving a lower - or at most comparable - robustness. Benedetta Tondi, Andrea Costanzo, Mauro Barni |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Boosting CNN-based primary quantization matrix estimation of double JPEG images via a classification-like architectureabstractAbstract Estimating the primary quantization matrix of double JPEG compressed images is a problem of relevant importance in image forensics since it allows to infer important information about the past history of an image. In addition, the inconsistencies of the primary quantization matrices across different image regions can be used to localize splicing in double JPEG tampered images. Traditional model-based approaches work under specific assumptions on the relationship between the first and second compression qualities and on the alignment of the JPEG grid. Recently, a deep learning-based estimator capable to work under a wide variety of conditions has been proposed that outperforms tailored existing methods in most of the cases. The method is based on a convolutional neural network (CNN) that is trained to solve the estimation as a standard regression problem. By exploiting the integer nature of the quantization coefficients, in this paper, we propose a deep learning technique that performs the estimation by resorting to a simil-classification architecture. The CNN is trained with a loss function that takes into account both the accuracy and the mean square error (MSE) of the estimation. Results confirm the superior performance of the proposed technique, compared to the state-of-the art methods based on statistical analysis and, in particular, deep learning regression. Moreover, the capability of the method to work under general operative conditions, regarding the alignment of the second compression grid with the one of first compression and the combinations of the JPEG qualities of former and second compression, is very relevant in practical applications, where these information are unknown a priori. Benedetta Tondi, Andrea Costanzo, Dequ Huang, Bin Li 0011 |
EURASIP J. Inf. Secur. | 2 |
| 2018 | Cnn-Based Detection of Generic Contrast Adjustment with Jpeg Post-ProcessingabstractDetection of contrast adjustments in the presence of JPEG post processing is known to be a challenging task. JPEG post processing is often applied innocently, as JPEG is the most common image format, or it may correspond to a laundering attack, when it is purposely applied to erase the traces of manipulation. In this paper, we propose a CNN-based detector for generic contrast adjustment, which is robust to JPEG compression. The proposed system relies on a patch-based Convolutional Neural Network (CNN), trained to distinguish pristine images from contrast adjusted images, for some selected adjustment operators of different nature. Robustness to JPEG compression is achieved by training the CNN with JPEG examples, compressed over a range of Quality Factors (QFs). Experimental results show that the detector works very well and scales well with respect to the adjustment type, yielding very good performance under a large variety of unseen tonal adjustments. Mauro Barni, Andrea Costanzo, Ehsan Nowroozi, Benedetta Tondi |
ICIP | 2 |
| 2017 | Aligned and non-aligned double JPEG detection using convolutional neural networks
Mauro Barni, Luca Bondi, Nicolò Bonettini, Paolo Bestagini, Andrea Costanzo, Marco Maggini, Benedetta Tondi, Stefano Tubaro |
J. Vis. Commun. Image Represent. | 5 |
| 2014 | Exploiting perceptual quality issues in countering SIFT-based Forensic methodsabstractScale Invariant Feature Transform (SIFT) has been widely employed in several image application domains, including Image Forensics (e.g. detection of copy-move forgery or near duplicates). Recently, a number of methods allowing to remove SIFT keypoints from an original image have been devised studying the problem of SIFT security against malicious procedures. Such techniques are quite effective in producing an attacked image with very few (or no) keypoints, but at the expense of an image distortion. Final perceptual quality has been taken in account very roughly so far. In this paper, effectiveness of the attacking methods is evaluated also from the side of perceptual image quality; a new version of a SIFT keypoint removal method, based on a perceptual metric, is presented and an extended series of perceptive experiments is reported. Irene Amerini, Federica Battisti, Roberto Caldelli, Marco Carli, Andrea Costanzo |
ICASSP | 5 |
| 2014 | Forensic Analysis of SIFT Keypoint Removal and InjectionabstractAttacks capable of removing SIFT keypoints from images have been recently devised with the intention of compromising the correct functioning of SIFT-based copy-move forgery detection. To tackle with these attacks, we propose three novel forensic detectors for the identification of images whose SIFT keypoints have been globally or locally removed. The detectors look for inconsistencies like the absence or anomalous distribution of keypoints within textured image regions. We first validate the methods on state-of-the-art keypoint removal techniques, then we further assess their robustness by devising a counter-forensic attack injecting fake SIFT keypoints in the attempt to cover the traces of removal. We apply the detectors to a practical image forensic scenario of SIFT-based copy-move forgery detection, assuming the presence of a counterfeiter who resorts to keypoint removal and injection to create copy-move forgeries that successfully elude SIFT-based detectors but are in turn exposed by the newly proposed tools. Andrea Costanzo, Irene Amerini, Roberto Caldelli, Mauro Barni |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | SIFT keypoint removal and injection for countering matching-based image forensicsabstractScale Invariant Feature Transform (SIFT) has been widely employed in several image application domains, including Image Forensics (e.g. detection of copy-move forgery or near duplicates). Until now, the research community has focused on studying the robustness of SIFT against legitimate image processing, but rarely concerned itself with the problem of SIFT security against malicious procedures. Recently, a number of methods allowing to remove SIFT keypoints from an original image have been devised. Although quite effective, such methods produce an attacked image with very few (or no) keypoints, thus leaving cues that can be easily exploited by a forensic analyst to reveal the occurred manipulation. In this paper, we explore the topic of reintroducing fake SIFT keypoints into a previously cleaned image in order to address the main weakness of the existing removal attacks. In particular, we evaluate the fitness of locally adaptive contrast enhancement methods to the task of injecting new keypoints. The results we obtained are encouraging: (i) it is possible to effectively introduce new keypoints whose descriptors do not match with those of the original image, thus concealing the removal forgery; (ii) the perceptual quality of the image following the removal and injection attacks is comparable to the one of the original image. Irene Amerini, Mauro Barni, Roberto Caldelli, Andrea Costanzo |
IH&MMSec | 4 |
| 2013 | Removal and injection of keypoints for SIFT-based copy-move counter-forensicsabstractAbstract Recent studies exposed the weaknesses of scale-invariant feature transform (SIFT)-based analysis by removing keypoints without significantly deteriorating the visual quality of the counterfeited image. As a consequence, an attacker can leverage on such weaknesses to impair or directly bypass with alarming efficacy some applications that rely on SIFT. In this paper, we further investigate this topic by addressing the dual problem of keypoint removal, i.e., the injection of fake SIFT keypoints in an image whose authentic keypoints have been previously deleted. Our interest stemmed from the consideration that an image with too few keypoints is per se a clue of counterfeit, which can be used by the forensic analyst to reveal the removal attack. Therefore, we analyse five injection tools reducing the perceptibility of keypoint removal and compare them experimentally. The results are encouraging and show that injection is feasible without causing a successive detection at SIFT matching level. To demonstrate the practical effectiveness of our procedure, we apply the best performing tool to create a forensically undetectable copy-move forgery, whereby traces of keypoint removal are hidden by means of keypoint injection. Irene Amerini, Mauro Barni, Roberto Caldelli, Andrea Costanzo |
EURASIP J. Inf. Secur. | 4 |
| 2012 | Dealing with uncertainty in image forensics: A fuzzy approachabstractImage forensics research has mainly focused on the detection of artifacts introduced by a single processing tool. In tamper detection applications, however, the kind of artifacts the forensic analyst should look for is not known beforehand, hence making it necessary that several tools developed for different scenarios are applied. The problem, then, is twofold: i) devise a sound strategy to elaborate the information provided by the different tools into a single output, and ii) deal with the uncertainty introduced by error-prone tools. In this paper, we introduce a framework based on Fuzzy Theory to overcome these problems. We describe a practical implementation of the proposed framework putting the theoretical principles in practice. To validate the proposed approach, we carried out some experiments addressing a simple realistic scenario in which three forensic tools exploit artifacts introduced by JPEG compression to detect cut&paste tampering within a specified region of an image. The results are encouraging, especially when compared with those obtained by simply XOR-ing the output of the the single detection tools. Mauro Barni, Andrea Costanzo |
ICASSP | 2 |
| 2012 | A fuzzy approach to deal with uncertainty in image forensics
Mauro Barni, Andrea Costanzo |
Signal Process. Image Commun. | 2 |
| 2010 | Identification of cut & paste tampering by means of double-JPEG detection and image segmentationabstractThis paper focuses on images whose content has been modified by means of a cut & paste operation. By relying on an existing scheme for the detection of double JPEG compressed images with desynchronized grids, we propose two algorithms for the detection of image regions that have been transplanted from another image. The proposed methods work whenever the pasted region is extracted from a JPEG compressed image and inserted in a target image that is subsequently compressed with a quality factor larger than that used to compress the source image. The new methods are intended as a complement to previous works relying on the detection of artifacts introduced by double JPEG compression with aligned compression grids. The experiments we carried out show the good performance of the novel schemes, the second one providing better results at a lower complexity thanks to the incorporation within the detection process of some information regarding the actual image content. Mauro Barni, Andrea Costanzo, Lara Sabatini |
ISCAS | 2 |