Biometrics, Multimedia Forensics and IoT

Academic Year 2026/2027 - Teacher: FRANCESCO BERITELLI

Expected Learning Outcomes

Objectives

The course aims to provide advanced knowledge and methodological tools for understanding, designing, and evaluating biometric systems, multimedia forensics techniques, and intelligent architectures for the Internet of Things. The course integrates theoretical and applied aspects related to biometric identification, security, privacy, digital evidence integrity, and the management of heterogeneous data originating from multimedia and sensor sources.

In particular, the course introduces the principles of biometric systems, performance metrics, and matching and decision techniques, with particular attention to multimodal systems. It then addresses methodologies for multimedia forensics, audio and video forensics, mobile forensics, and geolocation in mobile communication systems, including the analysis of manipulated content, deepfakes, speaker recognition, liveness detection, and procedures for the acquisition, preservation, and reporting of digital evidence.

The section devoted to the Intelligent Internet of Things covers architectures, protocols, access technologies, sensing, preprocessing, interoperability, security, and privacy in IoT systems. Artificial Intelligence of Things scenarios are also introduced for classification, prediction, anomaly detection, multimodal sensing, and data fusion in application domains such as Smart Cities, healthcare, environmental monitoring, Industrial IoT, and smart agriculture.

The course includes laboratory activities aimed at using forensic phonetics tools, Python libraries for face and speaker recognition, and real-world biometric, multimedia, and sensor datasets. These activities enable students to develop practical skills, problem-solving abilities, experimental performance evaluation skills, and an aptitude for teamwork.

At the end of the course, students will be able to critically analyze biometric, forensic, and IoT solutions; select tools and methodologies consistent with technical, regulatory, and ethical requirements; communicate technical results appropriately; and independently keep up to date with rapidly evolving technologies.

Knowledge and Understanding

Based on the knowledge acquired during the course, students will be able to understand the principles of biometric systems, multimedia forensics methodologies, IoT architectures and protocols, audio, video, and sensor data processing techniques, and the main requirements related to security, privacy, and reliability.

Applying Knowledge and Understanding

At the end of the course, students will be able to apply software tools and operational procedures to analyze biometric, multimedia, mobile, and IoT evidence; evaluate system performance and limitations; configure basic acquisition and processing pipelines; and carry out experimental activities on real-world datasets.

Making Judgements

Students will be able to critically evaluate methods, tools, and results in terms of accuracy, robustness, scalability, security, privacy, and digital evidence integrity. These skills will also be developed through application cases, exercises, and laboratory project activities.

Communication Skills

Students will be able to discuss biometric systems, forensic procedures, and IoT architectures using appropriate technical terminology, prepare short technical reports, and clearly present methodological choices, experimental results, and the limitations of the adopted solutions.

Learning Skills

Students will acquire the ability to independently study scientific literature, standards, technical manuals, and software documentation in the fields of biometrics, multimedia forensics, and IoT, while keeping up to date with developments in tools, algorithms, and applications.


Course Structure

Teaching Methods

Traditional face-to-face lectures, supplemented by exercises and laboratory activities.

Description of Teaching Methods

The course is co-taught and includes lectures (49 hours, corresponding to 7 CFU) and exercises or laboratory activities (30 hours, corresponding to 2 CFU), aimed at putting theoretical concepts into practice through the use of software tools, real-world datasets, and application cases. Laboratory activities may be carried out individually or in groups and focus on forensic analysis, biometric recognition, sensor data management, and experimental performance evaluation.

Teacher-led instruction is devoted to the presentation of basic and advanced concepts related to biometrics, digital and multimedia forensics, mobile forensics, geolocation, and Intelligent IoT. Interactive teaching activities include exercises, case discussions, guided use of tools, and the development of mini-projects or experimental activities.

The above teaching methods are consistent with the learning objectives of the course, which require both an understanding of methodological foundations and the ability to apply them in realistic technical scenarios. Should the course be delivered in blended or distance-learning mode, the necessary adjustments to the arrangements described above may be introduced in order to ensure completion of the programme specified in this syllabus.

Required Prerequisites

Essential Knowledge

  • Fundamentals of signals and systems in the time and frequency domains.
  • Basic concepts of probability, statistics, and performance evaluation.
  • Basic knowledge of digital communications and telecommunication architectures.

Important Knowledge

  • Basic concepts of digital signal, image, and audio processing.
  • Basic programming and data analysis skills, preferably using Python or MATLAB.
  • General knowledge of networks, communication protocols, and mobile communication systems.

Useful Knowledge

  • Fundamentals of machine learning and statistical classification.
  • Introductory concepts of privacy and digital evidence management.
  • Basic knowledge of embedded devices, sensors, and data acquisition.

Attendance of Lessons

Although attendance at lectures is not mandatory, students are strongly encouraged to attend, particularly given the applied and experimental nature of the laboratory activities. Attendance at at least 70% of the laboratory activities is mandatory and also allows students to earn up to 4 points toward the final grade, in accordance with the procedures described in the assessment section.

Detailed Course Content

Detailed Programme

1. Biometric Identification Techniques — 9 hours

Lectures: 6 hours – Exercises and laboratory activities: 3 hours

  • Introduction to biometric systems; authentication and identification.
  • Morphological and behavioral biometric identifiers; architecture of a biometric system.
  • Statistical methods, matching, and decision-making; FAR, FRR, ROC, EER, and DET metrics; multimodal systems.
  • Exercises on performance metrics for biometric recognition.

2. Introduction to Multimedia Forensics — 2 hours

Lectures: 2 hours – Exercises and laboratory activities: 0 hours

  • Multimedia forensics and mobile forensics.
  • Legal aspects, technical consultancy, and expert assessment; roles of the court-appointed technical expert (CTU) and party-appointed technical expert (CTP).

3. Audio Forensics — 10 hours

Lectures: 6 hours – Exercises and laboratory activities: 4 hours

  • Audio signal processing and compression; speech coding standards.
  • Forensic phonetics, audio surveillance recordings, and signal enhancement.
  • Speaker identification using auditory, semi-automatic, and automatic methods based on formants, LPC, MFCC, GMM, and i-vectors.
  • Voice imitation, deepfakes, anti-spoofing, liveness detection, and automatic transcription.
  • Laboratory activities using forensic phonetics tools, including PRAAT, Idem, and Nuance Forensic.

4. Video Forensics — 10 hours

Lectures: 6 hours – Exercises and laboratory activities: 4 hours

  • Image and video processing and compression.
  • Video forensics techniques and forensic indicators for detecting manipulation.
  • Generative models based on GANs, autoencoders, and diffusion models; detection of alterations and deepfakes.
  • Artificial Intelligence and Computer Vision for security in Smart Cities.
  • Exercises on image and video analysis, manipulation detection, and evaluation of synthetic content.

5. Mobile Forensics — 6 hours

Lectures: 3 hours – Exercises and laboratory activities: 3 hours

  • Principles and procedures of mobile forensics.
  • Preservation, acquisition, examination, analysis, and reporting of digital evidence.
  • Main analysis tools.
  • Exercises on workflows for the acquisition, examination, and reporting of digital evidence from mobile devices.

6. Geolocation in Mobile Communication Systems — 5 hours

Lectures: 5 hours – Exercises and laboratory activities: 0 hours

  • Geolocation services and systems.
  • Angle of Arrival, Time of Arrival, and Time Difference of Arrival techniques.
  • Triangulation, trilateration, hybrid techniques, and methods for reducing localization errors.
  • Exercises based on localization case studies and error estimation in mobile communication systems.

7. IoT Technologies and Architectures — 10 hours

Lectures: 6 hours – Exercises and laboratory activities: 4 hours

  • IoT architectures and communication models.
  • Bluetooth and BLE, IEEE 802.15.4, Wi-Fi, ZigBee, LoRa/LoRaWAN, and Sigfox.
  • MQTT-based communication and examples of interaction among IoT nodes.
  • Laboratory activities on the configuration and interaction of IoT nodes and MQTT communication.

8. IoT Sensing and Data Management — 7 hours

Lectures: 4 hours – Exercises and laboratory activities: 3 hours

  • Sensors, actuators, and embedded IoT devices.
  • Acquisition, preprocessing, and management of heterogeneous IoT data.
  • Data quality, time series, and interoperability.
  • Exercises on the acquisition, preprocessing, and analysis of sensor datasets.

9. Security, Privacy, and Forensics in IoT — 7 hours

Lectures: 4 hours – Exercises and laboratory activities: 3 hours

  • Vulnerabilities and security requirements of IoT systems.
  • Device authentication, access control, data protection, and privacy.
  • Acquisition aecurity and privacy scenarios and the acquisition of evidence from IoT devices.

10. Artificial Intellind analysis of digital evidence from IoT devices.

  • Exercises on sgence of Things and Applications — 13 hours

Lectures: 7 hours – Exercises and laboratory activities: 6 hours

  • Integration of Artificial Intelligence into IoT systems.
  • Classification, prediction, and anomaly detection applied to sensor data.
  • Multimodal sensing, data fusion, and applications to Smart Cities, environmental monitoring, healthcare, Industrial IoT, and smart agriculture.
  • Development of projects based on real-world biometric, multimedia, and sensor datasets, including experimental performance evaluation.

Contribution of the Course to the Goals of the 2030 Agenda for Sustainable Development

The topics addressed in the course and the knowledge acquired are directly or indirectly relevant to the development of sustainable, reliable, and secure technological solutions, while also contributing to high-quality education. In particular, the course contributes to Goals 3, 4, 9, 11, 12, 13, and 16 of the 2030 Agenda for Sustainable Development, with reference to applications in healthcare, digital infrastructures, Smart Cities, environmental monitoring, responsible use of data, and protection of digital evidence integrity.

Textbook Information

[1]  Lecture notes and teaching materials provided by the instructors during the course.

[2] A. K. Jain, A. A. Ross, K. Nandakumar and T. Swearingen, Introduction to Biometrics, 2nd ed., Springer, 2025.

[3] H. T. Sencar, L. Verdoliva and N. Memon, Multimedia Forensics, Springer, 2022.

[4] R. Ayers, S. Brothers and W. Jansen, Guidelines on Mobile Device Forensics, NIST Special Publication 800-101 Revision 1, 2014.

[5] O. Aouedi et al., “A Survey on Intelligent Internet of Things: Applications, Security, Privacy, and Future Directions,” IEEE Communications Surveys and Tutorials, vol. 27, no. 2, pp. 1238–1292, 2025. DOI: 10.1109/COMST.2024.3430368.

[6] F. Firouzi, K. Chakrabarty and S. Nassif, eds., Intelligent Internet of Things: From Device to Fog and Cloud, Springer, 2020. DOI: 10.1007/978-3-030-30367-9.

Course Planning

 SubjectsText References
1Section 1[1], [2]
2Section 2[1], [2], [3]
3Section 3[1], [2]
4Section 4[1], [2], [3]
5Section 5[1], [2], [3], [4]
6Section 6[1]
7Section 7[1], [5], [6]
8Section 8[1], [5], [6]
9Section 9[1], [5], [6]
10Section 10[1], [5], [6]

Learning Assessment

Learning Assessment Procedures

Assessment of Knowledge

  • Oral examination.
  • Assessment of a written assignment/project.

Description of Assessment Methods

Assessment consists of an oral examination, which may be supplemented by the discussion of a written assignment or project agreed upon with the instructors. The oral examination typically consists of two or three questions on the topics covered by the course and may include discussion of procedures, tools, or application cases addressed during laboratory activities.

The oral examination is worth up to a maximum of 26 points. Assessment takes into account the formal and substantive correctness of the answers, the ability to establish connections among biometric, forensic, and IoT aspects, appropriate use of technical terminology, the ability to provide application examples, and awareness of constraints related to security, privacy, and digital evidence integrity.

Active participation in laboratory activities and completion of any assigned project work may contribute up to 4 points to the final grade. Laboratory activities are generally organized into approximately 3–6 sessions and involve the use of forensic analysis tools, Python libraries, and real-world datasets. Any project or written assignment is evaluated on the basis of methodological correctness, quality of the analysis, clarity of the documentation, and the ability to critically discuss the results.

Assessment may also be conducted remotely should circumstances require it.

Examples of frequently asked questions and / or exercises

  • Describe the architecture of a biometric system and discuss the differences between authentication and identification.
  • Define FAR, FRR, ROC, EER, and DET and explain how these metrics are used to evaluate a biometric system.
  • Explain the main differences among digital forensics, computer forensics, and multimedia forensics.
  • Describe a correct procedure for the preservation, acquisition, analysis, and reporting of digital evidence in mobile forensics.
  • Discuss speaker recognition techniques based on formants, LPC, MFCC, GMM, and i-vectors and their use in audio forensics.
  • Explain the role of anti-spoofing, liveness detection, and deepfake detection in biometric and forensic systems.
  • Describe the forensic indicators that can be used to detect image and video manipulation, including content generated by Artificial Intelligence models.
  • Compare geolocation techniques based on AoA, ToA, and TDoA, highlighting their advantages, limitations, and sources of error.
  • Describe an IoT architecture based on sensors, actuators, communication protocols, and data management, including the role of MQTT.