Andrea Asperti
Full Professor at the Department of Computer Science and Engineering,
University of Bologna.
Iacopo Masi
Full Professor at the Department of Computer Science at Sapienza,
University of Rome.
Maura Pintor
Assistant Professor at the Department of Electrical and Electronic Engineering,
University of Cagliari.
Mauro Andreolini
Associate Professor at the Department of Sciences, Physichs, and Informatics,
University of Modena and Reggio Emilia (UniMoRe).
Elena Loli Piccolomini
Full Professor at the Department of Computer Science and Engineering,
University of Bologna.
Salvatore Fiorilla
In this module, students will be introduced to the main families of generative models, including GANs (Generative Adversarial Networks), VAEs (Variational Autoencoders), and diffusion models. These approaches have become central tools in Generative AI, each offering different strengths in how they learn and produce realistic data such as images, text, or audio. The session will present the core ideas behind each model, the types of problems they are suited for, and the architectures commonly used—such as convolutional networks, encoder-decoder frameworks, and attention-based designs. In addition to the theoretical overview, the module includes hands-on activities in Python, where students will implement and experiment with generative models to better understand how they work in practice.
In this talk, I show how discriminative models equipped with a softmax classifier can be reinterpreted as Energy-Based Models (EBMs), a lens that connects adversarial robustness, large language models, and generative modeling. I first use this perspective to explain robust and catastrophic overfitting in adversarial training and to characterize adversarial attacks as energy-landscape phenomena. From there, I follow two directions. The same energy view, applied to autoregressive language models, gives a training-free method for detecting hallucinations from internal model values. And moving from discriminative to generative, model inversion turns robust classifiers, CLIP, and differentiable renderers into generative samplers. Flipping the lens, I then ask what adversarial training means for models that are generative by construction: for diffusion models, robustness must be achieved while preserving equivariance to the data distribution.
Learning-based systems achieve strong performance in many application domains, from computer vision to cybersecurity. Their predictions, however, can be easily subverted by adversarial perturbations of the input data. Adversarial machine learning is the research field that studies this vulnerability. In this lecture, we review existing methods and show how to configure reliable robustness evaluations of ML models. We then apply these techniques to modern document understanding systems, showing how attackers can craft adversarial examples that force targeted or corrupted answers through visually subtle perturbations. Finally, we discuss why this is a new and largely unexplored attack surface, with real-world consequences for automated document processing by AI agents.
This module introduces the paradigm of AI agents and examines their use in automating cybersecurity tasks in both offensive and defensive settings. It provides an overview of the current state of research, with particular attention to the main architectures proposed, their capabilities, and their current limitations. The module also discusses issues concerning reliability, autonomy, security, and the supervision of activities performed by agents. It concludes with a hands-on session demonstrating how an AI agent can tackle a Capture The Flag (CTF) challenge, either autonomously or under human supervision.
In this lecture, we will explore how diffusion models can be exploited as powerful learned priors for reconstructing images from partial or degraded measurements. After introducing the formulation of image reconstruction as an inverse problem, we will discuss the main principles behind Diffusion Posterior Sampling, where a pretrained diffusion model is combined with information provided by the observed data to guide the generation process towards measurement-consistent solutions. We will examine how these methods can be applied to different imaging problems, including image inpainting, deblurring, and tomographic reconstruction, with particular attention to scenarios in which only incomplete measurements are available. Finally, we will discuss the main advantages of diffusion-based approaches, as well as their computational cost, underlying assumptions, and current limitations.
In this lecture, we will introduce Person Re-identification, the task of recognizing the same individual across images captured by different, non-overlapping cameras, and examine how generative artificial intelligence can support this process. Particular attention will be devoted to generative approaches that learn a representation of an individual as the conditioning information required to reconstruct or generate images of that person, offering an alternative perspective to traditional discriminative methods based on feature comparison. We will discuss the main technical challenges of Person Re-identification, including changes in viewpoint, pose, illumination, clothing visibility, and camera domain. Finally, the lecture will examine the security and ethical concerns associated with these technologies, considering their use in surveillance systems, the handling of biometric information, potential privacy violations, and the risks introduced by synthetic or manipulated visual content.