Skip to content
IT-703 (A) · Cyber Laws and Forensics/Quick Revision Short Notes

Cyber Laws and Forensics (IT-703 (A)) - Unit 3 Short Notes

UNIT 3: Cyber Laws and Forensics in Emerging Technologies


I. Internet of Things (IoT) – Legal and Forensic Dimensions

A. IoT Fundamentals

Definition: A system of interrelated computing devices, mechanical and digital machines, objects, animals, or people provided with unique identifiers and the ability to transfer data over a network without requiring human-to-human or human-to-computer interaction.

Key Characteristics:

  • Connectivity: Seamless communication between devices, networks, and the cloud.

  • Things/Objects: Any physical or virtual entity assigned an identifier (IP address, RFID).

  • Data: Raw data collected by sensors is processed into actionable information.

  • Communication: Protocols enabling data exchange between devices and platforms.

  • Intelligence: Ability to analyze data and act (e.g., via algorithms, AI).

  • Action: Output from the system, often via actuators.

  • Ecosystem: The entire environment of devices, platforms, and users.

IoT vs. Web of Things (WoT):

Feature IoT (Internet of Things) WoT (Web of Things)
Core Idea Connecting any physical object to the internet. Integrating IoT devices into the existing Web architecture (HTTP, URIs).
Primary Focus Device connectivity, data collection, M2M. Making IoT data and services discoverable and usable via standard web technologies.
Architecture Often proprietary, layered (Perception, Network, Application). Uses Web standards (REST, JSON, HTTP) as an application layer on top of IoT.
Analogy Building the roads and connecting cars. Creating traffic rules, maps (Google Maps), and gas stations (web services) for those cars.

IoT Architectural Framework (Layered View):

  1. Perception Layer (Physical Layer): Sensors & actuators gather physical data/perform actions.

  2. Network Layer: Transmits data via various networks (Wi-Fi, Bluetooth, 6LoWPAN, cellular).

  3. Middleware/Service Layer: Core processing, service discovery, data management, often cloud-based.

  4. Application Layer: User-facing applications (smart home apps, industrial dashboards).

  5. Business Layer: Overall management, business models, and legal/regulatory compliance.

Physical & Logical Design:

  • Physical Design: Deals with hardware components (sensors, actuators, microcontrollers, communication modules) and their physical layout.

  • Logical Design: Focuses on software layers, data flow, protocols, and service architectures (e.g., Service-Oriented Architecture - SOA).

Major Applications:

  • Smart Home: Thermostats, lighting, security systems.

  • Smart Cities: Traffic management, waste management, smart grids.

  • Industrial IoT (IIoT): Predictive maintenance, supply chain optimization.

  • Healthcare: Remote patient monitoring, wearable fitness devices.

  • Agriculture: Precision farming, soil/crop monitoring.

[!TIP] Exam Focus: Be prepared to draw and explain the layered architectural framework. Distinguish IoT (connectivity) from WoT (web integration) clearly.


B. Sensors and Actuators

Sensor Node: A complete, autonomous unit in a wireless sensor network (WSN) consisting of:

  1. Sensor: To sense physical phenomena.

  2. Microcontroller/Processor: For local computation and control.

  3. Communication Module: For wireless data transmission.

  4. Power Source: Typically a battery (energy harvesting is key research area).

  5. Memory: For data storage.

Key Features of Sensors:

  • Range: Minimum and maximum detectable values.

  • Accuracy & Precision: Closeness to true value and repeatability.

  • Sensitivity: Change in output per unit change in input.

  • Resolution: Smallest detectable change in input.

  • Response Time: Time to reach a certain percentage (e.g., 90%) of final output.

  • Stability & Drift: Performance change over time/temperature.

Types of Sensors:

Basis Type Description & Examples
Quantity Scalar Measures a single quantity (magnitude only). <br> Example: Thermometer (temperature).
Vector Measures magnitude and direction. <br> Example: Accelerometer (3-axis), Magnetometer.
Signal Analog Provides continuous output signal (voltage/current). <br> Example: LM35 temperature sensor.
Digital Provides discrete digital output (binary). <br> Example: DS18B20 (1-Wire digital temp).

Sensor Evolution & Importance:

  • Evolution: From large, wired, expensive, single-function devices → to MEMS (Micro-Electro-Mechanical Systems) based, miniaturized, low-cost, multi-functional, wireless nodes.

  • Importance: Sensors are the "senses" of IoT. Their evolution (smaller, cheaper, smarter) has enabled ubiquitous deployment, forming the foundation for all data-driven IoT applications. Without advanced sensors, there is no raw data.

Common Sensor Errors:

Error Definition Analogy
Bias A constant, fixed offset from the true value. A scale that always reads 0.5 kg heavy.
Drift A slow, time-dependent change in the output for a constant input. A thermometer's reading slowly increases over hours even in constant room temp.
Hysteresis Different output values for the same input depending on whether input is increasing or decreasing. A magnetic sensor gives different readings when approaching a magnet vs. moving away.
Quantization Error Error due to converting a continuous analog signal to discrete digital levels. The maximum error is ±½ of the least significant bit (LSB). Rounding a number to 2 decimal places; 1.234 becomes 1.23 (error 0.004).

Types of Actuators & Roles:

  • Electrical: Relays, solenoids, motors (DC, stepper, servo). Role: Convert electrical signal to motion/force.

  • Hydraulic: Use fluid pressure. Role: High-force applications (construction equipment).

  • Pneumatic: Use compressed air. Role: Fast, clean motion (factory automation).

  • Thermal: Heaters, coolers (Peltier). Role: Temperature control.

  • Role in IoT: Actuators are the "effectors"—they execute decisions made by the IoT system's intelligence (e.g., turn on a pump, lock a door, adjust a valve).

[!TIP] Exam Focus: Bias vs. Drift is a classic confusion. Bias is constant offset; Drift is changing over time. Know the LSB formula for quantization error: $$\displaystyle Max\_Error = \pm \frac{1}{2} LSB $$.


C. IoT Communication and Protocols

Wireless Communication Methods (Short-Range):

Tech Full Form Key Features & IoT Use
RFID Radio-Frequency Identification Passive tags (no battery), short range (cm-m). Used for asset tracking, inventory, access control.
Bluetooth - Short-range (10m), moderate data rate. BLE (Bluetooth Low Energy) is dominant in IoT for wearables, beacons.
ZigBee - Low-power, low-data rate, mesh networking. Based on IEEE 802.15.4. Used in smart home, industrial.
NFC Near Field Communication Extremely short range (<10 cm), pairing/payment. Used for device configuration, contactless transactions.
6LoWPAN IPv6 over Low-Power WPAN Adaptation layer allowing IPv6 packets to run over IEEE 802.15.4 (like ZigBee's PHY/MAC). Enables IP-based addressing for constrained devices.

Machine-to-Machine (M2M) Communication:

  • Definition: Direct communication between devices/machines without human intervention.

  • How it works: A device (sensor/meter) collects data → transmits it (via cellular, satellite, wired) to a central server/application → server may send a command back to another device (actuator).

  • IoT vs. M2M: M2M is often point-to-point, proprietary, vertical (e.g., a vending machine sending data to a specific server). IoT is IP-based, horizontal, cloud-centric, enabling broader connectivity and analytics. M2M is a subset/enabler of IoT.

Application Layer Protocols (Key for Exam):

Protocol Full Form Key Features & Components Message Types / Frame Types
MQTT Message Queuing Telemetry Transport Lightweight, publish/subscribe (broker-based). <br> Components: Client, Broker (server), Topic. <br> QoS Levels: 0 (At most once), 1 (At least once), 2 (Exactly once). CONNECT, PUBLISH, SUBSCRIBE, UNSUBSCRIBE, PINGREQ/PINGRESP, DISCONNECT.
CoAP Constrained Application Protocol RESTful (like HTTP), for constrained nodes. <br> UDP-based (low overhead). <br> Components: Client, Server, Resource. <br> Methods: GET, POST, PUT, DELETE. Confirmable (CON), Non-Confirmable (NON), Acknowledgement (ACK), Reset (RST).
AMQP Advanced Message Queuing Protocol Robust, enterprise messaging (broker-based). <br> Components: Producer, Consumer, Exchange, Queue, Binding. <br> Guaranteed delivery, security. 0: OPEN, 1: BEGIN, 2: ATTACH, 3: FLOW, 4: TRANSFER, 5: DISPOSITION, 6: DETACH, 7: END, 8: CLOSE.
XMPP Extensible Messaging and Presence Protocol XML-based, decentralized (client-server), presence-aware. <br> Originally for chat (Jabber). Good for real-time, person-to-thing communication. Stanzas: <message>, <presence>, <iq> (info/query).
SMQTT Secure MQTT MQTT with added security layer. <br> Uses symmetric encryption (AES) for message payloads. <br> Addresses MQTT's lack of built-in message confidentiality. Same as MQTT, but payload is encrypted.

Communication APIs in IoT:

  • Purpose: Provide standardized interfaces for applications to interact with hardware (sensors/actuators) and network protocols.

  • Role: Abstract low-level complexity, enable portability, speed up development.

  • Examples:

    • Platform APIs: AWS IoT SDK, Azure IoT SDKs.

    • Hardware Abstraction: Arduino Wire.h (I2C), SPI.h libraries.

    • Protocol Libraries: Paho MQTT client library, libcoap.

[!TIP] Exam Focus: CoAP vs. MQTT is a key differentiator: CoAP is RESTful/UDP (request/response), MQTT is Pub/Sub/TCP. AMQP frame types are numbered (0-8). SMQTT specifically adds AES encryption to MQTT payloads.


D. IoT Security, Privacy, and Legal Issues

Major Privacy & Security Issues:

  • Device Vulnerabilities: Weak/default passwords, unpatched firmware, lack of secure boot.

  • Data Privacy: Massive collection of personal, often sensitive, data (location, health, habits). Inadequate consent mechanisms.

  • Network Attacks: DDoS attacks using botnets of IoT devices (e.g., Mirai).

  • Lack of Standardization: Fragmented security protocols across vendors.

  • Physical Security: Tampering with devices in public/unsecured locations.

  • Lifecycle Management: Devices deployed for years without security updates.

Legal Compliance & Regulations:

  • GDPR (EU): Strict rules on personal data collection, consent, right to erasure. Applies to any device collecting EU resident data.

  • CCPA/CPRA (California): Similar consumer privacy rights.

  • Sector-Specific: HIPAA (US healthcare data), NIST Guidelines (US federal), India's Digital Personal Data Protection Act (DPDPA), 2023.

  • Liability Issues: Unclear legal responsibility for harm caused by compromised IoT devices (e.g., smart car accident, medical device failure).

  • Forensic Challenges: Data volatility, device heterogeneity, jurisdictional issues (cloud/data centers across borders), lack of standard forensic tools for IoT.

[!TIP] Exam Focus: Link specific issues to regulations. E.g., "Inadequate consent" violates GDPR's "lawful basis for processing." Mirai botnet is the canonical example of IoT-based DDoS.


E. Cloud Computing and Data Analytics in IoT

Role of Cloud Computing:

  • Storage: Massive, scalable, cost-effective storage for time-series IoT data.

  • Processing/Compute: Elastic compute power for batch/real-time analytics (big data processing).

  • Device Management: Provisioning, monitoring, updating fleets of devices.

  • Application Enablement: Platform-as-a-Service (PaaS) for building IoT apps.

  • Data Aggregation: Centralized repository from distributed devices.

Cloud Storage Models:

Model Description IoT Fit
Object Storage Stores data as objects (files) with metadata. Highly scalable, durable. (e.g., AWS S3, Azure Blob). Ideal for raw, unstructured IoT data (logs, images, sensor readings).
Block Storage Raw block devices (like virtual hard drives). High performance. (e.g., AWS EBS). Used for VMs/containers running analytics engines that process IoT data.
File Storage Hierarchical file system (like NAS). (e.g., Azure Files). Less common for raw IoT data; used for shared config files, logs.

Data Analytics for IoT Insights:

  • Stream Processing: Real-time analysis of incoming data streams (Apache Kafka, Flink, Spark Streaming). Use case: Anomaly detection in factory sensors.

  • Batch Processing: Analyzing large historical datasets (Hadoop, Spark). Use case: Predictive maintenance models.

  • Time-Series Analysis: Specialized for sequential, timestamped data (InfluxDB, TimescaleDB). Use case: Energy consumption trends.

  • Machine Learning/AI: Building predictive and prescriptive models. Use case: Forecasting demand, optimizing routes.

[!TIP] Exam Focus: Object Storage (S3/Blob) is the primary model for raw IoT data ingestion. Connect analytics type to use case: Stream = real-time alerts; Batch = historical model training.


F. IoT Platforms and Development

IoT Platforms (Features & Management):

A platform provides a suite of integrated tools to build, deploy, manage, and secure IoT applications.

  • Key Features:

    • Device Management: Onboarding, monitoring, firmware updates (OTA).

    • Data Ingestion & Storage: Connectors, brokers (MQTT/CoAP), databases.

    • Rules Engine & Analytics: Define actions based on data (e.g., "if temp>40, send alert").

    • Application Enablement: APIs, SDKs, dashboards.

    • Security: Authentication, authorization, encryption.

  • Examples: AWS IoT Core, Microsoft Azure IoT Hub, Google Cloud IoT Core, IBM Watson IoT, ThingWorx.

Development Boards:

Board Core Key Specs & IoT Role Typical Use Case
Arduino AVR/Microchip (8/32-bit) Easy I/O, vast shield ecosystem, simple IDE. Low cost, low power. Real-time tasks. Prototyping, sensor interfacing, simple control systems. Good for beginners.
Raspberry Pi Broadcom SoC (ARM Cortex) Full Linux OS (Raspbian), USB/Ethernet/HDMI, GPIO. More compute, memory. General-purpose computer. Edge computing, complex processing, gateway, vision apps (with camera). Runs Python, Node.js easily.

[!TIP] Exam Focus: Arduino = Microcontroller (real-time, I/O focused). Raspberry Pi = Microprocessor (full OS, compute/gateway focused). Platform features often follow the device-data-app-security lifecycle.


II. Social Networks – Cyber Law and Security Perspectives

A. Foundations of Social Networks

Emergence of the Social Web:

  • Transition from Web 1.0 (static pages) → Web 2.0 (user-generated content, interactivity) → Social Web (people-centric platforms).

  • Driven by: Broadband, mobile, platforms (Facebook, Twitter, LinkedIn), APIs for integration.

  • Key Shift: From information consumption to participation, sharing, and networking.

Types of Web-Based Networks:

  • Email Groups / Mailing Lists: Asynchronous group communication (e.g., Google Groups).

  • RSS Feeds: Content syndication/push (blog/news updates).

  • Social Networking Sites (SNS): Profile-based (Facebook, LinkedIn).

  • Microblogging: Short updates (Twitter/X).

  • Content Communities: Media sharing (YouTube, Instagram, TikTok).

  • Virtual Worlds: Immersive environments (Second Life).

  • Collaborative Projects: Wiki (Wikipedia), code (GitHub).

Social Network Analysis (SNA) Importance:

  • Study of social structures using graph theory (nodes=actors, edges=relationships).

  • Applications: Marketing (influencer identification), cybersecurity (detect fake accounts/communities), public health (disease spread), law enforcement (criminal networks), organizational analysis.

Basic SNA Concepts:

  • Centrality: Measures node importance.

    • Degree Centrality: Number of direct connections.

    • Betweenness Centrality: How often a node lies on shortest paths (bridge/broker).

    • Closeness Centrality: How close a node is to all others (how fast it can spread info).

    • Eigenvector Centrality: Importance of a node's neighbors (influence).

  • Clustering / Clustering Coefficient: Tendency of a node's neighbors to be connected (density of triangles). High clustering = tight-knit groups.

  • Matrix Representation: Social network as Adjacency Matrix (A) where $$\displaystyle A_{ij} = 1 $$ if node i connects to j, else 0. Used for mathematical analysis (e.g., calculating centrality, paths).

[!TIP] Exam Focus: Know the 4 main centralities and their intuitive meaning. Matrix representation is $$\displaystyle A_{ij} = 1 $$ (connection) or 0 (no connection).


B. Ontologies and Digital Identity

Semantic Web Technologies (Layer Cake):

  • Goal: Make web data machine-readable and interoperable.

  • RDF (Resource Description Framework): Data model for statements. Triple: (Subject) - (Predicate) - (Object). E.g., (Alice) - (knows) - (Bob).

  • RDF Schema (RDFS): Provides basic vocabulary (classes like Person, properties like knows) and simple constraints (domain, range).

  • OWL (Web Ontology Language): More expressive ontology language built on RDF/RDFS. Allows:

    • Class equivalence/disjointness.

    • Property characteristics (transitive, symmetric).

    • Cardinality restrictions (has exactly 2 parents).

    • Reasoning (inferring new facts).

FOAF (Friend of a Friend) & Social Ontology:

  • FOAF: A popular RDF-based vocabulary/ontology for describing people, their relationships, and activities on the web.

  • Key Classes: foaf:Person, foaf:Organization.

  • Key Properties: foaf:knows (relationship), foaf:name, foaf:mbox (email), foaf:homepage.

  • Significance: Provides a standard, machine-readable way to represent social profiles and connections across different sites, enabling decentralized social networking and data portability.

[!TIP] Exam Focus: RDF = Triples (data). RDFS = Basic vocabulary. OWL = Rich ontology with reasoning. FOAF is an application of RDF for social networks.


C. Privacy and Security in Online Social Networks (OSNs)

Privacy Issues & Challenges:

  • Data Collection & Profiling: Extensive harvesting of personal data for targeted advertising/surveillance.

  • Visibility & Context Collapse: Different audiences (family, friends, employers) see the same profile.

  • Re-identification: "Anonymous" data can be re-linked to individuals.

  • Location Privacy: Geotagging reveals real-time location.

  • Third-Party Apps: Malicious apps harvesting friend data.

  • Default Settings: Often opt-out, favoring sharing over privacy.

  • Complex Privacy Policies: Users don't understand terms.

Decentralized OSNs (DOSNs) Challenges:

  • Concept: User data stored on user-controlled servers (federated) or fully peer-to-peer (e.g., Mastodon, Diaspora*).

  • Challenges:

    • User Experience & Onboarding: Complex setup vs. one-click sign-up on Facebook.

    • Network Effects: Hard to attract friends if they are on centralized platforms (critical mass problem).

    • Moderation & Abuse: Difficult to enforce community standards across independent servers.

    • Interoperability: Federation protocols (ActivityPub) are still maturing.

    • Data Portability & Backup: User responsibility for their own data.

    • Monetization: Lack of centralized ad platform; reliance on donations/grants.

[!TIP] Exam Focus: Contrast Centralized OSN (single entity controls data, easy UX, privacy risk) with DOSN (user control, privacy-preserving, but suffers from network effects & UX complexity).


D. Attacks and Countermeasures

Attack Spectrum:

Attack Description Countermeasure
Plain Impersonation Creating a fake profile pretending to be a real person. Profile verification (blue ticks), user reporting, AI-based fake account detection.
Profile Cloning Copying a victim's profile info (name, photo) to create a near-identical fake. Unique identifiers (user ID, not just name), monitoring for duplicate photos/names, user alerts.
Profile Hijacking Gaining unauthorized access to a legitimate user's account (via phishing, credential stuffing). Strong 2FA/MFA, password hygiene education, login anomaly detection.
Profile Porting Moving a verified/trusted profile from one OSN to another to gain trust on the new platform. Cross-platform identity verification, caution with new connections, checking account history/age.
Censorship Attacks Malicious reporting of legitimate content/accounts to get them suspended/removed by the platform. Review of mass reports, appeal mechanisms, detection of coordinated reporting campaigns.

[!TIP] Exam Focus: Cloning vs. Impersonation: Cloning copies an existing profile; impersonation creates a new fake of a real person. Hijacking is about taking over a real account.


E. Community Detection and Evolution

Definitions of Community:

  • Global Definition: A community is a subgraph where nodes inside are more connected to each other than to nodes outside. (Modularity-based).

  • Local Definition: A community is a set of nodes reachable from a starting node via internal connections. (e.g., using random walks).

  • Vertex-based Definition: Each node is assigned a community label; nodes with same label belong to the same community. (e.g., label propagation).

Evolution Metrics in Web Communities:

Measuring how a community changes over time (from a series of web archives/snapshots):

  • Growth: Increase in number of nodes/members.

  • Contraction: Decrease.

  • Birth: New community appears.

  • Death: Community dissolves.

  • Merging: Two communities combine.

  • Splitting: One community divides.

  • Stability: Core members remain over time.

Network Reduction Techniques: Simplify a large, dense network to reveal community structure.

  • k-core Decomposition: Iteratively remove nodes with degree < k. The remaining "core" often reveals dense communities.

  • Girvan-Newman Algorithm: Based on edge betweenness. Remove edges with highest betweenness to split graph into communities.

  • Spectral Clustering: Uses eigenvalues of the graph Laplacian matrix to partition nodes.

[!TIP] Exam Focus: k-core finds dense cores; Girvan-Newman removes high-betweenness edges. Evolution metrics are about dynamic changes (birth, death, merge, split).


F. Enabling Human Experiences and Ethical Considerations

Reality Mining:

  • Definition: Collection and analysis of real-time, context-aware data from mobile devices (location, Bluetooth proximity, call logs, app usage) to understand human behavior, social patterns, and relationships.

  • Applications: Urban planning, epidemiology (disease spread), targeted advertising, productivity analysis.

  • Ethical Implications: Mass surveillance, consent (often implied), data aggregation risks, function creep.

Context Awareness:

  • Definition: Systems that sense and react to the user's environment, situation, and activity (location, time, social setting, device state).

  • In OSNs: Tailoring content feeds, suggesting connections, adjusting privacy settings based on location/activity.

  • Ethical Implications: Filter bubbles, manipulation (dark patterns), discrimination based on inferred context.

Ethical Considerations (General for OSNs):

  • Autonomy & Manipulation: Algorithmic feeds shaping opinions/behavior.

  • Justice & Fairness: Algorithmic bias in content moderation, job ads, credit scoring.

  • Privacy: As above.

  • Transparency: Opaque algorithms and data practices.

  • Addiction & Well-being: Design patterns promoting compulsive use.

  • Misinformation & Polarization: Amplification of extreme content.

[!TIP] Exam Focus: Reality Mining = mining phone sensor data for behavior. Context Awareness = adapting system to user's situation. Both raise consent and surveillance red flags.


III. Digital Image Processing for Forensic Applications

A. Fundamentals of Image Processing

Image Formation (Human Eye - Brightness Adaptation & Discrimination):

  • Image Formation: Scene → Lens → Retina (inverted). Photoreceptors (rods & cones) convert light to neural signals.

  • Brightness Adaptation: The eye's ability to adjust sensitivity over a huge range (10¹⁰:1) of luminance. Done by iris adjustment (pupil size) and photoreceptor sensitivity.

  • Brightness Discrimination: The ability to distinguish small differences in brightness. Weber's Law: $$\displaystyle \frac{\Delta I}{I} = constant $$. Just noticeable difference (JND) is proportional to background intensity $I$.

Sampling & Quantization:

  • Sampling: Digitizing spatial coordinates (x,y). Number of samples per unit area = Spatial Resolution. Aliasing occurs if sampling rate < 2x max spatial frequency (Nyquist).

  • Quantization: Digitizing amplitude (intensity). Number of gray levels = $$\displaystyle L = 2^k $$ (k = bits/pixel). Quantization Error = difference between actual and quantized value. More bits → lower error, larger file size.

Noise Parameters & Estimation:

  • Noise: Undesired random variation in image intensity.

  • Types: Gaussian, Rayleigh, Gamma, Exponential, Uniform, Impulse (salt-and-pepper).

  • Estimation (from a "noisy" image $g(x,y)$):

    • If noise-free image $f(x,y)$ is known: $$\displaystyle \hat{n}(x,y) = g(x,y) - f(x,y) $$.

    • If only noisy image available: Assume noise is zero-mean, uncorrelated with signal. Estimate noise variance $$\displaystyle \sigma_n^2 $$ from flat regions (homogeneous areas) where signal variance is low.

    • Method: Select a flat region $R$. Compute $$\displaystyle \sigma_g^2 = \text{variance in } R $$. Since $$\displaystyle \sigma_g^2 \approx \sigma_n^2 $$ in flat region, $$\displaystyle \sigma_n^2 \approx \sigma_g^2 $$.

Fourier Transform Properties (Linearity):

  • 2-D Continuous FT: $$\displaystyle F(u,v) = \int_{-\infty}^{\infty} \int_{-\infty}^{\infty} f(x,y) e^{-j2\pi(ux+vy)} dx dy $$

  • 2-D Discrete FT (DFT): $$\displaystyle F(u,v) = \sum_{x=0}^{M-1} \sum_{y=0}^{N-1} f(x,y) e^{-j2\pi(ux/M + vy/N)} $$

  • Linearity: If $$\displaystyle f_1(x,y) \leftrightarrow F_1(u,v) $$ and $$\displaystyle f_2(x,y) \leftrightarrow F_2(u,v) $$, then $$\displaystyle a f_1(x,y) + b f_2(x,y) \leftrightarrow a F_1(u,v) + b F_2(u,v) $$ for any scalars $a, b$.

  • Proof (DFT): Direct substitution and linearity of summation/exponential.

[!TIP] Exam Focus: Weber's Law for discrimination. Nyquist for sampling. Noise estimation from flat regions. Linearity proof is straightforward substitution.


B. Image Enhancement and Restoration

Histogram Processing (Color Images):

  • Goal: Modify image histogram to improve contrast/appearance.

  • For Grayscale: Direct histogram equalization (CDF as transform function).

  • For Color (RGB): Problem: Equalizing each channel independently can cause color hue shift.

  • Solutions:

    1. Convert to HSI/HSV/Lab: Equalize only the Intensity (I) / Value (V) / Lightness (L) channel, then convert back to RGB.

    2. Histogram Specification: Match histogram of each channel to a desired shape (careful to preserve color balance).

    3. 3-D Histogram Equalization: Equalize in full 3-D color space (computationally expensive).

Spatial Filtering (Sharpening):

  • Goal: Enhance edges and fine details.

  • Based on: Highpass filtering (attenuates low frequencies/smooth areas, passes high frequencies/edges).

  • Common Filters:

    • Ideal Highpass: $$\displaystyle H_{ihp}(u,v) = 1 $$ if $$\displaystyle D(u,v) > D_0 $$, else 0. (Ring artifacts).

    • Butterworth Highpass (Order n):

$$H_{bhp}(u,v) = \frac{1}{1 + \left(\frac{D_0}{D(u,v)}\right)^{2n}}$$

*   **Gaussian Highpass:** 

$$H_{ghp}(u,v) = 1 - e^{-\frac{D^2(u,v)}{2D_0^2}}$$

  • Sharpening in Spatial Domain: $$\displaystyle g(x,y) = f(x,y) + c \cdot \nabla^2 f(x,y) $$ (Laplacian). Or using unsharp masking: $$\displaystyle g = f + k(f - f_{blur}) $$.

Homomorphic Filtering:

  • Problem: Image $$\displaystyle f(x,y) = i(x,y) \cdot r(x,y) $$ (illumination $i$ × reflectance $r$). Multiplicative noise.

  • Solution: 1. Take log: $$\displaystyle \ln f = \ln i + \ln r $$. 2. Apply linear filter (highpass) in log domain to separate illumination (low freq) from reflectance (high freq). 3. Exponentiate.

  • System Function:

$$H_{hom}(u,v) = (H_{hp}(u,v) - \gamma) + \gamma$$

where $\gamma$ controls balance. Often $$\displaystyle H_{hp} $$ is Gaussian/Butterworth.

  • Block Diagram: Input f → log → FFT → Multiply by H_hom → IFFT → exp → Output g.

Wiener Filtering & MMSE:

  • Goal: Restore a degraded image $$\displaystyle g(x,y) = h(x,y) * f(x,y) + \eta(x,y) $$ (convolution with PSF $h$ + noise $\eta$).

  • Wiener Filter (Frequency Domain):

$$H_w(u,v) = \frac{H^*(u,v) S_f(u,v)}{|H(u,v)|^2 S_f(u,v) + S_\eta(u,v)}$$

*   $H(u,v)$: Degradation filter (PSF) FT.

*   $$\displaystyle S_f(u,v) $$: Power spectrum of original image.

*   $$\displaystyle S_\eta(u,v) $$: Power spectrum of noise.

*   $$\displaystyle H^* $$: Complex conjugate.
  • MMSE (Minimum Mean Square Error): Wiener filter minimizes $$\displaystyle E[(f - \hat{f})^2] $$. It's the optimal linear filter in MSE sense if $$\displaystyle S_f $$ and $$\displaystyle S_\eta $$ are known.

  • Practical Issue: $$\displaystyle S_f $$ is usually unknown. Estimated from degraded image or assumed constant (e.g., $$\displaystyle S_f \propto 1/(u^2+v^2)^{\beta} $$).

Image Point Operations:

  • Definition: Operation where output pixel $g(x,y)$ depends only on input pixel $f(x,y)$ at same location. $$\displaystyle g = T(f) $$.

  • Examples:

    • Contrast Stretching: Linear or non-linear mapping to use full gray range.

    • Thresholding: $$\displaystyle g=0 $$ if $$\displaystyle f<T $$, else $$\displaystyle g=L-1 $$.

    • Negative: $$\displaystyle g = L-1 - f $$.

    • Log Transformation: $$\displaystyle g = c \log(1+f) $$ (compresses high intensities, expands low).

    • Power-Law (Gamma): $$\displaystyle g = c f^\gamma $$. $$\displaystyle \gamma<1 $$ expands dark, $$\displaystyle \gamma>1 $$ expands bright.

[!TIP] Exam Focus: Homomorphic = log + linear filter + exp (for multiplicative illumination). Wiener formula must be memorized. Color histogram → convert to HSI, equalize I. Point ops are location-independent.


C. Segmentation and Morphological Operations

Region-Based Segmentation:

  • Goal: Partition image into homogeneous regions (objects/background).

  • Methods:

    • Thresholding: Global (single T) or adaptive/local (T varies). Otsu's method finds optimal global T by maximizing inter-class variance.

    • Region Growing: Start with "seeds", add neighboring pixels with similar intensity/texture.

    • Region Splitting & Merging: Start with whole image, recursively split heterogeneous regions, then merge adjacent similar regions.

    • Watershed: Treat gradient magnitude as topographic surface. "Flood" from minima to find catchment basins (segments). Prone to over-segmentation; needs markers.

Motion-Based Segmentation:

  • Goal: Segment objects based on relative motion (e.g., moving cars in static scene).

  • Methods:

    1. Frame Differencing: $$\displaystyle |I_t - I_{t-1}| $$. Simple, but holes in moving objects.

    2. Background Subtraction: Maintain statistical model of background (running average, Mixture of Gaussians). Foreground = current frame - background model.

    3. Optical Flow: Estimate dense motion field (velocity vectors per pixel). Segment by clustering motion vectors.

Morphological Operations (on binary images, but extends to grayscale):

  • Structuring Element (SE): Shape (kernel) used to probe image. Defined by shape, size, origin.

  • Erosion: $$\displaystyle A \ominus B = \{ z | (B)_z \subseteq A \} $$. Shrinks A. Removes small objects, separates connected ones.

  • Dilation: $$\displaystyle A \oplus B = \{ z | (B)_z \cap A \neq \emptyset \} $$. Expands A. Fills small holes/gaps, connects nearby objects.

Morphological Algorithms:

  • Boundary Extraction: $$\displaystyle \partial A = A - (A \ominus B) $$. (Original minus eroded).

  • Hole Filling: Start with a point inside hole. Iteratively: $$\displaystyle X_0 = \{p\} $$, $$\displaystyle X_{k+1} = (X_k \oplus B) \cap A^c $$. Stop when $$\displaystyle X_{k+1} = X_k $$. $$\displaystyle X_k $$ fills the hole.

  • Connected Components: Find all 8-connected (or 4-connected) regions.

  • Skeletonization: Thinning to 1-pixel wide representation while preserving topology.

[!TIP] Exam Focus: Erosion = shrink, Dilation = grow. Boundary = A - Erode(A). Hole fill = iterative dilation of seed point intersected with complement of A. Optical Flow gives dense motion vectors; Frame Differencing is simpler but sparse.


D. Compression and Coding

Need for Compression:

  • Reduce storage requirements (massive image/video databases).

  • Reduce bandwidth for transmission (web, streaming, IoT sensor images).

  • Two Types:

    • Lossless: Original data perfectly reconstructable. (PNG, GIF, ZIP). Compression ratio low (2:1 to 5:1).

    • Lossy: Some information discarded, irreversible. Higher compression (10:1 to 100:1). (JPEG, MPEG).

Vector Quantization (VQ):

  • Concept: Group pixels (or vectors of pixels) into codebook of representative vectors (codewords).

  • Encoder:

    1. Training: Create codebook $$\displaystyle C = \{c_1, c_2, ..., c_N\} $$ from typical images (e.g., using Linde-Buzo-Gray algorithm).

    2. For input image block (vector) $\mathbf{x}$, find nearest neighbor codeword $$\displaystyle c_i $$ (minimize distance, e.g., Euclidean). Encode by sending index $i$.

  • Decoder: Simple lookup. Receives index $i$, outputs codeword $$\displaystyle c_i $$.

  • Pros: Simple decoder, good rate-distortion at low bitrates.

  • Cons: Complex encoder (codebook generation, search), codebook must be transmitted/stored, blocking artifacts.

Lossy Predictive Coding:

  • Concept: Predict current pixel/block from past (causal) pixels. Encode the prediction error (residual) which has lower entropy.

  • Encoder Block Diagram:

    Input f(x,y) → Predictor → Predicted \hat{f} → Subtractor (-) → Error e → Quantizer → Encoded bits → Transmitter.

    Also: \hat{f} → Local Decoder (Quantizer + Adder) → Reconstructed \hat{f}_{rec} (for feedback to predictor).

  • Decoder Block Diagram: Receiver → Decoded bits → Dequantizer → Error \hat{e} → Adder (+) → Reconstructed \hat{f}_{rec}.

    (Uses same predictor initialized with same state).

  • Predictor Types: DPCM (1-D), 2-D predictors (e.g., $$\displaystyle \hat{f}(x,y) = \alpha_1 f(x-1,y) + \alpha_2 f(x,y-1) + \alpha_3 f(x-1,y-1) $$).

  • Key: Prediction reduces redundancy; quantization introduces loss.

[!TIP] Exam Focus: VQ: Encoder = search codebook; Decoder = lookup. Predictive Coding: Encoder sends error, decoder reconstructs using same predictor. Draw both block diagrams.


E. Feature Extraction and Recognition

Texture Analysis:

  • Definition: Visual patterns of spatial variation of intensity/color. No single definition.

  • Approaches:

    1. Statistical: Analyze gray-level co-occurrence matrix (GLCM). Extract features: Contrast, Correlation, Energy, Homogeneity.

    2. Structural: Identify primitives (e.g., bricks, tiles) and their arrangement rules.

    3. Spectral: Use Fourier or wavelet transform. Energy in specific frequency bands indicates texture coarseness.

    4. Model-based: Fractals (fractal dimension), Markov Random Fields.

Object Recognition:

  • Goal: Assign a label to an object in an image.

  • Steps:

    1. Segmentation: Isolate object from background.

    2. Feature Extraction: Compute descriptive features (shape: moments, Fourier descriptors; texture: GLCM; color histograms).

    3. Classification: Use trained model to match features to class.

  • Methods:

    • Template Matching: Direct pixel comparison (sensitive to scale/rotation).

    • Geometric/Hough Transform: Detect specific shapes (lines, circles).

    • Statistical Classifiers: Minimum distance, Bayesian, SVM.

    • Deep Learning (CNNs): State-of-the-art. Learn hierarchical features automatically.

[!TIP] Exam Focus: GLCM features (4 main: Contrast, Correlation, Energy, Homogeneity). Object recognition pipeline: Segment → Extract Features → Classify.


F. Forensic Considerations

Admissibility of Processed Images:

  • Legal Standard: Evidence must be relevant, reliable, and authentic. (Daubert standard in US, Indian Evidence Act).

  • Challenges for Processed Images:

    • Authenticity: Has the image been altered? Chain of custody must document every processing step with software, parameters, version.

    • Reliability: Is the algorithm scientifically valid and generally accepted? (Need peer-reviewed validation).

    • Original vs. Derivative: Courts prefer original, unprocessed images. Processed images are "derivative evidence" and may be excluded if processing is questionable.

    • Expert Testimony: Forensic expert must explain methodology, error rates, and why processing was necessary.

Tamper Detection and Analysis:

  • Goal: Detect if an image has been manipulated (copy-move, splicing, retouching).

  • Techniques:

    • Pixel-based: Statistical anomalies (inconsistent noise patterns, JPEG blocking artifacts).

    • Format-based: Inconsistencies in metadata (EXIF), JPEG quantization tables.

    • Physics-based: Inconsistent lighting/shadows, perspective geometry.

    • Sensor-based: Photo Response Non-Uniformity (PRNU) - each camera sensor leaves a unique noise pattern. Can link image to source camera or detect splicing (different PRNU in parts).

    • Copy-Move Detection: Use robust keypoint detectors (SIFT, SURF) to find duplicated regions.

    • ELA (Error Level Analysis): Resave image at known quality; areas with different compression artifacts may indicate editing.

[!TIP] Exam Focus: PRNU is a key forensic sensor fingerprint. Chain of custody is paramount for admissibility. ELA is a common initial screening tool for tampering.


Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in