Scalpel3: A High-Performance Data Carving Architecture for Recovery of Fragmented Files

📅 2026-06-17
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Scalpel3通过高度并行架构解决文件碎片恢复问题,支持研究人员开发新恢复策略,并集成ONNX Runtime以利用学习模型。
📝 Abstract
File carving recovers files from raw storage media without relying on filesystem metadata, a key capability in digital forensics, data recovery, and digital exploration. Traditional tools such as Foremost, Scalpel v1/2, and PhotoRec handle contiguous files effectively, and some support fragmented recovery for specific formats under simplifying assumptions, but no publicly available tool provides a general-purpose, high-performance framework for developing and deploying fragmented recovery strategies across many file types at scale. This paper presents Scalpel3, the first general-purpose, open source, massively parallel file carving framework designed to support both contiguous and fragmented recovery at scale. Its primary contribution is an extensible, high-performance architecture that enables researchers to develop, test, and deploy new carving strategies without implementing their own multithreaded backends or I/O infrastructure. Adding support for new file types typically requires only development of single-threaded file validation logic and, where useful, block validation or custom reassembly logic -- the Scalpel3 backend manages parallelization, synchronization, and fast I/O automatically. The architecture also integrates the ONNX Runtime, allowing learned classifiers to participate in block validation and reassembly when useful. Beyond raw performance, Scalpel3 introduces practical features for real-world investigations: persistent checkpointing for long-running jobs, human-in-the-loop control allowing operators to monitor progress and redirect effort interactively, and block-level deduplication to shrink the search space. By making this framework publicly available, we aim to lower barriers to experimentation and help translate file carving research into practitioner-ready tools.
Problem

Research questions and friction points this paper is trying to address.

file carving
fragmented recovery
high-performance framework
digital forensics
Innovation

Methods, ideas, or system contributions that make the work stand out.

massively threaded architecture
fragmented file recovery
format-agnostic
ONNX Runtime integration
human-in-the-loop control
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
K
Karley Waguespack
Division of Computer Science and Engineering, Louisiana State University; Center for Computation and Technology, Louisiana State University; LSU Cyber Center, Louisiana State University
S
Samuel Goodwin
Division of Computer Science and Engineering, Louisiana State University; Center for Computation and Technology, Louisiana State University; LSU Cyber Center, Louisiana State University
G
George Hendrick
Division of Computer Science and Engineering, Louisiana State University; Center for Computation and Technology, Louisiana State University; LSU Cyber Center, Louisiana State University
S
Samuel Hildebrand
Division of Computer Science and Engineering, Louisiana State University; Center for Computation and Technology, Louisiana State University; LSU Cyber Center, Louisiana State University
T
Thomas Landaiche III
Division of Computer Science and Engineering, Louisiana State University; Center for Computation and Technology, Louisiana State University; LSU Cyber Center, Louisiana State University
Mingyang Li
Mingyang Li
Associate Professor, Industrial and Management Systems Engineering, The University of South Florida
data sciencereliability and qualitysystem informaticscomplex systems modeling and optimizationcomputational intelligence
J
Joshua McCain
Division of Computer Science and Engineering, Louisiana State University; Center for Computation and Technology, Louisiana State University; LSU Cyber Center, Louisiana State University
T
Tyler Saizan
Division of Computer Science and Engineering, Louisiana State University; Center for Computation and Technology, Louisiana State University; LSU Cyber Center, Louisiana State University
J
Jacob Tucker
Division of Computer Science and Engineering, Louisiana State University; Center for Computation and Technology, Louisiana State University; LSU Cyber Center, Louisiana State University
J
James M. Ghawaly
Division of Computer Science and Engineering, Louisiana State University; Center for Computation and Technology, Louisiana State University; LSU Cyber Center, Louisiana State University
Golden G. Richard III
Golden G. Richard III
Professor of Computer Science, Louisiana State University
digital forensicsmemory forensicsreverse engineeringmalware analysisoperating systems