Score
Collecting, validating, and analyzing digital artifacts and chains of evidence to reconstruct system state, identities, reasoning, and causality during incident recovery or investigation.
Event reconstruction in digital forensics suffers from fragmented perspectives, inconsistent terminology, and methodological fragmentation, lacking a systematic, unifying framework. Method: This paper proposes the first unified temporal event reconstruction framework tailored for digital forensics—adapting classical forensic reconstruction models to the digital domain; constructing a comprehensive, lifecycle-spanning conceptual map of temporal reconstruction; and conducting a systematic literature review (SLR) coupled with conceptual modeling to clarify terminological relationships and process elements. Contribution/Results: The study identifies three core challenges—data scale, temporal distortion, and semantic ambiguity—and establishes an extensible classification system. It delivers a consensus-based terminology set and a standardized process paradigm, thereby providing a rigorous theoretical foundation for the development and evaluation of automated event reconstruction tools.
This study addresses the absence of a unified investigative framework for AI system incidents, which hinders behavior reconstruction, accountability attribution, and supply chain traceability. It proposes the first AI forensics process model structured around investigators’ levels of system access—white-box, gray-box, and black-box—and organized into four phases: collection, preservation, analysis, and reporting. The work introduces a method for ranking evidence volatility and integrates multi-source data—including logs, context windows, retrieval corpora, and training lineages—into a structured forensic workflow matrix. By clarifying critical open issues such as black-box evidence preservation and model version authentication, the paper identifies four core challenges and establishes a theoretical foundation for designing auditable and accountable AI systems.
This study addresses the absence of a systematic framework in digital vehicle forensics (DVF), where evidence is fragmented across in-vehicle systems, mobile devices, manufacturer backends, and third-party services. Through a structured review of academic literature, standards, and real-world cases, this work identifies eight core characteristics of DVF for the first time, incorporates an adversarial perspective, formalizes the initial forensic triage problem, and proposes a feature-driven prioritization workflow. The resulting reproducible conceptual framework clarifies strategies for selecting and correlating evidence sources, significantly enhancing the efficiency and rigor of forensic investigations in accident reconstruction, criminal inquiries, and cybersecurity incident response—while explicitly accounting for safety, legal, and privacy constraints.
This study addresses the challenges of insufficient evidentiary reliability and lack of traceability in current AI-assisted digital forensics, particularly when large language models (LLMs) are involved, which often fail to meet judicial standards for trustworthiness. To overcome these limitations, the authors propose an automated framework that integrates LLMs with a Digital Forensics Knowledge Graph (DFKG), enabling end-to-end traceability of forensic data through deterministic unique identifiers (UIDs). The framework further incorporates a cross-validation mechanism to ensure both the integrity of the evidence chain and contextual consistency. Evaluated on a real-world 13 GB dataset, the approach achieves over 95% accuracy in forensic item extraction, establishing a novel, auditable, scalable, and legally compliant paradigm for AI-assisted digital investigations.
In digital forensics, the atomicity and integrity of storage snapshots lack rigorous definitions that jointly guarantee both instantaneousness and causal ordering—undermining evidentiary admissibility in legal proceedings. To address this, we propose a novel atomicity definition grounded in causal consistency, overcoming the limitation of conventional time-based atomicity models. We further rectify conceptual flaws in existing integrity definitions and introduce a revised, theoretically sound yet engineering-practical integrity criterion—explicitly supporting copy-on-write (CoW) implementations. Our approach integrates causal modeling, formal snapshot semantics, CoW mechanism analysis, and formalization of forensic quality criteria, yielding a verifiable snapshot semantic framework. This work establishes the first theoretical foundation for forensic tool design that unifies causal ordering with instantaneous state capture, thereby significantly enhancing the forensic validity and judicial admissibility of live data acquisition.
This study addresses the longstanding disconnect between detection engineering and digital forensics, which has led to a gap between real-time alerts and post-incident analysis. To bridge this divide, the authors propose a unified detection-and-forensics methodology based on Velociraptor that triggers targeted evidence collection immediately upon detection events, thereby integrating monitoring and forensic workflows. The approach introduces an innovative four-stage framework that transforms forensic artifacts into reusable, testable detection rules, enabling efficient initial triage without requiring full disk imaging. By leveraging BaseVQL data sources—such as Prefetch, USN Journal, and WMI—it facilitates cross-artifact correlation and periodic analysis, allowing effective screening even in the absence of Windows Event Logs. This significantly reduces data acquisition volume while supporting continuous monitoring.
This study addresses the challenges posed by rapid evolution in digital forensic systems and tools, which induces drift in evidentiary behaviors and tool outputs, thereby undermining result reproducibility and trustworthiness. To mitigate this, the authors propose a test-driven forensic methodology that introduces state-transition testing for causal attribution, encoding forensic expectations as executable specifications. The approach integrates virtual machine environments with computer vision–guided GUI automation to simulate authentic user interactions and verify system state changes. An open web platform is developed to facilitate sharing and replication of experiments. The method’s efficacy is demonstrated through five case studies, including a regression analysis across 25 versions of Autopsy, which uncovered numerous undocumented, substantial changes in its reporting output.
This study addresses the multifaceted sociotechnical challenges inherent in real-world unmanned aerial vehicle (UAV) incident response, an area lacking empirical grounding in frontline practitioners’ experiences. Adopting a sociotechnical perspective, the research systematically identifies critical non-technical barriers—spanning organizational coordination, legal and policy frameworks, and forensic capabilities—through focus group interviews with UAV and counter-UAV professionals from U.S. industry and government sectors, followed by thematic analysis. The findings reveal five core challenges: insufficient situational awareness, fragmented inter-agency coordination, limited forensic traceability, regulatory gaps, and inadequate training. By providing the first empirical account of these operational realities, this work fills a significant gap in the literature and offers both theoretical insights and practical foundations for developing more effective UAV incident response systems.
This study addresses the challenges in digital forensics posed by heterogeneous network data, whose incompatible schemas and timestamp formats hinder reliable evidence correlation and timeline reconstruction, while existing preprocessing methods suffer from poor reproducibility. To overcome these limitations, this work proposes a deterministic forensic preprocessing framework that transforms raw data into a standardized, reproducible form through three core operations: schema normalization, temporal normalization, and provenance tracking. The framework innovatively formalizes the preprocessing pipeline using set-theoretic constructs and rigorously proves its determinism, information preservation, and provenance completeness. Furthermore, it introduces a bounded-memory, chunk-based streaming architecture enabling scalable processing. Empirical evaluation on the UNSW-NB15, IoT-23, and TON_IoT datasets demonstrates 100% output consistency and efficient handling of datasets ranging from millions to hundreds of millions of records.
Digital forensics in criminal proceedings faces significant challenges—including data proliferation, rapid technological evolution, and insufficient collaboration between legal and technical professionals—that hinder its effective integration. This study addresses these issues by reconceptualizing digital forensics as a sociotechnical system through the novel lens of usability and human-centered security. Drawing on survey data from 101 judicial practitioners in North Rhine-Westphalia, Germany, the research develops an integrated analytical framework that bridges usability and human-centered security principles. Findings highlight critical needs to enhance workflow integration, align stakeholder expectations, and strengthen cross-disciplinary communication. The study further proposes that interdisciplinary collaboration, streamlined data access, and targeted training can substantially improve system usability, thereby offering both theoretical insights and practical guidance for optimizing digital forensics in judicial practice.