Skip to content

New AI System Combines Malware and Digital Evidence for Cyber Forensics

By Sourabh
New AI System Combines Malware and Digital Evidence for Cyber Forensics

Researchers have developed a new AI-based cyber-forensics framework designed to combine different types of digital evidence, including malware, memory artifacts, network traffic, malicious scripts and phishing-related audio.

The system, described in a new Scientific Reports paper published October 5, uses multiple AI components to align evidence across time, reconstruct potential attack sequences and generate confidence-aware threat assessments.

In benchmark testing, the framework achieved 99.26% classification accuracy, a 99.20% F1 score and 99.66% AUC. Its performance fell to 95.18% when tested against temporally separated data and 92.34% when evaluated against malware families excluded from training.

The researchers evaluated the system using datasets containing malware samples, network flows, scripts and audio-based phishing or social-engineering artifacts. The complete model contains about 96.3 million parameters and recorded an average inference time of 73.2 milliseconds under the reported test environment.

However, the researchers caution that the results were obtained under controlled benchmark conditions and do not establish definitive real-world attribution or universal forensic performance.

The research points toward a future where forensic investigators could correlate multiple evidence sources through a single AI-assisted analysis pipeline rather than examining each evidence type independently.

Tagsforensics
Share

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.