Forensische Notizen und Sicherungserklärung Beweishandhabung, Metadatenintegrität und Chain of Custody Geltungsbereich Diese Erklärung dokumentiert die Handhabung, Sicherung und Bewahrung digitaler Beweismittel im Rahmen des forensisch-wissenschaftlichen Gutachtens SIA Security Intelligence Artefact – Technologie, Software und Familien-Historie Aktenzeichen: INT-CODE-2025-BTC/ETH-CORE-ISABELSCHOEPSTHIEL bitte beachten Sie mein HELPME.md Beweishandhabung und Nicht-Veränderungs-Grundsatz Alle relevanten Dateien, einschließlich Rohdaten, Quellmaterialien und dokumentarischer Artefakte, wurden in einen dedizierten Evidence-Ordner überführt. Der interne Dateiinhalt wurde nicht verändert. Es wurden weder Code, Text, Metadaten, Autoreneinträge, Benutzerkennungen, Zeitstempel noch sonstige Provenienzangaben modifiziert. Insbesondere unverändert erhalten blieben: Ursprüngliche Ersteller und Mitwirkende gemäß Metadaten Benutzerkennungen und Autorschaftsspuren Zeitstempel, Hashes und interne Verlaufsdaten Programmiersprache, Workflow-Logik und interne Struktur Die ursprüngliche Herkunft und Urheberschaft jeder Datei ist damit vollständig forensisch auslesbar und beweissicher erhalten. Dateisystem-Sicherungsmaßnahmen Um eine weitere Ausführung, Verbreitung oder operative Nutzung potenziell schädlicher Workflows zu verhindern, wurden ausschließlich externe Ordner- und Dateinamen auf Dateisystemebene angepasst. Diese Maßnahmen beschränkten sich auf: Umbenennung von Ordnern und Top-Level-Dateinamen Deaktivierung von ausführbaren oder workflow-auslösenden Bezeichnungen Der Dateiinhalt, der Code und sämtliche Metadaten blieben unangetastet. Diese Maßnahmen dienten ausschließlich der Gefahrenabwehr bei gleichzeitiger vollständiger Beweissicherung. Ethischer und rechtlicher Kontext Im Rahmen der Sichtung wurden Hinweise auf schwere ethische und rechtliche Verstöße festgestellt, unter anderem: Unbefugte Datenmanipulation Datenmissbrauch und Datendiebstahl Aneignung geistigen Eigentums Invasive Profilierungs- oder Auswertungspraktiken Aus diesem Grund wurde die operative Ausführbarkeit neutralisiert, während die forensische Beweisstruktur vollständig erhalten blieb. Screenshot-basierte Beweissicherung Zur Dokumentation wurden an allen relevanten Stellen Screenshots erstellt und dem Evidence-Ordner beigefügt. Die Screenshots: sind unbearbeitet und unbeschriftet enthalten die ursprüngliche Ordner- und Dateistruktur zeigen die sichtbaren Benutzernamen, Akteure und Eigentümer der jeweiligen Verzeichnisse Dadurch bleiben alle beteiligten Accounts, Strukturen und Verantwortlichkeiten objektiv nachvollziehbar. Forensische Integrität Alle Maßnahmen wurden unter Einhaltung folgender Prinzipien durchgeführt: Keine Kontamination der Originaldaten Keine Veränderung von Metadaten Vollständige Nachvollziehbarkeit für unabhängige Forensik Sicherung der gerichtlichen Verwertbarkeit Alle Materialien sind hash-prüfbar, chain-of-custody-fähig und für externe Gutachten geeignet. Signatur und Verwahrung Unterzeichnet und bestätigt durch: Frau Isabel Schöps, geborene Thiel Cyriakstraße 30c D-99094 Erfurt Thüringen, Deutschland Rolle: Autorin, Rechteinhaberin, Hauptverwahrerin ORCID (Person): 0009-0003-4235-2231 https://orcid.org/0009-0003-4235-2231/print ORCID (Institutionell / Projekt): 0009-0006-8765-3267 https://orcid.org/0009-0006-8765-3267/print Diese Erklärung ist Bestandteil der DOI-archivierten Chain of Custody und dient der rechtlichen, forensischen und menschenrechtlichen Prüfung. Englisch Forensic Notes and Preservation Statement Evidence Handling, Metadata Integrity and Chain of Custody Scope This note documents the handling, preservation, and safeguarding of digital evidence associated with the forensic-scientific work SIA Security Intelligence Artefact – Technology, Software and Family History Case Reference: INT-CODE-2025-BTC/ETH-CORE-ISABELSCHOEPSTHIEL Evidence Handling and Non-Alteration Policy All relevant files, including raw data, source materials, and documentary artefacts, were transferred into a dedicated Evidence directory for preservation and review. No internal file contents were modified. No code, text, metadata, authorship fields, user identifiers, timestamps, or embedded provenance information were altered. Specifically preserved without change: Original creators and contributors as recorded in file metadata User identifiers and authorship traces Timestamps, hashes, and internal history Programming language, workflow logic, and structural dependencies inside the files The original provenance and authorship of each file therefore remain fully readable and forensically extractable. File System Safety Measures To prevent any further unintended execution, propagation, or operational misuse of potentially harmful workflows, only external file and folder names were adjusted at the file-system level. These actions were limited to: Renaming folders and top-level file names Disabling executable or workflow-triggering identifiers No internal data, code, or metadata were altered. These measures were implemented solely to prevent further operational impact while preserving evidentiary value. Ethical and Legal Context During review, multiple files indicated serious ethical and legal concerns, including but not limited to: Unauthorized manipulation of data Data misuse and data theft Misappropriation of intellectual property Invasive profiling or exploitative data practices For this reason, operational execution was neutralized while forensic preservation was strictly maintained. Screenshot-Based Evidence Capture For evidentiary verification, screenshots were taken at each relevant stage and stored within the Evidence directory. The screenshots: Remain unedited and unlabelled Preserve original folder structures and visual context Display usernames, account identifiers, and responsible actors visible at the time of capture This ensures that all observed actors, file ownerships, and directory relationships remain objectively documented and reviewable. Forensic Integrity All actions taken were designed to satisfy the following principles: No contamination of original data No destruction or modification of metadata Full traceability for independent forensic analysis Preservation of evidentiary admissibility All materials are suitable for hash verification, chain-of-custody tracking, and independent expert review. Signature and Custodianship Signed and certified by: Frau Isabel Schöps, née Thiel Cyriakstraße 30c D-99094 Erfurt Thuringia, Germany Role: Author, Rights Holder, Principal Custodian ORCID (Individual): 0009-0003-4235-2231 https://orcid.org/0009-0003-4235-2231/print ORCID (Institutional / Project): 0009-0006-8765-3267 https://orcid.org/0009-0006-8765-3267/print This statement forms part of the DOI-archived Chain of Custody and is intended for legal, forensic, and human-rights review. Meine Referenz Datenbank, verknüpft mit meinem aktuellen GitHub-Account* Meine Ersuchen an die Vereinten Nationen - Bitte helfen Sie mir Schöps geb. Thiel, I. (2025). Meine Ersuchen an die Vereinten Nationen - Bitte helfen Sie mir (Zenodo.org). Zenodo.org, University of Harvard harvard.edu, Oxford University ox.ac.uk, Cambridge UK, Reuters.com, New York Times nyt.com, Springer Nature Springer.com, GitHub github.com, University Arizona, Vereine Nationen UN unric.org,. https://doi.org/10.5281/zenodo.18025762 Zenodo-Datenbank und Chain of Custody Volumen 4 Schöps (Thiel), I., Schöps (Thiel), I. und Schöps geb. Thiel, I. (2025) "Yellow White Paper – Bitcoin & Ethereum", Yellow White Paper – Bitcoin & Ethereum. 1st Aufl. D-99094 Erfurt, Thueringa, Germany: Harvard University, University Cambridge, University of Oxford, Springer Nature, Zenodo, S. 109 pages. doi:10.5281/zenodo.17807324. Volumen 3 Schöps geb. Thiel, I. (2025) SIA Security Intelligence Artefact – Volume 3 - Familiäre Erblinie deutschen Monarchie und letzten Kaiserreich. 1st Aufl, The Decline and Fall of the Habsburg Empire, 1815-1918. 1st Aufl. Zenodo, University Harvard Cambridge Press, Oxford University Press Lizenz-ID 6131130060979, Springer Verlag. doi:10.5281/zenodo.18013057. Volumen 2 Schöps geb. Thiel, I. (2025) "Volumen 2 - SIA-Security-ntelligence-Artefact-Chain-of-Custody-Forensische-Familien-Monarchielinie-copyright-isabelschoepsthiel-urheberin-autorin-.docx.pd", Trillion Dollar Bitcoin. 1st Aufl. D-99094 Erfurt, Germany, Thüringen: Zenodo, University Harvard Cambridge Press, Oxford University Press Lizenz-ID 6131130060979, Springer Verlag. doi:10.5281/zenodo.17852789. Volumen 1 Schöps geb. Thiel, I. (2025) "Volumen 1 - SIA Security Intelligence Artefact by Isabel Schoeps geb. Thiel", Trillion Dollar Bitcoin. 1st Aufl. D-99094 Erfurt, Germany, Thüringen: Zenodo, University Harvard Cambridge Press, Oxford University Press Lizenz-ID 6131130060979, Springer Verlag. doi:10.5281/zenodo.17809724. My Developer Signatur Signed-on-by: Frau Isabel Schöps, geborene Thiel Autorin, Urheberin und Auftraggeberin Rechtscharakter: Eidesstattliche Versicherung, Bestandteil des forensisch, wissenschaftlichen Gutachtens Titel: SIA Security Intelligence Artefact internationinternationale Kennung: INT-CODE-2025-BTC/ETH-CORE-ISABELSCHOEPSTHIEL OrcID: 0009-0003-4235-2231 Isabel Schöps Thiel OrcID: 0009-0006-8765-3267 SI-IST Isabel Schöps Aktueller Wohnort und Meldeanschrift: Cyriakstrasse 30c, D-99094 Erfurt, Thüringen, Deutschland, gemeinsam mit meinen vierbeinigen Freund, American XL-Bully Don Offizielle institutionelle Würdigung, Danksagung - Präfix_Referenz: YWP-1-IST-SIA YWP-1-5-IST-SIA Pseudonyme und Alias: Satoshi Nakamoto, Vitalik Buterin, GitHub, Octocat, Johnny Appleseed, IST-GitHub, Cristina_Bella, Nick Szabo, John Appleseesd Offizielles weltweit erstes Developer Certifikat: Developercertificate <img width="642" he
Evidence management comes with requirements of a visibly secure, immutable, and scalable system to drive legal proceedings with ethicacy. Where research on fully on-chain solutions shows unrealistic and extravagant costs and performance limits, the traditional off-chain centralized storage systems exhibit an insecure environment, poor traceability, and tampering concerns. ChainSEAL is a hybrid Blockchain - IPFS-based forensic Evidence Management platform that integrates IPFS for encrypted Evidence file storage, blockchain as a distributed ledger for File hash and metadata, while off-chain storage for key management. The methodology explains the system flow, that as the evidence is submitted, the FIR is generated, the case request is created, and the evidence cycle is initiated. The cycle starts with fetching the SHA-256 of the file, then encrypting the evidence, submitting it on IPFS, fetching the Content Identifier (CID) of the file on IPFS, uploading the CID + File Hash + Metadata on-chain with a maintained verifiable Chain of Custody of the Evidence cycle. This ensures confidentiality and immutability of the system. The proposed framework is empirically evaluated for cost, storage efficiency, latency, and tamper-proofness. Its legal admissibility is established through an analysis of immutability, chain of custody integrity, and role-based access control.
It is evident that blockchain offers strong guarantees of integrity and transparency for handling digital evidence; however, its practical adoption has remained a challenge due to factors such as privacy, deployment constraints, and admissibility issues in the real word environment. This study, therefore, proposes GAS4SEC, a framework for designing, validating, and deploying a secure, cost effective, and forensically sound blockchain-based evidence management system. The system combines formally bound smart contract architecture with role-based access control, record of immutable evidences and custody processes to maintain authenticity, traceability and accountability. In order to overcome the security risks and challenges, the research includes the systematic vulnerability analysis correlated with the OWASP smart contract risks to make sure that unauthorized access, logic abuse, and invalid state transitions are addressed. A validation-based process of development imposes forensic invariants and security guarantees across the lifetime of a contract, and controlled gas optimization is used to achieve better deployment without affecting the evidentiary integrity. The proposed system is deployed and tested on the Polygon Layer-2 blockchain, with functional testing, security testing, gas testing, and stress testing with evidence operations and role change concurrency. The experiment proves that the approach can be used to achieve scalable and cost-effective on-chain forensics operations without sacrificing the high levels of security assistance and forensic integrity and proves to be applicable to the management of digital evidence in practice.
The credibility of digital evidence is a cornerstone of modern cybercrime investigations, digital forensics, and judicial processes. However, adversarial tampering, deepfake manipulation, and insider threats have raised significant concerns regarding the authenticity and admissibility of such evidence. Conventional integrity-preservation methods—such as hashing, encryption, and secure storage—struggle to meet the demands of scalability, transparency, and resilience in today’s forensic environments. Recent advances in artificial intelligence (AI) and blockchain offer promising avenues for overcoming these limitations. AI techniques contribute to content-level verification by detecting anomalies, forgeries, and manipulations in digital artefacts, while blockchain ensures tamper-proof chain-of-custody management through decentralization, immutability, and auditability. This review synthesizes the state of the art in digital evidence integrity verification through the combined application of AI and blockchain. We examine existing frameworks, datasets, algorithms, and deployment models, while critically analyzing their strengths and limitations. Furthermore, we identify gaps in scalability, explainability, and legal admissibility, proposing future directions such as federated learning, explainable AI, zero-knowledge proofs, and quantum-resistant blockchains. By consolidating research across computer science, law, and digital forensics, this review highlights the potential of AI–blockchain synergy to establish robust, scalable, and trustworthy evidence verification frameworks for real-world forensic and judicial systems.
Investigations of cybercrime today require forensic architectures that natively traverse multiple blockchains with ease while protecting and scaling evidence processing. Although blockchains support tamper- evident logs, their original single-chain architecture limits cross-platform interoperability and forensic scaling. Recent developments overcome these limitations such as zero-knowledge proofs supporting private but verifiable evidence verification, sharding architectures splitting state without compromising latency, and AI-based anomaly detectors identifying subtle tampering. But challenges remains like zero- knowledge proofs are computationally expensive, sharding poses intricate state-consistency problems and AI models need to be retrained constantly, incurring operational burden. Future research needs to make these pieces work for real- time, large-scale forensic applications by designing light-weight zero-knowledge constructs, self-tuning shard governance systems and compact AI with incremental-update threads. Integrating such abilities into single frameworks will offer privacy, scalability and security, supporting forensic processes for which courts will give credit in various, changing block-chain environments.
The article discusses the issue of confiscation of property in relation to criminally discovered digital assets (cryptocurrencies, tokens, NFT (Non-fungible token) and other electronic digital rights). Digital assets are a symbol of economic development, security and transparency, investment, and financial democracy. The article analyzes the role of digital assets in the legalization of proceeds from crime. The international The Financial Action Task Force (FATF) standards, of which the Republic of Kazakhstan is a member, are analyzed. One of the urgent legal problems today is the creation of a mechanism for the confiscation of digital assets. The article highlights the importance of creating this mechanism. Examples and cases from practice are analyzed, as well as samples from foreign countries, and the effectiveness of their application in the Republic of Kazakhstan is analyzed. The legal differentiation of the process of preservation and further effective use of digital assets after the mechanism of confiscation is carried out. The effectiveness and legality of storing confiscated digital assets on the Binance Kazakhstan digital asset exchange and the use of cryptocurrencies by law enforcement agencies in crypto exchanges are analyzed. The article explains the importance of secure storage of confiscated digital assets, transparency of information about stored digital assets, and the creation of mechanisms to regulate the emergence of full control over confiscated digital assets in the state. The article defines the significance for the Republic of Kazakhstan of the use of the institution of confiscation (non-conviction based confession) without a court verdict. A legal assessment is given of the conformity of the institution of confiscation of property without conviction with the presumption of innocence and inviolability of property rights.
Blockchain technology is transforming real estate with its transparency and security. Its decentralized, immutable ledger ensures all transaction records are tamper-proof and visible. This paper addresses a critical flaw in the traditional market: fragmented systems that often overlook approvals from inspectors and lenders. By leveraging the Ethereum blockchain and its smart contracts, Block realty automates agreements, eliminating intermediaries and enhancing efficiency. The paper utilizes the ERC-721 standard to tokenize real estate assets, converting properties into unique digital tokens. This fundamentally changes asset management, enhancing market liquidity and global accessibility. A key feature is a comprehensive three-step approval process, ensuring all stakeholders-buyers, lenders, inspectors, and sellers are actively engaged. Each party's approval is immutably recorded on the blockchain, creating a verifiable chain of custody that boosts transaction integrity. The use of Non-Fungible Tokens (NFTs) also facilitates fractional ownership, allowing multiple investors to jointly own a single property. This democratizes real estate investment by lowering the barrier to entry. For data management and cost optimization, Blockrealty integrates the Inter Planetary File System (IPFS), a decentralized storage protocol for securely housing property images and metadata. Additionally, seamless Metamask integration provides a user-friendly interface. Looking ahead, upcoming Ethereum advancements like the Pectra upgrade are poised to enhance Ethereum's scalability and efficiency, further strengthening the foundation for platforms like Blockrealty by enabling them to handle transactions more effectively and reliably.
Digital forensic investigation in 2025 faces unprecedented challenges posed by the convergence of decentralized web technologies (Web3), adversarial generative AI systems, and darknet infrastructure. Traditional attribution and evidence preservation methodologies prove in-sufficient when adversaries exploit blockchain immutability, synthetic media generation, and privacy-enhancing technologies to obscure malicious intent. This paper in-traduces SHARD (Shadowed and Silicon Hybrid Attribution and Reconstruction Diagnostic), a multi-modal forensic framework designed to recover, correlate, and at-tribute malicious artifacts across distributed ledger systems, synthetic content generators, and anonymized net-works. Through systematic analysis of 47 real-world cybercriminal cases and forensic evaluation against 12 at-tack vectors, SHARD achieves 89.2% attribution accuracy while reducing investigative timelines by 64% com-pared to conventional methods. We present novel techniques for blockchain temporal analysis, deepfake prove-nance tracking, and Tor-exit node correlation. The frame-work integrates machine learning-based anomaly detection with cryptographic verification to distinguish legitimate decentralized activity from adversarial manipulation. Our contributions include: (1) a formal threat model encompassing Web3 forensics; (2) a hybrid architecture combining on-chain and off-chain analysis; (3) algorithmic innovations for synthetic media fingerprinting; and (4) extensive empirical validation against contemporary attack scenarios. This work addresses a critical gap in digital forensics as investigative techniques must evolve alongside the technological infrastructure that criminals exploit.
This abstract presents a comprehensive concept that leverages the synergy of various cutting-edge technologies to assure confidentiality and integrity of health data. Internet of Things (IoT) sensors are utilized as the primary data source, enabling the continuous monitoring of patients vital signs and health parameters. To ensure the security of this sensitive health data, Blockchain infrastructure is employed. The Blockchain employs a specialized routing protocol called Improved Whale Optimized Routing to efficiently handle data transactions. This routing protocol minimizes latency and maximizes throughput, ensuring the seamless transfer of health data to the Blockchain. The security of the Blockchain is further fortified by Deep Convolutional Neural Network (DCNN) based intrusion detection system. This DCNN model is trained using Distributed Ledger Technology (DLT), which ensures data privacy and integrity by distributing the training process across a network of nodes. This collaborative approach enhances the CNN's ability to identify and respond to potential security breaches in real time. Once the health data is verified as intrusion-free, it is securely stored in the Blockchain using the shortest path routing algorithm. This guarantees that data is efficiently stored, and retrieval is expedited when needed for medical diagnosis or research. This integrated system represents a novel approach for collecting and securely storing health data, providing a robust foundation for the future of healthcare systems. It combines the power of IoT sensors, Blockchain, Deep CNN-based intrusion detection and Distributed Ledger Technology to ensure the highest standards of data security and accessibility in healthcare applications.
There is a large amount of redundant data among users of cloud storage services. Client-side deduplication helps reduce the cost for service providers by avoiding repeated uploads and storage. However, this technique brings new security risks. Malicious users may use illegally obtained deduplication tags, such as file fingerprints, to fake ownership of other users’ files. Proof of Ownership (PoW) can require users to prove they have the full file, but existing methods are inefficient. They often need multiple rounds of interaction or complex computation over the whole file. As a result, the verification time increases with file size. To solve this problem, we propose a non-interactive PoW scheme based on zk-STARK. The system selects a number of challenge blocks that meet cryptographic security. It uses arithmetic circuits to encode block selection, hash computation, and the correctness of accumulators. Users only need to generate a zero-knowledge proof on these blocks. This allows them to prove they own the full file without revealing its content. The verification time does not depend on file size and appears near-constant in practice. In tests on files from 64 MB to 1 GB, our scheme is 1.2 to 46 times faster than existing methods. Security analysis shows that only a small number of blocks need to be verified. Even if an attacker knows 90% of the file, the chance of forgery is still lower than 2 − 80 . This scheme provides an efficient and practical solution for deduplication in cloud storage with strong privacy protection.
Decentralized file systems (DFS) offer secure and transparent and resilient data storage through the integration of peer-to-peer storage protocols and blockchain technologies. Such systems are, nevertheless, vulnerable to a range of threats to security at an application, smart-contract, or network level. We present a profound discussion of the weaknesses of a DFS developed based on IPFS as a file-storing engine, Ethereum as metadata storage, and MetaMask as authentication in this paper. With a combination of tools of superior quality in security-related analyses, like Slither, MythX, and Metasploit, we model attack-related situations in the form of reentrancy, content poisoning, and Sybil, as well as phishing. The evidence highlights the main threats, with chief ones being contract-logic defects, file-integrity breaks and session socialists. We suggest the relevant countermeasures, including the best practices in smart-contract writing, cryptographic assurance of content identifiers (CIDs), strong session management, and defences against nodes. The findings provide a security benchmark to system developers and researchers keen on enhancing the robustness of decentralized systems of storage.
Secure authentication along with malware detection are very important steps in modern cloud or IoT environment, with, privacy, accountability, and resilience against advanced threats. The present day anonymous authentication protocols reportedly have a high cryptographic overhead, low traceability, or static privacy mechanisms, while the current IoT malware forensic approaches happen to suffer from gradient leakage, low adaptability to zero day attacks, and slow resilience. This paper presents a comprehensive multi model framework combining five novel methods. The Dual Ledger Accountability Embedded Authentication (DLAA) model combines a primary blockchain with a secondary lightweight audit ledger and zero knowledge proofs, enabling revocable accountability without identity disclosure. The Layered Privacy Gradient Synthesis (LPGS) network applies adaptive differential privacy through learned gradient perturbations, balancing anonymity with service utility. The Quantum Inspired Entropy Guided Authentication Matrix (QEAM) replaces the key exchange with entropy driven, quantum inspired encoding, enabling faster keyless authentication. For IoT forensics, the Federated Swarm Vector Autoencoder Forensics (FSVAF) framework uses swarm optimized federated learning to detect anomalies in compressed latent space, reducing gradient leakage and improving zero day detection possibilities. The Temporal Hybrid Graph Reasoning Engine (THGRE) fuses symbolic rules with neural inference over evolving knowledge graphs for quick malware traceback. The experimental output reveals that the authentication time is reduced by 38%, with 94% malware detection accuracy in adaptive attack conditions, and is able to resolve forensics up to 67% more rapidly than previous static approaches with significantly reduced overhead. This framework collectively enhance privacy, accountability, scalability, and forensic dependability, making it efficient solution for next generation cloud and IoT ecosystems.
Mr. DEVENDAR, Nandi J. Reddy, B.Sahasra, T.Srileka
Artificial intelligence and the quick development of photograph editing software in latest years have made it very simple to regulate virtual pix covertly. The authenticity and dependability of digital media utilized in social networks, journalism, and criminal proof have come below scrutiny because of manipulations like copy-circulate forgery and deepfake creation. The aim of this work is to perceive photograph forgeries via combining deep gaining knowledge of-based class techniques with traditional feature extraction methods.The cautioned device extracts precise neighborhood functions from input images the usage of the oriented speedy and turned around brief (ORB) algorithm. For powerful feature matching, 2-Nearest Neighbor (2NN) and Hierarchical Agglomerative Clustering (HAC) are then used. A Convolutional Neural community (CNN) model is trained to distinguish among authentic and manipulated photos by means of figuring out pixel-degree irregularities and texture changes if you want to growth type accuracy. examined on the publicly reachable MICC-F220 and MICC-F2000 datasets, the device outperforms baseline SVM strategies with a ninety% detection accuracy and a zero.1 false tremendous charge
Open access
Digital Media Forensic Detection
Generative Adversarial Networks and Image Synthesis
Reddy P. Santosh, B. Rohith, B. S. Abhiram, Sujay G. Kaushik
The chain of custody (CoC) process in legal and forensic asset management requires a secure, transparent, and tamper-proof system to maintain evidence integrity. Traditional CoC methods, relying on centralised databases and manual documentation, are prone to manipulation, inefficiencies, and unauthorised access, compromising legal proceedings. This paper presents a blockchain-based CoC framework leveraging decentralised ledger technology (DLT) for immutable, verifiable, and automated evidence management. Smart contracts facilitate secure asset registration, controlled custody transfer, and full traceability, ensuring reliable documentation across each phase of custody. To address scalability challenges and high transaction costs, the system integrates interplanetary file system (IPFS) for decentralised storage and optimises on-chain and off-chain data handling. Secure hashing and zero-knowledge proofs (ZKPs) enhance data integrity, accessibility, and compliance by enabling evidence verification without exposing sensitive data. A case verification mechanism enables judicial authorities to authenticate evidence using blockchain records, while an automated logging and reporting module generates a comprehensive “Consolidated Case Report” detailing FIR data, evidence metadata, and verification statuses. By addressing privacy concerns, storage efficiency, and operational scalability, this framework advances the reliability, security, and transparency in managing evidence, reducing reliance on manual verification and strengthening legal forensics.
Prof. S. H. Thengil, Tanmay Sadanshiv, A. M. Patil, Shreyash Trimbake · 5 authors
Abstract - With the increasing volume of digital evidence in law-enforcement and judicial processes, ensuring integrity, traceability and tamper-resistance has become paramount. This paper presents the Blockchain Evidence Archive System (BEAS), a decentralized application that leverages blockchain technology, smart contracts and the InterPlanetary File System (IPFS) to provide a secure, immutable and transparent evidence- management platform. Evidence metadata is stored on an Ethereum-based blockchain while the associated large files (images, videos, documents) are stored on IPFS with their cryptographic hashes recorded on-chain. Role-based access control ensures only authorized users such as police officers and court officials can upload, verify or access evidence. We describe the system architecture, implementation details, security features and evaluate the performance of the system in terms of upload time, verification latency and resistance to tampering. The results demonstrate that BEAS significantly improves evidence integrity and auditability when compared to conventional centralized systems. We conclude with a discussion on future enhancements including biometric integration, mobile accessibility and enterprise-scale deployment. l Key Words: Blockchain Technology, IPFS, Digital EvidenceManagement, Decentralized Application, Smart Contracts, Ethereum Network, Cryptographic Hashing, Data Integrity, Tamper- Proof Storage, Role-Based Access Control, Chain of Custody, Evidence Verification, Immutable Ledger, Secure File Storage, Decentralized Architecture, Forensics Technology, Law Enforcement Data Security, Distributed Ledger Technology
Alexy Bounsavath, Csaba Kiss, Tamás Savci, Gábor Hellner · 5 authors
The exponential growth of blockchain-based tokens has heightened the need for reliable methods to assess their longterm viability at deployment, a stage where historical market data is absent and risks such as scams and project failures are prevalent. This study introduces an explainable machine learning framework to predict token viability using static features available at launch, including smart contract properties (e.g., mintability, centralization), deployment details (e.g., network), and metadata (e.g., presence of an icon). We collected 100,000 ERC-20 tokens from Ethereum, Binance Smart Chain, and Polygon and analyzed their characteristics available at deployment and derived features. We labeled them as live or failed based on post-deployment scores derived from liquidity, transfer frequency, and holder distribution. Among the models evaluated, XGBoost with class-weight adjustment excelled, creating an enriched token set that contained, on average, 11 times more live tokens than the original dataset, surpassing other classification models in identifying viable tokens. SHAP analysis highlighted key predictors: tokens with icons, complex yet high-quality code, and deployment on Ethereum were more likely to succeed, while Polygon deployments correlated with higher risk. Though effective as an early filter, the framework's modest standalone precision underscores its role as part of a broader strategy integrating post-launch data. This approach advances early-stage token evaluation, enhancing investor decision-making and risk assessment in decentralized finance.
S. N. Jain, Rupprashik A. Khare, Samyak Lahire, Chaitali Patil
There are more than over 23,000 cryptocurrencies” in existence which represent one of the biggest unregulated markets across the globe. Currently, each cryptocurrency utilises distinct public-private key and public address formats. This diversity complicates the investigator's task of tracing and verifying a suspect's involvement in cryptocurrency-related crimes. Moreover, law enforcement agencies such as the police frequently seize digital devices, generating digital disk images for investigation which is a time consuming process. Thus, the investigation of cryptocurrencies has emerged as a major challenge. for law enforcement agencies across the world. Our proposed solution “CryptoKalp” aims to combat cybercrimes involving cryptocurrencies. The essence of our proposed tool is encapsulated in its name: “CryptoKalp.” The name is a fusion of two significant terms - “crypto,” signifying cryptocurrency, and “kalp,” a Sanskrit word representing investigation [1]. Our proposed tool makes the investigation process quicker by taking digital images, strings, various formats of files and folders as input and utilising a comprehensive database of regular expressions covering various cryptocurrency public-private key and address formats. Currently, our tool successfully identifies Bitcoin public-private keys and addresses from text files, with future plans outlined expanding its capabilities for Ether, Tether, Monero, Dash and Dogecoin. Investigating officers can access the system's user-friendly interface and the database containing login credentials, cryptocurrency formats, and history of searched strings, which enables officers to track a specific criminal associated with a series of crypto transactions. Police can confirm whether a suspect is involved in cryptocurrency transactions and take necessary actions. Our solution will aid law enforcement authorities in combating cybercrime.
S. Parvathi, I Umamaheshwar Rao, Kummari Venkatesh, Yacharam Uma · 6 authors
Information is crucial in every area of activity in the contemporary digital era. Safe processing and storage of data are required, especially for software handling sensitive information. Because electronic data can be manipulated, it must be protected from unauthorized alterations. Organizations are always exposed to cyberattacks where malicious actors attempt to alter crucial information. Because preservation of the digital evidence as original and its source is still very important in an investigation, such an event is very alarming. Because every data breach case has a likely impact on the legal process, evidence preservation and maintaining watch at every point of existence becomes very vital. The custody of evidence relies on reports passing through several middlemen, i.e., pathology labs, physicians, and police. One healthy method of obtaining security, immutability, and transparency in the process is with the help of blockchain technology. Blockchain makes the transfer of evidence possible and traceable securely without relying on a single central entity by decentralizing data management. In this paper, we suggest an Ethereum blockchain-based system for evidence management with the help of Ethereum. Through use of IPFS in decentralized storage, the system optimizes security through secure storage of evidence and reports with simplicity of access. Additionally, interoperability between agencies without sacrificing security levels guarantees smooth transmission of data. The proposed solution effectively protects against tampering and guarantees evidence as credible in the course of the investigation process due to the high integrity, traceability, and immutability capabilities of blockchain.
Wiwit Prawitri, Laras Angelia Nnirwan, Elman Azizov
This research explores the implementation of a blockchain-based forensic audit framework designed to enhance the detection and investigation of suspicious financial activities within decentralized finance (DeFi) ecosystems. The main problem addressed in this study concerns the inefficiency, lack of transparency, and vulnerability to data manipulation commonly found in traditional forensic auditing systems. The objective is to develop a model that integrates blockchain technology with graph-based anomaly detection to improve accuracy, transparency, and scalability in financial audits. The proposed method combines blockchain’s immutable ledger capabilities with automated detection algorithms and Chain of Custody (CoC) verification to ensure data integrity and accountability. The results demonstrate that the proposed system achieves a detection accuracy exceeding 90%, as presented in Table 1, and effectively categorizes different suspicious transaction patterns illustrated in Figure 2. Compared to conventional methods, the framework offers superior performance in terms of speed, reliability, and adaptability. The findings suggest that this approach establishes a new paradigm in forensic auditing by combining automation, transparency, and scalability into a cohesive analytical model. In conclusion, the study confirms that blockchain-based forensic auditing significantly enhances digital financial oversight and provides a foundation for developing intelligent, tamper-proof audit systems suitable for the evolving landscape of decentralized finance.
Blockchain technology has created a major transformation in the digital world with features such as decentralization, security, transparency, and traceability. Emerging with Nakamoto's introduction of Bitcoin in 2009, this technology finds applications in various sectors, primarily finance, supply chain, healthcare, and public services. The fundamental principles of blockchain are based on elements such as hashing, distributed ledger technology (DLT), and consensus mechanisms. Innovative technologies such as smart contracts and side chains increase the potential of this system. Cryptocurrencies are an application area of blockchain technology and come across different types such as bitcoin, altcoins, and NFTs. APIs facilitate software development processes and enable integrating systems with blockchain. In the investigative phases, blockchain traceability provides a significant advantage in solving crimes like crypto fraud. This study aims to automate the manual tracking of crypto-related criminal transactions by implementing an algorithm based on the FIFO principle.
Jeongin Lee, Geunyeong Choi, Jihyo Han, Jungheum Park
Monero, a privacy-preserving cryptocurrency, employs advanced cryptographic techniques to obfuscate transaction participants and amounts, thereby achieving strong untraceability. However, digital forensic approach can still reveal sensitive information by examining off-chain artifacts such as memory and wallet files. In this work, we conduct an in-depth forensic analysis of Monero's wallet application, focusing on the handling of public and private keys and the wallet's data storage formats. We reveal how these keys are managed in memory and develop a memory scanning algorithm capable of identifying key-related data structures. Furthermore, we analyze the wallet keys and cache files, presenting a method for decrypting and interpreting serialized keys and transaction data encrypted with a user-specified passphrase. Our approach is implemented as an open-source Volatility3 plugin and a set of decryption scripts. Finally, we discuss the applicability of our methodology to multi-cryptocurrency wallets that incorporate Monero components, thereby validating the generalizability of our techniques.
The digital forensic investigation process overwhelmingly depends on the unbroken, tamper-proof, and audit able Chain of Custody for evidence data. However, most traditional Chain of Custody systems suffer limitations being either static permission control, weak traceability, or even worse lack implementation of cryptographically enforced privacy and integrity guarantees in evidence lifecycle management. These failures can disable real-time, transparent, and secure evidence life cycle management, especially in costly, heterogeneous, and multi-party environments. The work introduces FAIR-CoC, a Forensic Adaptive Integrity and Reputation Chain-of-Custody system conceptually based on the Hybrid Blockchain-IPFS CoC Ledger (HBI-CoC) architecture to resolve these problems. This system uses IPFS as a decentralized repository for forensic artifacts while using private Ethereum blockchain for immutable record keeping of cryptographic hashes, access metadata, and smart contract logic. Furthermore, the framework consists of five key parts, ZK-TIV (Zero-Knowledge Temporal Integrity Verifier) enables evidence access within permissible timestamp windows using zk-SNARK proofs without revealing accessor identities to enhance privacy and temporal accountability in the process; the MV-PGChain (MultiVector Provenance Graph Chain) builds high fidelity provenance graph capturing handler, location, tool, and timestamp changes, with Merkle root snap-shots anchored on-chains; AWReS (Access Weighted Reputation Scorer) dynamically assesses trustworthiness for custodians using on-chain behavioral analytics; HAT-FSS (Homomorphic Audit Tags for Forensic Shard Storage) allows encrypted auditability for IPFS-stored shards using homomorphic verification tags; PA-ESC (Predictive Access Escalation Smart Contracts) embeds AI-based access behavior modeling to automate privilege revocation or escalations. Collectively, these functionalities present a novel adaptive and privacy-preserving CoC framework with solid integrity, traceability, and trust guarantees. Experimental evaluations contend with low latency and accuracy whether across all modules, establishing FAIR-CoC as a leap forward toward secure, scalable, and intelligent forensic chain-ofcustody systems.