Improving Cybercrime Detection and Digital Forensics Investigations with Artificial Intelligence
Silvia Lucia Sanna, Leonardo Regano, Davide Maiorca, Giorgio Giacinto
TL;DR
The paper addresses the challenge of augmenting cybercrime detection and digital forensics with artificial intelligence in the face of rising cybercrime in Europe. It surveys existing detection and DF workflows, arguing that AI—including generative AI and large language models—can enhance data augmentation, reasoning, and interactive engagement with criminals, all under a human-in-the-loop and with strong privacy safeguards. It outlines AI-enabled DF pipelines across collection, examination, analysis, and reporting, and discusses the handling of genAI data, including attribution and anti-forensics, with calls for explainable AI to justify decisions. A case study using Gemini, Copilot, and chatGPT demonstrates both the dual-use risks of steganography techniques and the potential for AI-assisted tooling, underscoring the need for ad hoc tools, standards, and ongoing governance to safely deploy AI in cybercrime detection and DF.
Abstract
According to a recent EUROPOL report, cybercrime is still recurrent in Europe, and different activities and countermeasures must be taken to limit, prevent, detect, analyze, and fight it. Cybercrime must be prevented with specific measures, tools, and techniques, for example through automated network and malware analysis. Countermeasures against cybercrime can also be improved with proper \df analysis in order to extract data from digital devices trying to retrieve information on the cybercriminals. Indeed, results obtained through a proper \df analysis can be leveraged to train cybercrime detection systems to prevent the success of similar crimes. Nowadays, some systems have started to adopt Artificial Intelligence (AI) algorithms for cyberattack detection and \df analysis improvement. However, AI can be better applied as an additional instrument in these systems to improve the detection and in the \df analysis. For this reason, we highlight how cybercrime analysis and \df procedures can take advantage of AI. On the other hand, cybercriminals can use these systems to improve their skills, bypass automatic detection, and develop advanced attack techniques. The case study we presented highlights how it is possible to integrate the use of the three popular chatbots {\tt Gemini}, {\tt Copilot} and {\tt chatGPT} to develop a Python code to encode and decoded images with steganographic technique, even though their presence is not an indicator of crime, attack or maliciousness but used by a cybercriminal as anti-forensics technique.
