Authors: Jong-in Kim, Dohyun Kim
DFRWS APAC 2026
Abstract
The recent surge in deepfake-enabled digital sexual crimes calls for digital forensic techniques that trace the entire creation-to-distribution process of deepfake content. However, prior work has remained limited to social media user-behavior analysis or deepfake authenticity detection, and no methodology has linked and traced the creation-to-distribution process. This study examines four Android deepfake creation apps and three social media apps, cross-analyzing the artifacts generated in the /data and /sdcard partitions during app use, and proposes a methodology that connects file system metadata and hash values by file identity and temporal order to verify whether creation and distribution occurred. In scenario-based verification, the entire process could be established in the absence of anti-forensic actions, and even when some storage areas were deleted, the verifiable scope from the remaining artifacts was specified. Furthermore, to compensate for cases where hash values are not preserved, visual-similarity verification based on face-recognition models (RetinaFace, ArcFace) was introduced as an auxiliary means. This verification confirmed that same-person candidates could be screened by visual similarity even for files whose hashes had changed. The proposed methodology can serve as an evidence-acquisition framework that establishes a verifiable evidentiary chain for deepfake crimes in real investigative settings.