Authors: Ruud Schramp, Jan Gruber
DFRWS APAC 2026
Abstract
Digital forensic examiners typically assess evidential strength informally rather than within the likelihood ratio (LR) framework. The LR framework applies in principle to any digital trace; operational feasibility varies currently by trace class. We systematize thirteen data-driven works that apply the frameworkto traces generated by device or system operation, grouped into three clusters: sensor-derived measurements, mobility-pattern matching, and event-stream matching. We characterize each work by its approach, proposition level, and trace class, and position it on two axes—reference-data engagement and validation maturity—that jointly indicate operational readiness. All thirteen works address variability in trace generation, countering the view that digital traces are purely deterministic. We find four gaps: First, the clusters cover only a fraction of the relevant trace classes; the framework has yet to be applied to IoT sensor measurements, operating-system traces, and high-volume classes such as log data, databases, and caches. Second, similarity score-based methods dominate as a pragmatic response to high-dimensional data but discard typicality information a well-posed LR requires. Third, reference data are rarely adequate: convenience corpora often stand in for casework conditions, and only two works substantively engage the relevant population. Fourth, validation is uneven: six works go no further than reporting discrimination, and none has been validated under casework conditions or externally corroborated. Closing these gaps demands extension to the neglected trace classes, methods that capture typicality, shared reference corpora, and adherence to validation guidelines.