Research Output
Publications
Peer-reviewed publications, theses, posters, and presentations from the Forensics and Security Research Group.
2026
- Investigation of large language models, GenAI, and proprietary AI systems: Digital forensic evidence, readiness and regulation
Forensic Science International: Digital Investigation Vol. 57 Article 302135
- Plug to place: Indoor multimedia geolocation from electrical sockets for digital investigation
Forensic Science International: Digital Investigation Vol. 56 Article 302056
- AutoDFBench 1.0: A benchmarking framework for digital forensic tool testing and generated code evaluation
Forensic Science International: Digital Investigation Vol. 56 Article 302055
- VAAS: Vision-Attention Anomaly Scoring for image manipulation detection in digital forensics
Forensic Science International: Digital Investigation Vol. 56 Article 302063
- Objects as Universal Geolocation Cues: A Computer Vision Approach
13th Annual Digital Forensics Research Workshop Europe (DFRWS EU 2026)
2025
- Towards a standardized methodology and dataset for evaluating LLM-based digital forensic timeline analysis
Forensic Science International: Digital Investigation Vol. 54S Article 301982
- An AI-Based Network Forensic Readiness Framework for Resource-Constrained Environments
Proceedings of the 18th International Workshop on Digital Forensics, part of the 20th International Conference on Availability, Reliability and Security
- Fine-Tuning Large Language Models for Digital Forensics: Case Study and General Recommendations
ACM Digital Threats: Research and Practice Article 3748264
- AutoDFBench: A Framework for AI Generated Digital Forensic Code and Tool Testing and Evaluation
Digital Forensics Doctoral Symposium
- Low-overhead and Non-invasive Electromagnetic Side-Channel Monitoring for Forensic-ready Industrial Control Systems
Digital Forensics Doctoral Symposium
- Exploring the Potential of Large Language Models for Improving Digital Forensic Investigation Efficiency
Forensic Science International: Digital Investigation Vol. 52 Article 301859
2024
- Context Based Password Cracking Dictionary Expansion Using Generative Pre-trained Transformers
2024 Cyber Research Conference - Ireland (Cyber-RCI)
- Perceptual Colour-based Geolocation of Human Trafficking Images for Digital Forensic Investigation
2024 Cyber Research Conference - Ireland (Cyber-RCI)
- Pushing Network Forensic Readiness to the Edge: A Resource Constrained Artificial Intelligence Based Methodology
2024 Cyber Research Conference - Ireland (Cyber-RCI)
- A Comprehensive Evaluation on the Benefits of Context Based Password Cracking for Digital Forensics
Journal of Information Security and Applications
- A Digital Forensic Methodology for Encryption Key Recovery from Black-Box IoT Devices
Proceedings of the 12th International Symposium on Digital Forensics and Security
- A Framework for Integrated Digital Forensic Investigation Employing AutoGen AI Agents
Proceedings of the 12th International Symposium on Digital Forensics and Security
- DFRWS EU 10-Year Review and Future Directions in Digital Forensic Research
Forensic Science International: Digital Investigation Vol. 48 Article 301685
- Ensuring Cross-Device Portability of Electromagnetic Side-Channel Analysis for Digital Forensics
Forensic Science International: Digital Investigation Vol. 48 Article 301684
- DFPulse: The 2024 digital forensic practitioner survey
Forensic Science International: Digital Investigation Vol. 51 Article 301844
2023
- An Evaluation of AI-Based Network Intrusion Detection in Resource-Constrained Environments
14th Annual IEEE Ubiquitous Computing, Electronics & Mobile Communication Conference (IEEE UEMCON)
- Context-Based Password Cracking for Digital Investigation
School of Computer Science, University College Dublin
- Digital forensic investigation in the age of ChatGPT
Forensic Science International: Digital Investigation Vol. 44 Article 301543
- Harder, Better, Faster, Stronger: Optimising the Performance of Context-Based Password Cracking Dictionaries
Forensic Science International: Digital Investigation Vol. 44S Article 301507
- ChatGPT for digital forensic investigation: The good, the bad, and the unknown
Forensic Science International: Digital Investigation Vol. 46 Article 301609
2022
- Deep Learning Based Network Intrusion Detection System for Resource-Constrained Environments
The 13th EAI International Conference on Digital Forensics and Cyber Crime
- Data Exfiltration through Electromagnetic Covert Channel of Wired Industrial Control Systems
Applied Sciences Vol. 13 Article 2928
- A Novel Dictionary Generation Methodology for Contextual-Based Password Cracking
IEEE Access Vol. 10 pp. 59178-59188
- Security, Ethics and Privacy Issues in Remote Extended Reality for Education
Mixed Reality for Education
2021
- Identifying Internet of Things Software Activities using Deep Learning-based Electromagnetic Side-Channel Analysis
Forensic Science International: Digital Investigation Vol. 39 Article 301308
- PCWQ: A Framework for Evaluating Password Cracking Wordlist Quality
The 12th EAI International Conference on Digital Forensics and Cyber Crime
- How Viable is Password Cracking in Digital Forensic Investigation? Analyzing the Guessability of over 3.9 Billion Real-World Accounts
Forensic Science International: Digital Investigation Vol. 37 Article 301186
- Digital Forensics: Leveraging Deep Learning Techniques in Facial Images to Assist Cybercrime Investigations
School of Computer Science, University College Dublin
- A Comparative Study of Support Vector Machine and Neural Networks for File Type Identification Using n-gram Analysis
Forensic Science International: Digital Investigation
- TraceGen: User Activity Emulation for Digital Forensic Test Image Generation
Forensic Science International: Digital Investigation
- Vec2UAge: Enhancing Underage Age Estimation Performance through Facial Embeddings
Forensic Science International: Digital Investigation
- On Offloading Network Forensic Analytics to Programmable Data Plane Switches
Book Series: World Scientific Series in Digital Forensics and Cybersecurity
2020
- A Survey Exploring Open Source Intelligence for Smarter Password Cracking
Forensic Science International: Digital Investigation Vol. 35 Article 301075
- Alleviating the Digital Forensic Backlog: A Methodology for Automated Digital Evidence Processing
School of Computer Science, University College Dublin
- Electromagnetic Side-Channel Analysis Methods for Digital Forensics on Internet of Things
School of Computer Science, University College Dublin
- Retracing the Flow of the Stream: Investigating Kodi Streaming Services
The 11th EAI International Conference on Digital Forensics and Cyber Crime
- SoK: Exploring the State of the Art and the Future Potential of Artificial Intelligence in Digital Forensic Investigation
The 13th International Workshop on Digital Forensics (WSDF), held at the 15th International Conference on Availability, Reliability and Security (ARES)
- Facilitating Electromagnetic Side-Channel Analysis for IoT Investigation: Evaluating the EMvidence Framework
Forensic Science International: Digital Investigation
- Assessing the Influencing Factors on the Accuracy of Underage Facial Age Estimation
The 6th IEEE International Conference on Cyber Security and Protection of Digital Services (Cyber Security)
- Automated Artefact Relevancy Determination from Artefact Metadata and Associated Timeline Events
The 6th IEEE International Conference on Cyber Security and Protection of Digital Services (Cyber Security)
- Smarter Password Guessing Techniques Leveraging Contextual Information and OSINT
6th IEEE International Conference on Cyber Security and Protection of Digital Services (Cyber Security)
- Cutting through the Emissions: Feature Selection from Electromagnetic Side-Channel Data for Activity Detection
Forensic Science International: Digital Investigation Vol. 32 Article 300927
- DeepUAge: Improving Underage Age Estimation Accuracy to Aid CSEM Investigation
Forensic Science International: Digital Investigation Vol. 32 Article 300921
- EMvidence: A Framework for Digital Evidence Acquisition from IoT Devices through Electromagnetic Side-Channel Analysis
Forensic Science International: Digital Investigation Vol. 32 Article 300907
2019
- Improving Borderline Adulthood Facial Age Estimation through Ensemble Learning
The 8th International Workshop on Cyber Crime (IWCC), held at the 14th International Conference on Availability, Reliability and Security (ARES)
- Methodology for the Automated Metadata-Based Classification of Incriminating Digital Forensic Artefacts
The 12th International Workshop on Digital Forensics (WSDF), held at the 14th International Conference on Availability, Reliability and Security (ARES)
- A Survey of Electromagnetic Side-Channel Attacks and Discussion on their Case-Progressing Potential for Digital Forensics
Digital Investigation Vol. 29 pp. 43-54
- Improving the Accuracy of Automated Facial Age Estimation to Aid CSEM Investigations
Digital Investigation Vol. 28 Article S142
- Solid State Drive Forensics: Where Do We Stand?
Digital Forensics and Cyber Crime pp. 149-164
2018
- Accuracy Enhancement of Electromagnetic Side-channel Attacks on Computer Monitors
The Second International Workshop on Criminal Use of Information Hiding (CUING), part of the 13th International Conference on Availability, Reliability and Security (ARES)
- Cloud Investigations of Illegal IPTV Networks
Proceedings of the 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications (TrustCom-18) pp. 1942-1947
- Deduplicated Disk Image Evidence Acquisition and Forensically-Sound Reconstruction
Proceedings of the 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications (TrustCom-18) pp. 1674-1679
- Enabling the Non-Expert Analysis of Large Volumes of Intercepted Network Traffic
Advances in Digital Forensics XIV pp. 183-197
- Deep Learning at the Shallow End: Malware Classification for Non-Domain Experts
Digital Investigation Vol. 26 pp. S118 - S126
- Digital Forensic Investigation of Two-Way Radio Communication Equipment and Services
Digital Investigation Vol. 26 pp. S77 - S86
- Electromagnetic Side-Channel Attacks: Potential for Progressing Hindered Digital Forensic Analysis
Proceedings of the International Workshop on Speculative Side Channel Analysis (WoSSCA 2018)
- Evaluating Automated Facial Age Estimation Techniques for Digital Forensics
12th International Workshop on Systematic Approaches to Digital Forensics Engineering (SADFE), IEEE Security & Privacy Workshops
- Hierarchical Bloom Filter Trees for Approximate Matching
Journal of Digital Forensics, Security and Law Vol. 13 pp. 81-96
- Expediting MRSH-v2 Approximate Matching with Hierarchical Bloom Filter Trees
Digital Forensics and Cyber Crime. ICDF2C 2017 Vol. 216 pp. 144-157
- Private Web Browser Forensics: A Case Study on Epic Privacy Browser
Journal of Information Warfare Vol. 17
2017
- Data Analytics for Digital Forensics and Cybersecurity
Predict Conference; Europe's Leading Data Conference (Predict 2017)
- Privileged Data within Digital Evidence
Proceedings of the 16th IEEE International Conference On Trust, Security And Privacy In Computing And Communications (TrustCom-17) pp. 737-744
- Evaluation of Digital Forensic Process Models with Respect to Digital Forensics as a Service
Proceedings of the 16th European Conference on Cyber Warfare and Security (ECCWS 2017) pp. 573-581
- Forensic Analysis of Epic Privacy Browser on Windows Operating Systems
Proceedings of the 16th European Conference on Cyber Warfare and Security (ECCWS 2017) pp. 341-350
- Integration of Ether Unpacker into Ragpicker for plugin-based Malware Analysis and Identification
Proceedings of the 16th European Conference on Cyber Warfare and Security (ECCWS 2017) pp. 419-425
- Behavioral Service Graphs: A Formal Data-Driven Approach for Prompt Investigation of Enterprise and Internet-wide Infections
Digital Investigation Vol. 20S pp. 47-55
- EviPlant: An Efficient Digital Forensic Challenge Creation, Manipulation, and Distribution Solution
Digital Investigation Vol. 20S pp. 29-36
2016
- Behavioral Service Graphs: A Big Data Approach for Prompt Investigation of Internet-wide Infections
Proceedings of the IFIP International Workshop on Cybercrime Investigation and Digital Forensics (CID) pp. 1-5
- Towards the Leveraging of Data Deduplication to Break the Disk Acquisition Speed Limit
Proceedings of the IFIP International Workshop on Cybercrime Investigation and Digital Forensics (CID) pp. 1-5
- Battling the Digital Forensic Backlog
Proceedings of the 2nd International Workshop on Cloud Security and Forensics (WCSF 2016) pp. 10-14
- Battling the Digital Forensic Backlog through Data Deduplication
Proceedings of the 6th IEEE International Conference on Innovative Computing Technologies (INTECH 2016)
- IPv6 Security and Forensics
2nd International Workshop on Cloud Security and Forensics (WCSF 2016) pp. 743-748
- An Analytical Approach to the Recovery of Data From 3rd Party Proprietary CCTV File Systems
15th European Conference on Cyber Warfare and Security (ECCWS 2016)
- Current Challenges and Future Research Areas for Digital Forensic Investigation
The 11th ADFSL Conference on Digital Forensics, Security and Law (CDFSL 2016) pp. 9-20
- Increasing Digital Investigator Availability through Efficient Workflow Management and Automation
The 4th International Symposium on Digital Forensics and Security (ISDFS 2016) pp. 68-73
- On the Benefits of Information Retrieval and Information Extraction Techniques Applied to Digital Forensics
Advanced Multimedia and Ubiquitous Engineering: FutureTech & MUE pp. 641-647
- Tiered Forensic Methodology Model for Digital Field Triage by Non-Digital Evidence Specialists
Digital Investigation Vol. 16 pp. 75-85
2015
- An Evaluation of Google Plus Communities as an Active Learning Journal Alternative to Improve Learning Efficacy
Proceedings of 8th International Conference on Engaging Pedagogy (ICEP 2015)
- Forensic Analysis and Remote Evidence Recovery from Syncthing: An Open Source Decentralised File Synchronisation Utility
Digital Forensics and Cyber Crime Vol. 157 pp. 85-99
- Network Investigation Methodology for BitTorrent Sync: A Peer-to-Peer Based File Synchronisation Service
Computers & Security Vol. 54 pp. 27 - 43
- Project Maelstrom: Forensic Analysis of the BitTorrent-Powered Browser
Journal of Digital Forensics, Security and Law: Proc. of 10th International Conference on Systematic Approaches to Digital Forensic Engineering (SADFE 2015) pp. 115-124
- Overview of the Forensic Investigation of Cloud Services
10th International Conference on Availability, Reliability and Security (ARES 2015) pp. 556-565
- Remote Evidence Acquisition
Proceedings of the International Workshop on Digital Forensics (WSDF 2015)
- Towards the Forensic Identification and Investigation of Cloud Hosted Servers through Noninvasive Wiretaps
Proceedings of 10th International Conference on Availability, Reliability and Security (ARES 2015)
- HTML5 Zero Configuration Covert Channels: Security Risks and Challenges
The 10th ADFSL Conference on Digital Forensics, Security and Law (CDFSL 2015) pp. 135-150
2014
- An analysis of BitTorrent cross-swarm peer participation and geolocational distribution
23rd International Conference on Computer Communication and Networks (ICCCN 2014) pp. 1-6
- BitTorrent Sync: Network Investigation Methodology
Proceedings of 9th International Conference on Availability, Reliability and Security (ARES 2014) pp. 21-29
- Leveraging Decentralisation to Extend the Digital Evidence Acquisition Window: Case Study on BitTorrent Sync
Journal of Digital Forensics, Security and Law: Proc. of Sixth International Conference on Digital Forensics & Cyber Crime (ICDF2C 2014) pp. 85-99
- Digital Evidence Bag Selection for P2P Network Investigation
Proceedings of the 7th International Symposium on Digital Forensics and Information Security (DFIS-2013), Future Information Technology, Application, and Service pp. 307-314
- BitTorrent Sync: First Impressions and Digital Forensic Implications
Digital Investigation Vol. 11, Supplement 1 pp. S77-S86
- The Case for a Collaborative Universal Peer-to-Peer Botnet Investigation Framework
Proceedings of the 9th International Conference on Cyber Warfare and Security (ICCWS 2014) pp. 287-293
2013
- Investigating Cybercrimes That Occur on Documented P2P Networks
Pervasive and Ubiquitous Technology Innovations for Ambient Intelligence Environments pp. 109-115
- Universal Peer-to-Peer Network Investigation Framework
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on pp. 694-700
2012
- Peer-to-Peer Botnet Investigation: A Review
Proceedings of the 6th International Symposium on Digital Forensics and Information Security (DFIS-2012), Future Information Technology, Application, and Service pp. 231-238
2011
- Investigating Cybercrimes That Occur on Documented P2P Networks
International Journal of Ambient Computing and Intelligence Vol. 3 pp. 56-63
2010
- A week in the Life of the Most Popular BitTorrent Swarms
Proceedings of the 5th Annual Symposium on Information Assurance (ASIA 2010) pp. 32-36
2009
- Online Acquisition of Digital Forensic Evidence
Proceedings of International Conference on Digital Forensics and Cyber Crime (ICDF2C 2009) pp. 122-131