NEW APPROACH OF BYTE-LEVEL RECONSTRUCTION FOR ENHANCED DIGITAL FORENSIC DATA RECOVERY BASED ON ML
DOI:
https://doi.org/10.37943/MXHY2915%20Keywords:
machine learning, ensemble learning, data recovery, digital forensics, byte-level reconstructionbyte-level reconstruction, integrity assessmentAbstract
The exponential growth of digital data and the increasing sophistication of cyber threats have made traditional data recovery methods, which rely on file system metadata and signature-based carving, inadequate for modern forensic investigations. Solid-state drives with TRIM and wear leveling, file fragmentation and partial corruption frequently leave investigators with incomplete evidence and without any quantitative measure of its reliability. The aim of this study is to develop and validate a machine learning-based ensemble framework for intelligent byte-level data recovery and integrity assessment. The proposed method extracts an 18-dimensional feature vector describing the statistical, structural, entropy and pattern properties of each file segment and combines three complementary models: a Random Forest that predicts individual byte values from contextual windows, a Gradient Boosting model that reconstructs pattern-level structure, and a multilayer perceptron that estimates structural recovery confidence. Their outputs are merged through weighted voting with weights optimized by cross-validation, followed by structural validation and a multi-metric confidence assessment. The framework was evaluated on 10,247 files (PDF, JPEG, PNG, DOCX, MP4) stored on NTFS, ext4 and APFS and subjected to 15 synthetic corruption scenarios, including bit errors, block deletion, header damage, fragmentation, zero padding and pseudo-encrypted regions. The ensemble achieved 89.3% recovery accuracy and 92.1% precision, substantially surpassing Autopsy (62.4%), FTK Imager (58.7%) and EnCase (74.5%), and all improvements were statistically significant (p < 0.001). Accuracy remained stable across file systems (87.1–91.7%), and the confidence scores were well calibrated, with an Expected Calibration Error of 1.48%. The price of this gain is a longer processing time of 45.2 s per file. The results show that combining ensemble byte-level reconstruction with calibrated integrity assessment yields more complete evidence together with quantitative confidence measures suitable for legal proceedings, providing a practical complement to existing forensic tools.
References
Fakiha, B. (2024). Unlocking digital evidence: Recent challenges and strategies in mobile device forensic analysis. Journal of Internet Services and Information Security, 14(2), 68–84. https://doi.org/10.58346/JISIS.2024.I2.005
Srinivasan, A. (2025). Security and forensics – Is solid state drive a friend or a foe? In Proceedings of the International Symposium on Memory Systems (MEMSYS '25) (pp. 148–158). ACM. https://doi.org/10.1145/3767110.3767138
Hadi, H. J., Musthaq, N., & Khan, I. U. (2021). SSD forensic: Evidence generation and forensic research on solid state drives using TRIM analysis. In 2021 International Conference on Cyber Warfare and Security (ICCWS) (pp. 51–56). IEEE. https://doi.org/10.1109/ICCWS53234.2021.9702989
Kim, H., Kim, S., Shin, Y., Jo, W., Lee, S., & Shon, T. (2021). Ext4 and XFS file system forensic framework based on TSK. Electronics, 10(18), 2310. https://doi.org/10.3390/electronics10182310
Fatmah, N., & Indrayani, R. (2022). Analisis forensik digital pada solid state drive fungsi TRIM menggunakan tools Autopsy dan OSForensics [Digital forensic analysis of solid state drives with the TRIM function using Autopsy and OSForensics]. J-SISKO TECH, 5(2), 185. https://doi.org/10.53513/jsk.v5i2.5755
Muhardinata, M., Luthfi, A., & Ramadhani, E. (2023). Teknik disk carving untuk recovery solid state drive volume ReFS dan NTFS dengan fitur TRIM [Disk carving technique for recovering ReFS and NTFS solid state drive volumes with the TRIM feature]. JIIP – Jurnal Ilmiah Ilmu Pendidikan, 6(11), 9507–9515. https://doi.org/10.54371/jiip.v6i11.3133
Nath, S., Summers, K., Baek, J., & Ahn, G.-J. (2024). Digital evidence chain of custody: Navigating new realities of digital forensics. In 2024 IEEE 6th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA) (pp. 11–20). IEEE. https://doi.org/10.1109/TPS-ISA62245.2024.00012
Qadir, S., & Noor, B. (2021). Applications of machine learning in digital forensics. In 2021 International Conference on Digital Futures and Transformative Technologies (ICoDT2) (pp. 1–8). IEEE. https://doi.org/10.1109/ICoDT252288.2021.9441543
Khan, H., Hanif, S., & Muhammad, B. (2021). A survey of machine learning applications in digital forensics. Trends in Computer Science and Information Technology, 6(1), 20–24. https://doi.org/10.17352/tcsit.000034
Javed, A. R., Ahmed, W., Alazab, M., Jalil, Z., Kifayat, K., & Gadekallu, T. R. (2022). A comprehensive survey on computer forensics: State-of-the-art, tools, techniques, challenges, and future directions. IEEE Access, 10, 11065–11089. https://doi.org/10.1109/ACCESS.2022.3142508
Kuts, D., Porshnev, S., Kuts, M., & Popova, E. (2023). The peculiarities of deleted files recovery in FAT32 file system. In 2023 IEEE Ural-Siberian Conference on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT) (pp. 328–331). IEEE. https://doi.org/10.1109/USBEREIT58508.2023.10158866
Oh, J., Lee, S., & Hwang, H. (2022). Forensic recovery of file system metadata for digital forensic investigation. IEEE Access, 10, 111591–111606. https://doi.org/10.1109/ACCESS.2022.3213030
Alzaabi, M., & Al Shibli, A. (2025). A review of JPEG file carving: Challenges, techniques, and future directions. Applied Computing Journal, 5(1), 372–385. https://doi.org/10.52098/acj.20255124
Agboola, V., Osamor, J., & Olajide, F. (2024). Evaluating the efficiency of FTK, Autopsy, and mobile forensic tools: A comparative study in criminal investigations. International Journal of Intelligent Computing Research, 15(1), 1279–1291. https://doi.org/10.20533/ijicr.2042.4655.2024.0156
Ismail, I., & Ariffin, K. A. Z. (2025). The admissibility of digital evidence from open-source forensic tools: Development of a framework for legal acceptance. PLOS ONE, 20(9), e0331683. https://doi.org/10.1371/journal.pone.0331683
Dunsin, D., Ghanem, M. C., Ouazzane, K., & Vassilev, V. (2024). A comprehensive analysis of the role of artificial intelligence and machine learning in modern digital forensics and incident response. Forensic Science International: Digital Investigation, 48, 301675. https://doi.org/10.1016/j.fsidi.2023.301675
Mittal, G., Korus, P., & Memon, N. (2021). FiFTy: Large-scale file fragment type identification using convolutional neural networks. IEEE Transactions on Information Forensics and Security, 16, 28–41. https://doi.org/10.1109/TIFS.2020.3004266
Skračić, K., Petrović, J., & Pale, P. (2023). ByteRCNN: Enhancing file fragment type identification with recurrent and convolutional neural networks. IEEE Access, 11. https://doi.org/10.1109/ACCESS.2023.3340441
Ganaie, M. A., Hu, M., Malik, A. K., Tanveer, M., & Suganthan, P. N. (2022). Ensemble deep learning: A review. Engineering Applications of Artificial Intelligence, 115, 105151. https://doi.org/10.1016/j.engappai.2022.105151
Rohman, B. P. A., Nishimoto, M., & Ogata, K. (2022). Reconstruction of missing ground-penetrating radar traces using simplified U-Net. IEEE Geoscience and Remote Sensing Letters, 19, 1–5. https://doi.org/10.1109/LGRS.2021.3072028
Avanoz, T., & Akbal, E. (2025). Data recovery application from NAND flash memories using the chip-off technique in digital forensics. International Journal of Innovative Engineering Applications, 9(2), 232–242. https://doi.org/10.46460/ijiea.1797801
Kumar, M. (2021). Solid state drive forensics analysis: Challenges and recommendations. Concurrency and Computation: Practice and Experience, 33(24), e6442. https://doi.org/10.1002/cpe.6442
Rzayeva, L., Zhetpisbayeva, A., Zhakenov, M., & Abdykassym, A. (2026). A hybrid machine learning method for secure assessment of NAND flash health and SSD data recovery feasibility. Symmetry, 18(7), 1136. https://doi.org/10.3390/sym18071136
Ali, R. R., Mohamad, K. M. B., Mostafa, S. A., Zebari, D. A., Jubair, M. A., & Alouane, M. T.-H. (2023). A meta-heuristic method for reassemble bifragmented intertwined JPEG image files in digital forensic investigation. IEEE Access, 11, 111789–111800. https://doi.org/10.1109/ACCESS.2023.3321680
van der Meer, V., van den Bos, J., Jonker, H., & Dassen, L. (2024). Problem solved: A reliable, deterministic method for JPEG fragmentation point detection. Forensic Science International: Digital Investigation, 48, 301687. https://doi.org/10.1016/j.fsidi.2023.301687
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Articles are open access under the Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Authors who publish a manuscript in this journal agree to the following terms:
- The authors reserve the right to authorship of their work and transfer to the journal the right of first publication under the terms of the Creative Commons Attribution License, which allows others to freely distribute the published work with a mandatory link to the the original work and the first publication of the work in this journal.
- Authors have the right to conclude independent additional agreements that relate to the non-exclusive distribution of the work in the form in which it was published by this journal (for example, to post the work in the electronic repository of the institution or publish as part of a monograph), providing the link to the first publication of the work in this journal.
- Other terms stated in the Copyright Agreement.