NEW APPROACH OF BYTE-LEVEL RECONSTRUCTION FOR ENHANCED DIGITAL FORENSIC DATA RECOVERY BASED ON ML

Authors

DOI:

https://doi.org/10.37943/MXHY2915%20

Keywords:

machine learning, ensemble learning, data recovery, digital forensics, byte-level reconstructionbyte-level reconstruction, integrity assessment

Abstract

The exponential growth of digital data and the increasing sophistication of cyber threats have made traditional data recovery methods, which rely on file system metadata and signature-based carving, inadequate for modern forensic investigations. Solid-state drives with TRIM and wear leveling, file fragmentation and partial corruption frequently leave investigators with incomplete evidence and without any quantitative measure of its reliability. The aim of this study is to develop and validate a machine learning-based ensemble framework for intelligent byte-level data recovery and integrity assessment. The proposed method extracts an 18-dimensional feature vector describing the statistical, structural, entropy and pattern properties of each file segment and combines three complementary models: a Random Forest that predicts individual byte values from contextual windows, a Gradient Boosting model that reconstructs pattern-level structure, and a multilayer perceptron that estimates structural recovery confidence. Their outputs are merged through weighted voting with weights optimized by cross-validation, followed by structural validation and a multi-metric confidence assessment. The framework was evaluated on 10,247 files (PDF, JPEG, PNG, DOCX, MP4) stored on NTFS, ext4 and APFS and subjected to 15 synthetic corruption scenarios, including bit errors, block deletion, header damage, fragmentation, zero padding and pseudo-encrypted regions. The ensemble achieved 89.3% recovery accuracy and 92.1% precision, substantially surpassing Autopsy (62.4%), FTK Imager (58.7%) and EnCase (74.5%), and all improvements were statistically significant (p < 0.001). Accuracy remained stable across file systems (87.1–91.7%), and the confidence scores were well calibrated, with an Expected Calibration Error of 1.48%. The price of this gain is a longer processing time of 45.2 s per file. The results show that combining ensemble byte-level reconstruction with calibrated integrity assessment yields more complete evidence together with quantitative confidence measures suitable for legal proceedings, providing a practical complement to existing forensic tools.

Author Biographies

Leila Rzayeva, Astana IT University, Kazakhstan

PhD, Associate Professor, Director, CyberTech Research Center

Madi Shayakhmetov, Astana IT University, Kazakhstan; National Institute for Cyber Policy and Research, RSE on REM “Digital Government Support Center”

Master’s Degree, Research and Innovation Center CyberTech

Azamat Baibussinov, National Defense University of the Republic of Kazakhstan, Kazakhstan

Master’s Degree, Department of Technical Support

References

Fakiha, B. (2024). Unlocking digital evidence: Recent challenges and strategies in mobile device forensic analysis. Journal of Internet Services and Information Security, 14(2), 68–84. https://doi.org/10.58346/JISIS.2024.I2.005

Srinivasan, A. (2025). Security and forensics – Is solid state drive a friend or a foe? In Proceedings of the International Symposium on Memory Systems (MEMSYS '25) (pp. 148–158). ACM. https://doi.org/10.1145/3767110.3767138

Hadi, H. J., Musthaq, N., & Khan, I. U. (2021). SSD forensic: Evidence generation and forensic research on solid state drives using TRIM analysis. In 2021 International Conference on Cyber Warfare and Security (ICCWS) (pp. 51–56). IEEE. https://doi.org/10.1109/ICCWS53234.2021.9702989

Kim, H., Kim, S., Shin, Y., Jo, W., Lee, S., & Shon, T. (2021). Ext4 and XFS file system forensic framework based on TSK. Electronics, 10(18), 2310. https://doi.org/10.3390/electronics10182310

Fatmah, N., & Indrayani, R. (2022). Analisis forensik digital pada solid state drive fungsi TRIM menggunakan tools Autopsy dan OSForensics [Digital forensic analysis of solid state drives with the TRIM function using Autopsy and OSForensics]. J-SISKO TECH, 5(2), 185. https://doi.org/10.53513/jsk.v5i2.5755

Muhardinata, M., Luthfi, A., & Ramadhani, E. (2023). Teknik disk carving untuk recovery solid state drive volume ReFS dan NTFS dengan fitur TRIM [Disk carving technique for recovering ReFS and NTFS solid state drive volumes with the TRIM feature]. JIIP – Jurnal Ilmiah Ilmu Pendidikan, 6(11), 9507–9515. https://doi.org/10.54371/jiip.v6i11.3133

Nath, S., Summers, K., Baek, J., & Ahn, G.-J. (2024). Digital evidence chain of custody: Navigating new realities of digital forensics. In 2024 IEEE 6th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA) (pp. 11–20). IEEE. https://doi.org/10.1109/TPS-ISA62245.2024.00012

Qadir, S., & Noor, B. (2021). Applications of machine learning in digital forensics. In 2021 International Conference on Digital Futures and Transformative Technologies (ICoDT2) (pp. 1–8). IEEE. https://doi.org/10.1109/ICoDT252288.2021.9441543

Khan, H., Hanif, S., & Muhammad, B. (2021). A survey of machine learning applications in digital forensics. Trends in Computer Science and Information Technology, 6(1), 20–24. https://doi.org/10.17352/tcsit.000034

Javed, A. R., Ahmed, W., Alazab, M., Jalil, Z., Kifayat, K., & Gadekallu, T. R. (2022). A comprehensive survey on computer forensics: State-of-the-art, tools, techniques, challenges, and future directions. IEEE Access, 10, 11065–11089. https://doi.org/10.1109/ACCESS.2022.3142508

Kuts, D., Porshnev, S., Kuts, M., & Popova, E. (2023). The peculiarities of deleted files recovery in FAT32 file system. In 2023 IEEE Ural-Siberian Conference on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT) (pp. 328–331). IEEE. https://doi.org/10.1109/USBEREIT58508.2023.10158866

Oh, J., Lee, S., & Hwang, H. (2022). Forensic recovery of file system metadata for digital forensic investigation. IEEE Access, 10, 111591–111606. https://doi.org/10.1109/ACCESS.2022.3213030

Alzaabi, M., & Al Shibli, A. (2025). A review of JPEG file carving: Challenges, techniques, and future directions. Applied Computing Journal, 5(1), 372–385. https://doi.org/10.52098/acj.20255124

Agboola, V., Osamor, J., & Olajide, F. (2024). Evaluating the efficiency of FTK, Autopsy, and mobile forensic tools: A comparative study in criminal investigations. International Journal of Intelligent Computing Research, 15(1), 1279–1291. https://doi.org/10.20533/ijicr.2042.4655.2024.0156

Ismail, I., & Ariffin, K. A. Z. (2025). The admissibility of digital evidence from open-source forensic tools: Development of a framework for legal acceptance. PLOS ONE, 20(9), e0331683. https://doi.org/10.1371/journal.pone.0331683

Dunsin, D., Ghanem, M. C., Ouazzane, K., & Vassilev, V. (2024). A comprehensive analysis of the role of artificial intelligence and machine learning in modern digital forensics and incident response. Forensic Science International: Digital Investigation, 48, 301675. https://doi.org/10.1016/j.fsidi.2023.301675

Mittal, G., Korus, P., & Memon, N. (2021). FiFTy: Large-scale file fragment type identification using convolutional neural networks. IEEE Transactions on Information Forensics and Security, 16, 28–41. https://doi.org/10.1109/TIFS.2020.3004266

Skračić, K., Petrović, J., & Pale, P. (2023). ByteRCNN: Enhancing file fragment type identification with recurrent and convolutional neural networks. IEEE Access, 11. https://doi.org/10.1109/ACCESS.2023.3340441

Ganaie, M. A., Hu, M., Malik, A. K., Tanveer, M., & Suganthan, P. N. (2022). Ensemble deep learning: A review. Engineering Applications of Artificial Intelligence, 115, 105151. https://doi.org/10.1016/j.engappai.2022.105151

Rohman, B. P. A., Nishimoto, M., & Ogata, K. (2022). Reconstruction of missing ground-penetrating radar traces using simplified U-Net. IEEE Geoscience and Remote Sensing Letters, 19, 1–5. https://doi.org/10.1109/LGRS.2021.3072028

Avanoz, T., & Akbal, E. (2025). Data recovery application from NAND flash memories using the chip-off technique in digital forensics. International Journal of Innovative Engineering Applications, 9(2), 232–242. https://doi.org/10.46460/ijiea.1797801

Kumar, M. (2021). Solid state drive forensics analysis: Challenges and recommendations. Concurrency and Computation: Practice and Experience, 33(24), e6442. https://doi.org/10.1002/cpe.6442

Rzayeva, L., Zhetpisbayeva, A., Zhakenov, M., & Abdykassym, A. (2026). A hybrid machine learning method for secure assessment of NAND flash health and SSD data recovery feasibility. Symmetry, 18(7), 1136. https://doi.org/10.3390/sym18071136

Ali, R. R., Mohamad, K. M. B., Mostafa, S. A., Zebari, D. A., Jubair, M. A., & Alouane, M. T.-H. (2023). A meta-heuristic method for reassemble bifragmented intertwined JPEG image files in digital forensic investigation. IEEE Access, 11, 111789–111800. https://doi.org/10.1109/ACCESS.2023.3321680

van der Meer, V., van den Bos, J., Jonker, H., & Dassen, L. (2024). Problem solved: A reliable, deterministic method for JPEG fragmentation point detection. Forensic Science International: Digital Investigation, 48, 301687. https://doi.org/10.1016/j.fsidi.2023.301687

Downloads

Published

2026-09-30

How to Cite

Yermekov, Y. ., Rzayeva, L. ., Shayakhmetov, M. ., Baibussinov, A. ., Aldasheva, L. ., & Nyssanov, N. (2026). NEW APPROACH OF BYTE-LEVEL RECONSTRUCTION FOR ENHANCED DIGITAL FORENSIC DATA RECOVERY BASED ON ML. Scientific Journal of Astana IT University, 27(3), 240–252. https://doi.org/10.37943/MXHY2915

Issue

Section

Cybersecurity