Leveraging Centrality Matrix and Enhanced Walrus Evoked Learning Framework for Digital Forensics Anomaly Data Detection
Bibliographic record
Abstract
Digital forensics (DF) has emerged as a crucial strategy for tracing offenders and ensuring social justice for the common man.With the increasing exploitation of digital gadgets by criminals, cybercrimes have risen significantly, affecting people's daily lives.Consequently, the primary goal of DF is to ensure that digital evidence remains unaltered by identifying, collecting, analyzing, and assessing data to reconstruct historical events.However, detecting data anomalies that indicate illegal behavior remains one of the most daunting challenges in DF.Current systems hinder DF investigations due to inaccuracies in identifying aberrant patterns in forensic data.With the advent of artificial intelligence (AI), unusual activities in DF data can now be detected more effectively.However, achieving higher accuracy remains a major challenge in this field.This research article proposes a novel hybrid learning framework that integrates centrality measures with an Enhanced Walrus Evoked Extreme Feedforward Neural Network (EW-EFNN) to identify intrusions in crime-related digital forensic data.The proposed framework is trained using different traffic data generated on computers to determine whether they have been tampered with by specific intruder programs.Real-time datasets are created using Wireshark to analyze various DF anomaly patterns, followed by centrality measures for feature extraction and an enhanced walrus-evoked learning network for optimal detection performance.Comprehensive experiments are conducted using real-time traffic data, evaluating performance metrics such as accuracy, precision, recall, specificity, and F1score.The results demonstrate that the proposed model achieves 96% accuracy, 95.7% precision, 95.8% recall, and a 96% F1-score.Compared to existing systems, the proposed learning framework outperforms others in detecting anomaly patterns in DF data.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.001 | 0.007 |
| Meta-epidemiology (narrow) | 0.001 | 0.000 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.004 | 0.003 |
| Science and technology studies | 0.001 | 0.001 |
| Scholarly communication | 0.002 | 0.003 |
| Open science | 0.002 | 0.002 |
| Research integrity | 0.001 | 0.002 |
| Insufficient payload (model declined to judge) | 0.003 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".