Applying Dempster Shafer Theory and Causal Inference in Investigating Internet of Things Digital Forensic Challenge
- 1 Department of Computer Science, Faculty of Computers and Information, Mansoura University, Egypt
- 2 Department of Computer Science, Arab East Colleges, Saudi Arabia
- 3 Department of Communications and Computer Engineering, October University for Modern Sciences and Arts, Egypt
- 4 Department of Information Technology, Faculty of Computers and Information, Mansoura University, Egypt
Abstract
The rapid growth of IoT ecosystems has transformed digital forensics, creating challenges in analyzing distributed, heterogeneous, and uncertain evidence. Conventional forensic methods often struggle to handle ambiguous and conflicting IoT data, highlighting the need for robust frameworks that effectively manage uncertainty across multiple evidence sources. This research presents a hybrid forensic framework that integrates Dempster Shafer Theory (DST) for probabilistic uncertainty modeling with causal inference for deterministic reconstruction of event relationships. Together, these methods provide a comprehensive approach to evidence fusion and event attribution in complex IoT investigations. Using the DFRWS 2017 IoT Digital Forensic Challenge as a case study, the framework systematically processes and correlates diverse evidence sources, including Google Hangouts messages, Alexa voice logs, IoT sensor traffic, and wearable activity data. Results show that DST-based evidence fusion reduces the DST-based epistemic uncertainty (i.e., the proportion of uncommitted belief/ignorance) from 18% before evidence fusion to 0.2% after integrating all available evidence, while achieving a belief value of 97.4% for suspect identification. Complementary causal inference analysis reconstructs temporal and behavioral dependencies, improving the interpretability of probabilistic outcomes. The combined model enhances reliability, transparency, and reproducibility, offering a scientifically grounded methodology suited to modern, data-rich IoT forensic environments where traditional techniques fall short.
DOI: https://doi.org/10.3844/jcssp.2026.3015.3026
Copyright: © 2026 Mohamed El-Dosuky, Sherif K. Ratib and Mostafa M. El-Gayar. This is an open access article distributed under the terms of the
Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.
- 144 Views
- 26 Downloads
- 0 Citations
Download
Keywords
- Digital Forensic
- Dempster Shafer Theory
- Causal Inference
- Internet of Things
- Temporal Logic