Research Article

Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset

Volume: 40 Number: 2 August 31, 2026
EN TR

Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset

Abstract

Objective: Digital traces are an increasingly common form of evidence, yet the manual review of large activity logs is slow and observer-dependent. This study evaluated whether conventional supervised classification algorithms can separate suspicious from normal user activity in a structured, labelled cyber-crime forensic dataset after the removal of every identified channel of label leakage. Methods: A publicly available, synthetically generated cyber-crime forensic dataset of 7,400 activity records with 11 attributes was used. The anomaly type field, which is recorded only for suspicious records and therefore encodes the outcome, was removed from the data frame. All 1,233 suspicious records and a simple random sample of 1,235 normal records, drawn without any completeness restriction, formed a near-balanced working dataset of 2,468 records. Missing values were imputed with constants computed on the pooled data without reference to the label. After label encoding, the data were split 80/20 and 27 classification algorithms were compared at their default settings; a logistic regression reference model was additionally assessed by five-fold stratified cross-validation, its confusion matrix, and the magnitudes of its coefficients. Results: None of the algorithms performed better than random guessing in any meaningful way. The highest test-set accuracy was 0.581 (perceptron; balanced accuracy 0.569; ROC AUC 0.562), against a chance baseline of 0.462 accuracy and 0.500 balanced accuracy; only five of the 26 algorithms exceeded a balanced accuracy of 0.500, and no ROC AUC exceeded 0.562. Cross-validation of the reference model gave a mean ROC AUC of 0.503 (SD 0.049). No predictor correlated with the label beyond an absolute value of 0.05. By contrast, the same pipeline had produced accuracies up to 0.862 in the balanced design, and perfect scores in 19 of 26 algorithms in an imbalanced diagnostic run, while the leakage channels were open. Conclusion: The classification performance of approximately 86% reported for this dataset was an artefact of label leakage introduced during preprocessing, not evidence of genuine separability. After remediation, the predictors carry no detectable information about the label. The study is reported as a documented case of how leakage can fabricate convincing forensic classifiers.

Keywords

Supporting Institution

All stages of the study were carried out in accordance with the principles of scientific research and publication ethics set out in the Declaration of Helsinki, as revised in 2000.

Ethical Statement

This study was conducted using a publicly available, synthetically generated dataset. It did not involve human participants or animal subjects, and no records containing identifying information or personal data of real individuals were used. Accordingly, ethics committee approval and informed consent were not required. All stages of the study were carried out in accordance with the principles of scientific research and publication ethics set out in the Declaration of Helsinki, as revised in 2000.

Thanks

Not applicable

References

  1. Casey E. Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet. 3rd ed. Waltham, Massachusetts: Academic Press, 2011: p.187-196.
  2. Quick D, Choo KKR. Impacts of increasing volume of digital forensic data: A survey and future research challenges. Digital Investigation 2014;11(4):273-294. doi: https://doi.org/10.1016/j. diin.2014.09.002
  3. Studiawan H, Sohel F, Payne C. A survey on forensic investigation of operating system logs. Digital Investigation 2019;29:1-20. doi: https://doi.org/10.1016/j.diin.2019.02.005
  4. Ribeiro MT, Singh S, Guestrin C. “Why should I trust you?”: Explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. San Francisco: ACM, 2016: 1135-1144. doi: https://doi.org/10.1145/2939672.2939778
  5. Buczak AL, Guven E. A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys and Tutorials 2016;18(2):1153-1176. doi: https://doi.org/10.1109/COMST.2015.2494502
  6. Chandola V, Banerjee A, Kumar V. Anomaly detection: A survey. ACM Computing Surveys 2009;41(3):1-58. doi: https://doi. org/10.1145/1541880.1541882
  7. Ferrag MA, Maglaras L, Moschoyiannis S, Janicke H. Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications 2020;50:102419. doi: https://doi.org/10.1016/j.jisa.2019.102419
  8. Tavallaee M, Bagheri E, Lu W, Ghorbani AA. A detailed analysis of the KDD CUP 99 data set. In: Proceedings of the Second IEEE Symposium on Computational Intelligence for Security and Defense Applications. Ottawa: IEEE, 2009: 1-6. doi: https://doi.org/10.1109/ CISDA.2009.5356528

Details

Primary Language

English

Subjects

Computer Forensics

Journal Section

Research Article

Publication Date

August 31, 2026

Submission Date

July 31, 2026

Acceptance Date

August 27, 2026

Published in Issue

Year 2026 Volume: 40 Number: 2

APA
Okyay, T. M., & Şimşek, M. (2026). Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. Adli Tıp Dergisi, 40(2), 169-281. https://doi.org/10.61970/adlitip.2007916
AMA
1.Okyay TM, Şimşek M. Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. J For Med. 2026;40(2):169-281. doi:10.61970/adlitip.2007916
Chicago
Okyay, Tuğba Muhlise, and Muhammet Şimşek. 2026. “Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset”. Adli Tıp Dergisi 40 (2): 169-281. https://doi.org/10.61970/adlitip.2007916.
EndNote
Okyay TM, Şimşek M (August 1, 2026) Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. Adli Tıp Dergisi 40 2 169–281.
IEEE
[1]T. M. Okyay and M. Şimşek, “Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset”, J For Med, vol. 40, no. 2, pp. 169–281, Aug. 2026, doi: 10.61970/adlitip.2007916.
ISNAD
Okyay, Tuğba Muhlise - Şimşek, Muhammet. “Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset”. Adli Tıp Dergisi 40/2 (August 1, 2026): 169-281. https://doi.org/10.61970/adlitip.2007916.
JAMA
1.Okyay TM, Şimşek M. Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. J For Med. 2026;40:169–281.
MLA
Okyay, Tuğba Muhlise, and Muhammet Şimşek. “Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset”. Adli Tıp Dergisi, vol. 40, no. 2, Aug. 2026, pp. 169-81, doi:10.61970/adlitip.2007916.
Vancouver
1.Tuğba Muhlise Okyay, Muhammet Şimşek. Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. J For Med. 2026 Aug. 1;40(2):169-281. doi:10.61970/adlitip.2007916
Creative Commons Lisansı

Turkish Journal of Forensic Medicine is licensed under a Creative Commons Attribution 4.0 International License.
Our journal has adopted the Open Access Policy, and no fees will be charged from the authors at any stage of the publication for the articles submitted.