Araştırma Makalesi

Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset

Cilt: 40 Sayı: 2 31 Ağustos 2026
PDF İndir
EN TR

Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset

Öz

Objective: Digital traces are an increasingly common form of evidence, yet the manual review of large activity logs is slow and observer-dependent. This study evaluated whether conventional supervised classification algorithms can separate suspicious from normal user activity in a structured, labelled cyber-crime forensic dataset after the removal of every identified channel of label leakage. Methods: A publicly available, synthetically generated cyber-crime forensic dataset of 7,400 activity records with 11 attributes was used. The anomaly type field, which is recorded only for suspicious records and therefore encodes the outcome, was removed from the data frame. All 1,233 suspicious records and a simple random sample of 1,235 normal records, drawn without any completeness restriction, formed a near-balanced working dataset of 2,468 records. Missing values were imputed with constants computed on the pooled data without reference to the label. After label encoding, the data were split 80/20 and 27 classification algorithms were compared at their default settings; a logistic regression reference model was additionally assessed by five-fold stratified cross-validation, its confusion matrix, and the magnitudes of its coefficients. Results: None of the algorithms performed better than random guessing in any meaningful way. The highest test-set accuracy was 0.581 (perceptron; balanced accuracy 0.569; ROC AUC 0.562), against a chance baseline of 0.462 accuracy and 0.500 balanced accuracy; only five of the 26 algorithms exceeded a balanced accuracy of 0.500, and no ROC AUC exceeded 0.562. Cross-validation of the reference model gave a mean ROC AUC of 0.503 (SD 0.049). No predictor correlated with the label beyond an absolute value of 0.05. By contrast, the same pipeline had produced accuracies up to 0.862 in the balanced design, and perfect scores in 19 of 26 algorithms in an imbalanced diagnostic run, while the leakage channels were open. Conclusion: The classification performance of approximately 86% reported for this dataset was an artefact of label leakage introduced during preprocessing, not evidence of genuine separability. After remediation, the predictors carry no detectable information about the label. The study is reported as a documented case of how leakage can fabricate convincing forensic classifiers.

Anahtar Kelimeler

Destekleyen Kurum

All stages of the study were carried out in accordance with the principles of scientific research and publication ethics set out in the Declaration of Helsinki, as revised in 2000.

Etik Beyan

This study was conducted using a publicly available, synthetically generated dataset. It did not involve human participants or animal subjects, and no records containing identifying information or personal data of real individuals were used. Accordingly, ethics committee approval and informed consent were not required. All stages of the study were carried out in accordance with the principles of scientific research and publication ethics set out in the Declaration of Helsinki, as revised in 2000.

Teşekkür

Not applicable

Kaynakça

  1. Casey E. Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet. 3rd ed. Waltham, Massachusetts: Academic Press, 2011: p.187-196.
  2. Quick D, Choo KKR. Impacts of increasing volume of digital forensic data: A survey and future research challenges. Digital Investigation 2014;11(4):273-294. doi: https://doi.org/10.1016/j. diin.2014.09.002
  3. Studiawan H, Sohel F, Payne C. A survey on forensic investigation of operating system logs. Digital Investigation 2019;29:1-20. doi: https://doi.org/10.1016/j.diin.2019.02.005
  4. Ribeiro MT, Singh S, Guestrin C. “Why should I trust you?”: Explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. San Francisco: ACM, 2016: 1135-1144. doi: https://doi.org/10.1145/2939672.2939778
  5. Buczak AL, Guven E. A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys and Tutorials 2016;18(2):1153-1176. doi: https://doi.org/10.1109/COMST.2015.2494502
  6. Chandola V, Banerjee A, Kumar V. Anomaly detection: A survey. ACM Computing Surveys 2009;41(3):1-58. doi: https://doi. org/10.1145/1541880.1541882
  7. Ferrag MA, Maglaras L, Moschoyiannis S, Janicke H. Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications 2020;50:102419. doi: https://doi.org/10.1016/j.jisa.2019.102419
  8. Tavallaee M, Bagheri E, Lu W, Ghorbani AA. A detailed analysis of the KDD CUP 99 data set. In: Proceedings of the Second IEEE Symposium on Computational Intelligence for Security and Defense Applications. Ottawa: IEEE, 2009: 1-6. doi: https://doi.org/10.1109/ CISDA.2009.5356528

Ayrıntılar

Birincil Dil

İngilizce

Konular

Adli Bilişim

Bölüm

Araştırma Makalesi

Yayımlanma Tarihi

31 Ağustos 2026

Gönderilme Tarihi

31 Temmuz 2026

Kabul Tarihi

27 Ağustos 2026

Yayımlandığı Sayı

Yıl 2026 Cilt: 40 Sayı: 2

Kaynak Göster

APA
Okyay, T. M., & Şimşek, M. (2026). Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. Adli Tıp Dergisi, 40(2), 169-281. https://doi.org/10.61970/adlitip.2007916
AMA
1.Okyay TM, Şimşek M. Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. ATD. 2026;40(2):169-281. doi:10.61970/adlitip.2007916
Chicago
Okyay, Tuğba Muhlise, ve Muhammet Şimşek. 2026. “Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset”. Adli Tıp Dergisi 40 (2): 169-281. https://doi.org/10.61970/adlitip.2007916.
EndNote
Okyay TM, Şimşek M (01 Ağustos 2026) Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. Adli Tıp Dergisi 40 2 169–281.
IEEE
[1]T. M. Okyay ve M. Şimşek, “Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset”, ATD, c. 40, sy 2, ss. 169–281, Ağu. 2026, doi: 10.61970/adlitip.2007916.
ISNAD
Okyay, Tuğba Muhlise - Şimşek, Muhammet. “Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset”. Adli Tıp Dergisi 40/2 (01 Ağustos 2026): 169-281. https://doi.org/10.61970/adlitip.2007916.
JAMA
1.Okyay TM, Şimşek M. Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. ATD. 2026;40:169–281.
MLA
Okyay, Tuğba Muhlise, ve Muhammet Şimşek. “Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset”. Adli Tıp Dergisi, c. 40, sy 2, Ağustos 2026, ss. 169-81, doi:10.61970/adlitip.2007916.
Vancouver
1.Tuğba Muhlise Okyay, Muhammet Şimşek. Machine Learning-Based Anomaly Detection on a Labelled Cyber-Crime Forensic Dataset. ATD. 01 Ağustos 2026;40(2):169-281. doi:10.61970/adlitip.2007916

Creative Commons Lisansı
Adli Tıp Dergis Creative Commons Atıf 4.0 Uluslararası Lisansı ile lisanslanmıştır.
Dergimiz Açık Erişim Politikasını benimsemiş olup, gönderilen makaleler için yayının hiçbir aşamasında yazarlardan ücret talep edilmeyecektir.