EDBT 2026 Demo / reviewers in the wild / expert
Umit Karabiyik
dblp:151/7858
· DBLP profile ↗
24ranked-venue papers
1as first author
14since 2021 · last 2025
0000-0001-6760-259XORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Are Action Cameras the New Witness? A Forensic Examination of GoPro HERO13 and Quik App Data on Android and iOSabstractAction cameras capture experiences from a first-person perspective and are designed to be compact and hands-free. These features have made them widely used in areas such as sports, adventure, security, and healthcare. With the growing use of such devices, it is becoming more common for witnesses or victims to have them during incidents. These cameras record a broad range of data, including media and telemetry, which can provide records of crime and incident scenes and help reconstruct events. This study presents a forensic analysis of the GoPro HERO13 and its accompanying application, GoPro Quik, on Android and iOS platforms. We identified the paths and locations of key digital artifacts generated by the camera and the application, such as user profiles and device information, camera-related data, and app usage artifacts. For media artifacts, we identified the locations of logs for footage stored locally or linked to the cloud, as well as records of deleted media. We described GoPro’s file naming conventions and its unique sensor metadata format, GPMF. These not only help ensure the integrity and continuity of media files but also provide contextual information about the moment the media was captured. This study provides insights for digital forensic investigations by detailing the digital evidence paths and data locations generated by the action camera, which can be valuable for incident reconstruction and contextual understanding. Umit Karabiyik |
ISNCC | 2 |
| 2025 | DEFENDIFY: defense amplified with transfer learning for obfuscated malware frameworkabstractAbstract The existence of malicious software (malware) represents a potential threat to users who connect to a large set of services provided by multiple providers. Such malware is capable of stealing, spying on, encrypting data from users, and spreading, provoking impacts that are beyond a single citizen’s device and reaching critical information systems. To detect malware families, Machine Learning and Deep Learning techniques have been employed recently, demonstrating promising results. However, these techniques lack in detecting more advanced malware that employs obfuscation techniques. In this paper, we present DEFENDIFY, a novel framework, empowered by Computer Vision, Deep Learning, and Transfer Learning techniques, that is able to detect completely obfuscated malware with high performance in terms of accuracy and computational consumption. DEFENDIFY comprises three modules: Dataset Creation, Binary Obfuscation, and Model Generation. These modules work together to detect both obfuscated and non-obfuscated malware. The core module, i.e., the Model Generation, employs an entropy tester that determines whether a sample is obfuscated or not. Then, a Deep Learning model powered by Transfer Learning is employed to determine if it is malware or goodware. We validated our framework using real data gathered from malware repositories and legitimate software. The proposed framework was configured to test four Convolutional Neural Network architectures: ResNet18, ResNet34, EfficientNetB3, and EfficientNetV2S. Among them, the ResNet18 architecture obtained the best performance in detecting both non-obfuscated and obfuscated samples with an F1-score of 99.34% and 97.5%, respectively. Rodrigo Castillo Camargo, Juan Murcia Nieto, Nicolás Rojas 0004, Daniel Díaz López, Santiago Alférez, Ángel Luis Perales Gómez, Pantaleone Nespoli, Félix Gómez Mármol, Umit Karabiyik |
Cybersecur. | 9 |
| 2025 | Forensic examination of tencent QQ mobile application features for evidence collection on android and iOS devicesabstractAbstract Tencent QQ, established in 1999, ranks among the most extensively utilized instant messaging applications globally. At its peak, it attracted approximately 900 million users (Business Daily in Sohu 2023). Despite the emergence of numerous similar applications such as WeChat, QQ continues to hold a strong position within business and interest-based communities, particularly appealing to young adults. Forensic examinations of QQ have been ongoing since 2009, primarily addressing its memory function, instant messaging capabilities, and desktop version. However, there is a notable lack of thorough research on the many beneficial functions of the mobile version of QQ on both Android and iOS platforms. Additionally, online fraudsters, especially scam groups in Southeast Asia, have taken advantage of the app. Inadvertently, QQ provides scammers with the means to contact victims and extort property. To bridge this knowledge gap, this study performs a forensic analysis of QQ’s new features on Android and iOS. Our study covers new capabilities such as device detection, file editing and transferring, the integrated camera, document sharing, payment, and service functions, message withdrawal, real-time location sharing, phone numbers, contacts, QQ group activities, chat history with its backup, QQ zone, and privacy preservation and protection measures. The objective of this research is to assist investigators by enhancing the use of forensic tools concerning QQ and its new functionalities to discern what evidence can be acquired and recovered, thereby closing the existing knowledge gap. Yufeng Gong, Umit Karabiyik |
Discov. Comput. | 2 |
| 2024 | Forensic Intelligence Derived from Crime Scene Evidence Using Text EmbeddingsabstractForensic Intelligence and Crime Linkage are fields dedicated to studying patterns in criminal behavior to provide actionable insights for investigations. Despite their potential, both fields have seen limited advancements in leveraging recent developments in Artificial Intelligence. This study introduces a novel model that utilizes Natural Language Processing techniques to analyze criminal behavior patterns based on crime scene evidence. Our methodology involves transforming detailed crime scene narratives into a vectorized format, creating a multidimensional space that encapsulates the modus operandi of individual cases. When applied to a real-world dataset, preliminary results demonstrate the effectiveness of this approach in grouping similar crimes, including known serial offenses, and distinguishing unrelated cases based on location and forensic evidence analysis. This research aims to benefit both the academic and law enforcement communities, providing a tool that uncovers insights into criminal behavior patterns and potential case linkages. Umit Karabiyik |
IEEE Big Data | 2 |
| 2024 | The Hidden Realms of Router Apps: Forensic Analysis of TP-Link Tether and ASUS Router
Akif Ahsen Ozer, Umit Karabiyik |
ICDF2C (1) | 2 |
| 2024 | Forensics Analysis of Android Social Networking Application: Tencent QQ RevisitedabstractTencent QQ, founded in 1999, is a widely used instant messaging application globally. At its peak, it had 900 million users. Although numerous similar applications have emerged, such as WeChat, QQ continues to maintain its competitiveness in business and interest-based communities, particularly among young adults. There have been many forensic studies on QQ since 2009, focusing mainly on its memory function, instant messaging function, and computer version. However, many useful functions of mobile QQ have not been thoroughly researched. Additionally, online fraudsters, particularly scam syndicates in Southeast Asia, have exploited these opportunities. The application allows scammers to contact victims and extort property. To address this gap, this research conducted a forensic analysis of QQ's new functions on Android devices. It focused on new features including device detection, file editing and transferring, the built-in camera, shared documents, payment and service functions, message withdrawal, real-time location sharing, phone numbers, contacts, QQ group activities, chat history and its backup, QQ zone, payment, and private information preservation and protection. This research aims to assist investigators in effectively utilizing forensic techniques for QQ and its new features, to understand what evidence can be obtained and what can be recovered, thereby addressing the existing knowledge gap. Yufeng Gong, Umit Karabiyik |
ISNCC | 2 |
| 2024 | Shopping While Watching: An Updated Forensic Analysis of TikTok on Android and iOSabstractTikTok is one of the most popular social media platforms in the world. Despite its extensive use, mobile forensics research on TikTok has seen little progress in the past two years, possibly due to limitations faced by some researchers using this app. This paper presents a forensic analysis of TikTok, focusing on recent inadequacies in mobile forensic research on it, especially with the advent of features like the TikTok Shop. This study not only describes the forensic value of the new shopping feature, but also updates artifacts from previous studies on general information and media sections, providing investigators with information about TikTok-related folder structures and important data paths. For general information, we extracted data about user accounts and apps, and for media information, we found video content uploaded and viewed by users, and proposed possible methods to distinguish what users actually watched. This work improves the understanding of the digital environment and offers valuable forensic insights crucial to keeping up with rapid technological advancements in social media platforms for digital forensic investigations. Umit Karabiyik |
ISNCC | 2 |
| 2024 | Identifying Media Storage Locations in Baby Camera Apps: A Mobile Forensic ApproachabstractWith the proliferation of IoT and its integration with the internet, digital forensics has encountered a diverse array of potentially questioned devices. Baby cameras represent an example of such devices, characterized by a dearth of background information on forensic analysis and content storage mechanisms within devices and their associated applications. Given the potential for these devices to capture criminal behavior, notably instances of child abuse, there exists a compelling need to comprehensively understand the storage methodologies employed, particularly concerning media content. This study aims to bridge this gap by conducting forensic analyses on two popular baby cameras, with a focus on identifying potential data sources pertinent to investigators. Our investigation prioritized photos and video content, leading to the identification of seven distinct locations where media may be stored. These locations were meticulously detailed, with a particular emphasis on determining those capable of retaining deliberately deleted media. Despite our focus on media, we scrutinized the applications' log files and databases, uncovering potentially valuable information relevant to investigations, including details on Wi-Fi connections and user interactions. Umit Karabiyik |
ISNCC | 2 |
| 2023 | No Filters: A Deep Dive into Photo Sharing Apps on Android and iOSabstractPhoto and video-sharing applications have gained popularity among all age groups. These applications allow users to create, share, and interact with multimedia content. Unfortunately, some of these applications have been used to harass, exploit, cyberbully, solicit/groom minors, or track any users' physical location. Consequently, they have become a significant source of evidence in digital investigations. In this paper, we conduct a comprehensive forensic investigation of two relatively new and highly popular photo-sharing applications on both Android and iOS devices. Our goals are to (1) provide a forensic roadmap for forensic investigators who may encounter these or similar applications during a case, (2) highlight the privacy concerns that these applications' users should be made aware of, and (3) discuss the implications of not using multiple tools for artifact validation. Our findings illustrate the lack of privacy and security measures in place for these applications' users, which are location-specific artifacts that can be easily recovered along with plaintext chat messages. Additionally, our findings highlight the inability of commercial tools to uncover pertinent evidence and thus reinforce the need for investigators to use multiple tools during a forensic investigation. Mohammad Meraj Mirza, Shinelle Hutchinson, Rebecca Gee, Umit Karabiyik |
ISNCC | 4 |
| 2023 | Digital Forensic Analysis of AGPTEK Smartwatch Application on Android OSabstractAs wearable IoT devices become more popular, the likelihood for digital forensic investigators and analysts to encounter them in the field increases. Smartwatches are one of the most popular wearable IoT devices today, and many brands and devices have yet to be analyzed. Analysis of such devices plays an integral role in criminal investigations, as data collected by these devices may be used as inculpatory or exculpatory evidence. This paper provides a forensic analysis of the AGPTEK smartwatch application (FitCloudPro) on Android OS for both a non-rooted and rooted smartphone. The smartwatch was worn for a data population period while paired with the smartphone. The phone was then imaged using Magnet AXIOM Process and analyzed using Magnet AXIOM Examine. Directories, files, and databases of interest are documented. The smartwatch application creates one major database containing user and activity data (appDatabase). The logs for the application contain an abundant amount of descriptive data but only are retained for approximately three days. Claire Rightley, Umit Karabiyik |
ISNCC | 2 |
| 2022 | Forensic Analysis of Webex on the iOS Platform
Jiaxuan Zhou, Umit Karabiyik |
ICDF2C | 2 |
| 2022 | Watch Your WeChat Wallet: Digital Forensics Approach on WeChat Payments on Android
Jiaxuan Zhou, Umit Karabiyik |
ICDF2C | 2 |
| 2021 | Instagram Forensic Analysis Revisited: Does anything really vanish?abstractInstagram has become one of the most popular and sought-after social media to be on. People of varying ages from various backgrounds use Instagram and in order to keep things exciting for their users, Instagram frequently rolls out new and exciting updates to their applications. One such feature is the “vanish mode”, that aids people to have secure and private chats. By enabling the vanish mode, people can send messages which would disappear once the vanish mode is disabled. This feature might be of interest to criminals who find ways to clear their activity trace. Disappearing messages might provide people a sense of comfort about the privacy of their chats, but poses a challenge to the investigators to track messages and obtain digital evidence to catch criminals such as child predators, drug dealers, and cyberbullies. This research focuses on analyzing this aspect of the app to identify any artifacts that could be useful in a forensic investigation. The results presented in this paper indicate the presence of vanished messages in the application database. The research also identified inconsistencies in the databases regarding the visibility of the vanished messages. Furthermore, the manner in which user-uploaded media is stored in the database was investigated, and the findings on user searches on the explore page and the shopping tab are presented. The research work adds to the existing knowledge of work done in the digital forensics field by detecting the presence of disappearing messages to aid investigations where Instagram is being analyzed. Shreya Tarur Kumar, Umit Karabiyik |
ISNCC | 2 |
| 2021 | Enhancing IP Address Geocoding, Geolocating and Visualization for Digital ForensicsabstractInternet Protocol (IP) address holds a probative value to the identification process in digital forensics. The decimal digit is a unique identifier that is beneficial in many investigations (i.e., network, email, memory). IP addresses can reveal important information regarding the device that the user uses during Internet activity. One of the things that IP addresses can essentially help digital forensics investigators in is the identification of the user machine and tracing evidence based on network artifacts. Unfortunately, it appears that some of the well-known digital forensic tools only provide functions to recover IP addresses from a given forensic image. Thus, there is still a gap in answering if IP addresses found in a smartphone can help reveal the user’s location and be used to aid investigators in identifying IP addresses that complement the user’s physical location. Furthermore, the lack of utilizing IP mapping and visualizing techniques has resulted in the omission of such digital evidence. This research aims to emphasize the importance of geolocation data in digital forensic investigations, propose an IP visualization technique considering several sources of evidence, and enhance the investigation process’s speed when its pertained to IP addresses using spatial analysis. Moreover, this research proposes a proof-of-concept (POC) standalone tool that can match critical IP addresses with approximate geolocations to fill the gap in this area. Mohammad Meraj Mirza, Umit Karabiyik |
ISNCC | 2 |
| 2020 | Forensic Analysis of the August Smart Device EcosystemabstractSmart Homes are becoming increasingly popular with homeowners investing in new internet-connected technologies, from smart plugs to smart appliances. One particular area where homeowners use smart devices is at the front door, as they install smart doorbells and smart locks. In this paper, we embark on an investigative journey into the August smart device ecosystem, specifically looking at the interaction between the August Smart Doorbell Pro and the August Smart Lock Pro, with their controlling app, August Home. We aim to determine what type of data forensic investigators may be able to recover about these devices and their use. We also explore how these devices interact with each other, noting any privacy issues that may be discovered. We found that a wealth of forensic data could be recovered, particularly from rooted Android devices and jailbroken iPhone devices. Information about the owner of the smart device, guests who were given access to the devices, device interactions, and pictures taken by the doorbell camera, were all recoverable in plaintext. Our results also show that user's GPS coordinates associated with the lock's Auto-Unlock feature were recovered only from a rooted Android device. Shinelle Hutchinson, Umit Karabiyik |
ISNCC | 2 |
| 2020 | Asynchronous Forensic Investigative Approach to Recover Deleted Data from Instant Messaging ApplicationsabstractProliferation of digital platforms specifically Instant Messaging Applications (IMAs), have introduced new challenges to digital forensic investigations. With the rapidly increased use of WhatsApp application, it is plausible to speculate that WhatsApp became a potential source of threat and/or cybercrime. Some newly added features on WhatsApp, such as `delete for everyone', giving the users the ability to delete messages from both ends (sender and receiver), have resulted in complicating the cybercrime investigation process. Therefore, there is a need to revisit the investigation process and the structure of such updated features to be able to create a comprehensive digital forensic technique. This paper examines the forensic artifacts of the WhatsApp's `delete for everyone' feature. This feature is a great addition to the overall usability of IMAs, however, it is also crucial to update the digital forensic investigation techniques and test the capability of commercial forensic tools in recovering forensic evidence when a new technology has been introduced. During the course of this research, we tested and validated the digital forensic methodology and compared the investigation results with forensically sound commercial tools. During the data acquisition process, we conducted physical and logical forensic acquisitions of an Android device which led to a breakthrough discovery of a SQLite file called Write-Ahead-Log (WAL) which contains the application's latest messages, including deleted (allegedly) messages. Fahad E. Salamh, Umit Karabiyik, Marcus K. Rogers |
ISNCC | 2 |
| 2020 | Forensic Analysis of Dating Applications on Android and iOS DevicesabstractDating application use is on the rise, and with it comes the need to better understand what data can be recovered to assist in an investigation. While using these dating applications, people send countless messages (including pictures and videos) without ever considering exactly what data is being sent within that message. In this project, we conduct a forensic analysis of five popular dating applications (Her, Hily, Hinge, OkCupid, and Plenty of Fish (POF)) that are available on both Android and iOS devices. We also determined what forensically relevant data can be recovered from dating applications on both Android and iOS. Specifically, we determined what data can be recovered about the sender from the receiver's phone. Secondly, we identified any privacy concerns that result due to the recoverable data and discuss their implications for users. Lastly, we detailed the investigative process that should be followed and presented the locations of any relevant data to aid digital forensics investigators during an Investigation. Shinelle Hutchinson, Neesha Shantaram, Umit Karabiyik |
TrustCom | 3 |
| 2020 | A first look at forensic analysis of sailfishos
Krassimir Tzvetanov, Umit Karabiyik |
Comput. Secur. | 2 |
| 2019 | Are We Really Protected? An Investigation into the Play Protect ServiceabstractAndroid smartphones are becoming more and more popular each year. With this increased user base, comes an increased need for Android OS to protect its users from malicious applications that may violate users' privacy. The Google Play Store is the main means of dissemination for new applications and as such should provide a layer of efficient protection against malicious applications. However, there have been times when malicious applications were allowed on the Play Store, even after the introduction of the recent Play Protect Service. In this paper, we have opted to investigate the efficiency of the Play Protect Service in detecting malicious applications that are both sideloaded onto a device and uploaded directly to the Play Store. In order to accomplish this, we have developed a spyware application, called InstaCam, that is advertised as a simple camera app. However, it asks for functionally unnecessary permissions that make it a practically dangerous app. We tested InstaCam against various antivirus applications, including Play Protect. The results show that there is substantial delay in the ability of Play Protect to detect our malicious application while other popular antivirus software is capable of detecting InstaCam in a timelier manner. Shinelle Hutchinson, Bing Zhou 0002, Umit Karabiyik |
IEEE BigData | 3 |
| 2019 | A Targeted Data Extraction System for Mobile Devices
Sudhir Aggarwal, Gokila Dorai, Umit Karabiyik, Tathagata Mukherjee, Nicholas Guerra, Manuel Hernandez, James Parsons, Khushboo Rathi, Hongmei Chi, Temilola Aderibigbe, Rodney Wilson |
IFIP Int. Conf. Digital Forensics | 3 |
| 2019 | Drone Disrupted Denial of Service Attack (3DOS): Towards an Incident Response and Forensic Analysis of Remotely Piloted Aerial Systems (RPASs)abstractAccording to the Federal Aviation Administration (FAA), the number of Remotely Piloted Air Systems (RPASs), colloquially known as drones, will rapidly increase in the near future. Challenges with drones are focused not only on the security of these devices, but also on the criminal uses for drones which need to be carefully considered. Incident response and forensic analysis of such cases have not been sufficiently addressed by the research community. This paper focuses on incident response of cybercrimes related to drones as well as some possible anti-forensic techniques that could be used to alter digital evidence associated with drones. In addition, this paper also revisits the enacted regulations that purport to restrict the operation of drones in critical infrastructure areas. We evaluate drone incident response by exploring a case study using a hypothetical drone forensic tool to illustrate the acquisition of GPS metadata from both media files and flight logs, with a view towards aiding the incident responders and digital forensic investigators in analyzing illegal flight activities and report such incidents effectively. Fahad E. Salamh, Umit Karabiyik, Marcus K. Rogers, Fawaz AL-Hazemi |
IWCMC | 2 |
| 2018 | A secure and cloud-based medical records access scheme for on-road emergenciesabstractOn-road emergencies necessitates the availability of the patient's medical records to the emergency centers for better treatment. However, these medical records are often encrypted to preserve the patient's privacy. Revealing the secret key used to encrypt these records to the emergency center would not only give unlimited unauthorized future access to the medical records but also pose privacy concerns for the patient. In this paper, we propose a secure medical records access scheme that can be used to serve the patient effectively. An emergency medical center is able to decrypt a patient's medical records without revealing the secret key used to encrypt them with the help of the patient's smart phone and the cloud server. We use proxy re-encryption scheme to trigger a re-encryption process at the cloud server by sending the required credentials. With the help of the cloud server, only a specific emergency center is able to decrypt the medical records and access the patient's medical history. Our scheme allows in-time and more efficient health care and recovery in extreme life-threatening situations. Our analysis and evaluations show that the proposed scheme can secure the medical records and preserve the privacy of the patient with acceptable computation and communication overhead. Khaled Rabieh, Kemal Akkaya, Umit Karabiyik, Jennifer Qamruddin |
CCNC | 3 |
| 2016 | Advanced Automated Disk Investigation Toolkit
Umit Karabiyik, Sudhir Aggarwal |
IFIP Int. Conf. Digital Forensics | 1 |
| 2015 | Identifying Passwords Stored on Disk
Shiva Houshmand, Sudhir Aggarwal, Umit Karabiyik |
IFIP Int. Conf. Digital Forensics | 3 |