Detecting LLM usage in primary memory digital forensics
2025 (English)Independent thesis Advanced level (professional degree), 20 credits / 30 HE credits
Student thesis
Abstract [en]
This thesis investigates techniques used to forensically prove the use of LLMs through analysis of volatile memory. In today’s growing technological society, AI models are increasingly being integrated into workflows. As malicious or unauthorised LLMs pose growing risks within these environments, the need for a solid forensic methodology to investigate their usage becomes of great importance. By the analysis of physical memory and log artefacts generated before, during, and after LLM execution, the research provides a forensic framework that an analyst can use to detect and classify LLM activity and deployment type on a machine. Through the use of forensic tools, such as Volatility and NVML, artefacts relating to specific LLM models can be determined. These artefacts include active processes, environmental variables, opened files, network activity, and more. It was found that LLM-bound artefacts were more dependent on the deployment method than the LLM model used.
Additionally, a tool was developed to automatically localise LLM artefacts in RAM dumps, demonstrating that automating the extraction process of valuable artefacts is highly feasible. YARA rules were developed which, with 97.5% accuracy, could pinpoint the model present in a memory dump. The invented method demonstrated that it is possible to distinguish different artefacts related to specific LLM execution.
This research contributes to the field of LLM forensics by offering a thorough method and tools for detecting specific LLM usage, thus strengthening forensic investigations and aiding compliance with emerging legislative regulations.
Place, publisher, year, edition, pages
2025.
Keywords [en]
digital forensics, memory forensics, large language model, automation
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:bth-27943OAI: oai:DiVA.org:bth-27943DiVA, id: diva2:1962529
External cooperation
Orange Cyberdefense
Subject / course
Degree Project in Master of Science in Engineering 30,0 hp
Educational program
DVADS Master of Science in Engineering: Computer Security
Supervisors
Examiners
2025-06-112025-05-312025-09-30Bibliographically approved