Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Detecting LLM usage in primary memory digital forensics
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.
2025 (English)Independent thesis Advanced level (professional degree), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

This thesis investigates techniques used to forensically prove the use of LLMs through analysis of volatile memory. In today’s growing technological society, AI models are increasingly being integrated into workflows. As malicious or unauthorised LLMs pose growing risks within these environments, the need for a solid forensic methodology to investigate their usage becomes of great importance. By the analysis of physical memory and log artefacts generated before, during, and after LLM execution, the research provides a forensic framework that an analyst can use to detect and classify LLM activity and deployment type on a machine. Through the use of forensic tools, such as Volatility and NVML, artefacts relating to specific LLM models can be determined. These artefacts include active processes, environmental variables, opened files, network activity, and more. It was found that LLM-bound artefacts were more dependent on the deployment method than the LLM model used.

Additionally, a tool was developed to automatically localise LLM artefacts in RAM dumps, demonstrating that automating the extraction process of valuable artefacts is highly feasible. YARA rules were developed which, with 97.5% accuracy, could pinpoint the model present in a memory dump. The invented method demonstrated that it is possible to distinguish different artefacts related to specific LLM execution.

This research contributes to the field of LLM forensics by offering a thorough method and tools for detecting specific LLM usage, thus strengthening forensic investigations and aiding compliance with emerging legislative regulations.

Place, publisher, year, edition, pages
2025.
Keywords [en]
digital forensics, memory forensics, large language model, automation
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:bth-27943OAI: oai:DiVA.org:bth-27943DiVA, id: diva2:1962529
External cooperation
Orange Cyberdefense
Subject / course
Degree Project in Master of Science in Engineering 30,0 hp
Educational program
DVADS Master of Science in Engineering: Computer Security
Supervisors
Examiners
Available from: 2025-06-11 Created: 2025-05-31 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

fulltext(628 kB)362 downloads
File information
File name FULLTEXT01.pdfFile size 628 kBChecksum SHA-512
50fb34b50f16a68bfa6957ae30c8aff46896c93e52b0018fcf0188cdbb2d73415c1dd890724791ff874b15745abc0c6a9a3fd8bb94d0188e8ead340ae1257d5b
Type fulltextMimetype application/pdf

By organisation
Department of Computer Science
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 365 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 922 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf