Search papers, labs, and topics across Lattice.
This paper establishes a comprehensive framework for AI forensics by categorizing investigator access into white, grey, and black box levels, which significantly influences the processes of collection, preservation, analysis, and reporting of AI incidents. By introducing a process model matrix and an order of volatility for AI systems, the authors highlight critical aspects such as runtime state and model artifacts that need to be considered during investigations. The study identifies key research gaps, including challenges in black box preservation and uncertainty quantification, paving the way for more robust forensic practices in AI.
Understanding how different access levels to AI systems can drastically alter forensic investigations reveals critical gaps in current methodologies.
AI systems are increasingly involved in decisions and actions that may later require investigation. When an AI related incident occurs, investigators need to reconstruct what the system did, why it behaved that way, and which part of the system or supply chain contributed to the outcome. Existing work on AI forensics remains fragmented, often focusing on a specific system type, artifact, or analysis technique. This paper argues that investigator access is a useful starting point for organizing the field. We distinguish white box, grey box, and black box access and show how each access level changes what can be collected, preserved, analyzed, and reported. Based on this distinction, we propose a process model matrix for AI forensics across four phases: collection, preservation, analysis, and reporting. We also introduce an order of volatility for AI systems, covering runtime state, context windows, logs, retrieval stores, model artifacts, and training lineage. From this matrix, we derive an access conditioned examination framework and identify open research problems, including black box preservation, model version attestation, uncertainty quantification for surrogate based analysis, and chain of custody for mutable AI artifacts.