This paper organizes AI forensics around investigator access: white-box, grey-box, and black-box settings. It proposes a process-model matrix spanning collection, preservation, analysis, and reporting, and introduces an order of volatility for AI evidence, from runtime state and context windows to logs, retrieval stores, model artifacts, and training lineage. The paper also identifies open problems including black-box preservation, model-version attestation, uncertainty quantification for surrogate-based analysis, and chain of custody for mutable AI artifacts. Its contribution is primarily a structured framework and research agenda rather than a validated forensic tool.
No heat snapshots are available in the last 24 hours.