{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T10:14:13Z","timestamp":1783764853182,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":28,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819228584","type":"print"},{"value":"9789819228591","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,12]],"date-time":"2026-07-12T00:00:00Z","timestamp":1783814400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,12]],"date-time":"2026-07-12T00:00:00Z","timestamp":1783814400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-981-92-2859-1_1","type":"book-chapter","created":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T10:05:32Z","timestamp":1783764332000},"page":"3-18","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Holmes: Forensic-Aware Design and Evaluation of Large Language Models for Procedurally Constrained Digital Investigations"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-1618-3565","authenticated-orcid":false,"given":"Khalid","family":"Farhan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4382-0757","authenticated-orcid":false,"given":"Yuekang","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0380-3506","authenticated-orcid":false,"given":"Jingling","family":"Xue","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,12]]},"reference":[{"key":"1_CR1","unstructured":"Association of Chief Police Officers (ACPO) of England, Wales and Northern Ireland: ACPO good practice guide for digital evidence (2012) (2011). https:\/\/www.digital-detective.net\/digital-forensics-documents\/ACPO_Good_Practice_Guide_for_Digital_Evidence_v5.pdf, version 5.0"},{"key":"1_CR2","doi-asserted-by":"crossref","unstructured":"Bender, E.M., Gebru, T., McMillan-Major, A., Shmitchell, S.: On the dangers of stochastic parrots: can language models be too big? In: Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency (2021). https:\/\/api.semanticscholar.org\/CorpusID:262580630","DOI":"10.1145\/3442188.3445922"},{"key":"1_CR3","doi-asserted-by":"publisher","DOI":"10.1016\/j.fsidi.2025.301932","volume":"53","author":"F Breitinger","year":"2025","unstructured":"Breitinger, F., Studiawan, H., Hargreaves, C.: SoK: timeline based event reconstruction for digital forensics: terminology, methodology, and current challenges. Forensic Sci. Int. Digit. Invest. 53, 301932 (2025). https:\/\/doi.org\/10.1016\/j.fsidi.2025.301932","journal-title":"Forensic Sci. Int. Digit. Invest."},{"key":"1_CR4","first-page":"1877","volume":"33","author":"TB Brown","year":"2020","unstructured":"Brown, T.B., Mann, B., Ryder, N., Subbiah, M., Kaplan, J., et al.: Language models are few-shot learners. Adv. Neural. Inf. Process. Syst. 33, 1877\u20131901 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"1_CR5","unstructured":"Carrier, B.: File System Forensic Analysis. Addison-Wesley Professional (2005)"},{"key":"1_CR6","unstructured":"Casey, E.: Digital Evidence and Computer Crime: Forensic Science, Computers and the Internet, 3 edn. Academic Press (2011)"},{"key":"1_CR7","unstructured":"Casey, E.: Handbook of Digital Forensics and Investigation. Academic Press (2020)"},{"key":"1_CR8","doi-asserted-by":"crossref","unstructured":"Farber, S.: AI as a decision support tool in forensic image analysis: a pilot study on integrating large language models into crime scene investigation workflows. J. Forensic Sci. 70, 932\u2013943 (2025). https:\/\/api.semanticscholar.org\/CorpusID:277593930","DOI":"10.1111\/1556-4029.70035"},{"key":"1_CR9","doi-asserted-by":"publisher","first-page":"S64","DOI":"10.1016\/j.diin.2010.05.009","volume":"7","author":"SL Garfinkel","year":"2010","unstructured":"Garfinkel, S.L.: Digital forensics research: the next 10 years. Digit. Investig. 7, S64\u2013S73 (2010)","journal-title":"Digit. Investig."},{"key":"1_CR10","unstructured":"Guo, Z., et al.: Evaluating large language models: a comprehensive survey. arXiv preprint arXiv:2310.19736 (2023)"},{"key":"1_CR11","doi-asserted-by":"crossref","unstructured":"Huang, L., et al.: A survey on hallucination in large language models: principles, taxonomy, challenges, and open questions. ACM Trans. Inf. Syst. 43, 1\u201355 (2023). https:\/\/api.semanticscholar.org\/CorpusID:265067168","DOI":"10.1145\/3703155"},{"key":"1_CR12","doi-asserted-by":"crossref","unstructured":"Ji, Z., et al.: Survey of hallucination in natural language generation. ACM Comput. Surv. 55(12) (2023)","DOI":"10.1145\/3571730"},{"key":"1_CR13","doi-asserted-by":"crossref","unstructured":"Kent, K., Chevalier, S., Grance, T., Dang, H.: Guide to integrating forensic techniques into incident response. Special Publication 800-86, National Institute of Standards and Technology (NIST) (2006)","DOI":"10.6028\/NIST.SP.800-86"},{"key":"1_CR14","unstructured":"Lin, C.Y.: Rouge: a package for automatic evaluation of summaries. In: Text Summarization Branches Out: Proceedings of the ACL Workshop (2004)"},{"key":"1_CR15","doi-asserted-by":"crossref","unstructured":"Maynez, J., Narayan, S., Bohnet, B., McDonald, R.: On faithfulness and factuality in abstractive summarization. In: Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics (ACL) (2020)","DOI":"10.18653\/v1\/2020.acl-main.173"},{"key":"1_CR16","doi-asserted-by":"crossref","unstructured":"Papineni, K., Roukos, S., Ward, T., Zhu, W.J.: Bleu: a method for automatic evaluation of machine translation. In: Proceedings of the 40th Annual Meeting of the Association for Computational Linguistics (ACL) (2002)","DOI":"10.3115\/1073083.1073135"},{"key":"1_CR17","doi-asserted-by":"publisher","unstructured":"Scanlon, M., Breitinger, F., Hargreaves, C., Hilgert, J.N., Sheppard, J.: Chatgpt for digital forensic investigation: the good, the bad, and the unknown. Forensic Sci. Int. Digit. Invest. 46, 301609 (2023). https:\/\/doi.org\/10.1016\/j.fsidi.2023.301609. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266628172300121X","DOI":"10.1016\/j.fsidi.2023.301609"},{"key":"1_CR18","unstructured":"Scientific Working Group on Digital Evidence (SWGDE): Swgde best practices for mobile device evidence collection & preservation, handling, and acquisition (2020). https:\/\/www.swgde.org\/wp-content\/uploads\/2025\/09\/2020-09-17-SWGDE-Best-Practices-for-Mobile-Device-Evidence-Collection-Preservation-Handling-and-Acquisition_v1.2.pdf, version 1.2"},{"key":"1_CR19","doi-asserted-by":"crossref","unstructured":"Sharma, B., Ghawaly, J., McCleary, K., Webb, A.M., Baggili, I.: Forensicllm: a local large language model for digital forensics. Forensic Sci. Int. Digit. Invest. (2025)","DOI":"10.1016\/j.fsidi.2025.301872"},{"key":"1_CR20","doi-asserted-by":"crossref","unstructured":"Shui, R., Cao, Y., Wang, X., Chua, T.S.: A comprehensive evaluation of large language models on legal judgment prediction. In: Conference on Empirical Methods in Natural Language Processing (2023). https:\/\/api.semanticscholar.org\/CorpusID:264288754","DOI":"10.18653\/v1\/2023.findings-emnlp.490"},{"key":"1_CR21","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1038\/s41586-023-06291-2","volume":"620","author":"K Singhal","year":"2023","unstructured":"Singhal, K., Tu, T., Gottweis, J., et al.: Large language models encode clinical knowledge. Nature 620, 172\u2013180 (2023)","journal-title":"Nature"},{"key":"1_CR22","doi-asserted-by":"crossref","unstructured":"Studiawan, H., Breitinger, F., Scanlon, M.: Towards a standardized methodology and dataset for evaluating LLM-based digital forensic timeline analysis. arXiv abs\/2505.03100 (2025). https:\/\/api.semanticscholar.org\/CorpusID:278339066","DOI":"10.1016\/j.fsidi.2025.301982"},{"key":"1_CR23","doi-asserted-by":"crossref","unstructured":"Wang, S., et al.: A novel evaluation benchmark for medical LLMs illuminating safety and effectiveness in clinical domains. NPJ Digit. Med. 9 (2025). https:\/\/api.semanticscholar.org\/CorpusID:280401756","DOI":"10.1038\/s41746-025-02277-8"},{"key":"1_CR24","doi-asserted-by":"crossref","unstructured":"Wei, J., et al.: Chain-of-thought prompting elicits reasoning in large language models. In: Advances in Neural Information Processing Systems (2022)","DOI":"10.52202\/068431-1800"},{"key":"1_CR25","doi-asserted-by":"crossref","unstructured":"Wickramasekara, A., Breitinger, F., Scanlon, M.: SoK: exploring the potential of large language models for improving digital forensic investigation efficiency. Forensic Sci. Int. Digit. Investig. 52, 301859 (2024). https:\/\/api.semanticscholar.org\/CorpusID:268091311","DOI":"10.1016\/j.fsidi.2024.301859"},{"key":"1_CR26","doi-asserted-by":"publisher","unstructured":"Xu, E., Zhang, Y., et al.: Transforming digital forensics with large language models. In: Proceedings of the 33rd ACM International Conference on Information and Knowledge Management (CIKM 2024) \u2014 Tutorial (2024). https:\/\/doi.org\/10.1145\/3627673.3679091. https:\/\/dl.acm.org\/doi\/10.1145\/3627673.3679091","DOI":"10.1145\/3627673.3679091"},{"key":"1_CR27","unstructured":"Yin, Z., et al.: Digital forensics in the age of large language models. arXiv preprint arXiv:2504.02963 (2025)"},{"key":"1_CR28","doi-asserted-by":"crossref","unstructured":"Zhang, H.: The evidentiary value of ai-generated data: a framework for reliability and admissibility. Education and Social Work (2025). https:\/\/api.semanticscholar.org\/CorpusID:279929657","DOI":"10.63313\/ESW.9074"}],"container-title":["Lecture Notes in Computer Science","Knowledge Science, Engineering and Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-2859-1_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T10:05:34Z","timestamp":1783764334000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-2859-1_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,12]]},"ISBN":["9789819228584","9789819228591"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-2859-1_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,12]]},"assertion":[{"value":"12 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"KSEM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Knowledge Science, Engineering and Management","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Beijing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ksem2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ksem2026.rosc.org.cn\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}