Digital and Cyber Forensics Peer reviewed

Forensic data deduplication: A comprehensive survey of methods and challenges for digital investigation

Gunikhan Sonowal, Parag Rughani, Gaurav Gogia

Journal of Forensic Sciences | Sep 25, 2026

Scollr summary

What this paper is about

A five-dimensional forensic taxonomy is proposed that classifies techniques based on granularity, forensic integrity, temporal placement, verification methodology, and scope & scale, and shows that file-level and fixed-block deduplication have the highest DRI scores, indicating that they are optimally suited for forensic adoption.

Full abstract

Read the full abstract

The exponential expansion of digital evidence across traditional computing systems, mobile devices, cloud infrastructures, and IoT ecosystems presents new issues for forensic investigators. Modern forensic acquisitions frequently produce multi-terabyte datasets with substantial inter-case redundancy, which significantly affects storage capacity, processing time, and investigation costs. Data deduplication is a potential approach; however, its use in forensic contexts is limited by special operational requirements, such as total data integrity, court-admissible audit trails, and resistance to anti-forensic manipulation. This paper provides a comprehensive survey and evaluation of forensic data deduplication methods. We propose a five-dimensional forensic taxonomy that classifies techniques based on granularity, forensic integrity, temporal placement, verification methodology, and scope & scale. Using multi-criteria decision analysis, we create a Deduplication Reliability Index (DRI) to compare existing systems to forensic requirements statistically. We also systematically identify six types of adversarial threats particular to forensic deduplication, such as hash collision exploitation, deduplication oracle attacks, and reference mapping manipulation. Our analysis shows that file-level and fixed-block deduplication have the highest DRI scores (4.35-4.30), indicating that they are optimally suited for forensic adoption, whereas semantic, probabilistic, and lossy techniques score less than 3.0 due to poor verification and integrity assurances. The report concludes by proposing crucial research goals, such as standardized validation frameworks, adversarial-resilient deduplication structures, and efficient zero-knowledge verification algorithms for forensics.

Direct answer

What can I do from this paper page?

Use this page to scan "Forensic data deduplication: A comprehensive survey of methods and challenges for digital investigation" quickly: start with the summary and abstract, then check the authors, source, topics, and related papers. From here, open Scollr to follow Digital and Cyber Forensics research, save the paper, or map adjacent work.

Authors

Researchers on this paper

Gunikhan Sonowal

first | National Forensic Sciences University | ORCID 0000-0001-5626-2411

Parag Rughani

middle | National Forensic Sciences University

Gaurav Gogia

last | ORCID 0000-0003-2121-7500

Research areas

Follow related topics

Citation

BibTeX

@article{Sonowal2026Forensic,
  title = {Forensic data deduplication: A comprehensive survey of methods and challenges for digital investigation},
  author = {Gunikhan Sonowal and Parag Rughani and Gaurav Gogia},
  journal = {Journal of Forensic Sciences},
  year = {2026},
  doi = {10.1111/1556-4029.70480},
  url = {https://doi.org/10.1111/1556-4029.70480}
}

FAQ

Using this paper in a discovery workflow

How do I find related work for this paper?

Use the related papers and topic links on this page as starting points. In Scollr, you can also open the paper and build a literature map around its references, citing papers, and related work.

How can I keep up with new Digital and Cyber Forensics research papers?

Follow Digital and Cyber Forensics research in Scollr. New papers from the topic flow into a personalized feed, and you can save useful studies to revisit later.

Can I cite this paper from this page?

This page includes a static BibTeX block for Forensic data deduplication: A comprehensive survey of methods and challenges for digital investigation. Always verify the DOI, source, and publication details against the publisher record before submitting a manuscript.

Follow this research in Scollr

Follow the topics and authors behind this paper, save useful studies, and build a literature map when you are ready to go deeper.

Get the app