Scollr summary
What this paper is about
An automated tool is developed that parses, aligns, and visualizes multiple artifacts to reconstruct app-transition flows, confirming its practical applicability to mobile forensic analysis.
Full abstract
Read the full abstract
Smartphone operating systems generate artifacts such as snapshots, state databases, and usage logs to manage application state transitions during app-switching. However, these artifacts differ across operating systems in storage location, format, and retention period, which limits the reproducibility and interpretability of forensic analysis even when the underlying user behavior is identical. Android's Protobuf-serialized records and iOS's KTX-format snapshots further complicate analysis, as their complex structures and limited tool support often necessitate manual processing. This study examines app-switching artifacts on Android and iOS to reconstruct user behavior, focusing on UsageStats, Recent Tasks, and snapshot images on Android, and KnowledgeC.db, applicationState.db, and snapshot artifacts on iOS. We analyze how each platform records temporal information and application state during app-switching, termination, and device reboot, and show that correlation across artifacts enables cross-validation, resolving the resulting inconsistencies. The results reveal discrepancies between UsageStats records and other app-switching artifacts on Android, and missing endDate values and incomplete records during abnormal termination in iOS's KnowledgeC.db. These findings demonstrate that single-artifact analysis can lead to misinterpretation. We further develop an automated tool that parses, aligns, and visualizes multiple artifacts to reconstruct app-transition flows, confirming its practical applicability to mobile forensic analysis.
Direct answer
What can I do from this paper page?
Use this page to scan "Reconstructing user behavior with Android and iOS app‐switching artifacts" quickly: start with the summary and abstract, then check the authors, source, topics, and related papers. From here, open Scollr to follow Digital and Cyber Forensics research, save the paper, or map adjacent work.
Research areas
Follow related topics
Citation
BibTeX
@article{2026Reconstructing,
title = {Reconstructing user behavior with Android and iOS app‐switching artifacts},
author = {성세진 and 김은진 and Sunbum Song and Soojin Kim and Sangeun Lee and Gibum Kim},
journal = {Journal of Forensic Sciences},
year = {2026},
doi = {10.1111/1556-4029.70475},
url = {https://doi.org/10.1111/1556-4029.70475}
}
FAQ
Using this paper in a discovery workflow
How do I find related work for this paper?
Use the related papers and topic links on this page as starting points. In Scollr, you can also open the paper and build a literature map around its references, citing papers, and related work.
How can I keep up with new Digital and Cyber Forensics research papers?
Follow Digital and Cyber Forensics research in Scollr. New papers from the topic flow into a personalized feed, and you can save useful studies to revisit later.
Can I cite this paper from this page?
This page includes a static BibTeX block for Reconstructing user behavior with Android and iOS app‐switching artifacts. Always verify the DOI, source, and publication details against the publisher record before submitting a manuscript.
Follow this research in Scollr
Follow the topics and authors behind this paper, save useful studies, and build a literature map when you are ready to go deeper.
Get the app