Explainable Service-Oriented Investigative Intelligence for Automated Digital Evidence Prioritization in Cyber-Financial Crime
This paper proposes an explainable, service-oriented investigative intelligence architecture for national-level cyber-financial crime investigations in law-enforcement environments. The revised architecture specifies concrete service contracts for heterogeneous evidence ingestion, schema normalization, graph-based community analytics, outcome-aware prioritization, and explainable AI (XAI) decision support. It further introduces policy-driven, multi-tenant customization so that different investigative units and crime types can configure feature weights, alert thresholds, data-access rules, and explanation granularity without changing the core service fabric. To strengthen implementation clarity, the paper details the priority inference and XAI service design, including feature-group scoring, model-version control, local and global explanation generation, provenance linkage, and audit logging tied to chain-of-custody records. The evaluation is grounded in more than 2,500 cyber-financial crime cases and is expanded beyond manual comparison to include heuristic, graph-only, and classifier-only baselines, stratified holdout validation, statistical significance testing, and a reproducibility pathway based on anonymized schemas, synthetic benchmark generation, and shareable service-level protocols. The results indicate that EIIA substantially improves top-N concentration of high-impact indicators, reduces time-to-identification, and supports legally defensible, auditable investigative decision-making. Rather than claiming a new fraud-detection algorithm, this work contributes a reference architecture for operationalizing established graph analytics and XAI techniques as composable, trustworthy investigative services under stringent legal and data-governance constraints.