A three-month pilot at the Netherlands Forensic Institute is reported, in which 50 forensic and support staff used Robin, a ChatGPT-4o instance hosted in a Trusted Cloud environment of the Dutch Ministry of Justice and Security, governed by a Data Protection Impact Assessment and a GDPR-compliant processing agreement.
Abstract
Large Language Models (LLMs) such as ChatGPT promise efficiency gains in routine text-based work, but their use in forensic settings raises challenges for confidentiality, governance, and forensic validation. Prior studies have evaluated LLMs on single tasks within single forensic disciplines, leaving open the question under which conditions such models can be embedded in the day-to-day workflows of a forensic institute. This paper reports a three-month pilot at the Netherlands Forensic Institute, in which 50 forensic and support staff used Robin, a ChatGPT-4o instance hosted in a Trusted Cloud environment of the Dutch Ministry of Justice and Security, governed by a Data Protection Impact Assessment and a GDPR-compliant processing agreement. We report user-experienced applications gathered from semi-structured interviews, walk-in sessions, and follow-up mini-projects, and group them into three recurring categories: generating new text, reducing larger inputs to relevant information, and transforming text between styles, languages, or representations. Participants found Robin most useful for low-risk writing support, while expectations quickly extended towards system integration, document-grounded retrieval, coding assistance, and case-oriented support. We also discuss the technical, organisational, ethical, and legal conditions for sustainable deployment, and argue that workflow support and forensic reasoning require different levels of human oversight and discipline-specific validation. The pilot is presented as an exploratory institutional case study rather than as a performance evaluation of an LLM for forensic analysis.
A maturity rubric is introduced to characterize readiness for LLM integration and a research agenda emphasizing auditability and transparent explanation mechanisms to support safer adoption in SOC workflows is outlined.
Elnaz Rabieinejad, Ali Dehghantanha, F. Zarrinkalam et al.· 0 citations
The use of generative AI technologies in architectural threat modeling automation seems to be a promising alternative to ‘traditional’ formal approaches (e.g., attack-defense trees, domain-specific languages, knowledge graphs, etc.). The main advantage of Large Language Models (LLMs) is that they can work with system a...
Unknown authors· Journal of Superintelligence...· 0 citations
With more than 20,000 Common Vulnerabilities and Exposures (CVEs) reported annually, software vulnerabilities represent a critical cybersecurity challenge. This volume has intensified the demand for automated detection and analysis, motivating the integration of large language models (LLMs) for such tasks. However, exi...
Vishnu Teja Kandalam, Viet Duong, Xiaochang Li et al.· Proceedings of the 32nd ACM...· 0 citations
The findings demonstrate the feasibility of auditable LLM-supported TA through a modular workflow designed to scale to larger datasets, accommodate different LLMs, and support transfer across research domains, with domain adaptation primarily requiring adjustments to the prompting strategy.
Large Language Models (LLMs) introduce serious risks of content misuse, spanning copyright infringement in the legal domain and plagiarism in the ethical and academic domain. Although prior work has studied these risks, researchers and practitioners still need practical ways to audit, interpret, and evidence them. This...
Deng-Hui Zhang, Guangwei Zhang, Dongwon Lee· Proceedings of the 32nd ACM...· 0 citations
This paper formalizes the structure of prompt-injection artifacts, enabling defenders, red teamers, and cyber threat intelligence (CTI) teams to label, compare, and mutate attacks without relying on fragile string matching.
Jeremy McHugh· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.