GeoForensic-AI: A Lightweight and Explainable Forensic AI Framework for Modern Digital Ecosystems
Aravindhan Manivannan, Anthoniraj Amalanathan · IEEE Access · 2026
Modern digital ecosystems are becoming increasingly complex and heterogeneous, necessitating sophisticated forensic frameworks to contend with effective post-incident analytical tasks. This paper presents a new lightweight and explainable framework that combines state-of-the-art Explainable AI (XAI) methods, federated learning,causal inference, and privacy-preserving techniques to improve forensic analysis and computational efficiency with a lightweight, modular, and deployment-ready design. In the present framework, geo-location tagged event traces are utilised to improve detection accuracy, and attack chains are reconstructed by utilising causal graphs. The framework is designed to be scalable and adaptable and is built for hybrid and standalone deployment modes to integrate seamlessly with current Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) infrastructure. This paper validated multiple benchmark datasets (UNSW-NB15, CICIDS2017, NSL-KDD, TON-IoT, and Bot-IoT), and showed robust and effective performance against a multitude of network environments and attack types.The framework achieves a weighted-average detection accuracy of 98.1% (F1: 95.9%) across five benchmark datasets (UNSW-NB15, CICIDS2017, NSL-KDD, TON-IoT, and Bot-IoT), outperforming existing systems including XAI (90%), Log-driven anomalies (87%), and DFIRChain (83%). The framework achieves a per-event detection latency of 2.3-2.8 seconds with an explainability score of 0.91-0.96 and a memory footprint of only 62 MB, compared to 89-210 MB for competing frameworks. Geo-location tagged event traces improve detection accuracy, and attack chains are reconstructed using causal graphs. The framework integrates federated learning (FedAvg,DP-FedProx) with differential privacy (ε = 1.0, δ = 10−5) for privacy-preserving collaborative analysis across institutions. The ablation study confirms that all four principal components such as causal graphs, SHAP-based explainability, federated learning, and snapshot integrity contribute materially to overall system performance.