Ontology & Graphs

Loading cases…

CASE
Scroll to zoom · Drag nodes · Click to inspect
About this research

The ontology helps us explore what patterns sit across CaseLinker data: how platforms are misused, how exploitation and enforcement unfold at scale, and where intervention can close gaps sooner. The CAC graphs on this page are the research foundation on which platform-based and intervention-based analysis is built.

The Ontology Pipeline

To answer relational and analytical questions at corpus scale, enforcement narratives cannot stay only in relational tables and regex-derived tags. They must be expressed in a structured, graph-interoperable format so patterns can be queried, validated, and compared across cases. CaseLinker already extracts consistent features from each narrative; the ontology pipeline maps those features into a standard investigation vocabulary and builds a validated knowledge graph as the mechanism for cross-case analysis.

The vocabulary is the CAC Ontology (Crimes Against Children Ontology), developed by Project VIC International as an interoperable standard for structuring crimes-against-children investigations.

What is CAC Ontology

The stack is layered. gUFO provides foundational ontology primitives. UCO (Unified Cyber Ontology) models cyber investigation objects and relationships. CASE (Cyber-investigation Analysis Standard Expression) defines how investigation narratives are expressed as interoperable graphs. CAC extends that stack for crimes against children specifically — platforms, victims, offenders, investigations, and outcomes as typed entities rather than free text.

CAC is shepherded by Project VIC International, built on the Linux Foundation's Cyber Domain Ontology stack (UCO and CASE). CaseLinker case data is aligned to this vocabulary so graphs can be shared, validated, and queried with the same tools used in forensic and intelligence workflows.

The pipeline

  1. Deterministic case features — already extracted and stored (platforms, topics, investigation signals, prosecution outcomes, and related structured fields).
  2. Mapping layer — deterministic translation from CaseLinker fields to CAC Ontology entities and relationships.
  3. RDF emission — per-case graphs serialized as Turtle and JSON-LD.
  4. SHACL validation — each graph checked against CAC shape rules so only conformant assertions enter the corpus graph.
  5. SPARQL-queryable corpus — merged validated graphs become the substrate for cross-case analysis (GET|POST /sparql).

Phase 3 — Noesis

Q1–Q3 and the Affordances for Harm (AfH) framework are grounded in the ICAC/CSEA domain. Phase 3, completed in the forked repo CaseNoesis (with a live deployment), tests the boundary of those observations and extends the framework across a wider range of offense types.

Phase 2 is complete. Preprint: doi.org/10.5281/zenodo.21347781. Last updated July 15, 2026.