通过用户行为模式识别社交操控者,比分析内容更有效。
Beyond Content: Behavioral Policies Reveal Actors in Information Operations
- 将用户行为建模为序列决策过程,捕捉隐藏的操纵特征。
- 检测恶意账号的平均准确率高达94.9%,优于内容分析方法。
- 适合反虚假信息团队与平台安全研究者使用。
在线影响力操作的检测传统上依赖内容分析或网络特征,但随着生成模型产生逼真文本、平台限制行为数据访问、攻击者转向监管较弱空间,这些方法日益失效。本文提出一种平台无关的框架,通过建模用户行为策略来识别恶意账号,将用户活动视为序列决策过程。在包含99个与俄罗斯互联网研究机构相关的Reddit账号(2017年透明度报告)的12,064名用户中,分析了2015至2018年间超过3800万条行为记录。基于行为的表征方法(关注用户如何行动而非发布什么内容)在检测恶意账号方面持续优于内容模型。在区分操纵型账号(如水军)与普通用户时,策略类分类器达到中位宏F1为94.9%,高于文本嵌入的91.2%。政策特征还能实现更早发现,且在规避策略或数据损坏下表现更稳定。结果表明,行为动态在俄方关联活动中编码了稳定的可判别信号,为合成内容时代下的鲁棒检测提供了新方向。
原文摘要 · Abstract (English)
The detection of online influence operations -- coordinated campaigns by malicious actors to spread narratives -- has traditionally depended on content analysis or network features. These approaches are increasingly brittle as generative models produce convincing text, platforms restrict access to behavioral data, and actors migrate to less-regulated spaces. We introduce a platform-agnostic framework that identifies malicious actors from their behavioral policies by modeling user activity as sequential decision processes. We apply this approach to 12,064 Reddit users, including 99 accounts linked to the Russian Internet Research Agency in Reddit's 2017 transparency report, analyzing over 38 million activity steps from 2015-2018. Activity-based representations, which model how users act rather than what they post, consistently outperform content models in detecting malicious accounts. When distinguishing trolls -- users engaged in coordinated manipulation -- from ordinary users, policy-based classifiers achieve a median macro-F1 of 94.9\%, compared to 91.2\% for text embeddings. Policy features also enable earlier detection from short traces and degrade more gracefully under evasion strategies or data corruption. These findings show that behavioral dynamics encode stable, discriminative signals of manipulation on Reddit's IRA-linked campaign, and point to resilient detection strategies in the era of synthetic content and limited data access.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。