TrollMagnifier: Detecting State-Sponsored Troll Accounts on Reddit

TrollMagnifier: Detecting State-Sponsored Troll Accounts on Reddit
复制标题

DOI:
10.1109/sp46214.2022.9833706
复制
发表时间:
2021-12
期刊:
2022 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Mohammad Hammas Saeed;Shiza Ali;Jeremy Blackburn;Emiliano De Cristofaro;Savvas Zannettou;G. Stringhini
Mohammad Hammas Saeed;Shiza Ali;Jeremy Blackburn;Emiliano De Cristofaro;Savvas Zannettou;G. Stringhini
中科院分区:
其他
文献类型:
--
作者:
Mohammad Hammas Saeed;Shiza Ali;Jeremy Blackburn;Emiliano De Cristofaro;Savvas Zannettou;G. Stringhini

文献摘要

被引文献

相似文献

越来越多的证据表明,社交媒体上的影响力活动经常出现,这些活动通常由国家行为者赞助,旨在操纵敏感政治话题的公众舆论。通常情况下,活动是通过被称为巨魔帐户的工具帐户执行的;尽管它们很突出,但是,在野外检测这些帐户的工作很少。在本文中,我们提出了TROLLMAGNIFIER,一个检测系统的巨魔帐户。根据对Reddit确定的已知俄罗斯赞助的巨魔账户的分析,我们的主要观察结果是,他们表现出松散的协调,经常相互互动以进一步具体的叙述。因此,由同一个参与者控制的巨魔账户通常显示出可以用于检测的相似性。TROLLMAGNIFIER学习已知巨魔帐户的典型行为,并识别更多类似行为。我们在一组335个已知的巨魔账户上训练TROLLMAGNIFIER,并在Reddit账户的大型数据集上运行它。我们的系统识别了1,248个潜在的巨魔账户;然后我们提供了多方面的分析来证实我们分类的正确性。特别是,66%的检测到的帐户显示出被恶意行为者操纵的迹象(例如,他们是在同一天创建的一个已知的巨魔,他们已经被Reddit暂停等)。他们还讨论了与已知巨魔账户相似的主题,并在其活动中展示了时间同步。总的来说,我们表明,使用TROLLMAGNIFIER,可以将Reddit提供的潜在巨魔的初始知识增长超过300%。
Growing evidence points to recurring influence campaigns on social media, often sponsored by state actors aiming to manipulate public opinion on sensitive political topics. Typically, campaigns are performed through instrumented accounts, known as troll accounts; despite their prominence, however, little work has been done to detect these accounts in the wild. In this paper, we present TROLLMAGNIFIER, a detection system for troll accounts. Our key observation, based on analysis of known Russian-sponsored troll accounts identified by Reddit, is that they show loose coordination, often interacting with each other to further specific narratives. Therefore, troll accounts controlled by the same actor often show similarities that can be leveraged for detection. TROLLMAGNIFIER learns the typical behavior of known troll accounts and identifies more that behave similarly. We train TROLLMAGNIFIER on a set of 335 known troll accounts and run it on a large dataset of Reddit accounts. Our system identifies 1,248 potential troll accounts; we then provide a multi-faceted analysis to corroborate the correctness of our classification. In particular, 66% of the detected accounts show signs of being instrumented by malicious actors (e.g., they were created on the same exact day as a known troll, they have since been suspended by Reddit, etc.). They also discuss similar topics as the known troll accounts and exhibit temporal synchronization in their activity. Overall, we show that using TROLLMAGNIFIER, one can grow the initial knowledge of potential trolls provided by Reddit by over 300%.