<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>European Conference on Information Retrieval, April</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Coordinated Inauthentic Behaviors on YouTube</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Baris Kirdemir</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oluwaseyi Adeliyi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nitin Agarwal</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>COSMOS Research Center</institution>
          ,
          <addr-line>UA Little Rock, Little Rock, AR</addr-line>
          ,
          <country country="US">USA</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2022</year>
      </pub-date>
      <volume>1</volume>
      <fpage>0</fpage>
      <lpage>14</lpage>
      <abstract>
        <p>Online social networks and information consumed by their users have been increasingly targeted and altered by manipulative campaigns in recent years. YouTube is one of the most popular websites in the world. However, most of the existing systems and studies to detect and characterize manipulative influence campaigns focus on other platforms, while very little is known about the potential ways to detect and mitigate such attacks on YouTube. Furthermore, although recent literature is significantly developed in terms of assessing and detecting individual suspicious accounts across online social networks, more research is needed to detect, predict, and characterize large-scale coordinated campaigns in different contexts. This makes the analysis and detection of coordinated suspicious and inorganic activities on the given platform vital for researchers, policymakers, journalists, and more. In this paper, we report our study in progress to assess and characterize such suspicious activity on the level of YouTube channels, combining multiple layers of rolling window correlation analysis, anomaly detection, peak detection, rule-based supervised classification, network feature engineering, and unsupervised clustering approaches. Overall, the experimental dataset amounted to 39 views. The results show that channels exhibiting inauthentic activities are characterized by a relatively lesser number of peaks in their anomaly patterns. However, the magnitude of these peaks is usually higher compared to that of less suspicious channels. Also, coordination assessment based on network structures and features produces promising results for identifying clusters of suspicious behaviors across channels. Coordination, inauthentic behavior, YouTube, anomaly detection, social network analysis, 1 ROMCIR 2022: The 2nd Workshop on Reducing Online Misinformation through Credible Information Retrieval, held as part of ECIR 2022:</p>
      </abstract>
      <kwd-group>
        <kwd>channels</kwd>
        <kwd>936</kwd>
        <kwd>247 videos</kwd>
        <kwd>99</kwd>
        <kwd>415</kwd>
        <kwd>476 comments</kwd>
        <kwd>115</kwd>
        <kwd>825</kwd>
        <kwd>225 subscribers and over 51 billion</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Coordinated inauthentic campaigns use a wide variety of tactics, techniques, and procedures (TTPs)
to manipulate information as well as networks of communication across social media platforms. Given
their potential as well as proven effects on human behavior, beliefs, emotions, and attitude, such
campaigns lead to social, political, economic, financial, and psychological harm, covering both online
and offline realms. Within the last decade, many studies have used a variety of computational methods
to describe, explain, and predict inauthentic activities and manipulative campaigns online, with a special
focus on the detection and characterization of social media accounts [
        <xref ref-type="bibr" rid="ref18 ref5 ref9">5, 9, 18</xref>
        ], dynamics of
disinformation diffusion [
        <xref ref-type="bibr" rid="ref6">6, 30, 34</xref>
        ], characterization of TTPs and narratives [
        <xref ref-type="bibr" rid="ref1 ref4">1, 4, 24, 32</xref>
        ], and
assessment of their broader implications. In particular, a significant portion of such data-driven systems
and scientific research aimed to detect automated or semi-automated social media accounts.
Nevertheless, the literature and existing counter-disinformation toolkits still lack comprehensive
approaches that would enable a better understanding of how coordinated inauthentic campaigns occur
and how they can be assessed, characterized, and detected on less-studied yet popular and influential
social media platforms.
      </p>
      <p>2022 Copyright for this paper by its authors.</p>
      <p>
        YouTube, as one of the most popular social media platforms across the world, has been a particularly
influential medium of choice for video sharing, news consumption, content monetization, political
activism, and cross-platform information dissemination. Thus, for many inauthentic, hostile, and
coordinated manipulation campaigns, the platform constitutes an important channel [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. Coordinated
manipulative activities often involve inorganic boosting of explicit engagement metrics such as views,
likes, and comments, as such services are also provided openly or in the online black markets by many
commercial entities [28]. However, due to a variety of reasons (i.e., data availability), most of the
existing scientific literature and systems for countering online information manipulation focus or rely
on data collected from other platforms, such as Twitter, that have a significantly different platform
architecture in comparison to YouTube.
      </p>
      <p>
        In addition, the timely detection and characterization of coordination remain a significant research
problem overall. Existing literature has documented significant progress in the detection of individual
automated accounts (social bots, mostly on Twitter) and characterization of disinformation events by
tracing their artifacts and historical data. On the other hand, cross-campaign variety of TTPs and
evolving technologies of manipulation decrease the performance, effectiveness, and accuracy of
approaches focusing on individual actors and automated accounts. Behavioral and content-based
characteristics of individual accounts change over time and across campaigns, leading to a drop of
performance in machine learning systems. Also, coordinated information manipulation includes both
human and automated accounts with varying distributions. Therefore, as also argued by Cresci [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] and
Khaund et al. [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ], future studies should move beyond the current approaches and improve the
understanding and timely detection of anomalous coordination.
      </p>
      <p>In this paper, we present our study in progress for the characterization of coordinated inauthentic or
suspicious behaviors on YouTube. Using a sample of YouTube channels and their historical data, we
explore the performance and utility of two distinct but interrelated methodological approaches in the
prediction of suspicious coordinated activity on the channel level. First, we demonstrate a multi-step
time-series analysis of engagement trends and a combination of unsupervised and supervised machine
learning experiments. Second, we use co-commenter networks as an implicit artifact of coordination
and build a set of features that would signal high-level coordination and suspicious behavior.
Furthermore, we report and discuss the initial findings of unsupervised clustering of YouTube channels
based on a time series analysis of engagement trends and network features. We posit that by improving
the current understanding of coordinated suspicious activities and their artifacts, our study may lead to
the development of an accurate and effective methodology for the timely detection of harmful
manipulative campaigns on YouTube. Next, we introduce a survey of relevant literature.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related Work</title>
      <p>
        YouTube is one of the most popular online social media platforms for disseminating information,
but it has also been exploited by bad actors for spreading false or misleading narratives [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
Researchers have studied disinformation campaigns on various social media platforms, associated
narratives [31], and their influence on human behavior [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Recent studies have extended this research
into YouTube, analyzing crowd manipulation strategies on the platform [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. In a bid to uncover
inorganic behaviors within YouTube channels, the researchers analyzed the video posting behavior of
a YouTube channel with conspiracy theory videos as well as its user engagement statistics. YouTube’s
policy states that the platform does not permit any activities that increase the number of views, likes,
comments, or other metrics artificially, either by serving videos to unsuspecting viewers or through
other automated systems [36]. However, these activities have grown in popularity on YouTube in recent
years, increasing the engagement statistics of some channels and fueling disinformation campaigns.
The problem is compounded when such behaviors tap into the biases of a platform’s search and
recommendation algorithms [
        <xref ref-type="bibr" rid="ref19 ref20">19, 20</xref>
        ].
      </p>
      <p>
        Dutta et al. analyzed collusive entities on YouTube, studying black market services and fraud/spam
detection on online media platforms [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. The researchers studied a major black-market service used to
gain appraisals inorganically for YouTube channels, from video views to likes, subscribers, and
comments. They also investigated spam comments from a collusion perspective. The popularity of
YouTube videos is dependent on the amount of implicit and explicit engagement it receives from the
content consumers and with the advent of monetization on the platform, some content creators are
motivated to use inorganic means to get appraisals for their content. Our research, however, does not
study the motivations of the content creators, but the inauthentic behaviors exhibited by the YouTube
channels and utilize tactics towards gaining inorganic engagement. These behaviors are uncovered
through the analysis of user engagement statistics and network data from YouTube channels.
      </p>
      <p>
        Recent literature indicates that the study of coordination would enable an improved understanding
and more accurate characterization of modern manipulative information campaigns. Starbird et al. [29]
argue that a significant portion of modern information manipulation campaigns is "participatory” and
"collaborative" in nature, using target audiences also for further dissemination of amplified narratives.
Moreover, modern information campaigns exhibit organizational and structural variance leading to
changing characteristics of information dissemination. Kumar et al. [22], Hine et al. [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], and Cresci
[
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] demonstrate the significance of group-level coordination in the study of inauthentic and
manipulative information campaigns. Recently documented coordination assessment methodologies
also focused on inauthentic boosting of web links [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ], mass astroturfing [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ], and other deviant
moblike behaviors that interfere in political processes or dissemination of health-related information [
        <xref ref-type="bibr" rid="ref13">13,
26</xref>
        ].
      </p>
      <p>Recent studies proposed several network-based approaches to examine coordination, with varying
levels of maturity and readiness for training machine learning/classification models. Pacheco et al. [25]
introduced an unsupervised and network structure-based methodology to detect coordinated
communities on social media. The authors used a multi-step network analysis approach to uncover
tightly knit clusters signaling coordination. Weber and Neumann [35] proposed a temporal window
approach using user account interactions and metadata. They focus on group-level activity, “regardless
of their degree of automation”, that exhibits “anomalously high levels of coordinated behavior”. Using
a set of coordination behavior artifacts, they present a slightly different version of the previously
reported FSA algorithm [27], FSA V, to distinguish Highly Coordinated Communities (HCCs) from
the rest of the network. They validate the results of the given approach with three supervised classifiers
to compare HCCs between campaigns and with ground truth data.</p>
      <p>Moving beyond the detection of individual accounts to campaign-level activities, Vargas et al. [33]
demonstrated one of the very few studies testing the feasibility of coordination network analysis and
features to detect coordinated disinformation campaigns on Twitter. They trained a binary classifier to
detect “Strategic Information Operations” (Twitter) against baseline activity of various “legitimate”
coordinated networks. They established the baseline activity from “communities exhibiting varying
levels of coordination” rather than random topic networks of Twitter accounts, aiming to have a better
representation of real-world campaigns. Their results showed that supervised classifiers based on
coordination network features perform well in predicting future instances of "same" coordinated
campaigns. However, the performance scores drop significantly when predicting previously unseen
campaigns, indicating the significance of the cross-campaign variety of tactics employed in information
operations [33].</p>
      <p>This study offers multiple original contributions to the existing literature. As stated in the previous
sections, the existing literature still lacks an overarching methodological framework that would enable
the assessment, characterization, and detection of coordinated suspicious behaviors on YouTube. Also,
due to YouTube’s unique platform architecture and its black-box characteristics, coordinated suspicious
activity on the platform often includes multiple implicit and latent features. The following sections
describe our multi-layered approach to tackling the given problem. We also present the initial results of
the documented methodology and their potential implications for future work on the timely detection
of such campaigns.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Data and Methods</title>
      <p>To uncover channel-level suspicious activity on YouTube, we employed two primary methodologies
consisting of a multi-step time-series analysis of engagement trends and the analysis of structural
properties of co-commenter networks as potential artifacts of coordinated suspicious behavior. For the
first, we processed metrics of video production and engagement (number of video postings, number of
views, number of comments, and number of channel subscribers) through a multi-step analytical
pipeline including rolling window correlation analysis, anomaly detection, peak detection, rule-based
classification, principal component analysis (PCA), and unsupervised clustering. Second, we
constructed co-commenter networks using the comment data collected from YouTube channels and
explored the utility of network structural features (group-level features, in particular) in the
identification of suspicious clusters of YouTube channels.
3.1.</p>
    </sec>
    <sec id="sec-4">
      <title>Data Collection</title>
      <p>
        We used the VTracker tool [23] and procedures described in Kready et al. [21] for collecting the
number of daily video postings, the number of comments, and comment-specific data (comment
content, commenter id, commented video id, timestamps), using the YouTube Data API [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. These data
were collected in accordance with YouTube’s Terms of Service and data collection guidelines [37]. To
collect daily subscriber counts and the number of daily video views we used Social Blade API [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]
which also provides public YouTube data in accordance with YouTube’s guidelines [38]. Overall, our
experimental dataset consisted of 39 YouTube channels. The topical categories in the experimental
dataset included news, defense and security, education, and entertainment, while the activity timeline
ranged from November 2017 to July 2021. The categorical variety of the experimental channels ranged
from highly popular news sources (Fox News, CNN) to football clubs (Barcelona FC) and suspicious
channels previously discovered as actively engaging in geopolitical influence campaigns [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. Data
preprocessing included the elimination of missing values in engagement metrics, computation of the
total number of views, the total number of subscribers, the total number of comments, and the total
number of video postings for each channel. In addition, we used anonymized commenter ids and video
ids for building the co-commenter networks, as discussed in the following sections.
      </p>
    </sec>
    <sec id="sec-5">
      <title>Characterization based on Engagement Trends</title>
      <p>Rolling window Correlation Analysis. We grouped the data into rolling windows of 100 days and
computed the pairwise correlation between total views, total subscribers, total comments, and total
videos for each window. This was done to capture inauthentic behaviors such as a channel with
decreasing subscribers but increasing views or, conversely, increasing subscribers but decreasing views.
The resulting data comprised start and end dates for each window, with the values of the correlation
pairs - views and subscribers, views and videos, views and comments, subscribers and videos,
subscribers and comments, videos and comments.</p>
      <p>Anomaly Detection. The output of the rolling window correlation analysis was used to train a long
short-term memory (LSTM) model on the time series data. The LSTM model was run through each
dataset with the Mean Squared Error loss function and Adam optimizer for loss function optimization.
A batch size of 32 was used due to the size of each dataset (approximately 1000 data points), with a
lookback size of 1. This lookback size was selected because a single data point represented a window
of 100 days. Each model was then trained over 30 epochs, with an average training loss of 13%. We
represented the losses from the computation as anomaly confidence scores and plotted the output on a
2-D plot. Figure 1 shows the sample output of the anomaly detection step for a channel; on the left we
see a steady pattern in the correlation between the views and subscribers statistics for the channel and
on the right, a peak can be seen in the correlation between the views and videos statistics within the
period of September 2019 and January 2020. This strong peak indicates an anomaly in the correlation
between the views and videos. To capture these anomalous periods, we set an anomaly threshold (based
on the anomaly confidence score) for each channel’s correlation pairs to capture all data points that
were placed above that threshold.</p>
      <p>The given procedure resulted in an anomaly list for each channel capturing the channel id, start and
end dates, duration (of the anomalous period), minimum correlation, and maximum anomaly score for
all six correlation pairs (also referred to as indicators).</p>
      <p>Peak Detection. We used the SciPy library [28] which takes a 1-D array and finds all local maxima
by comparing neighboring values to detect the peaks in the data represented by the 2D plot from the
anomaly detection. As a result of the noise in the chart, a lot of peaks were being detected. Hence, we
applied smoothening to the data to reduce noise and capture the significant peaks. Figure 2 shows the
peaks after smoothening. We then analyzed the number and intensity of the peaks across all the
channels, characterizing peaks from very high intensity to very low intensity.</p>
      <p>Rule-based Classification. As a result of YouTube’s actions on channels that exhibit inauthentic
behaviors, obtaining a validation set comprising such channels could be a challenging task as these
channels are sometimes taken down without a reason known to the public. Therefore, based on the
features generated from the anomaly detection step, we annotated the dataset and created a rule-based
classification algorithm to determine a suspicion score for each indicator, with a range of (0,1) where 0
represents the least suspicious and 1 represents the most suspicious. The suspicion scores across all six
indicators were then aggregated (by assigning weights to each indicator) to create a single suspicion
score for each observation. Table 3 explains the weights assigned to each indicator based on their
respective importance in detecting inauthentic behaviors. We determined these weights by examining
the semantics behind each indicator and the degree to which a positive and negative correlation between
the indicators points to suspicious behavior on YouTube. The weighting scheme used is explained as
follows:</p>
      <p>Views vs Subscribers: A positive correlation implies that views increased on the channel as
subscribers also increased. This is expected of YouTube channels; however, subscribers may grow at a
slower rate than views, but a positive correlation is still expected. A negative correlation implies that
views decreased on the channel as subscribers increased or vice versa which is unusual behavior for a
channel. While there are cases where unpopular channels upload a viral video, views could increase
drastically while subscribers remain the same or grow at a slower rate compared to views, but rarely do
we see these numbers go in the opposite direction. Therefore, this indicator was assigned a high ranking
for judging inauthentic behavior.</p>
      <p>Views vs Videos: A positive correlation implies that views increased on the channel as videos
increased and vice versa. While a channel might upload multiple videos within a period, the views may
not necessarily increase at the same upload rate and may take longer to catch up. Also, for videos that
go viral, a channel might upload lesser videos for the specific video to gain more views while the video
uploads remain the same. A negative correlation implies that videos decreased while views increased
on a channel, which is plausible for channels that choose to upload lesser videos. It is also possible for
the opposite to occur, where a channel racks up lesser views compared to video uploads. Therefore, this
indicator was assigned a medium ranking for judging inauthentic behavior.</p>
      <p>Views vs Comments: A positive correlation implies that views increased on the channel as
comments increased or vice versa. This is a common scenario as more views are acquired, more user
engagements are expected. However, for a negative correlation, we consider a channel where videos
have been uploaded and views have been acquired, users could engage for longer periods of time even
after the video has stopped gaining views. This is common on YouTube as commenters reply to
comments even when views have stopped growing. Also, some videos could have comments disabled
and still acquire a lot of views. Therefore, this indicator was assigned a low ranking for judging
inauthentic behavior.</p>
      <p>Subscribers vs Videos: A positive correlation implies that subscribers increased on a channel as
videos increased or vice versa. For popular channels that are consistent with uploads, this is a common
pattern as they increase upload rate and acquire more subscribers along the way. For a negative
correlation, we consider a case where a channel could increase uploads but remain on the same number
of subscribers or gain a lesser number of subscribers. There are also cases where viewers watch a video
they like and subscribe to the channel while the channel owner has not uploaded a video in a while.
Therefore, this indicator was assigned a low ranking for judging inauthentic behavior.</p>
      <p>Subscribers vs Comments: A positive correlation implies that comments increased on a channel as
subscribers increased or vice versa. This is common among channels as more user engagement is
expected as the number of subscribers increases (because of more people watching the videos). For a
negative correlation, we consider viral videos or videos recommended by YouTube’s recommendation
algorithm, where user engagement could continue to increase as more people watch the video, but these
viewers may not necessarily subscribe to the channel. Subscribers can also increase with comments
decreasing in a case where comments are disabled for some of these videos. However, these cases are
less common. Therefore, this indicator was assigned a high ranking for judging inauthentic behavior.</p>
      <p>Videos vs Comments: A positive correlation implies that comments increased on a channel as videos
increased or vice versa. This is common among channels as user engagement increases as more videos
are uploaded but in the case of a viral video, comments could increase quicker than more videos are
uploaded to the channel. For a negative correlation, we consider a scenario where engagement could
decrease as more videos are uploaded to a channel because of disabled comments for some videos. The
alternate case of comments increasing while video uploads decrease is also possible but is not always
common. Therefore, this indicator was assigned a high ranking for judging inauthentic behavior.</p>
      <p>These rankings were used to assign weights to each indicator to combine the suspicion scores under
each indicator and arrive at an overall suspicion score. To assign weights to the indicators, we used the
indicator rankings to represent the importance of each indicator and then assigned each indicator a value
representing a fraction of the overall suspicion score. The suspicion score for each indicator was then
multiplied by its weight and summed up to obtain a single suspicion score, with a range of (0,1).</p>
      <p>Principal Component Analysis. The output of the anomaly detection returned anomalous periods
with a large feature set and as a result, we used Principal Component Analysis (PCA) to reduce the
dimensions of the dataset and created a scatterplot using the first two principal components.</p>
      <p>
        Clustering. We visually identified clusters from the PCA scatter plot to group channels based on
their engagement trends. We also utilized DBSCAN, a density-based clustering algorithm, to
automatically identify the channel clusters [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. This was done because of the distribution of the data
points and also to verify that the clusters that were identified manually were computationally accurate.
3.3.
      </p>
    </sec>
    <sec id="sec-6">
      <title>Characterization based on Network Structures</title>
      <p>To trace network artifacts of activity, we built a co-commenter network for each channel in our
experimental list. We assume a connection (edge) between pairs of commenters if they commented on
the same video. To declutter the network and focus on the suspicious network clusters, we filtered out
commenter (node) pairs (low-weight edges) if they co-commented on less than 10 videos. This
threshold number is adjustable in practice. Nevertheless, because of our initial experiments, we fixed
the current threshold for co-commenter pairs to 10 to cover as many channels as possible and include
edges that signal frequent interactivity, while eliminating the random chance of co-commenter pairings.
Nodes are commenters in the final network of co-commenters, and the number of nodes (network size)
varies between different channels. Edges represent the connections between nodes, i.e., co-commenting
behavior of commenters.</p>
      <p>Furthermore, we computed a set of network features in the co-commenter networks that would
potentially enable the detection of suspicious clusters and behavior on the level of YouTube channels.
We combined two major categories of features. The first set of metrics are extracted from the
cocommenter networks by using well-established graph measures, including average degree, number of
nodes, number of edges, average clustering coefficient, and modularity.</p>
      <p>Second, we added an additional set of metrics by computing descriptive statistics and engineering
features in relation to maximal cliques. A clique in a graph is a tightly knit sub-network in which all of
its members are directly connected to each other. In network analysis terms, a maximal clique has the
maximum number of members it can contain and can't be expanded further with additional members in
the recursive computation process. Similar to the threshold we used for co-commenter networks, we
counted maximal cliques only if they have at least five members. We observed a high level of variation
between the channels in our experimental list in terms of the average clique sizes and the total number
of cliques. Although the total number of cliques is correlated with the size of the full co-commenter
graph, the variation of clique sizes implies increased and suspicious network activity in some channels.
Finally, apart from a simple count of maximal cliques, we used additional clique-based features by
computing the average degree of clique members, the average clustering coefficient of clique members,
and the median clique size for each channel. In addition, we included comparative features showing the
relationship between the given clique-based metrics with network measures extracted from the entire
co-commenter network for each channel.</p>
      <p>After building the co-commenter networks and computing the set of network and clique-based
features as described, we ran a feature similarity analysis using the Pearson correlation values.
Furthermore, using an unsupervised approach, we checked the feasibility of PCA, k-means clustering,
and hierarchical clustering methods with normalized feature values to examine if the current set of
network features and well-known clustering and dimensionality reduction algorithms lead to
meaningful clusters of the channels in the experimental list, while also enabling unsupervised detection
of channels with traces of suspicious and coordinated network activity. We note that our current analysis
of co-commenter networks does not include any temporal limitations. In the following phases of this
study, we may also experiment with features extracted from network activity in limited timeframes,
adding a time series aspect to our current approach.</p>
    </sec>
    <sec id="sec-7">
      <title>4. Analysis and Findings</title>
      <p>We discuss our findings in this section. First, we discuss the findings from our engagement
trendbased analysis and then the findings from network structural feature-based analysis will be discussed.
4.1.</p>
    </sec>
    <sec id="sec-8">
      <title>Characterization based on Engagement Trends</title>
      <p>The scatter plot in Figure 3 shows how the observations are spread across the two principal
components with a color map indicating the suspicion score of each observation. The suspicion score
is computed using the method described in Section 3.2. From the scatter plot, we visually identified
five clusters, as detailed in Table 4. This approach characterizes channels not only based on suspicion
but also allows us to identify channels with similar engagement trends and channels that deploy similar
tactics to grow their engagement statistics inorganically. The first cluster comprises mostly news
networks such as CNN, Fox News, BBC News, and more. The third cluster, with the largest number of
suspicious observations, consists of several misinformation-riddled defense channels, prominent in the
Indo-Pacific region. We compared these results with the output from the DBSCAN clustering algorithm
and we discovered the same number of clusters with highly similar cluster configurations as shown in
Figure 4 below.</p>
      <p>This experiment demonstrates that an unsupervised machine learning approach such as DBSCAN
can help achieve the same channel clustering as a manual inspection can, thereby having a potential
value in assisting human analysts. The most suspicious data point within the dataset is CIS News
Network (a channel focused on India, Pakistan, and China relationships) with a suspicion score of 0.43.
On further analysis of this channel, we saw that the channel had about 53,300 subscribers in August
2021, but the channel page shows videos with views running in millions as seen in Figure 5 below.
Videos featured on this channel are pushing false narratives that are factually incorrect. This behavior
was also spotted in a channel (BolongID) within Cluster 3, with a relatively high suspicion score of 0.4.
A further look into this channel revealed a relatively small number of comments, compared to the
number of views and subscribers of the channel. This channel includes videos with geopolitical content
relating to Indonesia and China. As of August 2021, the channel had 670,000 subscribers, 246,465,788
views with a relatively small number of comments (4176), while in January 2022 the number of
subscribers had dropped to 5320, and the view count had dropped to 448,577, showing an anomalous
change in engagement metrics.</p>
      <p>To further reveal the behaviors within the channels, we analyzed the peaks extracted from the output
of the LSTM model across all the channels. Before we applied our developed methodology, we took
note of one channel - Defense Flash News - where we had detected an unusual peak in the daily
subscriber trend in November 2020 (over +50,000 subscribers) that was later corrected by YouTube in
December 2020 by removing suspicious subscribers (over -10,000 subscribers) as shown in Figure 6.
Based on the behavior exhibited by this channel, we compared its anomaly plot generated from the
LSTM model with that of a “well-known” channel - FC Barcelona. Using SciPy, we detected and
represented the peaks within the plot using cross (x) marks as shown in Figures 7 and 8. This process
was repeated across all the channels and we observed that the more suspicious channels had fewer peaks
compared to the less suspicious channels, however, the magnitude of the peaks from the more
suspicious channels were higher.</p>
      <p>To validate this hypothesis, we analyzed the number and intensity of the peaks across each channel,
characterizing peaks from Very high intensity to Very low intensity. The degree of peak intensity was
determined as follows:
• Very high intensity - 2 or more standard deviations above the mean peak
• High intensity - 1 standard deviation above the mean peak
• Moderate intensity - The mean peak
• Low intensity - 1 standard deviation below the mean peak
• Very low intensity - 2 or more standard deviations below the mean peak</p>
      <p>We sorted the channels based on the number of very high peaks and extracted the top 6 channels as
shown in Table 5.
US Military 221 37 7</p>
      <p>Trend
US Military 129 1 32 48 8 12
Channel
PragerU 295 0 34 49 6 11
Defense 123 0 35 43 11 11
Flash News</p>
      <p>Geek &amp; 333 0 33 53 2 11
Sundry
CIS News 359 0 29 56 4 11
Network</p>
      <p>We discovered some similarities between these top channels and the channels with a high suspcion
score from the PCA plot, specifically the channels focused on defense, as well as CIS News Network.
On the other end of the spectrum, Table 6 shows the channels with the least number of very high peaks.
Channels on this spectrum tend to be “well-known” channels less likely to exhibit suspicious activities,
validating our hypothesis.</p>
      <p>High peaks
(percentage)</p>
      <p>Exploring the co-commenter networks and distributions of graph measures and clique-based feature
values we described in Section 3, we observed variation between the channels we experimented with.
Overall, co-commenter networks vary in size. This variation also corresponds with the total number of
cliques, and clique size distributions in each channel. To compute the clique-size distributions, we
simply counted the maximal cliques with each size (n&gt;4) and plotted the final distribution. Accordingly,
some channels have a long tail distribution of clique sizes with most of the cliques having less than 10
members, while several other channels tend to have bigger cliques and size distributions skewed right.
Figure 9 shows the box plot for the median clique size in our experimental list of channels.</p>
      <p>In addition, the feature similarity analysis and Pearson coefficient values show the pairwise
correlation between a small number of features. Although the current sample size is small, the size of
the co-commenter networks (threshold=10) seems to be strongly correlated with the total number of
maximal cliques (n members &gt; 4) in each corresponding co-commenter network. In the initial list of
channels, the number of maximal cliques ranged from 16 to 4.64 million. Similarly, the number of
nodes (co-commenters) ranged from 129 to 38,729. This variation of co-commenting and cliquish
behavior supports our initial assumption that implicit network behaviors may correspond with the level
of suspicious and coordinated behavior in relation to YouTube channels.</p>
      <p>One specific feature that may indicate the level of channel-level suspicious commenter behavior is
the ratio of the number of unique commenters in cliques to the total number of nodes (co-commenters)
in the network. As Figure 11 demonstrates, some co-commenter networks consisted of large numbers
of co-commenters who were also members of maximal cliques. Thus, this feature indicates that on some
channels, a higher number of nodes in the co-commenter network also form fully-knit cliques, signaling
strong coordination.</p>
      <p>Similarly, the modularity of co-commenter graphs showed a wide range of variation between
experimental channels. We observed that, in general, the networks with higher numbers of maximal
cliques tend to have larger modularity. Nevertheless, the pairwise relationship between the modularity
and the total number of maximal cliques is not necessarily linear. This contrasts the pairwise correlation
between the average clustering coefficient (co-commenter network level) and median clique size, which
seems to be more linear on a logarithmic scale.</p>
      <p>Finally, to record the level of the degree difference between cliques and co-commenter networks
overall, we simply divided the average degree of clique members by the average degree in the entire
co-commenter network. Clique members tend to have higher degree centrality in comparison to the
rest of the network. However, the given ratio does not seem to correlate with any other feature, as the
outlier channels signaling suspicious behavior seem to have either very high levels of clique-based
average degree or very high co-commenter participation in cliques. For example, cliques in the channel
with the highest ratio of participation in cliquish behavior (0.68) have an average degree 7.75 times
higher than the entire network. On the other hand, the channel with the highest difference in terms of
the average degree (26 times higher), has only limited participation of co-commenters in cliquish
behavior (0.22).</p>
      <p>Following the exploratory analysis of the co-commenter networks, maximal cliques, and additional
network features we computed using the given pair of categories, we combined the feature similarity
analysis with principal component analysis, k-means clustering, and hierarchical clustering to examine
of the current set of network features lead to meaningful clusters of channels in unsupervised settings.
Given the Pearson correlation coefficients, we first reduced the number of features by removing
multicollinearity above the threshold of 0.88. We then extracted five clusters of channels in a post-PCA
k-means clustering setting. Finally, we also ran a simple hierarchical clustering algorithm in the final
dataset. We observed that both unsupervised approaches extract clusters of similar channels. For
example, post-PCA k-means clustering grouped news channels such as CNN and Fox News together,
while clustering channels signaling high levels of coordinated activity grouped in other corresponding
clusters.</p>
    </sec>
    <sec id="sec-9">
      <title>5. Conclusion and Future Work</title>
      <p>Characterization and detection of coordinated inauthentic campaigns on social media remain an open
and significant problem. In this study, we aimed to explore new approaches to assess the latent and
implicit characteristics of coordination that indicate the manipulation of information and
communication networks on YouTube. We developed computational models to study suspicious and
coordinated inauthentic behaviors exhibited by various channels. These models leverage a multi-step
time-series analysis of engagement trends, network structural feature-based analysis, particularly the
group behavior of co-commenter networks, and a combination of unsupervised and supervised machine
learning experiments. Our models afford identification of suspicious behaviors overall as well as the
precise time periods during which such behaviors are prominent in the channel’s history. Furthermore,
our models allow the identification of coordination among commenters and clusters of YouTube
channels that exhibit similar behavioral profiles.</p>
      <p>The results of our research show that channels exhibiting inauthentic activities are characterized by
a relatively lesser number of peaks in their anomaly patterns. However, the magnitude of these peaks
is usually higher compared to that of less suspicious channels. We also identified clusters of channels
with similar engagement trends which is useful in detecting groups of channels that deploy similar
tactics. In terms of user engagement statistics that characterize inauthentic behaviors in YouTube
channels, the views and subscribers stand out as the most relevant indicator. This could suggest that
channels that grow appraisals inorganically focus more on their views and subscriber count, however
other indicators also characterize inauthentic behaviors. In addition, the models based on co-commenter
networks and tightly knit sub-networks uncover clusters of channels that exhibit similar suspicious
coordination of comments. In future phases, we aim to combine two methodological components and
build a unified source of suspicious behavior signals. We posit that by improving the current
understanding of coordinated suspicious activities and their artifacts, our study may lead to the
development of an accurate and effective methodology for the timely detection of harmful manipulative
campaigns on YouTube.</p>
    </sec>
    <sec id="sec-10">
      <title>6. Acknowledgements</title>
      <p>This research is funded in part by the U.S. National Science Foundation (OIA-1946391,
OIA1920920, IIS-1636933, ACI-1429160, and IIS-1110868), U.S. Office of Naval Research
(N00014-101-0091, N00014-14-1-0489, N00014-15-P-1187, N00014-16-1-2016, N00014-16-1-2412,
N00014-171-2675, N00014-17-1-2605, N68335-19-C-0359, N00014-19-1-2336, N68335-20-C-0540,
N0001421-1-2121, N00014-21-1-2765, N00014-22-1-2318), U.S. Air Force Research Lab, U.S. Army
Research Office (W911NF-20-1-0262, W911NF-16-1-0189), U.S. Defense Advanced Research
Projects Agency (W31P4Q-17-C-0059), Arkansas Research Alliance, the Jerry L. Maulden/Entergy
Endowment at the University of Arkansas at Little Rock, and the Australian Department of Defense
Strategic Policy Grants Program (SPGP) (award number: 2020-106-094). Any opinions, findings,
and conclusions or recommendations expressed in this material are those of the authors and do
not necessarily reflect the views of the funding organizations. The researchers gratefully acknowledge
the support.</p>
    </sec>
    <sec id="sec-11">
      <title>7. References</title>
      <p>In: Thomson R., Hussain M.N., Dancy C., Pyke A. (eds) Social, Cultural, and Behavioral
Modeling. SBP-BRiMS 2021. Lecture Notes in Computer Science, vol 12720. Springer, Cham.
https://doi.org/10.1007/978-3-030-80387-2_7
[21] Kready, Joseph, Muhammad Nihal Hussain, and Nitin Agarwal. YouTube Data Collection Using
Parallel Processing. IEEE Workshop on Parallel and Distributed Processing for Computational
Social Systems (ParSocial 2020), May 22, 2020, New Orleans, Louisiana USA.
[22] Kumar S, Hamilton WL, Leskovec J, Jurafsky D (2018) Community Interaction and Conflict on
the Web. In: Proceedings of the 2018 World Wide Web Conference on World Wide Web
WWW’18, ACM Press, pp 933–943, DOI 10.1145/3178876.3186141
[23] Marcoux, Thomas, Nitin Agarwal, Recep Erol, Adewale Obadimu, and Muhammad Nihal
Hussain. Analyzing Cyber Influence Campaigns on YouTube Using YouTubeTracker. In: Çakırtaş
M., Ozdemir M.K. (eds) Big Data and Social Media Analytics. Lecture Notes in Social Networks.</p>
      <p>Springer, Cham. pp. 101-111. 2021. https://doi.org/10.1007/978-3-030-67044-3_5
[24] Nimmo B, François C, Eib CS, Ronzaud L, Ferreira R, Hernon C, Kostelancik T (2020) Exposing
secondary infektion. Report, Graphika. https://secondaryinfektion.org/
[25] Pacheco, D., Hui, P. M., Torres-Lugo, C., Truong, B. T., Flammini, A., &amp; Menczer, F. (2021,
May). Uncovering Coordinated Networks on Social Media: Methods and Case Studies. In
Proceedings of the International AAAI Conference on Web and Social Media (Vol. 15, pp.
455466).
[26] Schafer, F., Evert, S., &amp; Heinrich, P. (2017). Japan’s 2014 General Election: Political Bots,
RightWing Internet Activism, and Prime Minister Shinz Abe’s Hidden Nationalist Agenda. Big Data,
5(4), 294–309
[27] Şen, F., Wigand, R., Agarwal, N., Tokdemir, S., &amp; Kasprzyk, R. (2016). Focal structures analysis:
identifying influential sets of individuals in a social network. Social Network Analysis and Mining,
6(1), 17.
[28] SciPy documentation — SciPy v1.9.0.dev0+1313.ecb800f Manual. (n.d.). SciPy. Retrieved</p>
      <p>January 22, 2022, from https://scipy.github.io/devdocs/index.html
[29] Singularex, 2019. The Black Market for Social Media Manipulation. Riga: NATO Strategic</p>
      <p>Communications Centre of Excellence.
[30] Starbird, K., Arif, A., &amp; Wilson, T. (2019). Disinformation as collaborative work: Surfacing the
participatory nature of strategic information operations. Proceedings of the ACM on
HumanComputer Interaction, 3(CSCW), 1-26.
[31] Stewart, Leo G, Ahmer Arif, and Kate Starbird. 2018. Examining trolls and polarization with a
retweet network.
[32] U.S. Department of State Global Engagement Center, 2022, Kremlin-Funded Media: RT and</p>
      <p>Sputnik’s Role in Russia’s Disinformation and Propaganda Ecosystem.
[33] Vargas, L., Emami, P., &amp; Traynor, P. (2020, November). On the detection of disinformation
campaign activity with network analysis. In Proceedings of the 2020 ACM SIGSAC Conference
on Cloud Computing Security Workshop (pp. 133-146).
[34] Vosoughi, S., Roy, D., &amp; Aral, S. (2018). The spread of true and false news online. Science,
359(6380), 1146-1151
[35] Weber, D., &amp; Neumann, F. (2021). Amplifying influence through coordinated behaviour in social
networks. Social Network Analysis and Mining, 11(1), 1-42.
[36] YouTube. Fake engagement policy - YouTube Help. (n.d.). Google Support. Retrieved January
21, 2022, from https://support.google.com/youtube/answer/3399767?hl=en&amp;ref_topic=9282365
[37] YouTube API Services Terms of Service. (2021, July 1). Google Developers. Retrieved March 4,
2022, from https://developers.google.com/youtube/terms/api-services-terms-of-service
[38] Terms of Service. (2021, November 9). Social Blade. Retrieved March 4, 2022, from
https://socialblade.com/info/terms</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Al-Khateeb</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Agarwal</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          (
          <year>2015</year>
          , March).
          <article-title>Analyzing deviant cyber flash mobs of ISIL on Twitter</article-title>
          . In International conference on social computing, behavioral
          <article-title>-cultural modeling, and prediction</article-title>
          (pp.
          <fpage>251</fpage>
          -
          <lpage>257</lpage>
          ). Springer, Cham.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>API</given-names>
            <surname>Reference | YouTube Data</surname>
          </string-name>
          <string-name>
            <surname>API</surname>
          </string-name>
          .
          <article-title>(2021, July 2)</article-title>
          .
          <source>Google Developers. Retrieved January 21</source>
          ,
          <year>2022</year>
          , from https://developers.google.com/youtube/v3/docs
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Bovet</surname>
          </string-name>
          ,
          <source>Alexandre and Hernán A Makse</source>
          .
          <year>2019</year>
          .
          <article-title>Influence of fake news in Twitter during the 2016 US presidential election</article-title>
          .
          <source>Nature communications 10</source>
          ,
          <issue>1</issue>
          (
          <year>2019</year>
          ),
          <fpage>1</fpage>
          -
          <lpage>14</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Carley</surname>
            ,
            <given-names>K. M.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>Social cybersecurity: an emerging science</article-title>
          .
          <source>Computational and mathematical organization theory</source>
          ,
          <volume>26</volume>
          (
          <issue>4</issue>
          ),
          <fpage>365</fpage>
          -
          <lpage>381</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Cresci</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>A decade of social bot detection</article-title>
          .
          <source>Communications of the ACM</source>
          ,
          <volume>63</volume>
          (
          <issue>10</issue>
          ),
          <fpage>72</fpage>
          -
          <lpage>83</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Del</given-names>
            <surname>Vicario</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Bessi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Zollo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            ,
            <surname>Petroni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            ,
            <surname>Scala</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Caldarelli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            , ... &amp;
            <surname>Quattrociocchi</surname>
          </string-name>
          ,
          <string-name>
            <surname>W.</surname>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>The spreading of misinformation online</article-title>
          .
          <source>Proceedings of the National Academy of Sciences</source>
          ,
          <volume>113</volume>
          (
          <issue>3</issue>
          ),
          <fpage>554</fpage>
          -
          <lpage>559</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Dutta</surname>
            ,
            <given-names>H. S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jobanputra</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Negi</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Chakraborty</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          (
          <year>2021</year>
          ,
          <article-title>August)</article-title>
          .
          <source>Detecting and Analyzing Collusive Entities on YouTube. ACM Transactions on Intelligent Systems and Technology</source>
          ,
          <volume>37</volume>
          (
          <issue>4</issue>
          ), 111. https://doi.org/10.1145/1122445.1122456
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Ester</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kriegel</surname>
            ,
            <given-names>H. P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sander</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Xu</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          (
          <year>1996</year>
          ,
          <article-title>August). A density-based algorithm for discovering clusters in large spatial databases with noise</article-title>
          .
          <source>In KDD</source>
          (Vol.
          <volume>96</volume>
          , No.
          <volume>34</volume>
          , pp.
          <fpage>226</fpage>
          -
          <lpage>231</lpage>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Ferrara</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Varol</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Davis</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Menczer</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Flammini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>The rise of social bots</article-title>
          .
          <source>Communications of the ACM</source>
          ,
          <volume>59</volume>
          (
          <issue>7</issue>
          ),
          <fpage>96</fpage>
          -
          <lpage>104</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Galeano</surname>
            , Katrin Kania, LTC Rick Galeano, Esther Mead, Billy Spann, Joseph Kready, and
            <given-names>Nitin</given-names>
          </string-name>
          <string-name>
            <surname>Agarwal</surname>
          </string-name>
          .
          <article-title>The Role of YouTube during the 2019 Canadian Federal Election: A Multi-Method Analysis of Online Discourse and Information Actors</article-title>
          .
          <source>Journal of Future Conflict, Issue</source>
          <volume>2</volume>
          ,
          <year>Fall 2020</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>22</lpage>
          . Queen's University, Canada.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <article-title>Getting started with the Business API (Matrix) - Socialblade</article-title>
          .com. (n.d.).
          <source>Social Blade. Retrieved January 21</source>
          ,
          <year>2022</year>
          , from https://socialblade.com/business-api
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Giglietto</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Righetti</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rossi</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Marino</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>It takes a village to manipulate the media: coordinated link-sharing behavior during 2018 and 2019 Italian elections</article-title>
          .
          <source>Information, Communication and Society</source>
          , 1-
          <fpage>25</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Graham</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bruns</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhu</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Campbell</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>Like a virus: The coordinated spread of coronavirus disinformation. Report commissioned for the Centre for Responsible Technology</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Hine</surname>
            <given-names>GE</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Onaolapo</surname>
            <given-names>J</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cristofaro</surname>
            <given-names>ED</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kourtellis</surname>
            <given-names>N</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Leontiadis</surname>
            <given-names>I</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Samaras</surname>
            <given-names>R</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stringhini</surname>
            <given-names>G</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Blackburn</surname>
            <given-names>J</given-names>
          </string-name>
          (
          <year>2017</year>
          )
          <article-title>Kek, cucks, and God Emperor Trump: A measurement study of 4chan's politically incorrect forum and its effects on the web</article-title>
          .
          <source>In: ICWSM</source>
          , AAAI Press, pp
          <fpage>92</fpage>
          -
          <lpage>101</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Hussain</surname>
            ,
            <given-names>M. N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tokdemir</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Agarwal</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Al-Khateeb</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          (
          <year>2018</year>
          ,
          <article-title>August)</article-title>
          .
          <article-title>Analyzing disinformation and crowd manipulation tactics on YouTube</article-title>
          .
          <source>In 2018 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM)</source>
          (pp.
          <fpage>1092</fpage>
          -
          <lpage>1095</lpage>
          ). IEEE.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>Information</given-names>
            <surname>Operations</surname>
          </string-name>
          .
          <source>Twitter. Retrieved January 20</source>
          ,
          <year>2022</year>
          . https://transparency.twitter.com/en/reports/information-operations.html
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17] Keller, F.
          <string-name>
            <given-names>B.</given-names>
            ,
            <surname>Schoch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            ,
            <surname>Stier</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            , &amp;
            <surname>Yang</surname>
          </string-name>
          ,
          <string-name>
            <surname>J.</surname>
          </string-name>
          (
          <year>2020</year>
          ).
          <article-title>Political Astroturfing on Twitter: How to coordinate a disinformation Campaign</article-title>
          .
          <source>Political Communication</source>
          ,
          <volume>37</volume>
          (
          <issue>2</issue>
          ),
          <fpage>256</fpage>
          -
          <lpage>280</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Khaund</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kirdemir</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Agarwal</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Morstatter</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          (
          <year>2021</year>
          ).
          <article-title>Social Bots and Their Coordination During Online Campaigns: A Survey</article-title>
          .
          <source>IEEE Transactions on Computational Social Systems.</source>
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Kirdemir</surname>
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Agarwal</surname>
            <given-names>N.</given-names>
          </string-name>
          (
          <year>2022</year>
          )
          <article-title>Exploring Bias and Information Bubbles in YouTube's Video Recommendation Networks</article-title>
          . In: Benito R.M.,
          <string-name>
            <surname>Cherifi</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cherifi</surname>
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Moro</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rocha</surname>
            <given-names>L.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>SalesPardo</surname>
            <given-names>M</given-names>
          </string-name>
          .
          <article-title>(eds) Complex Networks &amp; Their Applications X. COMPLEX NETWORKS 2021</article-title>
          .
          <article-title>Studies in Computational Intelligence</article-title>
          , vol
          <volume>1016</volume>
          . Springer, Cham. https://doi.org/10.1007/978-3-
          <fpage>030</fpage>
          -93413-2_
          <fpage>15</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Kirdemir</surname>
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kready</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mead</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hussain</surname>
            <given-names>M.N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Agarwal</surname>
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Adjeroh</surname>
            <given-names>D.</given-names>
          </string-name>
          (
          <year>2021</year>
          )
          <article-title>Assessing Bias in YouTube's Video Recommendation Algorithm in a Cross-lingual and Cross-topical Context</article-title>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>