Last updated:

What is cognitive warfare? How it differs from fake news, information manipulation and FIMI

The term 'fake news' is not enough to describe what is happening. The content may be entirely true, only selected and forwarded in concentrated waves. The accounts may never lie, yet use a coordinated rhythm to make a certain emotion appear widespread. This article sorts out the origins and differences of the related terms, and explains the methods, detection signals, defenses and Taiwan's regulations.

Infographic for What Is Cognitive Warfare? FIMI and Disinformation for Defense, illustrating key concepts from AI Knowledge Hub

Quick answer: what is cognitive warfare?

Cognitive warfare is the intentional, organized activity of influencing the cognition, attitudes and behavior of a target group. Its means are not limited to disinformation and may also include selective amplification of true information, emotional mobilization and coordinated dissemination. In a 2023 article, NATO Allied Command Transformation (ACT) described it as activity carried out in synchronization with other instruments of power, influencing, protecting or disrupting the cognition of individuals and groups in order to affect attitudes and behavior and gain an advantage.

This article focuses on the manipulative part of it: beyond whether content is true or false, identification should also look for coordinated, deceptive behavior patterns. What a monitoring system can provide is suspicious signals and investigative leads; determination of truth, attribution and disposition are decided by human verification.

Definition: why cognitive warfare is not the same as 'fake news'

In NATO Allied Command Transformation's 2023 description, information content is only a means; what is affected is cognition itself: which issues are seen, which frame is used to understand them, and which institutions are trusted. The definition also covers both influencing and protecting.

Why is it not the same as fake news? In their 2017 report 'Information Disorder' for the Council of Europe, Wardle and Derakhshan point out that the term 'fake news' is ambiguous and inadequate for describing these phenomena. They divide information disorder into misinformation, disinformation and malinformation, based on whether the information is false and whether there is intent to harm. This article uses disinformation to mean false information spread deliberately. Cognitive warfare may use means beyond this, and may rely entirely on true information.

This distinction has practical consequences. Selective amplification, emotional mobilization and coordinated spreading do not necessarily contain a single claim that can be judged false. Fact-checking still has to examine the content and its context, but it also needs observation of accounts, networks and time series. Meta's 2020 CIB report likewise explains that action against coordinated inauthentic behavior is based on the deceptive nature of the behavior, not on the content itself.

Terminology table: misinformation, disinformation, information manipulation, FIMI, CIB and cognitive warfare

These terms overlap, but they differ in origin and analytical purpose. In the table, 'information manipulation' and 'influence operations' are working definitions adopted in this article, not quoted from a specific organization. When citing them, we recommend noting this.

Term Definition Proposed or used by Key difference
Misinformation False information, but the person spreading it has no intent to cause harm Wardle and Derakhshan, Council of Europe report (2017) It differs from disinformation in the intent to harm, for example an incorrect message forwarded with good intentions
Disinformation Spread with the knowledge that it is false, with the aim of causing harm Same as above The content may be identical to misinformation. The difference lies in knowledge and intent
Malinformation True information used to cause harm, such as making private information public Same as above The content is true, and the harm comes from how it is used
Information manipulation Behavior that distorts the information environment through deceptive or coordinated means, regardless of whether the content is true or false Working definition in this article The focus is whether the means are manipulative, not whether the content is true
Influence operations Organized actions to influence the views or decisions of a specific audience Working definition in this article Describes the operation as a whole; information manipulation may be one of its means
FIMI (foreign information manipulation and interference) A pattern of behavior that is mostly not illegal but threatens or may negatively affect values, procedures and political processes. It is manipulative in nature and conducted in an intentional and coordinated manner, and the actors can be state or non-state actors and their proxies Put forward by the European Union in 2021; adopted in the FIMI threat reports the EEAS has published since 2023 Emphasizes foreign origin, intent and coordination; focuses on behavior patterns, not on whether the content is unlawful
Coordinated inauthentic behavior (CIB) Coordinated manipulation of public debate for a strategic goal, with fake accounts at the core of the operation Meta's CIB report (2020) A term the platform uses for enforcement; action is based on the deceptive nature of the behavior, not on the content itself
Cognitive warfare Activities conducted in synchronization with other instruments of power that influence, protect or disrupt the cognition of individuals and groups in order to affect attitudes and behavior and gain an advantage NATO Allied Command Transformation (ACT) (2023 article) Focuses on cognition itself, and the definition also includes a protective dimension; it overlaps with the concepts above but has a different analytical purpose

This table can be read along four dimensions. Intent: misinformation and disinformation may have identical content, and the difference is whether the person knew it was false and intended to cause harm. Truth: true content can also be used to cause harm. Coordination: FIMI and CIB look at behavior patterns rather than whether content is true or false, and FIMI is further limited to foreign actors. Purpose: cognitive warfare focuses on changing cognition and behavior, and overlaps with the other concepts, but it is not a strict superordinate or subordinate relationship.

Two kinds of confusion should be avoided when reading. One is interpreting a platform's CIB takedown report as saying that these accounts spread fake news, when the action was based on behavior and the content is not necessarily false. The other is treating all misinformation as manipulation by someone, which overlooks forwarding done with good intentions. When writing reports or specifications, state the definitions and versions you adopt.

Methods: understanding an information manipulation operation by tactical stage

To describe methods, you can refer to the DISARM framework. It models disinformation incidents on the structure of MITRE ATT&CK from the security field, and originated in the MisinfoSec working group of the Credibility Coalition. It is divided into the Red framework (the manipulators' tactics, techniques and procedures, or TTPs, arranged by tactical stage) and the Blue framework (the countermeasures of responders).

This article borrows the idea of the Red framework's arrangement by tactical stage and groups methods into four stages. The stage names are our own summary and are not official DISARM tactic names or numbers.

Stage (as summarized in this article) Example tactics Externally observable traces
1. Goal and narrative design Narrative framing: placing events into a pre-set way of interpretation Hard to observe directly; can be inferred from the same frame recurring across unrelated events
2. Asset preparation Fake identities, bulk account creation, and pre-prepared graphics and short videos Accounts created within a concentrated time window, templated profiles, and impersonating pages with names highly similar to the genuine ones
3. Seeding and spread Selective amplification, emotional mobilization, coordinated account networks, cross-platform relay Large numbers of similar posts in a short time, the same group of accounts reposting each other, content moving between groups and public platforms
4. Sustaining and adjusting Changing the story after a debunk, continuing the same narrative with new material Variant content appearing after a clarification; the core narrative stays the same while only details and material change

Organizing clues by stage helps plan verification and response processes for different points in time, for example by watching for clusters of anomalous accounts or impersonating pages already in stage two.

Narrative framing

For example, the same equipment failure can be understood as a single incident, or framed as evidence that the system has long been failing. A frame does not necessarily contain false statements, but it may shape how audiences interpret later news.

Selective amplification

Picking out fragments that fit a preset narrative and reposting them intensively while ignoring contrary information. Even if an individual fragment is true, omitting context can still make it misleading.

Emotional mobilization

For example, sensational headlines, clipped videos and polarizing questions can drive reposting and provoke strong emotional reactions; sources and full context should still be checked before forwarding.

Impersonation

Imitating agency announcements, creating fan pages with similar names, or speaking as fictitious local residents; deepfake audio and video are an extension of this.

Coordinated account networks

A group of accounts reposting and commenting on each other at similar times with similar content can create the impression of majority opinion. What matters is whether their relationships and rhythm look natural.

Cross-platform relay

For example, content may move from groups into public social media and then flow to other platforms as screenshots, or it may flow in the opposite direction. The path must be reconstructed from case evidence, and any single platform shows only one segment of it.

How to identify it: four layers of signals (content, accounts, network, timing)

Identification should observe four layers and cross-check them.

Layer What to look at Example signals Common misjudgments
Content layer Claims, text, images and video Matches an already fact-checked false claim, highly similar text, altered images, suspected deepfake audio or video Popular topics naturally attract similar statements; reposting the same content is not the same as coordination
Account layer Account attributes and posting behavior Creation times clustered together, mechanical posting rhythm, templated profiles, almost entirely reposts with little original content Genuine and enthusiastic supporters may also post frequently and repost heavily
Network layer Relationships between accounts A fixed group reposting and commenting on each other, sharing the same material, the same set of identities appearing across platforms Interest communities and supporter groups are naturally tightly connected
Timing layer Sequence of volume and posts Unnatural volume spikes, multiple accounts posting in sync, regular time gaps across platforms Major events, press conferences and news push notifications naturally cause synchronized reactions

The four layers should be read together: similar content alone may simply mean everyone reposted the same news story. When several signals appear at once, such as newly created accounts, mutual reposting and synchronized appearance, they can be listed as leads for further verification, while explanations such as normal community activity must still be ruled out. In practice, we recommend keeping verification records (screenshots, original links, capture times); for content involving identifiable individuals, confirm the basis and necessary scope for collecting, processing and using personal data. For the principles and limits of detection methods, see How AI detects fake news.

In the context of cybersecurity threat intelligence, the subject of analysis is cyber threats and risks to specific entities, which differs from information manipulation monitoring; the two can run in parallel. For details, see What is threat intelligence.

Defense and resilience: countermeasures, fact-checking and public sector communication

No single organization can handle information manipulation alone: platforms handle accounts and behavior, fact-checking organizations handle verifiable claims, and public sector bodies handle the facts and communication of their own business.

DISARM Blue: organizing countermeasures from the responder's perspective

The Blue framework organizes countermeasures from the responder's perspective. Alongside the Red framework, it helps plan intervention points against tactics at a specific stage, and gives different units a shared vocabulary when exchanging intelligence. Not every countermeasure the framework lists is appropriate; when adopting one, assess the legal basis, necessity, proportionality and freedom of expression.

Fact-checking ecosystem

Taiwan's fact-checking ecosystem includes Taiwan FactCheck Center, MyGoPen, and the crowdsourced verification platform Cofacts, which respectively offer different services such as fact-check reports, message lookup and user-collaborative responses. What the public sector can focus on is providing verifiable original data so that the public knows where to look things up.

Public sector early warning and communication

Agencies can write and rehearse early warning and communication processes in advance: which topics to watch, who interprets anomalies, at what point to clarify publicly, through which channel, and when to hold off responding to avoid widening reach. For the complete approach, see Fake News Detection and Cognitive Warfare Monitoring System, and for the steps of public clarification, see Sentiment crisis management SOP.

Legal framework: current provisions in Taiwan addressing false information

The table below lists only three laws that address specific acts of spreading false information. It is not a complete list, whether an act is unlawful is decided case by case, and the provisions should be checked against the current version in the Laws and Regulations Database of the Republic of China.

Law and article Conduct regulated Legal consequence
Social Order Maintenance Act, Article 63, Paragraph 1, Subparagraph 5 Spreading rumors in a manner sufficient to affect public peace Detention of up to three days or a fine of up to NT$30,000
Disaster Prevention and Protection Act, Article 53, Paragraph 3 (Article 41 at the time of the 2019 amendment; the article numbers were later adjusted) Spreading rumors or false information about a disaster in a manner sufficient to harm the public or others Imprisonment of up to three years, detention, or a fine of up to NT$1,000,000. If death or serious injury results, the penalty is increased under Paragraph 4 of the same article
Civil Servants Election and Recall Act, Article 104, Paragraph 1 Spreading rumors or false statements with intent to cause a candidate to be elected or not elected, or a recall motion to pass or fail, in a manner sufficient to harm the public or others Imprisonment of up to five years
Civil Servants Election and Recall Act, Article 104, Paragraph 2 (added in the 2023 amendment) Committing the offense in the preceding paragraph using a deepfake voice, image or electromagnetic record of the candidate, the person subject to recall, or the lead proposer of the recall motion Imprisonment of up to seven years
Civil Servants Election and Recall Act, Article 104, Paragraph 3 Committing either of the two preceding offenses with intent to profit The penalty is increased by up to one half, and a fine of NT$2,000,000 to NT$10,000,000 may also be imposed

These provisions regulate specific acts of spreading false information, and each has its own conditions of application, such as being sufficient to affect public peace or to harm the public or others. Whether they apply must be judged case by case. Two things should also be kept apart: whether content is false is judged by fact-checkers based on evidence, while whether it is unlawful is determined by the competent authority according to law. Being judged false does not mean it is unlawful.

This article does not constitute legal advice. For the operational priorities during an election period, see Election disinformation monitoring checklist.

FAQ

The term fake news is used ambiguously. If it means false information spread deliberately, it is only one of the means cognitive warfare may use. The goal of cognitive warfare is to influence the perceptions, attitudes and behavior of individuals and groups. Its means can also include selective amplification of true information, emotional mobilization, impersonation and coordinated spreading, so beyond whether the content is true or false, you also need to look for coordinated manipulation.
FIMI is short for Foreign Information Manipulation and Interference, a concept the European Union put forward in 2021. In the FIMI threat reports it has published since 2023, the EEAS describes it as a pattern of behavior that is mostly not illegal but threatens or may negatively affect values, procedures and political processes. It is conducted in an intentional and coordinated manner, and the actors can be state or non-state actors and their proxies.
Coordinated Inauthentic Behavior is a term used by Meta. In its 2020 CIB report, Meta defines it as behavior that coordinates the manipulation of public debate for a strategic goal, with fake accounts at the core of the operation. Action is based on the deceptive nature of the behavior, not on the content itself, so the content posted by the accounts involved is not necessarily disinformation.
Not on its own. AI can find suspicious signals at four levels: content, accounts, networks and time. Examples include highly similar text, accounts created in a cluster, synchronized posting and anomalous volume, and it can rank investigation priorities. But these signals alone cannot establish intent or attribution. Analysts must verify verifiable evidence together before making a judgment.
Examples include the spreading of rumors under Article 63, Paragraph 1, Subparagraph 5 of the Social Order Maintenance Act, the spreading of disaster rumors or false information under Article 53, Paragraph 3 of the Disaster Prevention and Protection Act, and the election rumors and heavier penalties for deepfakes under Article 104 of the Civil Servants Election and Recall Act. Each provision has specific conditions of application, such as being sufficient to affect public peace or to cause harm. Whether an act is unlawful is determined by the competent authority case by case.

Want to build a monitoring and early-warning process for information manipulation?

Before a consultation, you can prepare three things: the topics you want to observe, the platforms that need to be covered, and your current reporting process. LargitData will use them to explain feasible ways to adopt the solution.

Contact Us