Fake News Detection and Cognitive Warfare Monitoring System
An edited image, a spliced video clip, or a set of similar posts appearing at the same time may be relayed across platforms and messaging app groups. The InfoMiner fake news detection and cognitive warfare monitoring system organizes public cross-platform content into narratives and spread paths and flags suspicious coordinated spreading and anomalous account clusters, so that spokesperson and response units can see the signals early.
What is a cognitive warfare monitoring system?
A cognitive warfare monitoring system continuously collects public content across platforms, identifies suspicious narratives, coordinated spreading and clusters of anomalous accounts, tracks spread paths and issues early warnings, and then hands the results to analysts for verification and assessment. General sentiment monitoring mainly organizes keywords, volume and sentiment. Cognitive warfare monitoring goes further to analyze narratives, account behavior and spread structure, providing leads on observable early sources, spreading nodes and suspected coordination.
The system produces suspicious signals and investigative leads. Whether content is true, attribution of manipulation and follow-up action are decided by your organization's manual verification.
Term definitions are in What is cognitive warfare? How it differs from fake news, information manipulation and FIMI, and detection techniques are covered in How does AI detect fake news? Five methods and what they cannot do; this page covers system capabilities, limitations and deployment.
Who it is for
- Spokesperson, public sentiment and news liaison units in government agencies: understand the source and scale in the early stage of spread, and decide whether and when to issue a clarification
- Critical infrastructure operators: watch for suspicious messages about service outages, water or power cuts, or contamination, so that the responsible authorities can verify and explain
- Election authorities and local governments: watch for suspicious messages about the voting and vote-counting process and public services, and prepare explanatory materials early
What problems it solves
- If an agency only finds out when a reporter calls or a supervisor forwards a screenshot, the time available to prepare an explanation is compressed
- You can see volume rising, but cannot tell whether it is natural discussion or a group of accounts pushing similar content at the same time
- Verification and clarification rely on individual experience, with no tiering rules and no verification records
What problem this system solves: from after-the-fact rebuttal to early warning
If your unit currently finds, verifies and clarifies items one by one, you can evaluate adding narrative tracking and early warning along the following three dimensions.
1. Speed of spread: response timing depends on how the spread actually unfolds
False information may spread quickly across platforms, or it may circulate within a small circle for a long time, so how quickly to respond should depend on how it is actually spreading. Early warning lets case officers see it while the spread curve is still flat, keeping the options to observe, prepare or respond open.
2. Cross-platform relay: no single platform shows the full picture
The same narrative may travel across platforms in different forms, such as forum posts, image cards and short videos. Looking at one platform shows only scattered posts; placing cross-platform content on a single timeline reveals where it first appears in the currently observable data and at which nodes it was amplified.
3. Manipulation does not always rely on false content
The Information Disorder report, written in 2017 by Wardle and Derakhshan for the Council of Europe, divides information disorder into three types: misinformation, disinformation and malinformation, the last being genuine information used to cause harm. It also argues that the term fake news is inadequate to describe these phenomena. Selective amplification, quoting out of context and emotional mobilization cannot always be handled by checking whether something is true, so monitoring has to look at content, account behavior and spread structure together.
| Dimension | After-the-fact debunking | Early warning |
|---|---|---|
| When it is detected | After a media inquiry, a forwarded message from a superior, or a public complaint | When a narrative appears in a few sources and has not yet been widely shared |
| Unit of analysis | Whether a single message is true | Narratives, account groups and spread paths |
| Basis for judgment | Case officer experience and ad hoc verification | Predefined tiering rules, combined with human verification |
| Response options | Issue a clarification | Keep observing, prepare a statement, clarify proactively, or report to the platform or competent authority |
| Records kept | The clarification itself | Original sources, spread timeline, assessment basis and response decisions |
The table above compares two operating configurations and does not describe any particular organization. Early warning gives you more response options: whether to respond publicly can be weighed against the scale of the issue, the spread trend, the public interest and the form of response, before deciding to observe first, prepare first or respond immediately.
The five-step monitoring process: from collection to human response
The first three steps are mainly handled by the system, the fourth is proposed by the system and confirmed by your organization, and the fifth is the responsibility of people. This division of labor is also the basis for assigning responsibilities during adoption.
| Step | What it does | Typical output | Main performer |
|---|---|---|---|
| 1. Collection | Continuously collect news, social media, forums and public data, including images and video | Raw content pool, sources and timestamps, gap records | System |
| 2. Narrative clustering | Group similar claims across platforms into the same narrative | Narrative list, representative content, distribution across platforms | System |
| 3. Spread and coordination analysis | Mark early nodes and spreading nodes in the observable data, and analyze posting rhythm, content similarity and account association networks | Spread timeline, key nodes, clusters of suspicious accounts | System, reviewed by analysts |
| 4. Tiered alerts | Apply tiering rules defined by the organization | Tiered alerts, notification records, escalation rules | Proposed by the system, confirmed by the organization |
| 5. Manual verification and response | Verify whether the content is true, assess whether it is manipulation, decide whether to observe, clarify, report or refer, and keep verification records | Verification conclusions, response decisions, verification records, post-incident review | Analysts and the supervisor with authority |
Step 5 requires clearly assigned staff and authority: who is responsible for verification, who approves whether to respond, and how quickly it must be completed. We recommend writing this into operating procedures before adoption.
Step 1: Collection (record what content was obtained and known gaps)
The scope is set by topics, business keywords, local place names and designated accounts, and exclusion terms reduce noise from identical names. Text in images is extracted with OCR, and videos and images go into multimodal analysis. This step keeps the content obtained and the capture time. We recommend recording separately any known gaps caused by platform changes.
Step 2: Narrative clustering (merge similar claims to reduce duplicate review)
The same claim may be reposted with a new headline, a redesigned graphic or a different opening. Clustering groups semantically similar content together and attaches representative content, the earliest time it appears in the observable data, and its distribution across platforms. Clustering is probabilistic, and similar claims with opposite positions may be grouped together, so each piece of content keeps its original source for tracing back.
Step 3: Spread and coordination analysis (look at behavior, not just content)
This step looks at a narrative's early nodes and amplifying nodes in the observable data, and at whether accounts show unnatural signs of coordination: whether posting times are concentrated, whether content is highly similar, and whether accounts have fixed forwarding relationships. In its 2020 CIB report, Meta defines coordinated inauthentic behavior as coordinated manipulation of public debate for a strategic goal, with fake accounts at the core of the operation, and bases action on the deceptive nature of the behavior rather than the content itself.
Step 4: Tiered alerts (so the right people receive them)
Tiering rules are defined by the organization, with dimensions including spread speed, number of platforms, relevance to the business and signs of coordination. For example, items appearing on a single forum go into the daily digest, items being forwarded at accelerating speed across platforms trigger an immediate notification to the spokesperson's office, and items involving disaster conditions or voting and vote-counting procedures notify the supervisor with authority directly.
Step 5: Manual verification and response (people make the decisions)
Verification includes comparing against original sources, confirming with the relevant business units, and referring to the results of the fact-checking ecosystem (for example Taiwan FactCheck Center, MyGoPen and Cofacts). Responses can be to observe, clarify, report to the platform or refer to the competent authority. The system can keep verification records such as screenshots, original links and capture times. Where legal proceedings are involved, separately confirm the preservation and forensic methods required.
Corresponding InfoMiner capabilities
Each of the following capabilities comes with prerequisites. We recommend writing them into the requirements specification at the time of procurement.
| Capability | What it does | Prerequisites |
|---|---|---|
| Cross-platform monitoring | News, social media, forums and public data, covering PTT, Dcard, Facebook, YouTube, Threads, TikTok/Douyin and LINE communities; overall monitoring spans more than 500,000 channels | Actual coverage depends on the plan and data source licensing; gaps may appear when a platform changes its layout or blocks access |
| Topic and sentiment analysis | Topic summarization and sentiment analysis of Traditional Chinese text | Sarcasm and emerging internet slang need to be calibrated during the comparison period |
| Abnormal volume alerts | Alerts are issued when volume deviates from the normal baseline | A baseline period must be built up first; sensitivity and false-alarm rate trade off against each other |
| Suspected fake news and narrative tracking | Identifies suspicious false information and tracks its spread paths and the earliest nodes visible in observable data | Output consists of suspicious signals; whether something is true or false is verified by people |
| Coordinated narrative pushing and anomalous account clusters | Analyzes posting rhythm, content similarity and relationship networks to flag suspected coordinated clusters | Requires configuration and tuning; based on publicly available platform fields, so findings are probabilistic assessments |
| Image and video analysis | Extracts text from images (OCR), performs image recognition, and detects manipulated video and deepfakes | Video and deepfake detection requires configuration and tuning; image quality and the number of re-encodings affect the results |
| Automated reports | Narrative summaries, incident reports and export of alert records | Format follows the unit's existing briefing setup |
| Case management | Case creation, assignment, progress tracking and retention of verification records | Can be custom-built around the agency's workflow |
Monitoring and analysis can go live relatively quickly, while coordinated-behavior analysis, multimodal analysis and case management need to be tuned or built together with the unit, so their schedules should be planned separately. For the full feature list, see InfoMiner Social Listening.
Capability boundaries: ready to use, needs configuration and tuning, needs custom assessment
In procurement, avoid listing a determination of truth or attribution of actors as a deliverable that has not been agreed on. The categories below are based on delivery difficulty:
| Category | Item | Prerequisites and limitations in disinformation scenarios |
|---|---|---|
| Ready to use | Keyword and narrative monitoring, sentiment analysis and abnormal volume alerts across public news, social media and forums | It can show that a claim is heating up and on which platforms it appears, but it cannot determine whether the claim is true or false. Private messages and non-public groups are out of scope. |
| Ready to use | Text extraction from images (OCR) | Text on image cards can be included in retrieval and narrative clustering; low resolution and decorative fonts reduce extraction quality. |
| Requires configuration and tuning | Detection of coordinated inauthentic behavior and anomalous account clusters | This relies on publicly available platform fields (posting time, interaction relationships, content similarity), so closed platforms cannot be covered. Spontaneous mobilization by fans and synchronized publishing by media outlets can also look coordinated, so findings are probabilistic assessments that require human verification. |
| Requires configuration and tuning | Video and deepfake detection | Re-encoding, compression and screen recording can weaken the features used for assessment; where legal proceedings are involved, confirm through a separate forensic channel. |
| Requires configuration and tuning | Tiered alert rules | Thresholds are calibrated against real feedback during the comparison period, based on the nature of the business and jurisdiction. |
| Requires custom assessment | Non-public sources, closed communities and in-depth coverage of specific languages | Legality and authorization must be confirmed first, and coverage verified through a proof of concept before inclusion. |
| Requires custom assessment | Integration of case management with the agency's existing systems | Can be custom-built around the agency's workflow; existing official document and incident reporting systems must be inventoried first. |
We recommend stating explicitly in the contract that the system makes no final determination of truth and provides no final attribution conclusion. In the FIMI threat reports it has published since 2023, the EEAS (European External Action Service) describes foreign information manipulation and interference as an intentional and coordinated pattern of behavior, whose actors may be state or non-state actors and their proxies; attribution requires a separate assessment of the strength of the evidence and of alternative explanations.
Deployment and data governance
Disinformation monitoring involves two kinds of data: external content from public, lawful sources, and the unit's internal assessment records and handling decisions. Both may contain personal data or sensitive information, so access permissions, retention periods and deployment location should be set separately according to content and purpose.
- Data hosting and security certification:InfoMiner data servers are located in Taiwan.
- On-Premise:Assessment records, internal knowledge and report generation can use RAGi On-Premise together with the QubicX on-premise AI platform; data processing and model inference run on the unit's internal network, and no data is sent to an external cloud.
- Records and auditing:Which operation and handling records must be kept, and in what format they are exported, can be assessed against the agency's audit requirements and planned together with the custom build of case management.
- Procurement channels:InfoMiner is qualified under the government Joint Supply Contract and can be procured through it; custom-build items are assessed separately according to requirements.
RAGi Enterprise AI Retrieval-Augmented Generation Engine · QubicX On-Premise AI Platform
The limits of monitoring: freedom of speech and personal data
This system analyzes narratives and behavior patterns, but designating accounts and running relationship analysis may still involve data that can identify individuals; being publicly visible does not mean personal data is not involved, so the legal basis and necessary scope of collection, processing and use should be confirmed. Before adoption, we recommend that the legal and business units define which accounts may be listed as accounts of interest and who approves them, the retention and deletion periods, and that results be used only for stated purposes such as clarification and reporting.
Laws that may be involved in handling
If a verification conclusion is to be referred or reported, the provisions on spreading rumors in the Social Order Maintenance Act, the Disaster Prevention and Protection Act and the Civil Servants Election and Recall Act may be involved; for a summary of the provisions, see What is cognitive warfare? How it differs from fake news, information manipulation and FIMI. Each of these laws has different elements of the offense: whether content is true or false is judged by fact-checkers based on evidence, and whether it is unlawful is determined by the competent authority in accordance with the law; being judged false does not mean being unlawful.
Who uses it and how
Scenario 1: government agency spokesperson and public sentiment units
The system produces narrative summaries on a schedule. The suggested operating rhythm is as follows:
- Daily summary:Provides a narrative list before the morning meeting, separating items to keep watching from those where a response is recommended.
- Real-time alerts:Narratives that affect the public's interests or are accelerating across platforms are sent directly to the contact point.
- Post-clarification tracking:Observe changes in publicly available reposts and discussion after the clarification.
If the clarification is only reposted within official accounts while the original narrative keeps growing on other platforms, consider changing the publishing channel or the way it is explained.
Scenario 2: critical infrastructure operators
Operators of power, water, transportation and communications can set up topics related to service outages, quality or contamination as monitoring scenarios. The monitoring scope is defined by service names and facility place names and linked to incident reporting: when a claim about a water or power cut in a certain area spreads quickly, the duty officer first checks the actual operating status and then decides whether to issue an explanation. For process design, see Public sentiment crisis SOP: a 7-step PR crisis guide.
Scenario 3: election authorities and local governments
The election scenarios on this page include the voting and vote-counting process, election operations, and suspicious content that impersonates candidates' words and actions. Voting day for Taiwan's 2026 local elections is November 28; before the election you can build a topic list and tiering rules, and switch to high-frequency monitoring around voting day. Monitoring must be politically neutral and focus only on the types of messages that affect election procedures. To track the overall level of public discussion, LargitData also offers 2026 Taiwan Election Lab, a real-time volume dashboard covering all 22 counties and cities in Taiwan. For a pre-election task checklist, see How to monitor election disinformation: a task checklist for the 60 days before the election.
Adoption process and acceptance criteria
Before comparing metrics such as accuracy, align the datasets, labeling criteria and sample distribution. This page recommends pairing acceptance with historical-event backtesting and comparison-period evaluation.
| Phase | Key Tasks | Client Stakeholder Roles | Deliverables |
|---|---|---|---|
| 1. Scope inventory | Confirm the topics of interest, keywords, designated accounts and existing reporting workflow | Spokesperson, public sentiment and business case officers | Monitoring scope list and division of responsibilities |
| 2. Historical-event backtesting | Using incidents the unit has handled, check whether the system can reconstruct the earliest observable nodes and spread paths | The case officers at the time | Backtest report, with items that can and cannot be covered |
| 3. Calibration Pilot Phase | Run in parallel with existing operations and give feedback on missed detections, false alarms and tiering | Public sentiment case officers | Calibrated tiering thresholds and report format |
| 4. Production Go-Live | Push summaries and alerts automatically, and conduct training on interpreting them | Spokesperson contacts and business unit liaisons | Daily summaries, tiered alerts and handling records |
Backtesting uses cases the unit knows well to check when the issue was found at the time, how far the system could have moved that time earlier within observable data, and which platforms' data could not be obtained; this also shows which items need tuning.
10 questions to ask when evaluating vendors
The evaluation should confirm data scope, assessment workflow and interface operation together. We recommend asking vendors to answer in writing:
- Source list: which platforms can be monitored? Which are collected in-house and which are obtained under license?
- Gap notification: when a platform changes its layout, how will we know which segment of data is incomplete?
- Cross-platform merging: when the same narrative is rewritten and reposted, how is it deduplicated and merged?
- Narrative clustering evaluation: which datasets and labeling criteria are used? When clustering is wrong, can analysts split or merge clusters?
- Basis for coordination assessment: which fields are used when flagging suspected coordination? Can they be shown to analysts?
- Handling false alarms: how is normal coordinated behavior excluded? Can false alarms be fed back to adjust the system?
- Multimodal scope: what are the conditions and limitations for image, video and deepfake detection?
- Explainability: can each alert explain its tier? Can the unit adjust the rules?
- Verification records: can screenshots, links and capture times be exported? Are records still kept after the original post is deleted? Which fields are retained in the operation log?
- Attribution stance: does the vendor claim it can determine truth or identify actors? On what basis?
We recommend writing the tenth question into the contract: if product materials describe suspicious signals directly as fake news or foreign manipulation, the unit takes on additional risk in both its external communications and legal proceedings.
Further Reading
- What is cognitive warfare? How it differs from fake news, information manipulation and FIMI
- How does AI detect fake news? Five methods and what they cannot do
- How to monitor election disinformation: a task checklist for the 60 days before the election
- Defense & Critical Infrastructure Intelligence Solutions
- What is Threat Intelligence? A Complete Enterprise Guide to Threat Intel
- Election sentiment analysis and public opinion tracking
- PR crisis monitoring and real-time response
FAQ
Book a demo of fake news detection and cognitive warfare monitoring
Using a false information incident your organization has handled as the example, we walk through the full process: cross-platform collection, narrative clustering, spread and coordination analysis, tiered alerts, and human verification with verification records kept.
Contact Us