Last updated:

Fake News Detection and Cognitive Warfare Monitoring System

An edited image, a spliced video clip, or a set of similar posts appearing at the same time may be relayed across platforms and messaging app groups. The InfoMiner fake news detection and cognitive warfare monitoring system organizes public cross-platform content into narratives and spread paths and flags suspicious coordinated spreading and anomalous account clusters, so that spokesperson and response units can see the signals early.

Infographic for Disinformation & Cognitive Warfare Early Warning for Defense, illustrating key concepts from Industry Solutions

What is a cognitive warfare monitoring system?

A cognitive warfare monitoring system continuously collects public content across platforms, identifies suspicious narratives, coordinated spreading and clusters of anomalous accounts, tracks spread paths and issues early warnings, and then hands the results to analysts for verification and assessment. General sentiment monitoring mainly organizes keywords, volume and sentiment. Cognitive warfare monitoring goes further to analyze narratives, account behavior and spread structure, providing leads on observable early sources, spreading nodes and suspected coordination.

The system produces suspicious signals and investigative leads. Whether content is true, attribution of manipulation and follow-up action are decided by your organization's manual verification.

Term definitions are in What is cognitive warfare? How it differs from fake news, information manipulation and FIMI, and detection techniques are covered in How does AI detect fake news? Five methods and what they cannot do; this page covers system capabilities, limitations and deployment.

Who it is for

  • Spokesperson, public sentiment and news liaison units in government agencies: understand the source and scale in the early stage of spread, and decide whether and when to issue a clarification
  • Critical infrastructure operators: watch for suspicious messages about service outages, water or power cuts, or contamination, so that the responsible authorities can verify and explain
  • Election authorities and local governments: watch for suspicious messages about the voting and vote-counting process and public services, and prepare explanatory materials early

What problems it solves

  • If an agency only finds out when a reporter calls or a supervisor forwards a screenshot, the time available to prepare an explanation is compressed
  • You can see volume rising, but cannot tell whether it is natural discussion or a group of accounts pushing similar content at the same time
  • Verification and clarification rely on individual experience, with no tiering rules and no verification records

What problem this system solves: from after-the-fact rebuttal to early warning

If your unit currently finds, verifies and clarifies items one by one, you can evaluate adding narrative tracking and early warning along the following three dimensions.

1. Speed of spread: response timing depends on how the spread actually unfolds

False information may spread quickly across platforms, or it may circulate within a small circle for a long time, so how quickly to respond should depend on how it is actually spreading. Early warning lets case officers see it while the spread curve is still flat, keeping the options to observe, prepare or respond open.

2. Cross-platform relay: no single platform shows the full picture

The same narrative may travel across platforms in different forms, such as forum posts, image cards and short videos. Looking at one platform shows only scattered posts; placing cross-platform content on a single timeline reveals where it first appears in the currently observable data and at which nodes it was amplified.

3. Manipulation does not always rely on false content

The Information Disorder report, written in 2017 by Wardle and Derakhshan for the Council of Europe, divides information disorder into three types: misinformation, disinformation and malinformation, the last being genuine information used to cause harm. It also argues that the term fake news is inadequate to describe these phenomena. Selective amplification, quoting out of context and emotional mobilization cannot always be handled by checking whether something is true, so monitoring has to look at content, account behavior and spread structure together.

Dimension After-the-fact debunking Early warning
When it is detected After a media inquiry, a forwarded message from a superior, or a public complaint When a narrative appears in a few sources and has not yet been widely shared
Unit of analysis Whether a single message is true Narratives, account groups and spread paths
Basis for judgment Case officer experience and ad hoc verification Predefined tiering rules, combined with human verification
Response options Issue a clarification Keep observing, prepare a statement, clarify proactively, or report to the platform or competent authority
Records kept The clarification itself Original sources, spread timeline, assessment basis and response decisions

The table above compares two operating configurations and does not describe any particular organization. Early warning gives you more response options: whether to respond publicly can be weighed against the scale of the issue, the spread trend, the public interest and the form of response, before deciding to observe first, prepare first or respond immediately.

The five-step monitoring process: from collection to human response

The first three steps are mainly handled by the system, the fourth is proposed by the system and confirmed by your organization, and the fifth is the responsibility of people. This division of labor is also the basis for assigning responsibilities during adoption.

Step What it does Typical output Main performer
1. Collection Continuously collect news, social media, forums and public data, including images and video Raw content pool, sources and timestamps, gap records System
2. Narrative clustering Group similar claims across platforms into the same narrative Narrative list, representative content, distribution across platforms System
3. Spread and coordination analysis Mark early nodes and spreading nodes in the observable data, and analyze posting rhythm, content similarity and account association networks Spread timeline, key nodes, clusters of suspicious accounts System, reviewed by analysts
4. Tiered alerts Apply tiering rules defined by the organization Tiered alerts, notification records, escalation rules Proposed by the system, confirmed by the organization
5. Manual verification and response Verify whether the content is true, assess whether it is manipulation, decide whether to observe, clarify, report or refer, and keep verification records Verification conclusions, response decisions, verification records, post-incident review Analysts and the supervisor with authority

Step 5 requires clearly assigned staff and authority: who is responsible for verification, who approves whether to respond, and how quickly it must be completed. We recommend writing this into operating procedures before adoption.

Step 1: Collection (record what content was obtained and known gaps)

The scope is set by topics, business keywords, local place names and designated accounts, and exclusion terms reduce noise from identical names. Text in images is extracted with OCR, and videos and images go into multimodal analysis. This step keeps the content obtained and the capture time. We recommend recording separately any known gaps caused by platform changes.

Step 2: Narrative clustering (merge similar claims to reduce duplicate review)

The same claim may be reposted with a new headline, a redesigned graphic or a different opening. Clustering groups semantically similar content together and attaches representative content, the earliest time it appears in the observable data, and its distribution across platforms. Clustering is probabilistic, and similar claims with opposite positions may be grouped together, so each piece of content keeps its original source for tracing back.

Step 3: Spread and coordination analysis (look at behavior, not just content)

This step looks at a narrative's early nodes and amplifying nodes in the observable data, and at whether accounts show unnatural signs of coordination: whether posting times are concentrated, whether content is highly similar, and whether accounts have fixed forwarding relationships. In its 2020 CIB report, Meta defines coordinated inauthentic behavior as coordinated manipulation of public debate for a strategic goal, with fake accounts at the core of the operation, and bases action on the deceptive nature of the behavior rather than the content itself.

Step 4: Tiered alerts (so the right people receive them)

Tiering rules are defined by the organization, with dimensions including spread speed, number of platforms, relevance to the business and signs of coordination. For example, items appearing on a single forum go into the daily digest, items being forwarded at accelerating speed across platforms trigger an immediate notification to the spokesperson's office, and items involving disaster conditions or voting and vote-counting procedures notify the supervisor with authority directly.

Step 5: Manual verification and response (people make the decisions)

Verification includes comparing against original sources, confirming with the relevant business units, and referring to the results of the fact-checking ecosystem (for example Taiwan FactCheck Center, MyGoPen and Cofacts). Responses can be to observe, clarify, report to the platform or refer to the competent authority. The system can keep verification records such as screenshots, original links and capture times. Where legal proceedings are involved, separately confirm the preservation and forensic methods required.

Corresponding InfoMiner capabilities

Each of the following capabilities comes with prerequisites. We recommend writing them into the requirements specification at the time of procurement.

Capability What it does Prerequisites
Cross-platform monitoring News, social media, forums and public data, covering PTT, Dcard, Facebook, YouTube, Threads, TikTok/Douyin and LINE communities; overall monitoring spans more than 500,000 channels Actual coverage depends on the plan and data source licensing; gaps may appear when a platform changes its layout or blocks access
Topic and sentiment analysis Topic summarization and sentiment analysis of Traditional Chinese text Sarcasm and emerging internet slang need to be calibrated during the comparison period
Abnormal volume alerts Alerts are issued when volume deviates from the normal baseline A baseline period must be built up first; sensitivity and false-alarm rate trade off against each other
Suspected fake news and narrative tracking Identifies suspicious false information and tracks its spread paths and the earliest nodes visible in observable data Output consists of suspicious signals; whether something is true or false is verified by people
Coordinated narrative pushing and anomalous account clusters Analyzes posting rhythm, content similarity and relationship networks to flag suspected coordinated clusters Requires configuration and tuning; based on publicly available platform fields, so findings are probabilistic assessments
Image and video analysis Extracts text from images (OCR), performs image recognition, and detects manipulated video and deepfakes Video and deepfake detection requires configuration and tuning; image quality and the number of re-encodings affect the results
Automated reports Narrative summaries, incident reports and export of alert records Format follows the unit's existing briefing setup
Case management Case creation, assignment, progress tracking and retention of verification records Can be custom-built around the agency's workflow

Monitoring and analysis can go live relatively quickly, while coordinated-behavior analysis, multimodal analysis and case management need to be tuned or built together with the unit, so their schedules should be planned separately. For the full feature list, see InfoMiner Social Listening.

Capability boundaries: ready to use, needs configuration and tuning, needs custom assessment

In procurement, avoid listing a determination of truth or attribution of actors as a deliverable that has not been agreed on. The categories below are based on delivery difficulty:

Category Item Prerequisites and limitations in disinformation scenarios
Ready to use Keyword and narrative monitoring, sentiment analysis and abnormal volume alerts across public news, social media and forums It can show that a claim is heating up and on which platforms it appears, but it cannot determine whether the claim is true or false. Private messages and non-public groups are out of scope.
Ready to use Text extraction from images (OCR) Text on image cards can be included in retrieval and narrative clustering; low resolution and decorative fonts reduce extraction quality.
Requires configuration and tuning Detection of coordinated inauthentic behavior and anomalous account clusters This relies on publicly available platform fields (posting time, interaction relationships, content similarity), so closed platforms cannot be covered. Spontaneous mobilization by fans and synchronized publishing by media outlets can also look coordinated, so findings are probabilistic assessments that require human verification.
Requires configuration and tuning Video and deepfake detection Re-encoding, compression and screen recording can weaken the features used for assessment; where legal proceedings are involved, confirm through a separate forensic channel.
Requires configuration and tuning Tiered alert rules Thresholds are calibrated against real feedback during the comparison period, based on the nature of the business and jurisdiction.
Requires custom assessment Non-public sources, closed communities and in-depth coverage of specific languages Legality and authorization must be confirmed first, and coverage verified through a proof of concept before inclusion.
Requires custom assessment Integration of case management with the agency's existing systems Can be custom-built around the agency's workflow; existing official document and incident reporting systems must be inventoried first.

We recommend stating explicitly in the contract that the system makes no final determination of truth and provides no final attribution conclusion. In the FIMI threat reports it has published since 2023, the EEAS (European External Action Service) describes foreign information manipulation and interference as an intentional and coordinated pattern of behavior, whose actors may be state or non-state actors and their proxies; attribution requires a separate assessment of the strength of the evidence and of alternative explanations.

Deployment and data governance

Disinformation monitoring involves two kinds of data: external content from public, lawful sources, and the unit's internal assessment records and handling decisions. Both may contain personal data or sensitive information, so access permissions, retention periods and deployment location should be set separately according to content and purpose.

  • Data hosting and security certification:InfoMiner data servers are located in Taiwan.
  • On-Premise:Assessment records, internal knowledge and report generation can use RAGi On-Premise together with the QubicX on-premise AI platform; data processing and model inference run on the unit's internal network, and no data is sent to an external cloud.
  • Records and auditing:Which operation and handling records must be kept, and in what format they are exported, can be assessed against the agency's audit requirements and planned together with the custom build of case management.
  • Procurement channels:InfoMiner is qualified under the government Joint Supply Contract and can be procured through it; custom-build items are assessed separately according to requirements.

RAGi Enterprise AI Retrieval-Augmented Generation Engine · QubicX On-Premise AI Platform

The limits of monitoring: freedom of speech and personal data

This system analyzes narratives and behavior patterns, but designating accounts and running relationship analysis may still involve data that can identify individuals; being publicly visible does not mean personal data is not involved, so the legal basis and necessary scope of collection, processing and use should be confirmed. Before adoption, we recommend that the legal and business units define which accounts may be listed as accounts of interest and who approves them, the retention and deletion periods, and that results be used only for stated purposes such as clarification and reporting.

Laws that may be involved in handling

If a verification conclusion is to be referred or reported, the provisions on spreading rumors in the Social Order Maintenance Act, the Disaster Prevention and Protection Act and the Civil Servants Election and Recall Act may be involved; for a summary of the provisions, see What is cognitive warfare? How it differs from fake news, information manipulation and FIMI. Each of these laws has different elements of the offense: whether content is true or false is judged by fact-checkers based on evidence, and whether it is unlawful is determined by the competent authority in accordance with the law; being judged false does not mean being unlawful.

Who uses it and how

Scenario 1: government agency spokesperson and public sentiment units

The system produces narrative summaries on a schedule. The suggested operating rhythm is as follows:

  • Daily summary:Provides a narrative list before the morning meeting, separating items to keep watching from those where a response is recommended.
  • Real-time alerts:Narratives that affect the public's interests or are accelerating across platforms are sent directly to the contact point.
  • Post-clarification tracking:Observe changes in publicly available reposts and discussion after the clarification.

If the clarification is only reposted within official accounts while the original narrative keeps growing on other platforms, consider changing the publishing channel or the way it is explained.

Scenario 2: critical infrastructure operators

Operators of power, water, transportation and communications can set up topics related to service outages, quality or contamination as monitoring scenarios. The monitoring scope is defined by service names and facility place names and linked to incident reporting: when a claim about a water or power cut in a certain area spreads quickly, the duty officer first checks the actual operating status and then decides whether to issue an explanation. For process design, see Public sentiment crisis SOP: a 7-step PR crisis guide.

Scenario 3: election authorities and local governments

The election scenarios on this page include the voting and vote-counting process, election operations, and suspicious content that impersonates candidates' words and actions. Voting day for Taiwan's 2026 local elections is November 28; before the election you can build a topic list and tiering rules, and switch to high-frequency monitoring around voting day. Monitoring must be politically neutral and focus only on the types of messages that affect election procedures. To track the overall level of public discussion, LargitData also offers 2026 Taiwan Election Lab, a real-time volume dashboard covering all 22 counties and cities in Taiwan. For a pre-election task checklist, see How to monitor election disinformation: a task checklist for the 60 days before the election.

Adoption process and acceptance criteria

Before comparing metrics such as accuracy, align the datasets, labeling criteria and sample distribution. This page recommends pairing acceptance with historical-event backtesting and comparison-period evaluation.

Phase Key Tasks Client Stakeholder Roles Deliverables
1. Scope inventory Confirm the topics of interest, keywords, designated accounts and existing reporting workflow Spokesperson, public sentiment and business case officers Monitoring scope list and division of responsibilities
2. Historical-event backtesting Using incidents the unit has handled, check whether the system can reconstruct the earliest observable nodes and spread paths The case officers at the time Backtest report, with items that can and cannot be covered
3. Calibration Pilot Phase Run in parallel with existing operations and give feedback on missed detections, false alarms and tiering Public sentiment case officers Calibrated tiering thresholds and report format
4. Production Go-Live Push summaries and alerts automatically, and conduct training on interpreting them Spokesperson contacts and business unit liaisons Daily summaries, tiered alerts and handling records

Backtesting uses cases the unit knows well to check when the issue was found at the time, how far the system could have moved that time earlier within observable data, and which platforms' data could not be obtained; this also shows which items need tuning.

10 questions to ask when evaluating vendors

The evaluation should confirm data scope, assessment workflow and interface operation together. We recommend asking vendors to answer in writing:

  1. Source list: which platforms can be monitored? Which are collected in-house and which are obtained under license?
  2. Gap notification: when a platform changes its layout, how will we know which segment of data is incomplete?
  3. Cross-platform merging: when the same narrative is rewritten and reposted, how is it deduplicated and merged?
  4. Narrative clustering evaluation: which datasets and labeling criteria are used? When clustering is wrong, can analysts split or merge clusters?
  5. Basis for coordination assessment: which fields are used when flagging suspected coordination? Can they be shown to analysts?
  6. Handling false alarms: how is normal coordinated behavior excluded? Can false alarms be fed back to adjust the system?
  7. Multimodal scope: what are the conditions and limitations for image, video and deepfake detection?
  8. Explainability: can each alert explain its tier? Can the unit adjust the rules?
  9. Verification records: can screenshots, links and capture times be exported? Are records still kept after the original post is deleted? Which fields are retained in the operation log?
  10. Attribution stance: does the vendor claim it can determine truth or identify actors? On what basis?

We recommend writing the tenth question into the contract: if product materials describe suspicious signals directly as fake news or foreign manipulation, the unit takes on additional risk in both its external communications and legal proceedings.

FAQ

No, and it should not. The system produces suspicious signals and investigative leads: which narrative is spreading, the earliest observable nodes, and whether there are signs of coordination. Establishing whether content is true requires checking the original source, confirming facts with the responsible department or consulting fact-checking organizations; the final call is made, and recorded, by an analyst with the proper authority.
The data sources are similar; the unit of analysis is different. Ordinary sentiment monitoring centers on keywords, volume and sentiment, and answers what people are talking about. Cognitive warfare monitoring centers on narratives, account behavior and spread structure, showing the earliest observable nodes, the amplification nodes and whether accounts show unnatural signs of coordination.
InfoMiner monitors news, social media, forums and public data, and can cover PTT, Dcard, Facebook, YouTube, Threads, TikTok/Douyin and LINE communities, with more than 500,000 channels overall. Actual coverage depends on the plan and licensing, and gaps may occur when platforms change or block access; private messages and non-public groups are out of scope.
It can provide leads. The system can extract text from images (OCR), perform image recognition, and run detection on videos and deepfakes. The output is a degree of suspicion, not a forensic conclusion; repeated re-encoding, compression and screen re-recording may weaken the features it relies on, so human verification is still required, and where legal proceedings are involved, confirmation should go through separate forensic channels.
Yes. Assessment records, verification findings and internal knowledge can run on RAGi On-Premise with the QubicX on-premise AI platform, so data processing and model inference take place inside your internal network and nothing is sent to an external cloud. InfoMiner's data servers are located in Taiwan.
The timeline depends on the monitoring scope and whether custom development is needed. We recommend accepting the system through a proof of concept combined with back-testing on historical incidents your organization has handled: check whether the system can reconstruct the earliest observable nodes, the spread path and the key nodes, list what it cannot cover, then calibrate alert thresholds during a parallel-run period before going live.

Book a demo of fake news detection and cognitive warfare monitoring

Using a false information incident your organization has handled as the example, we walk through the full process: cross-platform collection, narrative clustering, spread and coordination analysis, tiered alerts, and human verification with verification records kept.

Contact Us