Integrated content-network analysis to discover influential collectives for studying social cyber-threats from online social movements
Falah Amro,Hemant Purohit
DOI: https://doi.org/10.1007/s13278-023-01124-6
2023-09-24
Social Network Analysis and Mining
Abstract:Recent online social movements with offline violence events have been linked to activities of threat actors that exploit online social networks to instigate violence, among other ills. In recent years, researchers have begun to explore natural language processing (NLP) and social network analysis (SNA) tools in a myriad of applications for early detection, forecasting, and prevention of social cyber-threat actors to help preserve public safety. NLP-based approaches provide a promising direction to characterize the behavioral patterns of actors in online social movements that facilitate mechanisms for early detection of social cyber-threat actors. Similarly, SNA-based approaches provide tools to study structural patterns for actor interaction and measure different properties of the social network of participating actors in online social movements. However, tools designed using the foundation of an isolated approach of either NLP or SNA are insufficient to uncover patterns of connective and collective actions from the information disseminated during violent social movements, which could help identify the collective and connective set of influential actors behind the violent events in these movements. This paper proposes a novel integrated content-network analysis approach to combine NLP and SNA techniques to monitor actor interactions in social networks, which, in turn, enables us to identify actors of interest as an emerging social identity group and map their collective influence at different points in time. A mixed-method analysis using our approach on the dataset of a recent online social movement of "Freedom Convoy" in Canada shows that an influential group of actors, referred to here as, influential collective, generated aggressive and emotional content to influence others in developing coordinated activities of manipulation and instigation. We show that group centrality measures of SNA can be leveraged to discover the influential collective that is the primary driver to sustain the online social movement in the days leading up to the protest and during escalations. Using a variety of centrality measures, we examine how the influential collective both maintained its influence over time and increased it substantially in the peak days of the social movement. The resulting insights from the application of our analytical approach of integrating content and network analyses present opportunities for first responder agencies in the detection, monitoring, and prevention of offline violent activities instigated by online social movements as they unfold in real time, as well as inform how implicit social identities could be formed because of the emergence of such influential collectives.