Ilmu Komputer & AI editorial
Open AccessOA2026
Principled Detection of Coordinated Manipulation from Aggregate Distortion and Account Reuse
An aggregate-first evidence layer for detecting collective manipulation via distributional distortion and account reuse laws
Qian Guo; Yidan Hu; Rui Zhang· 2026· DOI 10.48550/arXiv.2609.13407
The core problem
Coordinated manipulation is inherently collective: multiple plausible accounts jointly distort ratings, rankings, and engagement metrics. Existing defenses typically construct evidence from identities, graphs, content, or co-activity patterns. This work proposes a fundamentally different approach—an aggregate-first evidence layer that treats the distortion of a context-level outcome distribution as the primary evidence object. The engine observes only a histogram, count, resolution, and reference distribution, deliberately withholding identities until interval evidence is fixed. This design addresses a critical gap: while individual accounts may appear benign, their collective impact on aggregate distributions can reveal coordinated manipulation. The authors motivate the need for methods that are robust to identity obfuscation and can detect manipulation even when accounts are reused across contexts. The paper's central insight is that raw discrepancies between observed and reference distributions have positive finite-sample expectation, requiring a matched null expectation subtraction to obtain signed evidence. This signed evidence then accumulates across accounts via participatio
Innovation
In a fixed-attack sweep against historical non-donor comparison accounts, reassigning the same manipulated events across identities with increasing reuse raises account-score ROC-AUC from 0.500 to 0.797. With activity- and exposure-matched clean twins, frequency-based detection remains at chance (ROC-AUC ≈ 0.500) while counterfactual attribution achieves ROC-AUC 0.744. Under a mean-preserving shape intervention, Wasserstein-1 and Jensen-Shannon evidence achieve ROC-AUC 0.909 and 0.967, respectively, whereas frequency and mean-based attribution remain at chance. The aggregate evidence complements repeated co-activity, improving mixed-mechanism ROC-AUC from 0.750 to 0.874 with a simple untrained combination. These results demonstrate that distributional shape evidence is highly discriminative even when mean and frequency are uninformative. The linear reuse law is empirically validated: as reuse increases, account scores increase proportionally, enabling detection of coordinated manipulation that would be invisible to identity- or graph-based methods. The controlled experiments isolate the contribution of aggregate distortion from other signals, confirming that the aggregate-first lay
Coordinated manipulation is inherently collective: multiple plausible accounts jointly distort ratings, rankings, and engagement metrics. Existing defenses typically construct evidence from identities, graphs, content, or co-activity patterns. This work proposes a fundamentally different approach—an aggregate-first evidence layer that treats the distortion of a context-level outcome distribution as the primary evidence object. The engine observes only a histogram, count, resolution, and reference distribution, deliberately withholding identities until interval evidence is fixed. This design addresses a critical gap: while individual accounts may appear benign, their collective impact on aggregate distributions can reveal coordinated manipulation. The authors motivate the need for methods that are robust to identity obfuscation and can detect manipulation even when accounts are reused across contexts. The paper's central insight is that raw discrepancies between observed and reference distributions have positive finite-sample expectation, requiring a matched null expectation subtraction to obtain signed evidence. This signed evidence then accumulates across accounts via participation logs, enabling detection of coordinated behavior without explicit identity tracking.
The proposed engine operates on aggregate statistics: a histogram of outcomes, total count , resolution , and a reference distribution . For each context, the raw discrepancy is computed as
. Because
under the null due to finite sampling, the method subtracts a matched null expectation
to obtain signed evidence
. Reference uncertainty is accounted for by integrating over a prior on . Participation logs then accumulate these fixed increments across accounts: for account , the score is
, where is the exposure weight. The authors characterize matched-exposure divergence, bound self-influence, establish finite-horizon separation, and derive an exact linear reuse law for paired contexts: if the same manipulated events are reassigned across identities with reuse factor , the expected score scales linearly with . The methodology is evaluated through controlled rotation experiments and paired counterfactual interventions on historical Amazon review streams, using synthetic identities with known coalition membership and exact clean twins as controls.
Why it matters
The paper's key contribution is shifting the evidentiary basis from individual-level features to aggregate distributional distortion. This approach is particularly powerful because it does not require identity resolution, graph construction, or content analysis—making it resilient to adversarial obfuscation. The matched null expectation subtraction is crucial: without it, raw discrepancies would yield false positives due to finite-sample noise. The signed evidence provides a principled measure of manipulation that accumulates across contexts. The exact linear reuse law offers a theoretical foundation for detecting account reuse, a common tactic in coordinated manipulation. The evaluation on historical Amazon review streams demonstrates practical viability, with ROC-AUC improvements up to 0.967 under shape interventions. The combination with co-activity evidence suggests that aggregate-first detection can complement existing methods, improving mixed-mechanism performance. Limitations include the need for a reliable reference distribution and the assumption that manipulation distorts the outcome distribution in detectable ways. Future work could extend the framework to dynamic settings and adversarial reference manipulation. Overall, this work establishes aggregate distortion as a first-class evidence object for detecting coordinated manipulation, with strong theoretical guarantees and empirical validation.
Who should read this
CS practitioners and researchers
Opening member content…