
‘Online influence operations’ are activities that systematically spread comments or posts to shape people’s perceptions and public opinion. Getty Images Bank
Analysis of about 110 million Naver News comments spanning roughly 20 years from 2006 to 2025 has identified around 24,000 suspicious accounts that pose as Koreans while amplifying social conflict and polarization through opinion manipulation. Rather than favoring a specific political bloc, these accounts were found to attack both progressive and conservative camps. The findings are expected to help quickly detect suspicious signs of opinion manipulation when major issues such as elections arise.
KAIST announced on the 12th that a joint research team led by Professor Lee Won-jae of the Graduate School of Culture Technology, Professor Cha Mi-young of the School of Computing (Director at the Max Planck Institute for Security and Privacy in Germany), and Professor Oh Hyeon, together with Professor Thorsten Holz of the Max Planck Institute, has developed an artificial intelligence (AI) tool that automatically detects patterns in online news comments suspected to be linked to foreign influence operations and presents the evidence for its judgments.
‘Online influence operations’ are activities that systematically spread comments or posts to shape people’s perceptions and public opinion. At low cost, they can amplify anger and hatred, expand social distrust and political conflict, and undermine the credibility of the online public sphere. Existing AI detection technologies have been limited in their ability to provide specific grounds for classifying a given account as suspicious.
In their prior work, the research team started from 70 foreign-linked accounts identified by the Korea Institute for National Security Strategy and then tracked other accounts that repeatedly posted comments on the same articles as those accounts.
They analyzed 112,658,554 Naver comments posted between April 2006 and March 2025, along with data from 4,047,831 users. Rather than focusing on a particular incident or single election, they examined over the long term when suspicious accounts began to appear, their messaging strategies, user reactions, and their main targets of attack.

Hierarchical structure of the explainable AI developed by the research team. KAIST
The AI developed by the team first looks for expressions or contextual clues that suggest the author may be linked to a foreign entity, and then analyzes whether emotions that can fuel social polarization—such as moral condemnation or blind praise—are present. It also determines which country or target those emotions are directed at.
The researchers designed the AI so that it presents the specific expressions in comments that underlie its decisions, allowing humans to verify the reasons. They also examine various behavioral patterns, including an account’s activity frequency and duration, and its activity correlations with other suspicious accounts. To focus on technical patterns rather than geopolitical disputes, the team anonymized the countries in their classification analysis.
The analysis identified 23,998 suspicious accounts. Their activity exhibited several noteworthy features. Instead of unilaterally supporting a particular political camp, they predominantly spread messages that intensify internal social conflicts and confrontations. In other words, most strategies aim not to praise foreign countries but to encourage a negative view of Korean society. Comments criticizing Korea increased sharply after 2017 and peaked in 2018.

Activity trends of foreign-linked suspicious accounts from 2006 to 2025. KAIST
Activity by suspected opinion-manipulation accounts was about 11% higher during election periods than outside election periods. Suspicious account activity was particularly elevated around the May 2017 presidential election held after the impeachment of former president Park Geun-hye.
Among the top 10 targets that received the most public engagement, seven were well-known domestic politicians. Rather than focusing on a specific party or ideology, the accounts targeted a wide range of figures and entities, including former and incumbent presidents from both progressive and conservative camps, presidential candidates, and political parties.
The research team concluded, “This shows that foreign-linked influence operations should not be viewed solely through the lens of ‘which political force they support’,” adding, “We must also consider the possibility that they exert influence not by directly supporting a particular camp, but by stoking existing political conflicts and thereby expanding social distrust and polarization.”

User engagement analysis by target country. KAIST
The developed technology is expected to be used to identify suspicious opinion-manipulation accounts during periods of heightened public interest and conflict, such as elections or security crises. The team emphasized that the AI should be used as a tool to support human experts’ judgment, rather than automatically blocking or sanctioning suspicious accounts.
Professor Lee said, “These suspicious accounts show a pattern of fueling conflict by criticizing Korea and domestic politicians rather than directly praising foreign countries,” and added, “This will serve as a criterion for filtering messages that should be prioritized for review during elections and other periods of heightened social conflict.”
Professor Oh explained, “The AI goes beyond the surface meaning of comments to jointly analyze conflict-inducing emotions and organized behavioral patterns of accounts,” and said, “We expect it to be useful for detecting increasingly sophisticated online influence operations.”
Professor Cha noted, “This is a case of ‘Actionable Data Science’, where data science is connected to solving real social problems,” and added, “We hope it will become a practical tool for enhancing the transparency and trustworthiness of the digital public sphere.”
The research findings will be presented on the 13th at the USENIX Security Symposium 2026, an international conference in the field of computer security.
– doi.org/10.48550/arXiv.2606.22785

From left: Kim Jae-hong, PhD student at KAIST Graduate School of Culture Technology; Kim Hyun-seung, master’s student; Kim Ji-seon, PhD student at the School of Computing; Professor Oh Hyeon of the School of Computing; Professor Thorsten Holz of the Max Planck Institute for Security and Privacy in Germany; Professor Lee Won-jae of the KAIST Graduate School of Culture Technology; and Professor Cha Mi-young of the School of Computing (Director at the Max Planck Institute for Security and Privacy). KAIST
Copyright ⓒ DongA Science. All rights reserved.