During election seasons or major national issues, online news comment sections often become heated spaces of conflict across gender, generation, and political lines. For years, there have been persistent concerns that behind some of these conflicts may lie “foreign winds,” or interventions by foreign actors seeking to manipulate public opinion and deepen social divisions. A KAIST research team has now developed a technology that uses big data on two decades worth of news comments and artificial intelligence (AI) to precisely detect traces of such hidden influence operations.
KAIST (President Choongsik Bae) announced on the 12th of August that a joint research team led by Professor Wonjae Lee of the Graduate School of Culture Technology, Professor Meeyoung Cha of the School of Computing (Scientific director at Max Planck Institute for Security and Privacy) and Professor Alice Oh of the School of Computing, in collaboration with Professor Thorsten Holz of the Max Planck Institute, has developed an explainable AI technology that automatically detects patterns suspected of foreign-linked influence operations in online news comments and provides specific evidence for its judgments.
The organized and repeated posting of comments or content by certain actors to shape public opinion in a desired direction is known as an “online influence operation.” Existing AI-based detection technologies have had a key limitation: even when they classify certain accounts as belonging to a “blacklist,” they often fail to provide clear evidence explaining why those accounts should be considered influence-operation accounts.
To overcome this limitation, the research team used 70 foreign-linked accounts previously identified by the Institute for National Security Strategy as starting points. They then tracked groups of accounts connected to them or repeatedly commenting on the same news articles, ultimately collecting and analyzing a large-scale dataset of 110 million comments posted on Naver News over a 20-year period from 2006 to 2025.
In particular, the AI developed by the research team examines accounts through a careful three-step process. First, it checks whether there are clues suggesting that the author may be linked to a foreign source. Second, it examines whether the comment contains emotionally polarizing expressions, such as moral condemnation or blind praise. Third, it identifies which country or target the emotional framing is directed toward.
The model does not stop at simply labeling an account as suspicious. It also highlights the specific phrases in the comments that served as the basis for its judgment. The team further combined this with multidimensional behavioral-pattern analysis, including account activity frequency, account lifespan, and activity links with other suspected accounts. As a result, among approximately 4 million Naver News users, the model ultimately identified 23,998 accounts exhibiting patterns consistent with suspected public-opinion manipulation.
The analysis also revealed the more subtle strategy of these suspected accounts. Their main target was not the victory of a particular political camp, but rather the maximization of division and confrontation within Korean society.
Among the top 10 targets that drew the highest public engagement, measured through likes and other reactions, seven were prominent domestic political figures. Notably, the attacks were not concentrated on a single party or ideology. Former and current presidents, presidential candidates, and political parties from both progressive and conservative camps were targeted across the spectrum. According to the research team, this suggests a sophisticated strategy aimed not so much at supporting a particular group, but at inflaming domestic political conflict and increasing social distrust and polarization.
This study is significant because it provides data-based evidence for influence-operation activity that had previously been discussed largely in terms of suspicion, while also offering a potential defense mechanism for protecting healthy online public discourse. In the future, portal platforms and related organizations could use this technology during elections or national crises to monitor the influx of suspicious accounts in real time and prioritize the review of coordinated attacks against domestic political figures. However, the research team emphasized that the AI should not be used to block accounts indiscriminately, but rather as an explainable content-moderation tool that supports the judgment of expert reviewers.
Professor Wonjae Lee said, “By analyzing 20 years of data, we found that suspected accounts tended to use messages criticizing Korea and domestic political figures rather than directly praising foreign countries, and that these messages gained higher visibility,” adding, “This research can provide empirical criteria for when and which messages platforms and monitoring organizations should prioritize for review, especially during socially sensitive periods such as elections.”
Professor Alice Oh said, “This is a meaningful achievement in which AI precisely identified not only the surface meaning of words in massive comment datasets, but also subtle emotional patterns and organized behavioral signals intended to provoke conflict,” adding, “It can become a powerful defense system against online influence operations, which are becoming increasingly sophisticated.”
Professor Meeyoung Cha said, “This study goes beyond simple blacklist-account analysis and represents the outcome of actionable data science that addresses real-world problems and drives practical change,” adding, “In an online environment where social conflict is deepening, we hope this technology will serve as a practical tool for protecting the transparency and trustworthiness of the digital public sphere.”
This research was led by KAIST Ph.D. candidate Jaehong Kim and master’s student Hyeonseung Kim as co-first authors. The paper is scheduled to be presented at the USENIX Security Symposium 2026, one of the most prestigious conferences in the field of computer security.
※ Paper title: Cross-National Information Attacks: A Two-Decade Analysis of Troll Behavior in Korea, DOI: 10.48550/arXiv.2606.22785
This research was supported by the Hyundai Motor Chung Mong-Koo Foundation, the Institute of Information & Communications Technology Planning & Evaluation, and the National Research Foundation of Korea, funded by the Ministry of Science and ICT.