Evidence of inter-state coordination amongst state-backed information operations

Since 2018, Twitter has steadily released into the public domain content discovered on the platform and believed to be associated with information operations originating from more than a dozen state-backed organizations. Leveraging this dataset, we explore inter-state coordination amongst state-backed information operations and find evidence of intentional, strategic interaction amongst thirteen different states, separate and distinct from within-state operations. We find that coordinated, inter-state information operations attract greater engagement than baseline information operations and appear to come online in service to specific aims. We explore these ideas in depth through two case studies on the coordination between Cuba and Venezuela, and between Russia and Iran.


Introduction
The current reach of social media platforms and their affordances for cheap and easy content dissemination, profiling, and targeting, have established social media as a primary avenue for information operations -efforts to manipulate public opinion by intentionally altering the information environment 1 .A substantial literature has emerged studying the tactics and strategies of information operations, particularly on Twitter, where data has been widely available [2][3][4] .These studies have focused on campaigns attributed to individual states or state-backed organizations.To the best of our knowledge, no prior work has looked at collaboration amongst states in these efforts.Yet, examples of international collaboration for the dissemination of propaganda date back to the first and second World Wars [5][6][7][8] .Our research explores evidence of inter-state coordination amongst state-backed information campaigns, operationalized through the following two research questions.RQ1: Do state-backed information campaigns operating on Twitter collaborate across states?If so, what distinguishes these efforts from internal information operations in terms of design, deployment, and impact?RQ2: Can we categorize strategic and tactical mechanisms underlying inter-state information operations?E.g., specific roles of individual accounts in support of collusion?
We extract interaction networks amongst thirteen state-backed campaigns operating on Twitter between 2011 and 2021, perform static and dynamic pairwise analyses of observed activity, and highlight the varied structure of inter-state information operations through two case studies.Our findings indicate that inter-state operations attract greater engagement than intra-state operations.We suggest that the strategies employed by state-backed information operations serve to create and maintain a desirable information habitat, e.g., by engaging in ambient affiliation through common hashtags 9 , initiating network expansion for increased exposure 10 , and referencing controversial topics to gain attention 11 .Our findings represent the first insights into tactics and strategies underlying global cooperation and collusion amongst states in strategic information operations deployed through social media.

Strategic information operations
Starbird et al. 1 use the term strategic information operations (IO) to refer to efforts by individuals and groups, including state and non-state actors, to manipulate public opinion and change how people perceive events in the world by intentionally altering the information environment.Tracing their roots to TV and radio propaganda in the 20th century, and in some variation even much earlier 12 , the modern digital age and in particular today's social media landscape have enabled these efforts with unparalleled efficiency and have raised a unique set of questions around response 13 .
A primary subset of information operations aims to disseminate inaccurate, incorrect, or misleading information, so-called disinformation.Disinformation operations have been strongly associated with political campaigns 14 , focused primarily on social media manipulation of public opinion through bot accounts and paid workers [15][16][17][18] .In attempt to combat disinformation, scholars have focused efforts on developing technical solutions for automated detection of multimodal disinformation, e.g., Since October 2018, Twitter has made public the tweets, media, and account-related information of users presumed to be involved in state-linked information operations, provided through the Twitter Moderation Research Consortium (TMRC).The TMRC suggests these users are engaged in manipulation that can be reliably attributed to a government or state-linked actor 46 .We aggregate all account activity shared by the TMRC between 2007 and 2021.In total, this represents 23 state-backed information operations consisting of the full activity of 84,262 distinct accounts and approximately 120 million archived tweets.
During preprocessing, we made the following modifications to the complete dataset.We combined accounts designated by Twitter as linked to Egypt and UAE.Twitter's documentation subsequent to the release of these accounts indicated that much of their activity was attributed to an operation managed out of both countries targeting Qatar and Iran with messaging supportive of the Saudi government 47 .We did not include data from one release in March 2020 which Twitter attributed to "Egypt, UAE and Saudia Arabia" because attribution to a single country was not possible.This omitted subset of the data was relatively small (5350 accounts, 6.3% of the total dataset).We did not find evidence of inter-state activity in content originating from Armenia, Bangladesh, Thailand, Tanzania, Mexico, Catalonia, Ghana, Nigeria, or Spain.These nine countries are therefore included in our dataset and analyses but not represented in the results, which focus on inter-state coordination.In sum, the number of tweets represented by these nine countries accounts for less than 0.2% of the data.Dataset statistics are further detailed in the analyses below.

RQ1: Inter-state activity
We use the terms "coordination" and "coordinated operations" to characterize purposeful collaboration in service to shared objectives.Informed by explanations of the dataset provided by the TMRC upon each data release, our analyses make the following assumptions: 1.All activities associated with accounts tagged by Twitter as participating in information operations are part of those operations; 2. All pairwise interactions between state-backed influence operation actors are coordinated information operations/platform manipulation.Evidence of inter-state coordination is informed by static and dynamic network and content analyses across state-linked accounts.

Inter-state interaction network
We build a global inter-state interaction network amongst state-linked accounts (Figure 1a).Nodes represent accounts and directed edges represent retweets, replies, mentions, and quotes, between 2011 and 2021.Node color corresponds to country and edge color matches source node.We observe two predominant substructures within the network.The first is a radiating pattern, consisting of one or a few central nodes with high out-degree centrality (e.g., Figure 1b(i)).This motif appears for countries with either dominating in-degree centralization or out-degree centralization.Central nodes function as either content creators or self-promoters surrounded by a substantial number of followers and amplifiers to disseminate content and establish new social ties.The contrasting motif is balanced with similar in-and out-degree (e.g., Figure 1b(ii)).Figure 1(c) distills the inter-state interaction network via aggregation by country.Node size is proportional to log-scaled number of associated accounts.Edge width is proportional to log-scaled number of interactions in each pair-wise coordination and edge color matches source node.We note that Cuba, Serbia, and Ecuador appear to use retweets and replies to connect with other states for network expansion and content promotion.Whereas, Venezuela, Russia, Turkey, and Iran are predominantly the target of interactions.Accounts linked to these countries disseminate relatively more original content.Indonesia, Egypt & UAE, China, and Saudi Arabia exhibit more balanced structures.We calculate the reciprocity of each state in the weighted network, decomposing dyadic fluxes into a fully reciprocated component and a fully non-reciprocated component 48

Temporal analysis of inter-and intra-state activity
Figure 2 shows the cumulative inter-and intra-state interaction counts over time, along with labeled interaction peaks for each of the 13 states.We observe that initial inter-state activity lags behind intra-state activity (avg.lag approximately 2 years).Notably, a majority of inter-state interactions reach peak activity synchronously in late 2017 and 2018.Comparing inter-and intra-state interactions for each state individually, we find that 10 out of the 13 countries in our dataset have substantially different temporal patterns.That is, in most cases, inter-state operations do not occur concurrently with intra-state operations.
Rather, they represent what appears to be a separate strategic operation.Seven peaks in inter-state and intra-state activities occur more than one year apart, three occur three to twelve months apart, two peaks occur within three months of one another, and one occurs simultaneously within the same month).

Measuring engagement with inter-state activity
Observing that one aim of inter-state coordination appears to be increased visibility, we measure differences in engagement statistics between inter-and intra-state activity using a two sample T-test.We perform a priori power analysis to determine the minimum sample size, set the significance level α to 0.05, power to 0.8, and Cohen's d effect size to 0.2.We obtain a minimum effective sample size of 394 to perform target statistical testing.Using this threshold value, we filter out two states (Turkey and Uganda) with less than 394 inter-state interactions.Given the significantly smaller fraction of quotes in the dataset (the number of quote tweets in the dataset is less than the effective sample size), we select likes, retweets, and replies as three indices for comparative study.We perform a Welch's T test to determine if observed differences are significant.We additionally perform engagement comparisons between inter-state interactions and state-backed accounts' interactions with external accounts, i.e., accounts not tagged by Twitter as state-backed actors, presumed "normal" accounts).As the data is imbalanced (see Table 1), we randomly sample external interactions matching the observed number of inter-state interactions.With a similar level of variance, we perform a regular two-sample T-test.Results are provided in Table S3 of Supplementary Material.We observe a general pattern of more likes and retweets associated with external accounts.This is expected as external accounts have greater visibility, e.g., news outlets, and likes and retweet counts are derived from the original post.However, number of replies associated with inter-state interactions is substantially greater than those associated with external interactions, indicating success of inter-state coordination to prompt meaningful engagement (e.g., Cuba, China, and Indonesia).

RQ2: Strategic and tactical mechanisms
We study the strategic use of network structure and shared content in service to inter-state coordination.These are explored in detail through two case studies -coordination between Cuba and Venezuela and between Russia and Iran.These examples are selected to highlight the diversity of structural and functional activity we observe across the dataset.In the case of Cuba and Venezuela, we observe relatively bi-directional interaction; both countries serve as source and target of coordinated activity.We also observe administrators playing distinct roles in the campaign.Russia and Iran's coordinated operations, on the other hand, are at a larger scale and structurally very different.

Ambient Affiliation
Implicit association among social network actors is facilitated through hashtagging, a phenomenon which has been studied in the sociolinguistics literature as ambient affiliation 9 .These indirect interactions enhance visibility of users' discourse through search 49 .The social role of hashtagging is to facilitate the establishment of ad hoc social interaction groupings or subcommunities, which constitute a temporal habitat for information operations.Hashtagging has been employed and proven effective across platforms, from "influencers" and organizations to disinformation operations, for acquiring followers and increasing exposure 1,[50][51][52] .We suggest that inter-state ambient affiliation is used by information operations to create idea habitats conducive to information spread.
We construct the inter-state hashtag network (Figure 3(a)).Nodes in the network represent accounts that both engage in hashtagging and are involved in inter-state coordination; Undirected edges indicate use of common hashtags by these accounts.There are 1, 014 nodes and 61, 010 edges in the network (density = 0.594; diameter = 11).The largest connect component contains 861 nodes and 60, 510 edges (density = 0.0817).Use of ambient affiliation is variable across operations (Figure 3(b)).While pervasive within Cuban operations, Russia, Serbia, and Turkey use this tactic only negligibly despite having large-scale operations.Notably, engagement in ambient affiliation appears correlated with greater engagement (see Table 2, e.g., we see greater engagement with content from Cuba and Honduras than from Russia and Serbia.) Globally, we identify 1, 148 unique hashtags that occur within inter-state activity a total of 33, 119 times.Figure 4 lists and categorized the hashtags which appear in at least 200 inter-state interactions.We observe pervasive, intentional exploitation of political controversy within inter-state hashtagging behavior.In the case of several prominent collaborative operations, a majority of inter-state interactions target specific political events (e.g.Honduras and Iran: 2017 Honduras' Election Crisis; Iran and Russia: 2016 U.S election; Iran and Venezuela: 2017 Venezuelan Protests).Other coordination activities incorporate media outlets associated mostly with unsubstantiated news.
In addition, we observe the use of hashtagging for network expansion, e.g., #syts, #openfollow, #siguemeytesigo (follow me and I'll follow you).This tactic appears to take one of two forms: (1) explicitly requesting followers; and (2) using mentions and tags for penetration into new communities.

Taxonomizing roles within inter-state operations
Within inter-state operations, we observe that different users/accounts appear to have different patterns of behavior.We contextualize these differences through the lens of role analysis, defining primary roles as follows: • Administrator.Manages operations of the information campaign.Administrators self-identify as group leaders through profile information and shared content.
• Influencer.A hub of the operation with high in-degree centrality.Typically, an influencer is the source of the information who exploits fake news sites and may have multiple similar accounts in the network to avoid takedown.We define users with in-degree greater than 10 as the influencers in the network.
• Promoter.Primarily promotes content for enhanced visibility and engagement.We define users with out-degree greater than 10 as promoters in the network.
• Broker.A gatekeeper, connecting multiple communities/organizations with relatively high in-degree and out-degree centrality.We identify users who meet criteria for both promoter and influencer as brokers.
• Follower.An actor with minor (observable) impact within the operation.Users that are not identified within aforementioned roles are categorized as followers.
We leverage this taxonomy in the case studies which follow.The two case studies are selected for their diversity with respect to structure and content.

5/15
Case Study 1: Coordination between state-linked accounts from Cuba and Venezuela

Network structure
We construct the inter-state interaction network between Cuban and Venezuelan state-linked accounts.We observe 6, 469 interactions between 56 Cuban and 62 Venezuelan accounts.Notably, the network has two well-connected clusters connected by a single edge (see Figure 5(a).We observe a relatively balanced network structure between Cuba and Venezuela where the interactive pattern is bidirectional (5, 464/6, 649 of Cuba's out-degree interactions point to Venezuela, and 1, 005/1, 027 Venezuela's out-degree interactions point to Cuba).In each cluster, a small subset of Cuban and Venezuelan nodes dominate activity while remaining nodes connect with them through retweets and mentions.This network structure is a trademark of Cuba's inter-state operations.We observe that Cuba's intra-state interaction network, by contrast, has greater connectivity and more uniform in-/out-degree sequences.

Content analysis
Notably, Cuban and Venezuelan information operations appear to center around structured teams, and each team has a self-identified administrator.Cluster 1.In Figure 5(b), we dive deeply into the inter-state operation structure.Within Cluster 1, we identify five representative nodes, two attributed to the Venezuelan campaign and three from Cuba.Representative nodes are selected as those with the most within-cluster interactions.The two team leaders are also identified though their user profiles and account descriptions.
V1 is a Venezuelan node with high out-degree centrality, and the two Cuban nodes with which V1 frequently interacts are designated C1 and C2.Actors C1 and C2 are administrators in TeamGoal and TeamPussicats, respectively.The majority of unilateral interactions from V1 to C1 and C2 take the form of direct retweets and retweets from others that mention C1 or C2.Manual content analyses suggest that the primary objective of these two Cuban actors is to promote their team and its members through establishing unique sets of emojis and hashtags that symbolize their team identities and consistent mentioning of the team leaders.By retweeting C1 and C2 as well as other members of their teams, V1 serves as a promoter of their content.Venezuelan node V2 has bilateral coordination with both C1 and C2.The majority of V2's activities are replies to users or tweets with direct mentions.These two sets of tweets focus mostly on promoting members of teams including C1 and C2 and others, e.g., GhostBand Team, Orgasmas Team, Incognitos Team, CódiceRasta Team, ElBúnker, and Team Dioses_Míticos.V2 acts as a broker between the aforementioned groups, facilitating communication and collaboration between the teams and the team members.Cluster 2. Within Cluster 2, we identify node V3 as an influencer.V3 primarily distributes fake news via the use of URLs and hashtags that receive considerable engagement (65.26% of total tweets from Cuba are connected to V3).We note that numerous accounts that closely resemble this suspended account still exist in the current social network to avoid being taken down by Twitter, as shown in Cluster 2 of Figure 5(b).V3 is linked to C4, C5, and several other Cuban promoter accounts, through both explicit (retweeting) and implicit interactions (common hashtags).
Role analysis of accounts within the inter-state Cuban-Venezuelan operations (see Supplementary Material) suggests that, broadly speaking, Venezuelan accounts act as influencers, while Cuban accounts primarily promote content shared by Venezuelan accounts.

URL analysis
We collect account profile information and tweets of all accounts engaged in inter-state operations between Cuba and Venezuela.In total, there are 16 accounts (13.56% of actors from both countries) whose profiles contain URLs.Further, we identify 1,913 unique URLs within their tweets, occurring over 2,553 interactions (39.47% of total interactions) (see Supplementary Material).Invalid URLs that include broken links and cannot be manually identified by name are removed.Then, we manually verify the status of each link, categorizing each as active if the link is still functioning and inactive if the content has been removed or the account has been set to private.A substantial number of URLs are invalid (70.10%), indicating that most were temporary.We observe that the majority of valid URLs in profiles redirect to accounts on other social networking sites like Facebook, Instagram, and YouTube (9.27% of total valid URLs, 37.74% of which are still active), and blogs with little or no regulations (28.85% of total valid URLs, 100% of which are still active).URLs within tweets often direct to politically-oriented news (57.00% of total valid URLs), e.g., Telesurtv.Some also point to social media content management applications such as Twitlonger to bypass the character limit and Twitpic for picture archiving (still accessible after the account has been taken down), as well as to manage followers from social media, likely for open follow practices, e.g., Tuitil.

Dynamic network structure
We construct a dynamic view of inter-state operations between Russia and Iran through four interaction networks, see Figure 6(a).We aggregate all interactions prior to 2016 and after 2018, since the majority of interactions occur between 2016 and 2017; 6/15 2016 and 2017 are represented as snapshots.A total of 54 Russian accounts and 329 Iran accounts are represented in the network.We observe several clusters that contain one Russian node and multiple Iranian nodes, in a radiating pattern.The radiating network topology is well-suited for executing strategic aims such as news media distribution and social network expansion.
Russian and Iranian accounts are dynamically involved in inter-state coordination globally (see Supplementary Material).These statistics are calculated over year-long network snapshots, beginning in 2011.We observe temporal uniformity for Iranian inter-state information operations; specifically, accounts reach out-degree interaction peak at around the same time (see Supplementary Material).This may suggest that inter-state operations were/are conducted concurrently.Although Iran has more incoming than outgoing interactions (see Table 1), Iran also exhibits particularly many outgoing interactions with Russia.Upon closer inspection, we observe that the reason behind Iran's high in-degree centrality is that several central news outlets, e.g., Iranian state-controlled Hispantv, is frequently and consistently retweeted by accounts linked to Cuba, Venezuela, and Honduras (99.01%, 99.58%, and 99.7% of the total tweets, respectively).Thus, Iran may be passively engaged in those interactions.However, in its coordination with Russia, Iranian actors actively disseminate content created by Russian actors, e.g., targeting the U.S. 2016 election.

Content analysis
Figure 6(b) explores the primary structure of inter-state operations between Russia and Iran.We observe that Iranian accounts actively initiate interaction with Russian actors; approximately 96.81% of activity in the inter-state interaction network are retweets of Russian accounts, the majority of which are affiliated with the Internet Research Agency (IRA).Manual analyses of tweets and profile descriptions indicate that content is primarily focused on political and politicized topics.This is in line with prior work examining Russian information operations targeting the 2016 U.S. election 53,54 .For instance, the profile description of the central node R2 is: Unofficial Twitter of Tennessee Republicans.Covering breaking news, national politics, foreign policy and more.#MAGA #2A In addition to U.S. election politics, inter-state activity also focuses on racial issues (e.g., R1 and R3).Iranian actors participate in these processes by disseminating material previously posted by Russian actors with high centrality , and connecting all three satellite communities.
As in Case Study 1, we identify account roles in the Russia-Iran inter-state campaign (see Supplementary Material).Russia and Iran differ significantly in terms of number of influencers and followers; Russian actors serve primarily as source content for the Iranian community.

URL analysis
Also as in Case Study 1, we collect profile information and tweets from all accounts engaged in inter-state operations between Russia and Iran.In total, there are just 7 accounts (1.83% of actors from both countries) that contain URLs within their profile descriptions.We identify 35 unique URLs within shared tweets over 77 total interactions (15.28% of total interactions).We categorize these URLs by type/platform and active status (see Supplementary Material).Among valid URLs, we see extensive reference to international political news from the United States, the United Kingdom, and Iraq (31.43%).While the majority of linked social media accounts are now defunct (75% for profile URLs and 100% for content URLs) URLs to most news outlets remain active and complement tweet content (68.75% for content URLs).

Discussion and Conclusions
Rapid and accurate detection of information operations remains a hard problem for social media platforms globally.Evidence that state-linked operations may collaborate or collude to improve the efficacy of their campaigns adds complexity to that challenge.Our work provides such evidence, and therefore informs ongoing efforts to detect and mitigate the impact of information operations deployed through social media.We have highlighted some recurring strategies and tactics employed by inter-state information operations on Twitter.We have observed that a substantial subset of coordinated inter-state activity can be identified as supportive of explicit aims, e.g., targeting high-stakes political events or seeking additional visibility.Regardless of motivation, it appears that inter-state activities are carried out separately from intra-state operations, resulting in a distinctive information ecosystem, or idea habitat.Relatedly, we discover that a majority of inter-state operations exploit ambient affiliation through hashtagging, and that individual accounts in the network may be tasked with distinct roles in some operations architectures.Overarchingly, our findings suggest that information operations represent collaborative work, not only at the individual level but also at the state level.Notably, our analyses also reveal that country size is not necessarily a determinant of the scale of observed inter-state activity.Smaller countries demonstrate the ability to engage in systematic coordination, strategically expanding their internal operations.
The scope of the current work is constrained in several ways.Our analyses make assumptions about the accuracy of identified accounts and about their activity, e.g., that all account activity serves ongoing operations.We assume that substantial observed interaction indicates strategic coordination.Ultimately, the emergence of inter-state coordination and the ways in which observed activities are moderated through planning remains an open question.Furthermore, the extent to which current insights can be leveraged for the advancement of automated approaches for detection of inter-state information operations will likely depend on the uniqueness of inter-state interaction patterns vs., e.g., standard content promotion strategies employed by traditional organizational accounts seeking visibility and influence.Future work would benefit from designing studies to compare these phenomena.
The inter-state activity we uncover here is likely a very small segment of much larger-scale, dynamic, cross-platform, multi-media, partially-observable coordinated operations.Our findings raise many more questions regarding the offline interactions which underlie observed activity, the ways in which they are facilitated, and the broader political agenda which they serve.The answers to these questions will be distinct across countries and over time.Our work therefore highlights the critical role of policy and international relations in this space.It also suggests that whether and how states cooperate to respond to information operations on social media will require a transdisciplinary research and policy agenda bringing together computational and social scientists, policy makers, and stakeholders.

Figure 1 .
Figure 1.a. Global inter-state interaction network; b.Observed network motifs; c.Inter-state interactions, aggregated by country

Figure 3 .
Figure 3. a. Inter-state hashtag network; Note: Components of size ≤ 20 are suppressed for clarity.b.Actor engagement within inter-state hashtag network, by country.

Figure 5 . 15 Figure 6 .
Figure 5. a. Inter-state interaction network between Cuba and Venezuela; b.Schematic structure of inter-state disinformation operations between Cuba and Venezuela (usernames are hashed for accounts with fewer than 5, 000 followers).

Table 1 .
. Reciprocity levels are 0.944, 0.924, 0.844, and 0.777 for Indonesia, Egypt & UAE, China, and Saudi Arabia, respectively.With the exception of Honduras, where we observe a comparable number of interactions as source and target, 94.9% of global outgoing interactions are directed to Russia, and 88.3% of global in-coming interactions originate from Ecuador (reciprocity: 0.0079).Count of inter-and intra-state interactions by country.Inter-state: source and target nodes associated with different state-linked operations; Intra-state: source and target nodes associated with the same state-linked operation; External & isolates: target node is not identified by Twitter as a state-linked actor, or content does not retweet/mention other actors.Note: External interactions and isolates do not inform the analyses provided in this work; the count is provided for context.

Table 2 .
Table2gives these results.In 7 of 11 states, inter-state interactions receive more likes on average than intra-state interactions, 5 of which are significant.Similar trends hold for retweets and replies.We observe that countries like Venezuela, China, Indonesia, and Egypt and UAE which are more active in inter-state coordination also apply tactics discussed later (RQ2).Comparison of inter-and intra-state engagement.