Information security ·

Decoding manipulative narratives in cognitive warfare

How Russian-language media used the threat of nuclear war to shape opinion about Ukraine, and how semantic networks and language models can pick that messaging out as it happens.

Read the paper PDF ↗ (opens in a new tab)

The problem

Most research on disinformation follows how it spreads. This paper looks instead at what it is made of and when it is released: messaging built to work on fear and on beliefs its audience already holds, with the aim of lowering trust in institutions and weakening support for Ukraine. Spread can be measured after the event. The emotional design and the timing are what a defender would need to see coming.

What the paper does

The material is Russian-language content from around 4,000 websites and 3,000 Telegram channels, collected from 1 November 2022 to 5 March 2023 and again across 2024. Of 36,821 candidate phrases the team kept 170 — “nuclear attack”, “dirty bomb”, “Kyiv authorities” and “nuclear treaties” among them — and built a network in which two phrases are linked by how often they appear together.

Clustering that network finds the themes. The Attack-Index tool scores how often and how intensely each one appears, and large language models look for what counting cannot see: euphemism, sarcasm and strategic framing. The results were checked against expert review and independent datasets rather than taken from the models on trust.

What it shows

The network falls into five clusters: the “special operation” and nuclear energy; “Kyiv authorities” and the “dirty bomb”; a possible Russian nuclear strike; nuclear programmes and treaties; and the navy and blackmail. Of 68,206 posts analysed, 35,974 — 52.7 per cent — were negative in tone, against 3,506 positive.

The sharpest finding is about timing. Nuclear rhetoric rose ahead of the Ramstein meetings, NATO and EU summits and G20 sessions rather than in response to them, and by 2024 the peaks were arriving earlier still: what the paper calls a move from reactive to proactive disinformation. The audiences were not treated alike. International political elites, Western publics and Russian domestic audiences were each worked on through different vulnerabilities.

What it does not claim

The paper is plain about what it cannot show. The sources may themselves be skewed; only public material was collected, so covert campaigns are missing; language models still struggle with irony and cultural reference; and a correlation between rhetoric and events is not evidence that the rhetoric changed anyone’s mind. It also notes that tools which detect manipulation could be turned to producing it.

Where it sits

Kingston, the fourth of four authors, worked on the formal analysis, the software and the visualisation, and on writing the paper. Its policy recommendations reach back to his main line of work: it argues for AI workflow tools of the kind Opus provides as a way to detect sophisticated disinformation, synthetic media included.

All 10 papers →