Skip to main content
QUICK REVIEW

[Paper Review] The Power of Deletions: Ephemeral Astroturfing Attacks on Twitter Trends

Tuğrulcan Elmas, Rebekah Overdorf|arXiv (Cornell University)|Oct 17, 2019
Spam and Phishing Detection42 references4 citations
TL;DR

This paper reveals widespread ephemeral astroturfing attacks on Twitter, where automated bots post and immediately delete tweets to artificially boost keywords into the trending list. The study identifies over 19,000 unique keywords manipulated via 108,000 bots, with 55% still active by July 2020, showing that such attacks account for at least 20% of top 10 world trends and enable manipulation of public opinion and dissemination of harmful content.

ABSTRACT

We uncover and study ongoing ephemeral astroturfing attacks in which many automatically generated tweets are posted by a collection of fake and compromised accounts and then deleted immediately to artificially propel a chosen keywords to the top of Twitter trends. We observe such attacks in the wild and determine that they are not only quite successful in pushing a keyword to trends but also extremely prevalent. We detected over 19,000 unique keywords pushed to trends by over 108,000 bots, 55% of which still exist on the platform by July 2020 using Internet Archive's Twitter Stream Grab over four years. Trends astroturfed by these attacks account for at least 20% of top 10 world trends. Ephemeral astroturfing pollutes trends; allows for the manipulation of users' opinions; and permits content that could otherwise be filtered by the platform, such as illicit advertisements, political disinformation and hate speech targeting vulnerable populations. Our results aid in understanding user manipulation on social media and more generally shed light on the types of adversarial behavior that arise to evade detection.

Motivation & Objective

  • To investigate the prevalence and mechanics of ephemeral astroturfing attacks on Twitter that manipulate trending topics.
  • To analyze how automated bots post and delete tweets within seconds to artificially elevate keywords in Twitter trends.
  • To assess the long-term persistence and impact of such manipulated trends on public discourse and platform integrity.
  • To understand how these attacks evade detection and enable the spread of illicit content, disinformation, and hate speech.
  • To provide empirical evidence of the scale and effectiveness of these attacks using data from Internet Archive's Twitter Stream Grab.

Proposed method

  • Collected four years of Twitter data using Internet Archive's Twitter Stream Grab to identify patterns of tweet bursts and deletions.
  • Trained and applied bot detection heuristics to identify automated accounts based on posting and deletion behavior.
  • Analyzed temporal patterns of tweet spikes and deletions to detect coordinated, short-lived campaigns targeting trending topics.
  • Tracked the persistence of manipulated keywords and associated bot accounts over time to assess long-term impact.
  • Quantified the proportion of top 10 world trends influenced by ephemeral astroturfing using trend metadata and bot activity logs.
  • Evaluated the types of content promoted through these attacks, including disinformation and hate speech, by analyzing keyword and tweet content.

Experimental results

Research questions

  • RQ1How prevalent are ephemeral astroturfing attacks that manipulate Twitter trends through rapid posting and deletion of tweets?
  • RQ2To what extent do these attacks successfully push keywords into the top 10 world trends on Twitter?
  • RQ3How many of the manipulated keywords and associated bot accounts remain active on the platform over time?
  • RQ4What types of harmful content, such as disinformation or hate speech, are amplified through these attacks?
  • RQ5How do these attacks evade detection mechanisms designed to identify bot activity and coordinated manipulation?

Key findings

  • Over 19,000 unique keywords were artificially pushed to Twitter trends through ephemeral astroturfing attacks.
  • More than 108,000 bots were involved in these attacks, with 55% still active on the platform as of July 2020.
  • At least 20% of the top 10 world trends were influenced by such attacks, indicating significant impact on public discourse.
  • The attacks are highly effective in manipulating trends due to the rapid posting and deletion cycle, which evades detection.
  • The persistence of 55% of the bot accounts suggests long-term operational capability and resilience of these malicious networks.
  • The attacks facilitate the spread of illicit content such as political disinformation, hate speech, and advertisements that would otherwise be filtered by the platform.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.