A research team at the Korea Advanced Institute of Science and Technology (KAIST) has identified about 24,000 foreign-linked accounts exhibiting behavior consistent with coordinated manipulation aimed at fueling political divisions on Korea’s largest news portal. The researchers developed a tool using artificial intelligence (AI) technology that can flag suspicious online accounts, and also explain the basis for its assessments.
The accounts did not focus on a particular political party or ideology, but instead posted messages targeting both conservative and liberal politicians, including former and incumbent presidents, in ways that could amplify divisions and confrontation, raising suspicions of links to foreign influence operations.
The team, led by professors Lee Won-jae, Cha Mee-young and Oh Hae-yun, will present their research, titled “Cross-National Information Attacks: A Two-Decade Analysis of Troll Behavior in Korea,” at USENIX Security Symposium 2026 on Thursday, according to KAIST.
The research was co-authored by doctoral student Kim Jae-hong and master’s student Kim Hyeon-seung, and joined by Thorsten Holz, a scientific director at the Max Planck Institute for Security and Privacy.
The team developed an AI system that automatically detects patterns in online news comments suspected of being linked to foreign influence operations and provides the reasoning behind its assessments. Using the system, the researchers analyzed 112.66 million comments posted on Naver’s news articles between 2006 and 2025 and data of 4.05 million accounts.
Based on data from 70 accounts that the Institute for National Security Strategy identified as being linked to foreign groups, the AI analyzed a total of 24 factors, including expressions of anger, locations, grammatical and cultural expressions, the countries that the accounts criticized and the proportion of repetitive comments.
Among the 23,998 accounts suspected of involvement in foreign-linked influence operations, a notable pattern was that they tended to post messages aimed at intensifying political polarization, conflict and confrontation rather than consistently supporting one particular political group.
One example comment cited in the research reads: “A demon race, the Koreans, and a demon state, South Korea. The have maintained a conscription-slavery system for 60 years that serves no purpose other than enslaving their own citizens. These Koreans loudly complain about forced labor from 70 years ago that they never personally experienced, yet remain silent about the ongoing forced labor imposed by their own government on Korean men today.”
There were comments that praised what the research described as a “major neighboring state (MNS).” One comment reads: “Korea does not seem suited for American-style democracy. It should learn from MNS-style socialism.”
The team noted that the findings do not necessarily mean the accounts were actually operated by specific foreign governments or organizations. However, the researchers added that the accounts posted significantly more messages using morally condemnatory rhetoric about Korea and Korean society.
The number of accounts that became newly active during major election periods was also about 51 percent higher than during nonelection periods.
In the research, the AI model provided classification results as well as the specific text segments in comments, usernames, posting locations and article headlines that served as evidence for its assessments.
The team stressed that the AI should be used as an “explainable content moderation tool” to support expert judgment, rather than as a system that automatically blocks or penalizes accounts deemed suspicious.
“After analyzing two decades of data, we found that the suspected accounts focused on condemning Korea and Korean politicians in ways that appeared intended to fuel political division,” Lee said. “The system can serve as a tool for identifying messages that require reviews during periods when the risks of social conflict are heightened.”