Coordination is a fundamental aspect of life. The advent of social media has made it integral also to online human interactions, such as those that characterize thriving online communities and social movements. At the same time, coordination is also core to effective disinformation, manipulation, and hate campaigns. This survey collects, categorizes, and critically discusses the body of work produced as a result of the growing interest on coordinated online behavior. We reconcile industry and academic definitions, propose a comprehensive framework to study coordinated online behavior, and review and critically discuss the existing detection and characterization methods. Our analysis identifies open challenges and promising directions of research, serving as a guide for scholars, practitioners, and policymakers in understanding and addressing the complexities inherent to online coordination. We also provide an interactive companion website for exploring the surveyed literature.
Figures & tables
Figure 1
Figure 3 . Interactive companion website, available at https://www.lorenzomannocci.it/coordinated-behavior/ , to facilitate the exploration of the reviewed literature.
Figure 3
reference
definition
Nizzoli et al. [98]
Unexpected, suspicious, or exceptional similarity between a number of users
Cinelli et al. [18]
The number of times two accounts behaved similarly , such as when they repeatedly retweet the same post
Giglietto et al. [42]
The act of making people and/or things be involved in an organized cooperation
Magelinski and Carley [70]
Many instances of a tweet-behavior, i.e. tweeted hashtag […] within a small predetermined time window
Weber and Neumann [140]
Anomalous levels of coincidental behavior
Magelinski et al. [71]
Users [that] take the same actions within minutes of one another
Table 1 . Examples of operational definitions used in recent academic literature. No definition is general enough to comprehensively describe coordinated online behavior. However, each definition grasps one or more relevant properties (highlighted in bold) that we leverage in our framework.
Figure 6 . Taxonomy of coordinated online behavior obtained by considering the dimensions of harmfulness and authenticity of our conceptual framework. The framework conveniently allows the mapping of disparate instances of online coordination.
Figure 7 . The analytical process of studying coordinated online behavior, involving the detection and characterization tasks. The input to the overall process is a set of users U and their activities H on one or more platforms. The output of the detection task is either a set of binary labels B , clusters C , or network communities G that differentiate coordinated and non-coordinated users. The characterization task receives these in input and outputs a set of indicators M .
Figure 8 . Main steps of the network science methods for the detection of coordinated online behavior. 1: The selected users become nodes in a network. 2: User similarities are computed with a similarity function and assigned to the edge weights of the network. 3: The network is filtered so as to retain only similarities with given properties. 4: Community discovery is performed to detect groups of strongly coordinated users.
Figure 9 . Differences between social ( A ), interaction ( B ), and coordination ( C ) networks. Solid black edges represent actions on the online platform, while dashed colored edges show how actions are translated into edges in the corresponding type of network. Coordination networks are typically undirected and link users performing similar actions at around the same time. Differently to social and interaction networks, coordination networks allow connecting users even if they never directly interact with one another.
reference
action
similarity
filters †
community detection
[ 17 ]
retweet
cardinality
threshold, ADJ
modularity clustering
[ 45 ]
retweet
cardinality
EDO
Louvain
[ 60 , 59 ]
retweet
cardinality
threshold, ADO
Louvain
[ 63 ]
retweet
cardinality
backbone, ADJ
Louvain
[ 112 ]
retweet
cardinality
EDO
[ 98 , 18 , 48 , 64 , 27 , 124 ]
retweet
cosine similarity TF-IDF
backbone
Louvain
Table 2 . Network science methods for detecting coordinated behavior based on single layer user networks. For each group of works we report the considered co-actions, similarity functions, filtering criteria, and community detection methods.
time window
network
reference
type
size
type
layer(s)
[ 140 , 141 , 139 ]
adjacent
15 min, 1 hour, 6 hour, 1 day
user
single
[ 133 ]
adjacent
1 day, 1 week
user
single
[ 63 , 17 , 20 ]
adjacent
1 week
user
single
[ 1 ]
adjacent
1 hour, 1 day,
content
single
[ 45 ]
evenly distributed overlapping
1 sec
user
single
Table 3 . Types and characteristics of the time windows and the coordination networks used by network science methods.
type
parameters
action sequence and valid co-actions
adjacent
Z Z δ O titi+1 Z t0t1t2t3t4t5t6 time
evenly distributed overlapping
action driven overlapping
Table 4 . Time window types, their parameters, and their effect on valid co-actions. To the right, a sequence of actions occurs at times t1,…,t6 . The same sequence results in different valid co-actions, marked by the lock icon, depending on the time window type.
reference
action
similarity
filters †
flattening
community detection
[ 30 ]
share, message, URL, hashtag
cardinality
threshold, ADO
Louvain, IPVC ‡
[ 68 , 26 ]
retweet, tweet, URL, hashtag
cosine similarity TF-IDF
threshold, ADO
unweighted edge union
[ 29 ]
retweet, URL, hashtag, image, token
cosine similarity TF-IDF
threshold
unweighted edge union
connected components
[ 49 ]
retweet, URL, hashtag, mention
temporal weighted cardinality
Generalized Leiden
[ 46 ]
retweet, text, URL, reply
cardinality
EDO
multigraph
connected components
[ 70 ]
URL, hashtag
cardinality
EDO
multi-view clustering
Table 5 . Network science methods for detecting coordinated behavior based on multiplex user networks, where each layer corresponds to a different co-action. For each group of works we report the considered co-actions, similarity functions, filtering criteria, and the optional flattening step applied before the community detection method.
reference
nodes
similarity
filters †
community detection
[ 4 ]
texts
cosine similarity TF-DID
[ 62 ]
texts
text similarity scores
threshold
loose strict campaign, cohesive campaign
[ 136 ]
texts, hashtags
cosine similarity, cardinality
EDO, threshold
hierarchical clustering
[ 23 , 141 ]
hashtags
cardinality
threshold
Louvain
[ 21 , 22 ]
cashtags
cardinality
threshold
[ 97 ]
images
Euclidean distance
kNN graph
Louvain
Table 6 . Network science methods for detecting coordinated behavior based on content networks, where nodes are posted contents and edge weights encode the similarity between the linked contents. For each group of works we report the types of content, similarity functions, filtering criteria, and the community detection methods.
reference
input
machine learning approach
time
[ 5 , 6 , 104 , 120 ]
text streams
text stream clustering
[ 119 ]
text streams, image captions
text stream clustering
[ 10 ]
text, user-content network
clustering of text and node embeddings
[ 56 ]
daily tweeting activity
expectation-maximization
[ 122 ]
hashtags
peak detection
[ 11 ]
account creation timestamps
burst detection
Table 7 . Data mining and machine learning methods, based on unsupervised learning for detecting coordinated behavior. For each group of works we report the input types, the machine learning approach, and whether the method takes time into account.
Table 8 . Data mining and machine learning methods, based on supervised learning, for detecting coordinated behavior. For each group of works we report the input types, the machine learning approach, whether the method takes time into account, and the prediction target.
Table 9 . Indicators used for characterizing coordinated behavior. For each group of indicators we report the works that used them, the high-level concept implemented, and the defining dimensions of coordination for which the indicators provide , or could provide , information. Table rows are grouped based on the type of information (i.e., user, content, network) leveraged by the indicator.
The study of online discourse has become central to understanding societal polarization. While much research has focused on detecting overt toxicity, the subtle dynamics of social cohesion, meaning the interaction between divisive and unifying narratives, remain computationally underexplored (Bail, 2021; Gonzalez-Bailon and Lelkes, 2023). This paper presents Cohesion-6K, a manually and ChatGPT-assisted annotated dataset of six thousand Arabic public Facebook posts related to the Israeli Occupation of Palestine. Each post is assigned to one of five discourse categories that represent a continuum from conflict to cohesion: Conflict, Resolution, Community Engagement, Supportive Interactions, and Shared Values. The annotation process combines expert human judgment with model-assisted pre-labeling verified by trained annotators, achieving substantial inter-annotator agreement (Cohens kappa = 0.85). Quantitative analysis reveals a consistent engagement gap, where conflict-oriented posts receive between two and four times more user interaction than resolution-oriented ones (p < 0.01). This pattern illustrates how divisive discourse tends to attract disproportionate visibility in Arabic social media spaces. Cohesion-6K provides a transparent and reproducible resource for the study of online cohesion and polarization. The dataset, annotation guidelines, and preprocessing code will be released for research use under an open license, supporting future work in computational social science, digital communication, and Arabic natural language processing.
Aisha Ali Al-Athba, Wajdi Zaghouani
Hamad Bin Khalifa University, Northwestern University in Qatar Doha, Qatar
Information Operations on social media networks have been identified as a significant threat to democracy and modern society, but they are challenging and expensive to detect by humans. Existing supervised IO detection methods fail to capture the dynamic nature of evolving IO user behavior, while existing unsupervised approaches rely on oversimplified assumptions of coordination among IO users that may not exist in practice. To overcome the limitations of existing methods, we formulate IO user detection as an anomaly detection problem and propose a novel unsupervised IO user detection approach called Temporal-bEhavior-laNguage Signals for information Operation Recognition (TENSOR), which leverages multimodal data, including temporal online user behavior, such as message posting activities, and the textual content of the messages. The motivation is that IO users are typically a very small fraction of all online users and have unique temporal behavioral and language patterns. Specifically, we train a Temporal Point Process (TPP) to capture abnormal temporal behavioral patterns of IO users because they are known to behave in a coordinated manner for IO campaigns. We further introduce a novel evidence function that converts LLM responses, which are generated from user post timelines, into quantitative scores to adjust the TPP outputs for better IO user detection. Experimental results show that TENSOR outperforms the baselines on five real-world IO datasets. Code is available at https://github.com/xiuzhenzhang/TENSOR.
Sishun Liu, Sajal Halder, Ke Deng +2
RMIT University, Melbourne, Victoria 3000, Australia · Macquarie University, Sydney, New South Wales 2000, Australia
During social movements, protesters need to gather with limited communication means and limited knowledge other than what they observe in their direct surroundings. We propose BeWater, a fully distributed walking protocol that achieves gathering thanks to city information like street length, number of restaurants, number of lanes, or street names. Even though using only one of these observables performs poorly, we show that combining them in more advanced tactics rapidly leads to groups of significant sizes. To do so, our work leverages OpenStreetMap data to perform experiments on several real-world cities.
Guillaume Moinard, Matthieu Latapy
Sorbonne Université, CNRS, LIP6, F-75005 Paris, France