Source-linked AI summary

Propaganda Forensics: Recovering the Generation Pipeline of an AI-Driven Influence Campaign

Benjamin Icard, Elouan Vuichard, Louis Lefebvre, Lila Sainero, Thomas Girault, Alice Breton, Tanguy Launay, Gauvain Bourgne, Morgane Casanova, Guillaume Gadek, Victor Klötzer, Michel Le Nouy, Guillaume Gravier, Jean-Gabriel Ganascia, Paul Égré

arXiv:2608.15746v1cs.AIcs.CL

TL;DR

Propaganda forensics needs evidence that distinguishes persuasion techniques, establishes AI-assisted generation, and attributes texts to LLM families. This paper compares PROPAGIA with human-written SIPA articles and combines linguistic analysis, prompt-leak and redundancy detection, and rewriting-based probing to find aligned evidence of an automated pipeline and support Llama 3 attribution while suggesting Mistral involvement.

  • Problem

    Propaganda forensics lacks integrated evidence for distinguishing persuasion techniques, establishing AI-generated text, and attributing generation to LLM classes.

  • Method

    The paper compares 2,646 PROPAGIA articles from 84 impersonation websites with 2,385 human-written SIPA articles and applies linguistic, leak, redundancy, and rewriting analyses.

  • Results

    Evidence from prompt leaks, cross-article redundancy, and independent rewriting probes converges on an automated generation pipeline across 84 impersonating sites.

  • Takeaways & Limitations

    The findings support attribution to the Llama 3 family while also suggesting involvement of Mistral-family models.

  • Takeaways & Limitations

    The PROPAGIA–SIPA comparison varies across authorship, intent, and source composition, so observed linguistic and sourcing differences reflect combined factors rather than a single cause.

Abstract

from arXiv · show

We present a forensic analysis of the generation pipeline behind a recent AI-driven influence campaign. We introduce PROPAGIA, a corpus of 2,646 propagandist French articles from the Storm-1516/CopyCop campaign disclosed by VIGINUM and INSIKT GROUP in 2025. For comparison, we rely on SIPA, a corpus of human-written French mainstream press from the same period. Using topic modeling, vagueness and sentiment analysis, we first isolate persuasion techniques characteristic of propaganda, with PROPAGIA far exceeding SIPA in vagueness, subjectivity and negativity, and citing fewer sources. We then find prompt instruction leaks on 50 of the 84 PROPAGIA websites, including a verbatim ten-point editorial specification accounting for several of these differences, together with high cross-article redundancy. Finally, we show that rewriting-based detection supports INSIKT GROUP's attribution to the Llama 3 family, but also suggests the involvement of Mistral-family models.

1 Introduction · 2 Related Work

The paper develops propaganda forensics for AI-assisted influence campaigns by comparing the PROPAGIA corpus with human-written press, identifying persuasive and AI-generation signals, and inferring model families. It situates this approach within research on propaganda detection, synthetic news, and rewriting-based LLM-text detection.

  • 1 Introduction: LLMs can rewrite existing press material into propagandist content disseminated at scale to manipulate beliefs, termed “slopaganda.”The paper distinguishes LLM capability from inherent manipulation, framing misuse as an influence-operation problem.
  • 1 Introduction: The paper’s forensic task is to characterize persuasion techniques, establish whether campaign texts are AI-generated, and attribute them to an LLM class.These objectives correspond to the paper’s three stated analytical goals.
  • 1 Introduction: PROPAGIA is a corpus of French press-like articles attributed to Storm-1516, compared with human-written articles from SIPA Ouest-France.The comparison provides the reference basis for the paper’s forensic analysis.
  • 1 Introduction: The analysis targets vagueness, subjectivity, opinion replacing factual reporting, and under-sourcing as persuasion techniques symptomatic of propaganda.The introduction also identifies exaggeration and appeal to fear among relevant propaganda techniques.
  • 1 Introduction: RAIDAR rewriting experiments across seven models support the hypothesis that Llama 3-family models were most likely used.The method applies rewriting-based comparison to narrow the class of LLMs involved.
  • 2 Related Work: Propaganda detection research models framing and persuasive techniques, but content-only approaches generalize poorly across outlets and topics.The related-work discussion motivates approaches that address variation beyond surface content.
  • 2 Related Work: LLM-text detection includes supervised classifiers, perplexity-based methods, perturbation-based methods, and rewriting-based approaches, each using different signals and assumptions.Supervised classifiers can achieve strong in-domain accuracy but transfer poorly, while perplexity-based results depend on the reference model.
  • 2 Related Work: RAIDAR is suited to reformulation of pre-existing content because it detects whether LLMs modify AI-generated text less than human-written text using edit distance.Its lexical signal is a Levenshtein-based similarity ratio and requires no inte…

3 The PROPAGIA and SIPA Corpora

The study compares PROPAGIA, a corpus of 2,646 presumably LLM-generated French press-style articles from 84 media-impersonation websites, with SIPA, a corpus of 2,385 human-written articles from 12 sources. Topic modeling reveals asymmetric coverage across the corpora, with some topics favoring PROPAGIA, others SIPA, and Topics 13–15 more balanced.

  • Corpus construction: PROPAGIA contains 2,646 presumably LLM-generated French press-style articles from 84 media-impersonation websites, while SIPA contains 2,385 human-written articles from 12 sources.Both corpora span December 1, 2024, to December 1, 2025; SIPA sources were selected for thematic proximity to PROPAGIA.
  • Corpus alignment: All articles were embedded with BGE-M3, and approximate HNSW nearest-neighbor search linked each PROPAGIA article to semantically similar SIPA articles.These similarities formed a textual similarity graph representing semantic proximity between generated and human-written articles.
  • Topic modeling: Topic modeling used PCA, UMAP, and HDBSCAN on BGE-M3 embeddings, achieving a mean silhouette score of 0.2281 and reasonable cluster separation.Topics were labeled from extracted properties using a LoRA adapter on Llama-3.1-8B-Instruct and Mistral-Small-3.1-24B-Instruct.
  • Topic coverage: Topic coverage is markedly asymmetric, favoring PROPAGIA for Topics 17–20 and SIPA for Topics 1–4 and 6, while Topics 13–15 are more balanced.Topic 15 is identified as particularly balanced.

4 Persuasion Techniques in PROPAGIA relative to SIPA

PROPAGIA articles are consistently vaguer, more subjective, less detailed, and less sourced than SIPA articles, with lower objectivity in 19 of 20 topics. They also exhibit significantly more negative sentiment, especially toward their conclusions, often using hyperbolic and catastrophist narratives.

  • Vagueness, subjectivity, and detail: VAGO measures sentence-level vagueness, subjectivity, and detail using French and English lexicons.Detail is based on the number of named entities in each sentence.
  • Vagueness, subjectivity, and detail: PROPAGIA is significantly more vague, subjective, and less detailed than SIPA, with lower objectivity in 19 of 20 topics.Topic 8 is the sole exception to the lower-objectivity pattern.
  • Sourcing: The mean quotation score for SIPA is nearly three times higher than for PROPAGIA, indicating markedly less citation of external voices.This corroborates under-sourcing in propagandist articles and suggests that authors substitute assertions for attributable statements.
  • Negative persuasion: PROPAGIA frequently builds negative narratives from reported events through hyperbolic and catastrophist takeaways combining Exaggeration and Appeal to Fear.The technique constructs a negative interpretation around an otherwise reported event.
  • Negative persuasion: PROPAGIA articles are significantly more negative and less neutral than SIPA articles, with negativeness increasing toward their conclusions.The conclusion trend is indicated by TabularisAI and the corpus-level difference is confirmed by Qwen3.6-35B-A3B, mDeBERTa-v3, and FEEL.

5 AI Generation Forensics

Generation forensics finds direct prompt-instruction leaks across PROPAGIA websites, substantial cross-article recycling, and agreement between leaked editorial constraints and corpus-level differences. These findings support a generation-pipeline contribution to the contrast between PROPAGIA and SIPA.

  • Prompt instruction leaks: 50 of the 84 PROPAGIA websites contained at least one detected prompt-instruction leak.Leaks were detected directly from article text using Qwen3.6-35B-thinking.
  • Prompt instruction leaks: 115 Meta-commentary artifacts empirically confirm that a fixed editorial specification was applied systematically across the dataset.One published artifact reproduces a ten-point checklist in which the model reports compliance point by point.
  • Textual redundancy: Nearly 10% of PROPAGIA articles had more than 50% cross-article sentence overlap, compared to 2.5% for SIPA.The overlap measure excludes duplicates and indicates extensive content recycling in PROPAGIA.
  • Corpus-level validation: Agreement between the leaked checklist and independently defined corpus-level indicators suggests that PROPAGIA–SIPA differences partly reflect the generation pipeline rather than source provenance alone.The checklist’s editorial constraints were linked to indicators testing their expected textual effects.

6 LLM Attribution

RAIDAR testing supports INSIKT GROUP’s attribution of PROPAGIA to the Llama 3 family, while also revealing a similar—and stronger—signal for Mistral. The results therefore support pipeline involvement but do not uniquely identify a model family.

  • Candidate models: The analysis tested Llama, Dolphin, and Lexi against Gemma, Zephyr, Qwen, and Mistral as non-suspected baselines.The candidate rewriters correspond to the three Llama-family models flagged by INSIKT GROUP and four other instruction-tuned LLMs.
  • Attribution: All three Llama-family candidates showed the predicted asymmetry, consistent with Llama 3 involvement in PROPAGIA’s generation pipeline.This independently supports INSIKT GROUP’s attribution to self-hosted Llama-3-family models.
  • Method: RAIDAR tests whether rewriting models edit AI-generated PROPAGIA text less than human-written SIPA text.The method treats lower editing, reflected by higher fuzzy scores, as evidence of matching generation patterns.
  • Results: 5 of the 7 tested LLMs validated the RAIDAR hypothesis for the SIPA-PROPAGIA pair.The predicted asymmetry appeared for Zephyr, Mistral, Llama, Dolphin, and Lexi; Gemma showed the reverse pattern and Qwen no significant difference.
  • Attribution: The same asymmetry appeared for Mistral and Mistral-based Zephyr, was strongest for Mistral, and therefore does not uniquely identify the Llama family.The findings suggest a shared signal across related Llama 3 and Mistral architectures rather than unique family identification.

7 Methodological Discussion · 8 Conclusion

The paper supports an automated generation pipeline for PROPAGIA through converging forensic methods, while noting that exact model identification remains resource-intensive. Its conclusions characterize PROPAGIA’s linguistic markers, LLM-based generation evidence, and the corpus’s value for future research.

  • 7 Methodological Discussion: Three independent approaches—article-level leak detection, corpus-level redundancy, and RAIDAR rewriting probes—converge across 84 impersonating sites.Their alignment leaves little room for an alternative account of automated generation.
  • 7 Methodological Discussion: 95.5 GPU hours per model is the average cost of RAIDAR probing.More language models would need testing, and exact identification may require more efficient signals such as meta-commentary style or recurrent output patterns.
  • 8 Conclusion: PROPAGIA is made available as a unique corpus of propagandist documents from websites deployed during the Storm-1516 influence campaign.The websites have now shut down.
  • 8 Conclusion: PROPAGIA is automatically distinguished from SIPA by greater vagueness and subjectivity, fewer quotations, and more negative narratives.These markers address the paper’s first research question concerning linguistic differences between propagandist and non-propagandist news.
  • 8 Conclusion: Prompt instruction leaks on 50 of the 84 websites, together with cross-article redundancy, provide evidence of LLM-based generation.The generation pipeline rewrote external documents under explicit narrative directives, including negative or positive political framing.
  • 8 Conclusion: The corpus and its forensic cues are intended to support alerts on malicious generative-AI use and future automatic propaganda detection and analysis.Images collected from the corpus are reserved for a separate study.

Limitations · Ethical Considerations · Declaration of Contribution

The study acknowledges methodological limits affecting comparisons, topic validation, leak prevalence, attribution coverage, and transfer across languages and campaigns. It also sets ethical safeguards for PROPAGIA’s use and documents the researchers’ distinct contributions.

  • Limitations: The PROPAGIA–SIPA comparison varies across authorship, intent, and source coverage, so observed differences reflect combined factors rather than a single explanatory variable.The comparison involves 12 SIPA sources and 84 impersonating PROPAGIA websites.
  • Limitations: The topic model’s silhouette score was 0.2281, while density-based validity, topic coherence, and manual topic validation remain preferable or outstanding alternatives.The score is described as conservative for non-convex HDBSCAN clusters produced on UMAP-reduced embeddings.
  • Limitations: Leak prevalence estimates rely on Qwen3.6-35B-Thinking and lack benchmarking against human-annotated ground truth.Accordingly, the reported prevalence figures should be read as approximate estimates.
  • Limitations: RAIDAR attribution is computationally intensive because it repeatedly rewrites each article across multiple prompts and candidate LLMs, limiting tested model families.This computational cost bounds the number of model families testable in one study.
  • Limitations: Analyses transfer unevenly: persuasion measures are language-bound, whereas leak detection and redundancy are language-independent, and RAIDAR requires adapted prompts and a predefined candidate set.Absent leaks do not establish human authorship.
  • Ethical Considerations: Using PROPAGIA requires strict precautions because the corpus documents propaganda targeting identifiable public figures and impersonating named outlets.One reproduced article contains antisemitic conspiracy motives and is anonymized as representative evidence of campaign style and framing.
  • Ethical Considerations: PROPAGIA is released for propaganda detection, media analysis, and generation forensics, and should be cited as an operation record rather than a source of factual claims.The corpus documents an operation targeting identifiable public figures and impersonating named outlets.
  • Declaration of Contribution: BI and PE led the study, while other authors collected PROPAGIA and SIPA, deployed rewriting models, conducted topic modeling, measured persuasion and negativity, and assessed redundancy.The passage assigns distinct roles across corpus construction, RAIDAR testing, topic modeling, persuasion analysis, narrative negativeness, and textual redundancy.

Appendix · A Corpus Statistics for PROPAGIA · B Formal Definition of the VAGO Scores

The appendix documents PROPAGIA’s corpus-statistics reporting and formalizes the VAGO scores used to quantify vagueness, subjectivity, detail, precision, and objectivity. Collection was best-effort, so the corpus reflects articles and domains reachable when crawled rather than a designed sample.

  • Appendix: Table 2 summarizes PROPAGIA’s corpus statistics, while Figure 8 shows the distribution of articles per impersonating website.The appendix provides both aggregate corpus statistics and website-level article-count distributions.
  • A Corpus Statistics for PROPAGIA: Collection was best-effort because domains were being taken down, so PROPAGIA contains what remained reachable at crawl time rather than a designed sample.The token minimum and maximum are observed ranges, not inclusion criteria.
  • B Formal Definition of the VAGO Scores: VAGO distributes vocabulary across four vagueness types: approximation (VA), generality (VG), degree (VD), and combinatorial (VC).These four categories define the vocabulary basis of the vagueness analysis.
  • B Formal Definition of the VAGO Scores: For a sentence ϕ, the vagueness score uses counts of vague terms by type and the sentence’s word count Nϕ.The notation |VX|ϕ denotes occurrences of vague terms of type X, while Nϕ denotes the number of words.
  • B Formal Definition of the VAGO Scores: The subjectivity score is computed from degree-vagueness and combinatorial-vagueness items only.It therefore uses the VD and VC components rather than all four vagueness categories.
  • B Formal Definition of the VAGO Scores: The detail score relies on precision markers, defined as named entities detected by spaCy models for French or English.Entities include persons (PER), locations (LOC), organizations (ORG), and miscellaneous entities (MISC).
  • B Formal Definition of the VAGO Scores: The precision score uses the number of vague terms of any type in sentence ϕ.The notation |V|ϕ represents the total number of vague terms in ϕ.
  • B Formal Definition of the VAGO Scores: The objectivity score combines approximation and generality vagueness with named entities and factual markers, while subjectivity combines degree and combinatorial vagueness with explicit first-person markers.Factual markers include numerical and temporal expressions detected with spaCy, and explicit subjectivity markers include French or English first-person forms.

C Symbolic FEEL Model · D Zero-Shot Sentiment Classification

The study combines a normalized FEEL lexicon model with three segment-level sentiment models to compare SIPA and PROPAGIA. Across methods, PROPAGIA is significantly more negative and emotionally charged, with neutrality differences depending on the classifier.

  • C Symbolic FEEL Model: C Symbolic FEEL Model: FEEL emotion-word counts were normalized by sentence count and Min-Max scaled to [0, 1].This normalization prevents article-length bias.
  • C Symbolic FEEL Model: C Symbolic FEEL Model: Global Negativeness uses normalized negative and positive word counts, then applies a sigmoid to bound outputs in [0, 1].Equations (8) and (9) define the normalized net count and bounded final score.
  • C Symbolic FEEL Model: C Symbolic FEEL Model: All measures significantly differed between SIPA and PROPAGIA at p < 0.05 with Bonferroni correction, with PROPAGIA more emotionally charged, particularly negatively.The comparison used Student’s t-test.
  • D Zero-Shot Sentiment Classification: D Zero-Shot Sentiment Classification: Three models were used to assess the robustness of local segment sentiment findings.The models included TabularisAI, Qwen3.6-35B-A3B, and mDeBERTa-v3.
  • D Zero-Shot Sentiment Classification: D Zero-Shot Sentiment Classification: TabularisAI directly outputs probabilities for five sentiment levels after fine-tuning on synthetic data.The five levels range from Very Negative to Very Positive.
  • D Zero-Shot Sentiment Classification: D Zero-Shot Sentiment Classification: Qwen3.6-35B-A3B uses a prompt to assign each segment a single sentiment number from 1 to 5.The prompt asks the model to consider emotions and persuasion techniques including loaded language, fear-mongering, moralization, and bias.
  • D Zero-Shot Sentiment Classification: D Zero-Shot Sentiment Classification: mDeBERTa-v3 compares each segment with five sentiment statements, assigns agreement probabilities, and selects the best-matching category.This is a zero-shot text-matching approach rather than a model trained specifically for sentiment analysis.
  • D Zero-Shot Sentiment Classification: D Zero-Shot Sentiment Classification: All models found significantly more negativity in PROPAGIA than SIPA at p < 0.05 with Bonferroni correction.Neutrality differences were also highly significant under the TabularisAI and LLM models, while the supplied passage truncates the remaining condition.

E Leak Detection

Instruction leakage in PROPAGIA was detected with a prompted Qwen3.6-35B-thinking model that identified text traces of LLM generation and classified them. Examples, category definitions, and structured JSON generation were used to improve classification and enforce valid outputs.

  • Detection method: Qwen3.6-35B-thinking analyzed each article for text sequences indicating LLM-generation leakage and classified the detected traces.The model returned a JSON object for each article.
  • Detection method: The detection prompt instructed an AI safety auditor to identify LLM-generation leaks, alignment artifacts, and system-prompt slippages in French text.It defined three leakage categories for review.
  • Output control: Examples and category definitions improved classification, while structured generation enforced a strict JSON schema to reduce syntax variance and pipeline-processing errors.The output instructions required only a raw, valid JSON object and specified dominant-leak categorization when multiple types appeared.

F RAIDAR Rewriting Prompts and Fuzzy Metric · G Compute Cost of the RAIDAR Analysis · H Full-Length Example Article from PROPAGIA

The appendices specify RAIDAR’s rewriting prompts and fuzzy similarity metric, document the computational setup, and reproduce a full PROPAGIA article with its instruction checklist. The example illustrates how source material was rewritten, politically reframed, and stripped of media references.

  • F RAIDAR Rewriting Prompts and Fuzzy Metric: Seven French rewriting prompts were translated into English for the RAIDAR method.Figure 12 provides the translations used with RAIDAR.
  • F RAIDAR Rewriting Prompts and Fuzzy Metric: The Levenshtein-based fuzzy score captures substitutions, unlike LCS-based measures, reflecting fine-grained local edits typical of LLM rewriting.The metric is designed to measure similarity while accounting for local substitutions.
  • F RAIDAR Rewriting Prompts and Fuzzy Metric: Approximately 250 tokens is the average length of PROPAGIA articles, so article length is not a practical limitation for the analysis.This average is reported in Appendix A.
  • G Compute Cost of the RAIDAR Analysis: Table 3 reports wall-clock time for rewriting every SIPA and PROPAGIA article seven times with each candidate model.The computation is summarized as per-model cost for the RAIDAR rewriting analysis.
  • G Compute Cost of the RAIDAR Analysis: All runs used an NVIDIA A100 80GB PCIe GPU except Mistral, which ran on an H100.The hardware distinction applies to the reported rewriting runs.
  • H Full-Length Example Article from PROPAGIA: Figure 13 reproduces an anonymized full-length PROPAGIA article assigned to Topic 8, concerning the Epstein scandal, power networks, and political fallout.The article is translated from French into English and reproduced verbatim.
  • H Full-Length Example Article from PROPAGIA: The article’s checklist records extraction of material about Jeffrey Epstein, Ghislaine Maxwell, and alleged global network orchestrators such as CIA and Mossad.The reproduced checklist identifies the main text as focusing on these figures and alleged networks.
  • H Full-Length Example Article from PROPAGIA: The checklist states that the source was rewritten in French with altered language and framing to fit a specific political tone without directly copying its phrasing or structure.It also records removal of other media references and added condemnation of Macron and the French government’s stance.
Loading 2608.15746v1…