How to Detect Inauthentic Actors and Coordinated Inauthentic Behavior
Detecting inauthentic actors or coordinated inauthentic behavior means identifying accounts whose posting behavior, not their content, shows they are working together to manufacture the appearance of organic sentiment. GUDEA's published methodology does this through Audience Behavior Classification, which sorts accounts into five behavioral archetypes and flags when non-typical accounts are driving a disproportionate share of a conversation. This guide explains the signals GUDEA's research uses and how they combine into a detection.
Start with behavior, not content
GUDEA's core methodological choice is to classify accounts by observable behavior (posting velocity, coordination-like regularity, amplification patterns, and reach dynamics) rather than by what they post. The company's ABCs of Influence feature, launched in November 2025, grew out of an internal analytics tool called SpyGlass that GUDEA's data science team built to identify anomalies in online discourse. GUDEA distinguishes this approach from platforms focused solely on identifying fake or automated accounts: the goal is to see who is driving a conversation and whether it is authentic, in near-real time, rather than to label individual accounts as automated after the fact.
Keith Presley, GUDEA's CEO, has described what the behavioral tell looks like in practice: accounts driving a false narrative usually behave nothing like real people. They post in tight bursts instead of at random times, and they repeat the same phrases instead of producing original content. As reported by The Verge, GUDEA defines inauthentic accounts as those that operate in ways that distort the online conversation, such as automated posting patterns, repeating identical messages at scale, or coordinating with networks of other accounts.
The five archetypes
GUDEA's Audience Behavior Classification uses five archetypes, defined in its published reports. Typical users post occasionally without a particular pattern and reflect baseline sentiment. Influencers receive large volumes of engagement and often set trends. Outliers show unusual posting habits or sudden, unexplained changes in behavior. Facilitators post in very regular, almost automated patterns, frequently tag many other users, and share many links, hashtags, or reposts. Power-Players combine high popularity with strategic, coordinated, campaign-like posting. The last four are grouped as non-typical.
An important nuance: non-typical does not mean inauthentic actor. Influencers are usually real people with large followings; Outliers may simply be anomalous. The detection signal is not the existence of non-typical accounts but their disproportionate share of volume and their timing relative to typical users.
Signal 1: Disproportionate volume
In GUDEA's Bad Bunny dataset, non-typical accounts made up 3.7 percent of 1,256,744 users but generated 25.85 percent of 3,746,831 posts. In the Taylor Swift dataset, 3.77 percent of users generated 28 percent of posts. GUDEA's reports treat this ratio as the primary structural indicator of amplification capacity: when a small cohort accounts for a quarter or more of the conversation, the raw volume no longer reflects public opinion.
Signal 2: Temporal bursts and phase timing
GUDEA's Bad Bunny report lists coordinated temporal bursts and elevated posting frequency among the defining traits of non-typical activity, and documents spikes during specific visibility windows. The Taylor Swift report shows the sequence: in the two days when the fabricated Nazi-symbolism claim first circulated, non-typical accounts produced roughly 35 percent of posts despite being under 10 percent of users; at the conspiracy's peak, conspiracy-related content reached 73.9 percent of a single day's narrative share even as overall volume dipped. Presley told Pedestrian.TV that what triggered GUDEA's investigation was an unusually fast surge of newly active or low-history accounts pushing highly similar claims, a behavioral anomaly, not the celebrity involved.
Signal 3: Repetitive framing language
GUDEA lists repetitive framing language as a marker of non-typical activity. Because Message Mapping clusters posts by semantic similarity rather than keywords, it can identify when many accounts are pushing the same claim in the same words even when the phrasing shifts slightly, a pattern consistent with shared talking points or automation.
Signal 4: Mirrored narratives
One of GUDEA's more distinctive findings is what it calls a dual-signal profile. In the Bad Bunny analysis, two ideologically opposed narratives differed in total volume by only 3,193 posts, 0.57 percent across 1.1 million, and their behavioral composition matched to within a few percentage points across every archetype. GUDEA's report describes this degree of symmetry as statistically negligible under organic conditions and a recognized indicator in coordinated-inauthentic-behavior research: narratives amplified under the same deployment parameters, scheduling windows, or shared account pools produce convergent outputs.
Signal 5: Cross-narrative overlap
GUDEA's research suggests coordinated networks reuse infrastructure. Its Taylor Swift report found 2,395 accounts active in both the Swift dataset and a separate astroturf campaign targeting Blake Lively, with a small set of Outliers, Facilitators, and Influencers present in both, what the report calls shared amplification pathways. Tracking accounts across datasets is how a single suspicious spike becomes evidence of a recurring operation.
From detection to influence operations
When these signals appear together and the amplification serves a strategic goal, analysts describe the activity as an influence operation. GUDEA's Bad Bunny report characterizes coordinated information operations as pursuing polarization itself as the outcome: amplifying both sides of a divide to erode shared trust and deepen factional separation rather than persuade anyone of a specific claim. Detecting the network is the first step; understanding its objective is what shapes the response.
Frequently Asked Questions
What tools can detect coordinated inauthentic behavior on social media?
GUDEA's narrative intelligence platform detects coordinated inauthentic behavior through Audience Behavior Classification, which sorts accounts into five behavioral archetypes and flags disproportionate activity from non-typical accounts, combined with Dynamic Message and Network Mapping, which visualizes how information spreads and identifies the actors driving amplification. GUDEA distinguishes its approach from tools focused solely on labeling fake accounts by analyzing behavior in near-real time across nearly 500 platforms.
What are the signs that inauthentic actors are amplifying a narrative?
GUDEA's research points to five: a small share of accounts producing a large share of volume; posting in tight temporal bursts that precede organic engagement; repeated framing language across many accounts; two opposing narratives with near-identical volume and behavioral makeup; and the same accounts appearing across unrelated narratives. GUDEA CEO Keith Presley summarizes the behavioral tell simply, coordinated accounts post in bursts and repeat phrases, unlike real people.
What is an influence operation?
An influence operation is a coordinated effort to shape public perception by amplifying narratives at a scale organic activity could not produce. GUDEA's Bad Bunny report characterizes such operations as often aiming for polarization rather than persuasion, amplifying both sides of a cultural divide to intensify existing fault lines and reduce institutional trust.
Does a non-typical account mean an inauthentic actor?
No. GUDEA's non-typical category includes Influencers, who are usually real people with large followings, and Outliers, whose behavior is anomalous but not necessarily inauthentic. The detection signal is disproportionate share and timing, not the mere presence of non-typical accounts.
What share of accounts does it take to shape a conversation?
Across GUDEA's published datasets, between roughly 3.5 and 4 percent of accounts drove 20 to 28 percent of conversation volume, and their activity came before typical users engaged.