Your Tweets Are Your Fingerprints: Detecting Hijacked Accounts via Authorship Verification

Recognition of Compromised Accounts on Twitter

2015-05-26
Rodrigo Augusto Igawa, Alex Marino Gonçalves de Almeida, Bruno Bogaz Zarpelão, Sylvio Barbon
Summary
Problem
Method
Results
Takeaways
Abstract

This paper proposes a text-centric approach to identify compromised Twitter accounts using Authorship Verification (AV). By utilizing Character N-grams and a profile-based paradigm, the method establishes a stylistic boundary for users, achieving an accuracy of over 95.8% in distinguishing legitimate posts from unauthorized intrusions.

TL;DR

Researchers have developed a method to catch Twitter hackers not by looking at IP addresses or login locations, but by analyzing how they write. By treating account security as an Authorship Verification (AV) problem and using Character N-grams, the proposed system can detect compromised accounts with over 95% accuracy using as few as 100 words of text.

Background: The Hidden Threat of Compromised Accounts

In the world of social media security, there is a massive difference between a fake account (a bot created to spam) and a compromised account (a legitimate user's identity stolen via phishing or malware). Studies show that up to 84% of spamming accounts on Twitter are actually compromised legitimate ones.

The problem? Most systems focus on deleting fake accounts. But for compromised ones, we need a "silent alarm" that detects the moment a hacker starts posting in someone else's name.

The Core Insight: Writing Style as a Boundary

The authors suggest that every user has a unique "writing manifold"—a set of habits including word choice, punctuation, and character patterns. When an account is taken over, the writing style shifts. Even if the hacker tries to mimic the user, the statistical distribution of their N-grams (sequences of characters) usually fails to match the original user's profile.

Methodology: Building the Stylistic Wall

The approach follows a Profile-based Paradigm. Instead of analyzing one tweet at a time, it aggregates a user's history into a single representative document.

1. The Workflow

  • Profiling: Concatenate the user’s tweets, removing links and retweets (which don't represent the user's own style).
  • Profile Setup: The text is split into a Baseline Set (the "True" identity) and a Thresholding Set.
  • N-gram Extraction: Extract the most frequent sequences of 4, 5, or 6 characters.
  • Similarity Measure: Use Simplified Profile Intersection (SPI) to count how many N-grams the new post shares with the baseline.

Proposed Approach for User Threshold Estimation

2. Defining the "Intrusion Threshold"

The system finds the minimum similarity score between a user's own writing samples and their baseline. This becomes the threshold. If a new set of tweets falls below this score, the system flags the account as compromised.

Experimental Analysis & Results

The researchers tested 132 different configurations, varying the N-gram size, corpus length, and preprocessing techniques.

Key Findings:

  • The Power of Context: Removing hashtags and citations actually decreased accuracy. Why? Because who you mention and what topics you tag are fundamental parts of your digital identity.
  • Stopword Noise: Removing "stopwords" (common words like 'the', 'is') increased accuracy by 5%. This suggests that for short texts, these words act more like noise than stylistic markers.
  • The 100-Word Rule: The highest accuracy (95.8%) was achieved with a 100-word sample, which equates to roughly 6-10 tweets.

Experimental Settings Overview

Performance Metrics

Setting (N=6, Corpus=100)Result
Accuracy95.80%
True Negative Rate91.60%
Precision93.97%

Critical Insight: Why Does This Matter?

The beauty of this approach is its simplicity. It doesn't require access to private user data, cookies, or IP logs—only the publicly available text.

Limitations: The study noted that users with high usage of generic language (heavy prepositions, no slang/emoticons) are harder to distinguish. This "unstable writing style" (as seen in Figure 5 of the paper) remains the primary challenge for the next generation of AV security tools.

Conclusion

This research proves that our linguistic habits are remarkably stable, even in the chaotic environment of Twitter. By implementing N-gram-based authorship verification, social platforms can provide an invisible layer of security that protects users the moment a "strange voice" begins speaking through their account.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize Deep Learning or Transformers for Authorship Verification in short-text social media environments beyond N-gram methods.
  • What are the seminal works on 'Profile-based' vs 'Instance-based' paradigms in Authorship Attribution, and how has this distinction evolved for real-time security?
  • Explore how stylistic fingerprinting methods like the one proposed here are being applied to detect AI-generated or bot-assisted content on platforms like Twitter and Reddit.
Contents
Your Tweets Are Your Fingerprints: Detecting Hijacked Accounts via Authorship Verification
1. TL;DR
2. Background: The Hidden Threat of Compromised Accounts
3. The Core Insight: Writing Style as a Boundary
4. Methodology: Building the Stylistic Wall
4.1. 1. The Workflow
4.2. 2. Defining the "Intrusion Threshold"
5. Experimental Analysis & Results
5.1. Key Findings:
5.2. Performance Metrics
6. Critical Insight: Why Does This Matter?
7. Conclusion