Trollslayer: Unmasking the "Abusive Birds" of Twitter via Social Graph Dynamics
Trollslayer: Crowdsourcing and Characterization of Abusive Birds in Twitter
This paper presents "Trollslayer," a victim-centric measurement study that crowdsources and characterizes abusive behavior on Twitter. By deploying a custom recursive crawler and an annotation platform, the authors developed a dataset of over 14,000 labeled tweets to identify "abusive birds" using novel graph-based similarity metrics like the Jaccard index.
TL;DR
Abuse on social media is evolving beyond simple "bad words." Researchers from Queen Mary University and INRIA have developed Trollslayer, a system that moves beyond textual analysis to identify abusive users through their social connections. By analyzing the "victim's perspective" and using a unique Jaccard similarity metric on follow-graphs, they've uncovered patterns in how trolls and bots systematically "deny, disrupt, degrade, and deceive."
The Problem: Why Keywords Aren't Enough
Current moderation systems often fail because they treat abuse as a linguistic problem. However, modern "abusive birds" (trolls and bots) are sophisticated. They might use polite language to spread misinformation or use automated tools to harass specific targets.
The authors argue that:
- Context is King: A "bad word" between friends isn't abuse, but a "clean" message repeatedly targeting a victim is.
- The Deception Gap: Human annotators are great at spotting hate speech but terrible at spotting "deceit" (like malicious fundraising bots).
- Privacy vs. Policing: Large-scale mining often violates user privacy; we need a "Victim-Centric" approach that only looks at the data surrounding the incident.
Methodology: The Victim-Centric Approach
The team built a recursive crawler using a Bounded Breadth-First-Search (bBFS) algorithm. Instead of crawling the whole of Twitter, they started with "seeds"—known or potential victims—and mapped the perpetrators connected to them.
The Feature Matrix
To distinguish between a "Benign Bird" and an "Abusive Bird," the authors extracted features across four categories:
- Message: Counts of mentions, hashtags, and the critical is_reply ratio.
- User: Account age, verification status, and posting frequency.
- Social: Follower/Followee counts and reciprocity.
- Similarity (The Secret Sauce): Using the Jaccard Index () to measure the overlap between the sender's and receiver's social circles.
Algorithm 1: The engine behind the Trollslayer crawler.
Key Insights from the Data
The study analyzed over 770,000 edges in the messaging graph. Two major discoveries stand out:
1. Trolls are "Reply-Heavy"
Abusive users seek controversy. The data showed a significant gap in the #Replies/#Tweets ratio. Trolls don't just broadcast; they inject themselves into others' timelines to disrupt conversations.
2. The Jaccard Gap
In a healthy social interaction, the sender and receiver often share common followers or interests. In abusive interactions, this similarity is almost non-existent. The Jaccard index of mutual subscriptions showed a clear divergence between acceptable and abusive content.
Figure (h): The Jaccard similarity of subscribers reveals a distinct pattern for abusive accounts.
Case Study: The Deceitful Bot
The authors identified a specific account, @jrbny, which human annotators found hard to flag. By looking at the source metadata, they found it used an automated scheduling platform ("Statusbrew") to drive traffic to a suspicious fundraising site. While the text looked "charitable," the social graph behavior (systematic mentions of strangers) flagged it as abusive "deception."
Critical Analysis & Conclusion
Trollslayer proves that the social graph is a powerful signal for moderation. However, there are limitations:
- Subjectivity: Even with experts, there is a 1.3% - 3.75% "perfect disagreement" rate on what constitutes abuse.
- Platform Limits: The method is constrained by Twitter's API limits and Terms of Service (TTC), which restrict how much graph data can be shared publicly.
The Takeaway: Future safety systems shouldn't just read what a user says—they should look at who the user is talking to and how they are connected. Mixing graph-based similarity with NLP is the only way to catch the most dangerous, subtle forms of online harm.
