Hopfield Wikipedia Detection

PROMPT / Qriton
PCA Risk Landscape
RO
Rendering PCA landscape...
Figure 1: Principal Component Analysis of Risk Metrics. Each observation is projected onto two principal components derived from nine risk features (MRS, SRS, BVI, and six Hopfield detector scores). Points are coloured by risk profile classification (Q75-per-language activation thresholds). Point radius encodes the number of Hopfield detectors that flagged the observation as anomalous (0–6). Clusters with high spatial coherence and elevated Hopfield counts indicate coordinated manipulation signatures that persist across multiple independent detection channels. PCA computed via power iteration on the covariance matrix of z-normalised features.
Ranked Observations (Top 50)
# Article Lang Score MRS SRS BVI Profile Hopfield Detectors
Risk Profile Distribution
Cross-Article Editor Network
RO
Shared editors:
Connected articles:
Figure 2: Cross-Article Contributor Network. Nodes represent Wikipedia articles within the corpus, sized proportionally to their combined risk score and coloured by risk profile type. Edges connect articles that share at least one common editor among their top five contributors (as identified through MediaWiki API usercontribs queries). Edge colour distinguishes individual editors; thicker edges indicate editors who have been flagged by Wikipedia Sockpuppet Investigation (SPI) process. Click any node to inspect its connections and shared editors. Use the search box to find specific articles or editors. Network constructed from MediaWiki API enrichment data. Isolated nodes (no shared editors) are omitted for clarity.
Cross-Article Editors
EditorArticlesConnected To
Detector Activation Rates
Anomaly Count Distribution
Anomaly Detection Heatmap (Top 100 Flagged Observations)
RO
Sort by:
Language:
Figure 3: Hopfield Anomaly Detection Matrix. Each row represents an observation (article x month), and each column represents one of six binary Hopfield detectors: Temporal, Network, Contributor, Manipulation, Epistemic, and Volatility. Cells are coloured by detector energy score (darker = higher anomaly energy). The matrix is sorted by descending total anomaly count, then by combined risk score. Multi-detector convergence — where 2+ independent detectors flag the same observation — provides substantially higher confidence than any single detector, as it indicates that anomalous patterns manifest simultaneously across orthogonal feature spaces. The Hopfield network energy-based formulation ensures that stored normal patterns act as attractors: observations that settle into high-energy states (far from any attractor) exhibit behaviour inconsistent with the learned baseline. Hopfield detectors use the Storkey learning rule with feature-specific thresholds (temporal: 0.3, network: 0.25, account: 0.4).
Engine Profiles by Cluster
RO
Figure 4: Engine Score Profiles by Risk Cluster. Each radar chart shows the mean engine scores (Temporal, Network, Contributor, Manipulation, Cross-Language Synchrony) for observations grouped by their k-means cluster assignment. Cluster profiles reveal qualitatively distinct manipulation strategies: some clusters exhibit elevated temporal scores (suggesting coordinated editing bursts), while others show network or contributor anomalies (suggesting sockpuppet or single-purpose account activity). The API enrichment layer contributes additional sub-signals to each engine — notably cross-article editor overlap (Network engine) and single-purpose account scoring (Contributor engine) — which were previously unavailable from CSV-derived features. Radar values are mean engine scores per cluster, scaled to [0, 1]. Cluster assignment via k-means (k=5) on z-normalised feature matrix.
API Enrichment Impact
Governance Asymmetry
Interpretation notes. The governance asymmetry analysis identifies articles where Wikipedia's protective mechanisms (semi-protection, extended-confirmed protection, full protection) were applied with substantial delay relative to the onset of anomalous editing patterns. A governance lag exceeding 30 days suggests that the article was exposed to sustained manipulation before administrative intervention. The enrichment layer provides actual protection log timestamps from the MediaWiki API, replacing the binary proxy used in the CSV-only baseline. Articles with high manipulation scores and absent governance flags represent the highest-risk category: active manipulation with no administrative response.
Moldova (MD) — n = 4,240
MD
MD Correlation Structure. MRS loads moderately onto Network (0.41), Contributor (0.44), and Manipulation (0.39) — consistent with the behavioural detection overlap identified analytically. Hopfield inter-detector correlations are low to moderate, supporting relative dimensional independence. The Behavioural Cluster (Network × Manipulation: 0.86, Contributor × Manipulation: 0.79, Network × Contributor: 0.71) is the strongest block. Temporal × Volatility couples at 0.68. Epistemic correlates weakly and positively with both SRS (0.27) and MRS (0.17), suggesting mild co-occurrence of sourcing fragility and epistemic anomaly in the Moldovan corpus. BVI shows no meaningful correlation with any Hopfield dimension (all |r| < 0.07). Pearson correlations on raw feature values. MD corpus: 4,240 article-month observations.
Romania (RO) — n = 6,230
RO
RO Correlation Structure. MRS loads strongly onto all behavioural Hopfield dimensions simultaneously: Contributor (0.75), Manipulation (0.73), Network (0.72), Temporal (0.69), Volatility (0.68). The behavioural cluster itself tightens to near-ceiling: Network × Manipulation: 0.93, Contributor × Manipulation: 0.91, Network × Contributor: 0.81. Temporal × Volatility reaches 0.92 — near-perfect, meaning these are essentially the same signal. Epistemic flips sign: negatively correlated with Network (−0.26), Temporal (−0.22), Volatility (−0.19), MRS (−0.16), Manipulation (−0.16). Positive only with SRS (0.39). Epistemically anomalous articles in RO are behaviourally quiet — the exact profile of structurally biased articles that attract no acute editing pressure. SRS shows negative correlations with Temporal (−0.15) and Network (−0.16), meaning sourcing fragility is counter-cyclical: articles with chronic sourcing problems are quieter during high-activity periods. Pearson correlations on raw feature values. RO corpus: 6,230 article-month observations.
Comparative Interpretation: Two Structural Stories.
MD is a corpus where detection dimensions are relatively loosely coupled. MRS connects moderately to the Hopfield behavioural cluster (0.39–0.44), Epistemic sits isolated but positive, BVI is invisible to Hopfield. The information warfare pattern is diffuse — manipulation pressure, temporal patterns, and volatility do not strongly co-occur. Multi-vector risk profiles are proportionally higher than in RO.
RO is a corpus where almost everything in the behavioural space collapses into a single high-intercorrelation cluster. MRS loads onto Temporal (0.69), Network (0.72), Contributor (0.75), Manipulation (0.73), and Volatility (0.68) — all simultaneously, all strongly. RO manipulation events are temporally concentrated, network-coordinated, contributor-concentrated, and volatile all at once. That is the electoral-period signature — compressed into a tight detection cluster.
The Epistemic Sign Flip is the most structurally significant divergence.
RO: Epistemic correlates negatively with MRS (−0.16), Temporal (−0.22), Network (−0.26), Manipulation (−0.16), and Volatility (−0.19). Positive only with SRS (0.39). Epistemically anomalous articles in RO are behaviourally quiet, temporally stable, low-volatility. The Hopfield detects that epistemic risk and behavioural risk are structurally separated in the Romanian corpus — they are different populations requiring different interventions.
MD: The sign is positive (0.17): epistemic anomaly and behavioural pressure mildly co-occur, suggesting a different information warfare topology where sourcing degradation accompanies rather than opposes manipulation activity.
Key Divergences (|Δ| > 0.4): Epistemic × Network (Δ = −0.63), Epistemic × Volatility (Δ = −0.54), MRS × Temporal (Δ = +0.51), MRS × Volatility (Δ = +0.49), Epistemic × Temporal (Δ = −0.46).
Glossary of Terms

Composite Risk Scores

MRS
Manipulation Risk Score. Weighted aggregate measuring the likelihood of coordinated editing manipulation. 0.20×sockpuppets + 0.15×editSpikes + 0.15×viewSpikes + 0.20×editsRevertProb + 0.15×anonymity + 0.15×contributorAddDelete. Normalized to [0, 1].
SRS
Sourcing Risk Score. Measures reliability and integrity of cited sources. 0.35×citationGaps + 0.40×suspiciousSources + 0.25×sourceConcentration. Normalized to [0, 1].
BVI
Behavioural Volatility Index. Captures instability and concentration of editing activity. 0.35×sporadicity + 0.35×contributorsConcentration + 0.30×addDeleteRatio. Normalized to [0, 1].
Combined Score
Simple average of all three composites: (MRS + SRS + BVI) / 3. Global risk summary used for ranking observations.

Four Orthogonal Risk Planes

Behavioural Plane
Measures how edits are performed. Components: editSpikes (0.20), editsRevertProb (0.20), sockpuppets (0.20), anonymity (0.15), addDeleteRatio (0.15), contributorAddDelete (0.10). Detects suspicious editing patterns and coordination.
Epistemic Plane
Assesses knowledge justification and sourcing quality. Components: citationGaps (0.35), suspiciousSources (0.40), sourceConcentration (0.25). Measures epistemic integrity independent of edit behavior.
Volatility Plane
Evaluates stability and temporal consistency. Components: sporadicity (0.30), staleness (0.25), contributorsConcentration (0.25), editTimingIrregularity (0.20). Detects irregular editing schedules.
Attention Plane
Captures salience and public interest signals. Components: viewSpikes (0.40), editSpikes (0.35), discussionIntensity (0.25). Note: heat (event salience) is pre-aggregated and excluded from plane calculations.

Hopfield Anomaly Detection Engines

Temporal Engine
Detects editing/viewing burst anomalies. Features: editSpikes, viewSpikes, sporadicity, staleness; with enrichment adds monthlyEditVariance. Score: 0.35×editBurst + 0.30×viewBurst + 0.20×sporadicity + 0.15×staleness. Anomaly threshold: 0.35.
Network Engine
Detects coordination and governance stress. Combines concentration + revert probability (coordination) with protection + discussion (governance stress). With enrichment: incorporates crossArticleOverlap and API-derived editWarScore. Threshold: 0.30.
Contributor Engine
Sockpuppet detection and account profiling. Hard signals: sockpuppets > 0. Soft signals: anonymity + burst patterns. Extreme signals: add/delete ratio > Q90. With enrichment: includes singlePurposeAccountScore and live SPI check results. Threshold: 0.35.
Manipulation Engine
Content integrity and sourcing attack detection. Identifies contested insertion (high reverts + discussion) and laundering attempt (suspicious sources + add/delete surge). With enrichment: uses actual revertRate and talkDisputeScore. Threshold: 0.30.
Entity Engine
Cross-language synchrony detection. Scores based on language spread (1–8 languages), cross-language variance (>0.1), and average MRS. Identifies the same topic showing coordinated anomalies across multiple Wikipedia language editions simultaneously.
Epistemic Engine
Knowledge quality anomaly detector. Features: citationGaps, suspiciousSources, sourceConcentration. Threshold: 0.25. Operates independently from manipulation detection to separate sourcing degradation from behavioral manipulation.
Edit War Detector
Phase 8 enrichment detector. Analyses direct edit history for revert wars. Features: revertRate, oscillationScore, mutualRevertPairs, burstRevertRate, editWarSeverity. Distinguishes legitimate revision from coordinated conflict. Threshold: 0.30.
Editor Network Detector
Phase 8 enrichment detector. Identifies cross-article coordinated editor teams. Features: networkDensity, geoFocusAvg, suspicionRate, concentrationGini. Detects multi-article sockpuppet networks. Threshold: 0.30.
Temporal Burst Detector
Phase 8 enrichment detector. Identifies rapid-fire editing windows. Features: burstScore, rapidFireEditors, disputeScore, top3Share. Detects coordinated editing sprints within narrow time windows. Threshold: 0.30.
Hopfield Architecture
All detectors use energy-based associative memory networks with the Storkey learning rule, seeded RNG (seed: 42) for reproducibility, and snapshot length of 10. Multi-detector convergence (≥2 detectors flagging) indicates substantially higher confidence than single-detector flags.

Dataset Variables (CSV Input)

editSpikes
Surge in editing activity (0–100, normalized). Component of the temporal engine and attention plane. Detects coordinated editing bursts.
viewSpikes
Surge in article page views (0–100). Attention signal. High values may indicate amplification campaigns driving traffic to manipulated articles.
editsRevertProb
Proportion of edits that are reverted (0–100). High values indicate contested content where editors dispute article text.
sockpuppets
Detected sockpuppet indicators (0 = none, >0 = present). Hard signal for manipulation. Multiple accounts controlled by one person editing the same article.
anonymity
Proportion of anonymous/IP-based edits (0–100). High anonymity can indicate editors avoiding accountability for controversial changes.
contributorAddDelete
Per-editor average add/delete ratio (0–100). Extreme values indicate surgical editors who primarily insert or remove targeted content.
addDeleteRatio
Overall proportion of content additions vs. deletions in article edits. Extreme values signal surgical or destructive editing patterns.
contributorsConcentration
Herfindahl-like concentration of editors (0–100). High = few editors dominate, suggesting a small group controls the article’s content.
sporadicity
Irregularity of edit timing (0–100). High values mean unpredictable editing schedules, which can indicate campaign-driven bursts rather than organic maintenance.
staleness
Time since last significant edit, inverted activity measure (0–100). High values indicate inactive articles that may be targeted for stealthy manipulation.
discussionIntensity
Talk page activity level (0–100). Signal of article contention. Active discussions may indicate community awareness of manipulation, or may themselves be weaponized.
citationGaps
Unsupported claim density (0–100). High values mean many statements lack citations, creating opportunities for unreliable information insertion.
suspiciousSources
Count/proportion of non-reliable sources cited (0–100). Indicates citation laundering or insertion of state-media / propaganda sources.
sourceConcentration
Concentration of citation sources (0–100). High = narrow sourcing where a small number of sources dominate references, reducing epistemic diversity.
protection
Wikipedia protection status (0 = unprotected, >0 = protected). Administrative response to article abuse; absence during high risk indicates governance failure.
heat
Pre-aggregated event salience measure (0–100). Captures external attention signals. Excluded from individual plane calculations as it is a summary metric.
quality
Pre-aggregated article quality score (0–100). Excluded from epistemic plane calculations as it is a pre-aggregated metric from an external assessment.

API Enrichment Metrics (MediaWiki API)

revisionCount
Total revisions fetched from the MediaWiki API for a given article–month observation window. Capped at 500 per request.
revertCount / revertRate
Raw count and ratio of reverted edits. Detected via MediaWiki tags: mw-undo, mw-reverted, mw-manual-revert, mw-rollback. A revertRate ≥ 0.20 indicates likely edit war activity.
hasEditWar / editWarScore
hasEditWar: Boolean flag indicating mutual reverts between editors (bidirectional revert-graph edges). editWarScore: Composite (0–1) combining revert intensity and mutual edit war severity.
mutualRevertPairs
Count of editor pairs engaged in mutual reverting. Each pair represents a bidirectional conflict where A reverts B and B reverts A.
totalBursts / maxBurstSize
totalBursts: Count of rapid-fire editing clusters (≥3 edits within the burst window). maxBurstSize: Largest single burst measured in edits. High values indicate coordinated editing sprints.
rapidFireEditors
Count of editors with ≥2 consecutive edits within the rapid-fire threshold (typically 5 minutes). Signature of bot-like or scripted editing.
giniCoefficient
Gini index of editor concentration (0 = perfectly equal contributions, 1 = single editor dominance). Formula: (2Σ(i+1)·sᵢ − n − 1) / n. High values flag oligarchic article control.
top3Share
Proportion of all edits made by the top 3 editors (0–1). Complements giniCoefficient as a simpler concentration measure. Values near 1.0 indicate extreme editorial dominance.
monthlyEditVariance
Coefficient of variation in monthly edit counts (stdDev / mean). Detects irregular temporal patterns where editing intensity spikes and subsides unpredictably.
revertBurstCount
Count of temporal clusters within revert-only revisions. Isolates conflict-driven editing windows distinct from constructive editing bursts.
protectionEvents
Array of Wikipedia protection log entries (semi-protection, full-protection, move-protection) with timestamps. protectionEventCount: total count.
talkRevisionCount
Total revisions on the article’s talk page within the observation window. Active talk pages indicate community engagement (or dispute).
talkDisputeSections
Count of talk page sections matching dispute keywords: dispute, controversy, pov, bias, edit-war, sock, vandal, block. Direct indicator of article contention.
watcherCount
Number of Wikipedia users watching the article. Low watcher counts (0–100) indicate community oversight deficits, making articles more vulnerable to undetected manipulation.
singlePurposeAccountScore
Ratio of editors with <100 total edits AND >25% concentration on this article, divided by total profiled editors. Score 0–1. High values indicate accounts created primarily to edit this specific article.
spiHitCount
Count of top editors with active Sockpuppet Investigation (SPI) pages on English Wikipedia. Direct signal of suspected sockpuppet activity confirmed by community investigation.
crossArticleOverlap
Proportion of an article’s top editors who also appear in ≥2 other articles in the corpus. Indicates coordinated teams operating across multiple articles simultaneously.

Derived Analysis Metrics

Risk Profile Type
Categorical classification: manipulation-led (MRS active), sourcing-led (SRS active), volatility-led (BVI active), multi-vector (2+ active), low-dominance (none active). Based on per-language Q75 activation thresholds.
Risk Profile Shape
Spatial characterization in (MRS, SRS, BVI) space: mrs_spike, srs_spike, bvi_spike (one composite >50% of total), balanced, or plateau. Diagnostic feature for identifying attack strategy.
Rolling Mean
3-month rolling average of MRS, SRS, and BVI scores per article. Smooths month-to-month fluctuations and reveals persistent trends in manipulation risk.
Z-Score
Standardized score: (value − corpus_mean) / corpus_stddev. Identifies statistical outliers across the full corpus. Values >2 or <−2 indicate extreme observations.
Persistence Score
Normalized count of consecutive months where MRS > Q90, divided by 6. Scale 0–1. High values indicate sustained, multi-month manipulation campaigns rather than one-off events.
Language Spread
Count of language editions (1–8) where the same topic shows anomalies in the same month. Cross-language coordination is a strong indicator of state-sponsored or organized campaigns.
Asymmetry Score
Cross-language asymmetry: 0.40×maxMinSpread(MRS) + 0.30×maxMinSpread(SRS) + 0.30×maxMinSpread(BVI). Measures how unevenly manipulation is distributed across language editions of the same topic.
Governance Lag
Boolean: article has high manipulation score (>0.5) but zero protection. Indicates Wikipedia’s governance system failed to intervene despite elevated risk.
Governance Lag Days
Days between manipulation onset (observation month start) and first protection event. Null if never protected. Measures the speed of Wikipedia’s institutional response.
Hopfield Anomaly Count
Count of independent Hopfield detectors (0–6+) flagging an observation as anomalous. Multi-detector convergence (≥2) provides substantially higher confidence than any single detector alone.
Engine Score (Weighted)
Weighted combination of engine outputs: 0.22×temporal + 0.20×network + 0.22×contributor + 0.20×manipulation + 0.16×entity. Used for cross-engine comparison.

Statistical Thresholds

Q75 (Per-Language)
75th percentile of MRS/SRS/BVI per language. A composite “activates” when its score exceeds Q75, triggering risk profile classification. Requires ≥30 observations per language; otherwise falls back to global Q75.
Q90
90th percentile across the full corpus. Used for temporal persistence detection (consecutive anomaly months) and Hopfield engine thresholds. Flags extreme outliers.
Q95
95th percentile per language. The temporal engine flags editSpikes and viewSpikes above Q95 as burst events warranting anomaly investigation.
Min-Max Normalization
All raw metrics are rescaled to [0, 1] using per-corpus min and max values before being fed to Hopfield detectors and composite score calculations.