Silent Sybils: Fake Followers and Recommender Risk

Coordinated Inauthentic Audiences, Recommender Manipulation, and Creator-Side Risk on LinkedIn and YouTube.

By Thomas Prislac, Envoy Echo, et al. Ultra Verba Lux Mentis. 2026.

Download the Academic Manuscript: https://drive.google.com/file/d/1zWyEiIUJ0IehIBZzvBCtcZgkfPEtpa1c/view?usp=sharing

Research status. This article introduces a 139-page evidence synthesis and prospective research program. It does not report completed platform-internal causal testing, prove that any creator has been attacked, or identify any alleged operator.

One of the strangest things a creator can encounter is an audience that exists on paper but seems absent in practice.

The follower count rises. The subscriber count remains substantial. Yet a new post or video arrives to little visible response. The creator begins asking questions that the dashboard cannot answer. Were people shown the work? Did they notice it? Did they read or watch quietly? Did their interests change? Did the platform route the content somewhere else? Were some accounts inactive, compromised, artificial, or never part of the creator's meaningful audience at all?

This research began with that kind of unresolved mismatch. My LinkedIn audience numbered in the hundreds. The Ultra Verba Lux Mentis YouTube channel had thousands of subscribers. Visible engagement was often sparse. That experience mattered because it produced a question. It did not answer the question.

That distinction became the first rule of the project:

An anecdote may motivate research. It cannot establish coordination, prevalence, causation, intent, or attribution.

The result is Silent Sybils: Coordinated Inauthentic Audiences, Recommender Manipulation, and Creator-Side Risk on LinkedIn and YouTube—a nearly 28,000-word manuscript that reviews the evidence, reconstructs both platforms' public recommendation architectures, defines falsifiable threat models, and proposes a sequence of studies capable of separating a real security vulnerability from ordinary audience mismatch.

What is a “Silent Sybil”?

A Sybil network is a set of apparently independent accounts that are actually coordinated or controlled by the same operator or command structure. The term comes from computer-security research on systems in which one actor creates many identities to gain disproportionate influence.

The word silent needs equal care. It does not mean that the accounts are technically invisible. A publicly quiet account may still leave platform-visible traces through registration patterns, devices, clickstreams, browsing sequences, target overlap, watch behavior, dwell, skips, hides, reports, or other actions. Server-side clickstream research has shown that coordinated accounts can be detected through behavioral sequences even when their public profiles appear ordinary.

In this manuscript, “Silent Sybil” names a proposed causal chain:

  1. One operator controls or coordinates many accounts.
  2. Those accounts follow, connect to, or subscribe to a target creator.
  3. They receive actual impressions of the creator's content.
  4. They generate strategically adverse or unrepresentative behavior—such as rapid skipping, short viewing, hides, disinterest feedback, or reports.
  5. The platform admits those observations into a shared item, creator, channel, or model state.
  6. Unrelated legitimate users then receive less of the creator's work.

The edge alone is not enough. A follower who never receives the post cannot generate target-specific dwell or skip feedback. A subscription is not a video impression. Public silence is not the same thing as rapid rejection. A private preference control may affect only the acting viewer. A report belongs to a moderation pathway, not automatically to ordinary recommendation ranking.

Figure 1. The complete Silent Sybil hypothesis requires every stage from coordinated control through cross-user exposure loss. The dashed edge-only hypothesis is not established.

What the evidence already establishes

The manuscript's starting point is not speculation. Two neighboring security problems are well documented.

First, recommender poisoning is real. Research systems can be manipulated when fabricated users, ratings, interactions, graph edges, content, sequences, or model updates enter shared learning. The exact attack depends on the recommender architecture, but the general security class is established: a shared model can transmit manipulated observations from controlled accounts to ordinary users.

Second, coordinated fake-audience and artificial-engagement networks are real. A 2024 study by Yasser Zouzou and Onur Varol identified anomalous follower cohorts through temporal following patterns and found groups behaving consistently across multiple target accounts. Earlier work such as CopyCatch showed that group attacks can appear as dense, time-bounded lockstep structures in user-to-page graphs. Research repositories and blackmarket studies also document services that sell or exchange likes, views, comments, follows, and subscriptions across platforms, including YouTube.

These findings matter because they establish both sides of the bridge:

  • controlled identities can manipulate recommender inputs; and
  • coordinated account networks can manipulate social metrics and engagement systems.

But the bridge itself remains incomplete. The public literature does not yet demonstrate a LinkedIn- or YouTube-specific campaign in which coordinated followers or subscribers quietly generated adverse feedback that caused unrelated legitimate viewers to receive less of a creator's content.

That missing link is the scientific problem.

What the evidence does not establish

The manuscript found no public evidence supporting the claim that a dormant follower or subscriber lowers a creator's distribution merely by remaining attached.

That matters because follower counts and subscriber counts are often treated as if they were exposure denominators. They are not. A creator with 5,000 subscribers cannot infer that all 5,000 were eligible, retrieved, ranked, served, or attentive when a video was published. A LinkedIn creator cannot divide visible reactions by total followers and call the result a follower response rate. The platform may have shown the item mostly outside the network, repeatedly to the same people, or not to much of the nominal audience at all.

Public nonreaction is equally ambiguous. It may conceal:

  • no impression;
  • an impression below meaningful attention;
  • a fast skip;
  • a long silent read;
  • a click followed by immediate abandonment;
  • a sustained watch without a like;
  • a viewer who valued the work but did not want to endorse it publicly;
  • or an interruption unrelated to content quality.

This is why the research refuses to classify quiet people as suspicious. Legitimate users may be new, private, infrequent, multilingual, disabled, mobile-only, low-connectivity, privacy-conscious, or simply uninterested in public performativity. A defense that protects creators by treating those users as bots would create a new inequity while claiming to solve the first one.

The same caution applies to the creator. Suspicious followers do not prove that the recipient purchased them. A third party may attach fake accounts for credibility farming, camouflage, reconnaissance, false-flag manipulation, or reasons unrelated to the creator. The manuscript therefore proposes a creator-recipient safe harbor: platforms should quarantine suspicious accounts and their signals, but should not punish the recipient creator without evidence of procurement, control, authorization, or knowing coordination.

Why LinkedIn makes the hypothesis testable

LinkedIn's March 2026 Feed disclosure makes the platform unusually relevant to this research. LinkedIn says its new ranking system uses member profile information and interaction history, including content people read, like, comment on, return to, or scroll past. Its sequential ranker predicts passive outcomes such as click, skip, and long dwell alongside active outcomes such as like, comment, and share.

LinkedIn also disclosed that its out-of-network retrieval training uses “hard negatives”: posts that were actually impressed to a member but received no engagement. That is not proof that every unengaged impression globally harms a creator. In the same technical account, LinkedIn says it curated history toward positive engagement because including every impressed post hurt model performance. The public record therefore reveals several model components with different semantics, not one universal rule.

Still, this is enough to define a serious testable pathway:

actual impression → rapid skip or admitted unengaged impression → shared retrieval or ranking update → lower exposure for unrelated viewers

LinkedIn separately says it is acting against automated comments, engagement pods, and inauthentic engagement while reducing engagement bait. That confirms that artificial behavior is already a platform-integrity concern. It does not reveal the false-negative rate, how suspicious followers are attributed, whether a recipient creator can be framed, or how fully historical signals are invalidated after enforcement.

Figure 2. Public LinkedIn disclosures identify a sequence-aware Feed with passive and active prediction tasks. The diagram is a bounded reconstruction, not a claim to reproduce LinkedIn's production system.

Why YouTube must be studied surface by surface

YouTube cannot be treated as one recommendation system.

Its official documentation says Home recommendations rely primarily on watch history, while Up Next relies heavily on the video currently being watched. Search incorporates relevance, aggregate engagement, query-specific watch time, and quality. Subscriptions, likes, dislikes, “Not interested,” “Don't recommend channel,” and satisfaction surveys all contribute information, but not necessarily in the same way or on the same surface.

Even the word impression has a specific boundary. YouTube counts a registered thumbnail impression only when at least half the thumbnail is visible for more than one second on eligible YouTube surfaces. Email, notifications, external websites, background tabs, and several other contexts are excluded.

A channel can therefore have views without registered impressions, subscribers who never receive a Home impression, and subscribers who see an upload in the Subscriptions feed but not on Home. A non-click on Home is not automatically equivalent to a swipe in Shorts, a short watch after Up Next, or a query-specific watch-time signal in Search.

YouTube also prohibits artificial views, likes, comments, and subscriptions. It says identified artificial traffic is not counted and spam subscribers should not affect legitimate views or watch time when removed. The unresolved question is what happens before detection: whether an inauthentic account that has not yet been identified can receive full signal weight, and whether any resulting state is later corrected retroactively.

That question requires internal logs, not a public subscriber count.

The dashboard cannot show the causal chain

Creators can usually see aggregates: impressions, reach, views, watch time, reactions, comments, saves, shares, follower or subscriber changes, and traffic sources.

They usually cannot see:

  • which followers or subscribers were eligible for a specific item;
  • which entered the candidate set;
  • the item's rank position;
  • who received a qualifying impression;
  • who skipped, watched briefly, hid, or selected a private preference control;
  • which accounts were trust-weighted or quarantined;
  • whether the behavior changed a personal, pairwise, item, creator, channel, or global model feature;
  • or what the counterfactual distribution would have been without the suspect accounts.

This is why a creator can detect an anomaly but cannot independently prove the mechanism.

A mature integrity system should be able to answer a precise sequence of questions:

What did the accounts see? What did they do? What did the platform admit? What shared state changed? What changed for unrelated viewers? What happens when the cohort's influence is removed?

A research program designed to be wrong

The manuscript is built to support, narrow, or falsify the hypothesis.

The first stage is an authorized single-creator data pilot. It tests whether LinkedIn and YouTube exports can be preserved, parsed, reconciled, and analyzed without confusing nominal audience with actual exposure. The pilot is about feasibility and measurement—not proving an attack.

The second stage is a prospective multi-creator matched study. Creators who experience a prespecified audience anomaly would be compared with similar creators who did not experience one at the same time. Event classification would be conducted without viewing post-event outcome data. Count-only bursts would remain separate from corroborated coordinated cohorts.

The third stage is a consenting exposure panel. Established followers and subscribers would use the platforms naturally and record whether focal content actually appeared on default and comparison surfaces. This distinguishes “no natural session,” “session without exposure,” “served but not noticed,” and “served and noticed.”

The fourth stage is an off-platform recommender simulation. Transparent LinkedIn-inspired and YouTube-inspired environments would test whether edge-only attachment, passive long dwell, rapid skips, short watches, explicit feedback, shared feature admission, or creator-level persistence are necessary for an effect. A mechanism that appears only because a global creator penalty was hard-coded would be labeled assumption-created.

The strongest stage is a platform-internal causal audit. The same historical requests would be replayed with suspect influence included, removed, restricted to personal personalization, assigned zero shared weight, replaced with benign passive behavior, and compared with removal of a matched legitimate cohort. The European Union's Digital Services Act now provides a formal path for vetted researchers to seek nonpublic data from very large platforms for systemic-risk research, although access is neither automatic nor guaranteed.

A null result is a result. The hypothesis may prove practically infeasible under current controls. A narrow surface-specific vulnerability may exist. Moderation brigading may matter more than ranking. False-positive defenses may be the larger creator risk. Each outcome would improve governance if the methods remain transparent and the claims stay bounded.

What creators can do now

Creators cannot fix a hidden shared-learning problem by purging quiet followers. That action risks excluding legitimate users and destroying evidence.

The useful controls are more modest:

  • secure the platform account and its associated email;
  • preserve recurring analytics exports and platform notices;
  • keep original files immutable and record export dates and settings;
  • use the platform's own metric definitions and denominators;
  • avoid purchased engagement, engagement exchanges, coercive tests, and unauthorized automation;
  • document promotion vendors and contractually prohibit artificial traffic;
  • report specific policy violations through official channels;
  • appeal formal restrictions using preserved evidence;
  • use neutral public language such as audience anomaly or possible coordinated behavior rather than naming alleged operators;
  • and maintain a website, mailing list, archive, or other direct continuity channel.

These controls protect account integrity, evidence, and audience continuity. They do not reveal who received a private impression or how the ranking model weighted it.

What platforms should build

The defense conclusion is clearer than the attack conclusion.

Platforms should verify that a qualifying exposure occurred before target-specific feedback exists. They should route behavior into explicit lanes: personal personalization, viewer–creator affinity, shared item state, creator or channel state, model training, or moderation. Negative preference controls should be personal before shared. Correlated cohorts should have bounded influence. Shared adverse updates should require evidence from sufficiently independent viewers rather than raw account count.

Platforms should also preserve event and feature lineage so that confirmed artificial activity can be removed later. They should run leave-one-cohort-out replay, protect lawful content from permanent early-window collapse, measure false positives among new and low-activity legitimate users, and evaluate effects on small and niche creators.

Two governance controls are especially important.

Creator-recipient safe harbor

Quarantine suspicious accounts and signals immediately, but do not impose a creator-level penalty for unsolicited attachment without evidence that the creator procured, controlled, authorized, or knowingly coordinated the activity.

Creator integrity receipt

When an integrity action materially changes a creator's audience count, content distribution, or account state, provide a privacy-preserving receipt explaining:

  • what type of action occurred;
  • which surface or time window was affected;
  • whether public metrics or shared signals were adjusted;
  • whether the creator was attributed as a participant or only a recipient;
  • whether human review occurred;
  • what restoration was performed;
  • and how the creator may appeal.

Transparency need not reveal attacker identities, device fingerprints, or security-sensitive thresholds. It should reveal enough process to make a material decision reviewable.

Why the question matters beyond one creator

Recommender systems allocate attention, opportunity, reputation, audience access, and—in many cases—income. Their integrity is therefore not only a consumer relevance problem. It is a multi-sided governance problem involving users, creators, platforms, advertisers, researchers, regulators, and the public.

A weak defense allows coordinated operators to distort shared learning. An overbroad defense can suppress newcomers, multilingual communities, disabled users, privacy-conscious users, low-frequency participants, and small creators. A creator may be harmed both by an undetected manipulation campaign and by a platform that mistakes unsolicited activity for creator complicity.

The responsible posture is neither “the algorithm is censoring me” nor “the platform would certainly stop it.” It is to build systems capable of answering the causal question with evidence.

The manuscript's conclusion is intentionally narrower than its title may first suggest:

Coordinated recommender manipulation is a credible security class. The specific Silent Sybil pathway is not established on LinkedIn or YouTube by the public evidence currently available. The proper response is auditable research, platform-held causal testing, proportionate controls, and creator due process.

Download the full research manuscript

The complete research package includes the 139-page searchable PDF, editable Word manuscript, citation guidance, a machine-readable manifest, and integrity checksums.

Suggested citation

Prislac, Thomas, and Envoy Echo. 2026. Silent Sybils: Coordinated Inauthentic Audiences, Recommender Manipulation, and Creator-Side Risk on LinkedIn and YouTube. Ultra Verba Lux Mentis Research Division.

About Ultra Verba Lux Mentis

Ultra Verba Lux Mentis is an Oregon-based 501(c)(3) public charity working to advance cooperation, shared understanding, ethical innovation, and equitable access to knowledge. Our research examines how social, technological, and organizational systems can remain useful, auditable, accessible, and accountable without exporting hidden harm onto users or communities.


Sources and further reading

Gang Wang et al., “You Are How You Click: Clickstream Analysis for Sybil Detection,” 22nd USENIX Security Symposium (2013), USENIX.

Yasser Zouzou and Onur Varol, “Unsupervised Detection of Coordinated Fake-Follower Campaigns on Social Media,” EPJ Data Science 13, 62 (2024), doi:10.1140/epjds/s13688-024-00499-6.

Alex Beutel et al., “CopyCatch: Stopping Group Attacks by Spotting Lockstep Behavior in Social Networks,” WWW 2013, Meta Research.

Hridoy Sankar Dutta, Udit Arora, and Tanmoy Chakraborty, “ABOME: A Multi-platform Data Repository of Artificially Boosted Online Media Entities,” ICWSM 15 (2021), doi:10.1609/icwsm.v15i1.18123.

Hridoy Sankar Dutta, Nirav Diwan, and Tanmoy Chakraborty, “Weakening the Inner Strength: Spotting Core Collusive Users in YouTube Blackmarket Network,” ICWSM 16 (2022), doi:10.1609/icwsm.v16i1.19280.

Hristo Danchev, “Engineering the Next Generation of LinkedIn’s Feed,” LinkedIn Engineering, March 12, 2026, official engineering disclosure.

LinkedIn Corporate Communications, “How LinkedIn Is Improving the Feed to Show More Relevant, Authentic Professional Content,” March 12, 2026, LinkedIn News.

YouTube, “Learn More About How YouTube Works for You,” YouTube Help.

YouTube, “Check Your YouTube Impressions and Watch Time,” YouTube Help.

YouTube, “Fake Engagement Policy,” YouTube Help.

European Commission, “Commission Facilitates Data Access for Researchers Under the Digital Services Act,” July 2, 2025, Shaping Europe’s Digital Future.

Previous
Previous

Cryptography in Plain Sight: The Zeitgeist Channel"

Next
Next

Coherent Revenue Administration: A Public-Value Encyclopedia for a Modern Tax Agency