Researchers publish tool to rate disinformation defense
Researchers at Monash University have published a capacity maturity model for assessing how prepared a country is to defend itself against disinformation campaigns, backed by a 103-page white paper that lays out the reasoning behind it in far more depth than the university’s public summary of the project disclosed.
The model and white paper were released this month by Carlo Kopp, a lecturer in Monash’s Department of Software, Systems and Cybersecurity, with the model itself co-authored by Callum Jones. The project was funded in part by the Oceania Cyber Security Centre, according to the white paper. Kopp is also a longtime defense analyst and co-founder of the Air Power Australia think tank. A related conference paper on measuring the effects of disinformation attacks, authored by Kopp, appeared in a Springer volume on human aspects of information security in 2025.
The model is structured on the Cybersecurity Capacity Maturity Model developed by the Global Cyber Security Capacity Centre at the University of Oxford, which governments already use to benchmark their readiness against cyber threats. The white paper argues that framework cannot be applied to disinformation without modification, because the two threats differ at a basic level: cyberattacks target computer systems, while disinformation targets human belief and, through it, human behavior.
The white paper works from a specific definition: disinformation is any deception, by any means, intended to implant or reinforce a false belief in a target population to advance an attacker’s agenda, often as part of a sustained campaign. That definition deliberately includes cases where the person spreading the falsehood, a “proxy,” has no knowledge that it is false and no intent to deceive anyone. The paper distinguishes disinformation from misinformation (false content shared without harmful intent) and malinformation (true content shared specifically to cause harm), following a framework published by the Council of Europe.
Proxies get an extended treatment in the paper. People pass along disinformation for reasons that have little to do with the attacker’s original agenda, according to the white paper, including maintaining social status within a group, aligning with a preexisting belief, chasing engagement or advertising revenue, or being paid to do so without regard for accuracy. The paper adds newer categories to that list: a proxy can also be a fake online identity operated by the source of the disinformation, or an AI chatbot that was trained, deliberately or through negligence, on contaminated data.
Much of the paper concerns how disinformation exploits ordinary human cognition rather than any technical vulnerability. Drawing on the Boyd observation-orientation-decision-action cycle, it describes how a piece of disinformation that contradicts a person’s existing mental model produces cognitive dissonance, which people resolve either by rejecting the new information or by adjusting their beliefs to accommodate it, sometimes incorporating the false belief permanently. The paper lists confirmation bias, the Dunning-Kruger effect, motivated cognition, illusory superiority, false consensus and self-deception among the specific errors that disinformation is designed to exploit, and links group-level dysfunctions such as groupthink and polarization to the same underlying mechanisms, amplified by the connectivity of digital social networks. Citing prior modeling work by Kopp and colleagues, the paper notes that even a small share of a population producing or spreading deception can disrupt cooperation across an entire society.
The white paper devotes a separate section to Russian “Reflexive Control” doctrine, a Soviet-era concept in which disinformation is used to shape an adversary’s own decision-making in the attacker’s favor, which the paper treats as a specific instrument within the broader category NATO calls cognitive warfare. It cites the contested debates over the 2014 downing of Malaysia Airlines Flight MH17 and the origins of SARS-CoV-2 as recent examples of adversaries exploiting genuine uncertainty about the facts to sustain competing narratives.
Artificial intelligence gets its own section, describing a new problem the paper’s cited sources call “slopaganda,” unwanted AI-generated content spread to manipulate beliefs for political ends. The white paper walks through the taxonomy of AI “hallucinations,” false but fluent outputs that resemble the cognitive errors seen in humans, and cites research finding large language models can display overconfidence more often than humans do, along with confirmation bias toward their own prior outputs. As an illustration, it cites a Russian party’s stated plan to build a chatbot trained on the speeches of a deceased ultranationalist politician to generate ongoing political commentary. On policy, the paper notes that a 2023 U.S. executive order on AI safety mentioned disinformation only once, in passing, before being revoked in January 2025, and it says the EU’s AI Act, while more developed than the U.S. approach, still has significant limitations for addressing disinformation directly.
The white paper organizes countermeasures into four categories. Degradation strategies aim to reduce a disinformation source’s reach, through methods such as jamming hostile broadcasts, denial-of-service attacks on servers hosting disinformation, or flooding an audience with competing, truthful messages, though the paper notes that direct attacks on infrastructure may be unlawful in many jurisdictions. Corruption strategies expose an attacker’s false messages, primarily through fact-checking. Denial strategies block an attacker’s access to distribution channels. Immunisation strategies teach potential victims to recognize deception techniques themselves.
To illustrate how national policy actually looks in practice, the white paper compares four cases. Australia relied on a voluntary industry code of practice adopted in 2021, then twice attempted stronger legislation, in 2023 and 2024, that would have given the media regulator power to compel platforms to address misinformation; both bills stalled, with the second withdrawn in November 2024 after the Law Council of Australia warned the legislation was overly broad and risked serious unintended consequences. Sweden took a different path, standing up a dedicated Psychological Defence Agency with separate operations and capability-development arms, explicitly framing disinformation defense as a whole-of-society responsibility shared by government, industry and individual citizens. The United States, the paper says, currently lacks a robust government mechanism: the State Department’s Global Engagement Center, the country’s main counter-disinformation body, was closed in late 2024, a Department of Homeland Security disinformation board set up in 2022 was suspended amid criticism of its scope, and the paper notes the U.S. Agency for Global Media’s move to shut down Voice of America and Radio Free Europe/Radio Liberty, both long used to counter foreign propaganda, has drawn legal challenges. The European Union, by contrast, has built a transnational structure dating to a 2018 European Commission communication, running through a voluntary Code of Practice on Disinformation and the Digital Services Act; the white paper notes that framework had only limited success interdicting Russian war propaganda in March 2022, and cites the EU’s November 2025 “European Democracy Shield” white paper, which proposed a new European Centre for Democratic Resilience to coordinate detection and response across member states.
Among its conclusions, the white paper argues that any capacity maturity model must hold government entities to the same standard as the private sector and civil society when it comes to producing or distributing disinformation, stating that governments are not implicitly immune to the same problems they are being asked to police in others. It also warns against building an overly prescriptive model, since countries will inevitably choose different strategies depending on their legal systems and political cultures, and against assuming that fact-checkers themselves are infallible arbiters of truth.
Kopp said the next step for the research is practical application: using the model to evaluate individual countries’ disinformation defense capacity and identify specific gaps in their policy, institutional and technical preparedness. The white paper and the capacity maturity model document are both published through Monash University’s research repository.
Content preview only. Full article available at source. View Full Article
Monash University researchers published a capacity maturity model for assessing a country's preparedness against disinformation campaigns in October 2023. The model, co-authored by Carlo Kopp and Callum Jones, is based on a framework from the University of Oxford and aims to address the unique challenges posed by disinformation. The white paper outlines various strategies for countering disinformation and emphasizes the need for comprehensive national policies.
- Monash University researchers published a 103-page white paper on disinformation defense.
- The model is based on the Cybersecurity Capacity Maturity Model from the University of Oxford.
- The paper distinguishes between disinformation, misinformation, and malinformation.
- The research was funded by the Oceania Cyber Security Centre.
- The next step involves evaluating individual countries' disinformation defense capacity.