OpenAI Disrupts China-linked Influence Operation "Spamouflage"

OpenAI has banned a small number of accounts linked to "Spamouflage," a China-origin influence operation attributed by Meta to individuals associated with Chinese law enforcement and by the FBI to a unit within China’s Ministry of Public Security. This action disrupts a network that utilized AI models to support a global influence campaign targeting the Chinese diaspora and critics of the Chinese government.

Actor Attribution and Targeting

The Spamouflage network targeted global audiences, focusing specifically on members of the Chinese diaspora and critics of the Chinese government. The operation generated content primarily in Chinese, with additional output in English, Japanese, and Korean.

According to OpenAI, the network's activity was attributed to entities within China, with specific links to law enforcement and the Ministry of Public Security.

AI Utilization and Behavioral Patterns

The network used OpenAI's models for a variety of technical and strategic purposes, ranging from code debugging to content generation. The specific behaviors identified include:

  • Technical Support: In 2023, the network used models to debug code for the WordPress theme of the website revealscum.com, a site used to publish personal information and criticisms of members of the Chinese diaspora.
  • Content Generation: The operation generated articles and social media comments. Examples include articles accusing Japan of damaging the marine environment via the Fukushima power plant wastewater release and English-language comments criticizing dissident Cai Xia.
  • Open-Source Research: The network used AI to research how to apply for social media developer accounts and to summarize social media posts written by critics of the Chinese government.
  • Operational Support: Some operators used the models for personal interests, such as researching camera lenses or completing test assignments for Chinese Communist Party members.

OpenAI noted that AI-generated content constituted only a minority of the network's overall output. Many identified accounts posted a higher volume of manually created content, often characterized by unidiomatic English, both before and after the use of AI-generated text.

Content Themes and Narratives

The campaign's content was divided by language and target audience:

  • Chinese Language Content: Topics included praising international law enforcement cooperation by the Chinese government and criticizing abuses against Native Americans in the United States. Some content also criticized the US government and Microsoft for exposing the "Volt Typhoon" hacking group.
  • English Language Content: This content primarily targeted prominent critics of the Chinese government, including Tibet activist Richard Gere and dissident Cai Xia.
  • Multilingual Content: Articles in English, Japanese, Chinese, Korean, and Russian accused Japan of polluting Pacific waters via the Fukushima nuclear plant discharge.
  • Specific Diplomatic Themes: A cluster of activity focused on positive comments regarding a visit by China’s Minister of Public Security to Uzbekistan.

Impact Assessment

Despite the scale of the network, OpenAI assesses the impact of this specific operation as low. Using the Breakout Scale’s Category 2 rating (on a scale of 1 to 6), the operation was characterized by posting activity across many platforms but lacked significant amplification by authentic users.

OpenAI reported that none of the identified blogs, articles, or social media accounts gained high numbers of engagements or follows from real people. In some instances, the only views recorded for the posts were from OpenAI's own investigative team.

Sources