Can We Unmask the Underground? Detecting and Predicting Hidden Forum Interactions

2026-06-16T08:52:13Ze17e13e6110f6bb5865ed38c9e6f8525f078a38e6d2fbef9437ea5fa0302233d
BERTBreachForumsCrackedHackForumsOSINTcommunity detectioncyber threat intelligencecybercrimeearly warningsemantic embeddingsthreat huntingunderground forumsunsupervised learning

What happened

Presents HADES, an unsupervised framework for detecting both dominant and small/hidden threat communities in cybercrime underground forums by modeling users from their textual interactions. HADES uses pretrained language models (BERT) to generate semantic user embeddings, clusters users by semantic similarity, and assigns topic labels to clusters to produce actionable CTI. Evaluated on HackForums, Cracked, and BreachForums, BERT embeddings improved cluster coherence and silhouette scores versus baselines and enabled identification of dozens of distinct communities (including subgroups with <~0

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arxiv_cs_si
Record identifier
e17e13e6110f6bb5865ed38c9e6f8525f078a38e6d2fbef9437ea5fa0302233d
Enrichment time
2026-06-16T08:52:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.