Can We Unmask the Underground? Detecting and Predicting Hidden Forum Interactions
2026-06-16T08:52:13Z•e17e13e6110f6bb5865ed38c9e6f8525f078a38e6d2fbef9437ea5fa0302233d
BERTBreachForumsCrackedHackForumsOSINTcommunity detectioncyber threat intelligencecybercrimeearly warningsemantic embeddingsthreat huntingunderground forumsunsupervised learning
What happened
Presents HADES, an unsupervised framework for detecting both dominant and small/hidden threat communities in cybercrime underground forums by modeling users from their textual interactions. HADES uses pretrained language models (BERT) to generate semantic user embeddings, clusters users by semantic similarity, and assigns topic labels to clusters to produce actionable CTI. Evaluated on HackForums, Cracked, and BreachForums, BERT embeddings improved cluster coherence and silhouette scores versus baselines and enabled identification of dozens of distinct communities (including subgroups with <~0
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arxiv_cs_si
- Record identifier
- e17e13e6110f6bb5865ed38c9e6f8525f078a38e6d2fbef9437ea5fa0302233d
- Enrichment time
- 2026-06-16T08:52:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.