Die heldin-Plattform ist keine weitere Faktencheck-App. Sie ist eine Analyse- und Reaktions-Infrastruktur, die die Produktionslogik koordinierter Einflussoperationen aufdeckt, ihr eine verhältnismäßige, lückenlos belegte Gegenwehr entgegensetzt und deren Wirkung misst – in einem auditierten Governance-Rahmen, mit bindenden roten Linien. Drei Layer, ein geschlossener Regelkreis.The heldin platform is not another fact-check app. It is an analysis and response infrastructure that exposes the production logic of coordinated influence operations, sets proportionate, fully evidenced countermeasures against it and measures their effect – inside an audited governance framework, with binding red lines. Three layers, one closed loop.
Desinformation skaliert, weil sie industriell produziert wird – und Demokratie hält nur dagegen, wenn ihre Antwort ebenfalls skaliert: auf der Skala der Belege, nicht der Bots. Die Angreifer-Industrie arbeitet in drei Stufen: Strategen entwerfen Narrative, anonyme Verstärker und Clickwork-Netzwerke produzieren und verteilen die Inhalte, und am Ende misst niemand die Wirkung. Genau dieser blinde Fleck macht das System unaufhaltbar. Unsere Architektur spiegelt alle drei Stufen, mit umgekehrten Vorzeichen.Disinformation scales because it is produced industrially – and democracy can only push back if its answer scales too: at the scale of evidence, not of bots. The attacker industry operates in three tiers: strategists design narratives, anonymous amplifiers and clickwork networks produce and distribute the content, and in the end nobody measures the effect. Precisely that blind spot makes the system unstoppable. Our architecture mirrors all three tiers, with the signs reversed.
Zielpublika-Analyse und verdeckte Taktiken, proprietär und unsichtbar.Audience analysis and covert tactics: proprietary and invisible.
Macht die verdeckte Strategie transparent und maschinenlesbar, eine formale TTP-Taxonomie.Makes the covert strategy transparent and machine-readable: a formal TTP taxonomy.
Anonyme, parasoziale, ausbeuterische Massenproduktion von Inhalten.Anonymous, parasocial, exploitative mass-production of content.
Provenance-signierte Vorab-Aufklärung und belegte Meldungen im Fan-out, mit Human-in-the-Loop.Provenance-signed prebunking and evidenced reports fanned out, with Human-in-the-Loop.
Keine Rechenschaft, keine Rückkopplung, Wirkung bleibt unmessbar und ungesteuert.No accountability, no feedback: the effect remains unmeasurable and uncontrolled.
Quantifiziert Verbreitung, Polarisierung und Schaden, und speist die Erkenntnisse zurück.Quantifies spread, polarization and harm, and feeds the findings back into the system.
Verhältnismäßige Gegenwehr, nicht Gegen-Lärm. heldin skaliert nicht die Inhalte, sondern die Belege: Aus einer einzigen, menschlich freigegebenen Entscheidung entstehen viele belegte Meldungen (Fan-out) plus Vorab-Aufklärung – mit messbarer Wirkung und vollem Governance-Substrat. Gegen-Bots und alles unter fremder Flagge sind bindend ausgeschlossen.Proportionate countermeasures, not counter-noise. heldin scales the evidence, not the content: a single, human-approved decision fans out into many evidenced reports plus prebunking – with measurable impact and a full governance substrate. Counter-bots and anything under a false flag are bindingly ruled out.
Layer 01 erkennt und klassifiziert den Angriff. Layer 02 produziert die Gegenkraft. Layer 03 misst die Wirkung, und speist sie zurück in Engine und Playbook. Querliegend unter allen drei Layern: ein durchgängiges Governance-Substrat.Layer 01 detects and classifies the attack. Layer 02 produces the counter-force. Layer 03 measures the effect and feeds it back into the engine and playbook. Running beneath all three layers: a continuous governance substrate.
Erkennt, attribuiert und klassifiziert koordinierte Einflussoperationen entlang einer Taxonomie, die methodisch an DISARM und MITRE ATT&CK angelehnt ist. Weil Inhalte neuester KI-Modelle kaum noch zuverlässig als KI-generiert erkennbar sind, verlagert sich die Detektion auf verhaltensbasierte Signaturen, und nutzt aus, dass KI-Personas paradoxerweise konsistenter agieren als Menschen.[8]Detects, attributes and classifies coordinated influence operations using a taxonomy methodologically aligned with DISARM and MITRE ATT&CK. Because content from the latest AI models can rarely be reliably identified as AI-generated, detection shifts to behavior-based signatures, exploiting the fact that AI personas paradoxically behave more consistently than humans.[8]
OSINT/SOCMINT aus Social Media, Messengern und News als Rohsignal.OSINT/SOCMINT from social media, messengers and news as raw signal.
NLP-Cluster, CIB-Erkennung (Coordinated Inauthentic Behavior), Cascade-Modelle und Behavioral Fingerprinting: Graph-Koordination, Posting-Sequenzen, Cross-Platform-Konsistenz.NLP clustering, CIB detection (Coordinated Inauthentic Behavior), cascade models and behavioral fingerprinting: graph coordination, posting sequences, cross-platform consistency.
Formale TTP-Taxonomie für Influence Operations, erstmals mit eigenem Tier für KI-native Akteure, methodisch analog zu MITRE ATT&CK.Formal TTP taxonomy for influence operations: first to include a dedicated tier for AI-native actors, methodologically analogous to MITRE ATT&CK.
C2PA-Signatur, Reverse-Image- und Fact-Check-Cross-Reference. Outputs anschlussfähig an SIEM/SOAR (STIX/TAXII).C2PA signature, reverse-image and fact-check cross-reference. Outputs compatible with SIEM/SOAR (STIX/TAXII).
Die operative Mitte der Plattform. Da reaktives Debunking immer langsamer ist als die Verbreitung (Halbwertszeit eines Beitrags auf X: ≈ 24 Minuten[6]), verschiebt sich der Hebel auf Geschwindigkeit (Prebunking, bevor ein Narrativ Momentum aufbaut) und auf Provenienz: Aus einer einzigen, menschlich freigegebenen Entscheidung entstehen viele belegte Meldungen an Registrare, Plattformen und Behörden (Fan-out). Grundsatz: Kennzeichnen statt Gegen-Wahrheit – Kampagnen werden öffentlich als organisierte, bezahlte Operationen ausgewiesen, statt sie Stück für Stück zu widerlegen.The operational center of the platform. Because reactive debunking is always slower than the spread (a post's half-life on X: ≈ 24 minutes[6]), the lever shifts to speed (prebunking before a narrative builds momentum) and to provenance: a single, human-approved decision fans out into many evidenced reports to registrars, platforms and authorities. Principle: label rather than counter-truth – campaigns are publicly identified as organized, paid operations instead of being refuted piece by piece.
Kognitive Inokulierung: zielgruppenspezifische Inhalte, gespeist aus dem Playbook. Die Wirksamkeit psychologischer Inokulierung ist experimentell belegt.[9]Cognitive inoculation: audience-specific content drawn from the playbook. The effectiveness of psychological inoculation is experimentally documented.[9]
C2PA-signierte, plattformspezifische Aufklärungs-Pakete: Herkunfts-Kennzeichnung[10], Inoculation, Prebunking über ein Partnernetz. Offen parteiische Gegen-Botschaften sind ausgelagert; verdeckte Gegen-Kampagnen bindend ausgeschlossen.C2PA-signed, platform-specific explainer packages: provenance labeling[10], inoculation and prebunking through a partner network. Openly partisan counter-messaging is externalized; covert counter-campaigns are bindingly ruled out.
Industrialisiert die heute manuelle Evidenzarbeit: Auto-Dossiers in den Formaten von DSA Art. 16 (Notice-and-Action) und nationaler Aufsichtsbehörden.Industrializes today's manual evidence work: auto-dossiers in the formats required by DSA Art. 16 (Notice-and-Action) and national regulatory authorities.
Distribution erst nach Compliance-Gate. Jede Ausspielung ist auditierbar und an Freigabe gebunden.Distribution only after a compliance gate. Every deployment is auditable and requires explicit approval.
Schließt den blinden Fleck der Wirkungsmessung. Liefert die quantifizierbaren Risiko-Metriken, die DSA Art. 34/35 und NIS2 verlangen: in keinem operativen Produkt gelöst, in der Forschung aber etabliert (kausale Einfluss-Schätzung).[7] Ausgewiesen wird zunächst zeitliche Korrelation; Kausalaussagen folgen erst mit belastbarer Methodik. Die Ergebnisse fließen über den Closed Loop zurück in Engine und Playbook.Closes the blind spot in impact measurement. Delivers the quantifiable risk metrics that DSA Art. 34/35 and NIS2 require: solved in no operational product, yet established in research (causal influence estimation).[7] What gets reported first is temporal correlation; causal claims follow only with robust methodology. The results flow back via the closed loop into the engine and playbook.
GNN- und SEIZ-basierte Vorhersage von Diffusionspfaden, predicted vs. real.GNN- and SEIZ-based prediction of diffusion paths: predicted vs. real.
Opinion-Dynamics-Modellierung: Hardening, Echo-Chamber-Effekte und Spaltungs-Index über Zeit.Opinion-dynamics modeling: hardening, echo-chamber effects and polarization index over time.
Realwelt-Indikatoren, Verhalten, Folgehandlungen, Harm-Reduction-Index.Real-world indicators: behavior, follow-on actions, harm-reduction index.
Wirkungsdaten verbessern Engine und Playbook. Die Plattform wird messbar besser über die Zeit.Impact data improves the engine and playbook. The platform becomes measurably better over time.
Ein Schaubild aus unserer Architekturarbeit zeigt, wie die drei Layer als ein System zusammenwirken: der Wirkungs-Kreislauf vom Angreifer-Playbook bis zur Wirkungsmessung. Die Farbabstufung kodiert nur die Reihenfolge im Kreislauf, keine Bewertung. Die Erkennungslogik im Detail legen wir bewusst nicht offen; Partner erhalten Einblick im Rahmen des Zwei-Stufen-Disclosure (siehe unten).One figure from our architecture work shows how the three layers interact as one system: the impact loop from adversary playbook to impact measurement. The color gradation encodes only the order in the loop, not any rating. We deliberately do not publish the detection logic in detail; partners get insight under the two-tier disclosure (see below).
EU AI Act, GDPR, DSA, NIS2, DORA, C2PA und Human-in-the-Loop liegen als Pflicht-Substrat unter allen drei Layern. Distribution ist erst nach einem Compliance-Gate möglich. Genau das macht die Plattform für demokratische Institutionen und regulierte Betreiber einsetzbar, und immun gegen die berechtigte Frage „Wer kontrolliert die Kontrolleur:innen?".EU AI Act, GDPR, DSA, NIS2, DORA, C2PA and Human-in-the-Loop sit as mandatory substrate beneath all three layers. Distribution is only possible after a compliance gate. This is precisely what makes the platform deployable for democratic institutions and regulated operators, and immune to the legitimate question: "Who controls the controllers?"
Dieselbe leistungsfähige Modellklasse wie auf der Angreiferseite, aber innerhalb eines vollständig EU-AI-Act-konformen, DSA-accountablen, C2PA-verifizierten Rahmens mit Audit-Log, Red-Teaming und Zero-Trust. Das ist kein ethisches Beiwerk, sondern ein regulatorischer Moat: Angreifer skalieren außerhalb jeder Regulierung, heldin innerhalb. Die Frage ist nicht, ob Frontier-KI in diesem Feld eingesetzt wird, sondern unter welcher Governance.The same powerful model class as on the attacker side, but inside a fully EU-AI-Act-compliant, DSA-accountable, C2PA-verified framework with audit log, red-teaming and zero-trust. This is not an ethical accessory but a regulatory moat: attackers scale outside any regulation; heldin operates inside it. The question is not whether frontier AI is used in this field, but under what governance.
Counter-Disinformation ist kein Themenfeld neben Cybersecurity, sondern eine eigenständige Disziplin darin: Cognitive Security. Die Plattform ist methodisch an etablierte Threat-Intel-Frameworks angeschlossen, regulatorisch an die einschlägigen EU-Richtlinien gekoppelt und operativ in bestehende SOC-/Threat-Intelligence-Stacks integrierbar.Counter-Disinformation is not a field alongside cybersecurity but an independent discipline within it: Cognitive Security. The platform is methodologically connected to established threat-intel frameworks, coupled to the relevant EU directives and operationally integrable into existing SOC and Threat Intelligence stacks.
| Standard / RegulierungStandard / Regulation | Was es definiertWhat it defines | Wo die Plattform anschließtWhere the platform connects |
|---|---|---|
| DISARM FrameworkOpen-Source TTP-TaxonomieOpen-source TTP taxonomy | Etablierte Klassifikation von Tactics, Techniques & Procedures für Influence Operations, getragen von DFRLab, EU DisinfoLab und der CTI-Community.Established classification of Tactics, Techniques & Procedures for influence operations, supported by DFRLab, EU DisinfoLab and the CTI community.[1] | Das Adversary Playbook (Layer 01) ist der operationalisierte Nachfolger: maschinenlesbar, durch Pattern Detection befüllt, mit Wirkungsdaten aus Layer 03 rückgekoppelt.The Adversary Playbook (Layer 01) is the operationalized successor: machine-readable, populated by pattern detection, fed back with impact data from Layer 03. |
| MITRE ATT&CKIndustriestandard Cybersec-TTPsIndustry standard cybersec TTPs | Globale Referenz-Taxonomie für Cyber-Adversary-Verhalten in SOC, Incident Response und Threat Intel.Global reference taxonomy for cyber-adversary behavior in SOC, incident response and threat intel.[2] | Methodische Analogie 1:1. Schemas folgen ATT&CK-Konventionen; Threat-Reports sind in STIX/TAXII publizierbar und damit direkt in SIEM/SOAR einspeisbar.Methodological analogy 1:1. Schemas follow ATT&CK conventions; threat reports are publishable in STIX/TAXII and thus directly ingestible into SIEM/SOAR. |
| NIS2-RichtlinieEU 2022/2555 · AT seitfrom 2024 | Erweitert die EU-Cybersecurity-Pflichten auf wesentliche und wichtige Einrichtungen, inkl. Risiko-Assessment für hybride und informationelle Bedrohungen.Extends EU cybersecurity obligations to essential and important entities, including risk assessment for hybrid and informational threats.[3] | Layer 03 liefert die quantifizierbaren Risiko-Metriken (Propagation, Polarization, Harm), die NIS2-Aufsicht als Nachweis akzeptiert, heute methodisch ungelöst.Layer 03 delivers the quantifiable risk metrics (Propagation, Polarization, Harm) that NIS2 supervision accepts as evidence: a challenge still methodologically unsolved. |
| DSA Art. 34/35Risk Assessment VLOPsRisk assessment VLOPs | Sehr große Online-Plattformen müssen systemische Risiken für Wahlen, Grundrechte und öffentlichen Diskurs jährlich quantifizieren und mitigieren.Very large online platforms must annually quantify and mitigate systemic risks to elections, fundamental rights and public discourse.[4] | Die Plattform liefert die Evidenz-Infrastruktur (Dismantle-Dossiers + Impact-Metriken), die DSA-Compliance heute manuell und fragmentiert erbringt.The platform delivers the evidence infrastructure (dismantle dossiers plus impact metrics) that DSA compliance currently provides manually and in fragmented form. |
| C2PAContent ProvenanceContent provenance | Offener Standard für überprüfbare Herkunft und Bearbeitungshistorie digitaler Inhalte.Open standard for verifiable origin and editing history of digital content.[5] | Quer durch alle Layer: signiert Counter-Content und macht authentische Inhalte in einem KI-gesättigten Raum unterscheidbar.Runs across all layers: signs counter-content and makes authentic content distinguishable in an AI-saturated information space. |
Jeder Baustein wäre für sich ein Ansatzpunkt. Verteidigbar wird die Plattform durch die Verkettung: Das Playbook konditioniert die Engine, die Engine speist die Messung, die Messung trainiert das Playbook. Wer es nachbauen will, baut den ganzen Stack, oder nichts.Each component would be an entry point on its own. The platform becomes defensible through the chain: the playbook conditions the engine, the engine feeds the measurement, the measurement trains the playbook. Anyone wanting to replicate it must build the whole stack, or nothing.
Eine MITRE-ATT&CK-äquivalente Klassifikation von Influence-Operations-Taktiken, in dieser strukturierten Form bislang nicht existent. Publizierbarer Forschungsbeitrag und operatives Werkzeug zugleich.A MITRE-ATT&CK-equivalent classification of influence-operations tactics: this structured form does not yet exist elsewhere. A publishable research contribution and an operational tool at once.
Der Vorteil liegt in Provenance-verifizierter Authentizität, Fan-out belegter Meldungen und Prebunking-Geschwindigkeit, nicht in Volumen. Voll auditiert, mit messbarer Wirkung – Gegen-Bots bindend ausgeschlossen.The advantage lies in provenance-verified authenticity, fanned-out evidenced reports and prebunking speed, not volume. Fully audited, with measurable impact – counter-bots bindingly ruled out.
Industrialisiert die heute manuelle Spitzenforschung (DFRLab, Bellingcat) in die Formate, die Plattformen und Behörden brauchen, und bricht den strukturellen Bottleneck.Industrializes today's manual cutting-edge research (DFRLab, Bellingcat) into the formats platforms and authorities require, breaking the structural bottleneck.
Propagation + Polarization + Harm liefern den belastbaren Nachweis, dass Gegenmaßnahmen Desinformation reduzieren, nicht nur verschieben. Schließt die zentrale Forschungslücke des Feldes.Propagation + Polarization + Harm deliver robust evidence that countermeasures reduce disinformation rather than merely displace it. This closes the central research gap in the field.
Intel → Engine → Impact → zurück. Wirkungsdaten verbessern die Pipeline kontinuierlich. Die Plattform wird über die Zeit messbar besser.Intel → Engine → Impact → back. Impact data continuously improves the pipeline. The platform becomes measurably better over time.
EU AI Act, DSA, NIS2, DORA, C2PA und Human-in-the-Loop sind Pflicht-Substrat, kein Add-on. Erst das macht die Plattform für regulierte Institutionen einsetzbar.EU AI Act, DSA, NIS2, DORA, C2PA and Human-in-the-Loop are mandatory substrate, not an add-on. This alone makes the platform deployable for regulated institutions.
heldin folgt einer Zwei-Stufen-Logik. Die Wissens- und Methodik-Schicht ist öffentlich nachvollziehbar und stärkt Forschung, Medien, Bildung und Zivilgesellschaft. Die operative Schicht bleibt bewusst geschützt, damit dieselben Werkzeuge nicht gegen ihren Zweck eingesetzt werden.heldin follows a two-tier logic. The knowledge and methodology layer is publicly transparent and strengthens research, media, education and civil society. The operational layer remains deliberately protected so that the same tools cannot be turned against their purpose.
Öffentlich, nachvollziehbar, anschlussfähig, die Grundlage für eine resiliente Forschungs- und Medien-Community.Public, transparent, compatible: the foundation for a resilient research and media community.
Zugriffsgebunden und auditiert, damit Wirkung nicht zur Waffe wird.Access-controlled and audited: so that impact cannot become a weapon.
Offenen Knowledge Graph ansehenView the open knowledge graph →
Die Plattform ist die operative Hälfte des heldin resilience lab. Die andere Hälfte ist die Wirkung, die sie erzeugt, und die Menschen, die sie bauen. Sieh dir das vollständige Wirkungsmodell an oder sprich direkt mit uns.The platform is the operational half of the heldin resilience lab. The other half is the impact it generates and the people who build it. View the full impact model or speak with us directly.