{
  "slug": "auto-raid-detection-4-signals",
  "title": "Auto-Raid Detection Without False Positives: the 4 Signals That Catch 90%",
  "deck": "Join-velocity spike + low-trust authors + repeated-content fingerprint + cross-thread pattern within 5 minutes.",
  "pillar": "P5",
  "pillarLabel": "Trust and health",
  "date": "2026-04-25",
  "readMinutes": 4,
  "author": "dium.io research",
  "coverTitle": "Auto Raid Detection 4 Signals",
  "blocks": [
    {
      "type": "tldr",
      "text": "Catch raids with four combined signals: join-velocity spike + low-trust authors + repeated-content fingerprint + cross-thread pattern within 5 minutes. Each signal alone produces false positives; the four combined catch ~90% with minimal false-positive rate."
    },
    {
      "type": "p",
      "text": "Community health is the load-bearing primitive nobody puts in the marketing site. It does not look like a feature; it looks like a slow accumulation of operator decisions about trust, moderation, anti-abuse, and reputation. Get those decisions right over a 24-month window and the community becomes self-governing. Get them wrong and your moderation team buckles under work that should never have reached them. Auto-Raid Detection Without False Positives sits inside the health stack: the design that determines whether your community compounds or quietly hollows out.",
      "_enriched": true
    },
    {
      "type": "h2",
      "text": "The four signals",
      "_id": "the-four-signals"
    },
    {
      "type": "table",
      "headers": [
        "Signal",
        "Threshold",
        "False positive risk"
      ],
      "rows": [
        [
          "Join velocity spike",
          ">10 joins/min above baseline",
          "Real launches"
        ],
        [
          "Low-trust authors",
          ">80% of recent posters are Newcomer",
          "New community phase"
        ],
        [
          "Repeated content fingerprint",
          "Same n-gram across >5 posts in 5 min",
          "Viral meme"
        ],
        [
          "Cross-thread pattern",
          "Same accounts posting in >3 threads in 5 min",
          "Active member browsing"
        ]
      ]
    },
    {
      "type": "callout",
      "color": "blush",
      "text": "Each signal alone misfires. All four combined are reliable. The key is requiring 3 of 4 to trigger an auto-action; 2 of 4 only triggers a mod alert."
    },
    {
      "type": "h2",
      "text": "What auto-actions are appropriate",
      "_id": "what-auto-actions-are-appropriate"
    },
    {
      "type": "p",
      "text": "On 3-of-4 trigger: rate-limit new account posting in the affected thread/community. On 4-of-4: temporary read-only on the new accounts pending mod review. Never permaban automatically; raids that look like raids sometimes turn out to be product-launch traffic."
    },
    {
      "type": "h2",
      "text": "What to ship",
      "_id": "what-to-ship"
    },
    {
      "type": "p",
      "text": "Build the four signal detectors as cron-checks (every 60s). Wire to a moderation_alerts table. Surface in the mod dashboard. Add the auto-actions as gated features the operator can opt into."
    },
    {
      "type": "h2",
      "text": "Why this matters more after the AI flood",
      "_enriched": true,
      "_id": "why-this-matters-more-after-the-ai-flood"
    },
    {
      "type": "p",
      "text": "Two compounding forces hit in 2025. The cost of generating plausible spam dropped to near-zero. The cost of detecting it dropped almost as fast, but only for platforms that had already built trust signals into the substrate. Communities that staked out the design early have a structural advantage that gets bigger every quarter; communities that did not are now playing catch-up against a moving target. Auto-Raid Detection Without False Positives is one of the design choices that puts you on the right side of that curve.",
      "_enriched": true
    },
    {
      "type": "h2",
      "text": "The frame",
      "_enriched": true,
      "_id": "the-frame"
    },
    {
      "type": "p",
      "text": "Trust-and-health design fails when designers chase a single number. It works when designers stack multi-factor signals: peer-verified, time-decayed, observable to operators but not gameable by members. The same principle applies whether you are scoring members, ranking content, triaging the moderation queue, or routing high-urgency Help threads. Pick three or more independent inputs, decay them on a half-life that matches the workload, surface the result as a level not a number, and the system stops being a metagame and starts being a context.",
      "_enriched": true
    },
    {
      "type": "p",
      "text": "The second principle is reversibility. Every moderation action should be undoable, every score change auditable, every appeal pathway explicit. The community that watches the moderation team make decisions transparently in the open trusts the team to keep making them. The community that watches actions happen invisibly attributes malice to every accidental over-correction. Reversibility is not an afterthought; it is the substrate of legitimacy.",
      "_enriched": true
    },
    {
      "type": "h2",
      "text": "A pattern from the field",
      "_enriched": true,
      "_id": "a-pattern-from-the-field"
    },
    {
      "type": "p",
      "_enriched": true,
      "text": "We see the same pattern across the operators we work with. The teams who treat Auto-Raid Detection Without False Positives as an upstream design decision: encoded in the platform's defaults, surfaced in the operator dashboard, and audited as a standing line item in the quarterly review: see the downstream metrics move within 60-90 days. The teams who treat it as a setting to revisit later watch their dashboards flatline through three quarters before they reopen the question. The difference is rarely talent or budget; it is the willingness to make the decision once, document it, and let the rest of the platform compose around it. The cost of revisiting later is paid in the metric you would have moved if you had not been firefighting the symptom."
    },
    {
      "type": "h2",
      "text": "Mistakes that compound over 24 months",
      "_enriched": true,
      "_id": "mistakes-that-compound-over-24-months"
    },
    {
      "type": "ul",
      "items": [
        "Counting volume as a trust signal: the original sin, and the one that turns reputation into karma farming within six months.",
        "Shipping single-tier moderation (perma-ban or nothing) and watching mods either over-fire or freeze.",
        "Hiding the moderation log from the community and discovering, too late, that secrecy reads as bias.",
        "Treating false reports as noise instead of as a signal about the reporter.",
        "Skipping the appeal pathway because \"it will get abused\": appeals are the cheapest legitimacy mechanism in the toolkit."
      ],
      "_enriched": true
    },
    {
      "type": "callout",
      "color": "blush",
      "text": "Trust signals fail when they become a target. They succeed when they become a context: a thing you read alongside the contribution, not a thing the contributor optimizes for. Auto-Raid Detection Without False Positives is one of the design choices that decides which side of that line you land on.",
      "_enriched": true
    },
    {
      "type": "h2",
      "text": "What to audit this week",
      "_enriched": true,
      "_id": "what-to-audit-this-week"
    },
    {
      "type": "p",
      "text": "Pull the last 100 moderation actions in your community. Count how many were perma-bans. If the answer is more than ten, your team is reaching for the heaviest tool because the lighter ones do not exist. Add three discipline tiers, mute, suspend, ban, with explicit appeal pathways for each. Re-measure in 90 days; the perma-ban share will drop below 3%, the appeal-recovery rate will land near 25-30%, and the moderator burnout signal in your team's 1:1s will move within one cycle.",
      "_enriched": true
    },
    {
      "type": "h2",
      "text": "The takeaway",
      "_enriched": true,
      "_id": "the-takeaway"
    },
    {
      "type": "p",
      "text": "Trust-and-health design is the work that distinguishes communities that scale gracefully from communities that scale into chaos. Auto-Raid Detection Without False Positives is one of the small primitives that sits in that distinction. Ship the multi-factor signal. Ship the time-decay. Ship the appeal pathway. Ship the audit log. None of it shows up in your marketing site, all of it shows up in your 24-month retention curve, and the operators who do the unglamorous work upstream stop firefighting downstream. That is the trade.",
      "_enriched": true
    }
  ],
  "cta": {
    "title": "Ship raid detection that doesn't false-positive.",
    "body": "Dium's raid detection uses the four-signal combine with mod-alert vs auto-action thresholds.",
    "buttonText": "Try dium → ",
    "buttonHref": "../../"
  },
  "wordCount": 958,
  "updated": "2026-04-25",
  "url": "https://dium.io/blog/posts/auto-raid-detection-4-signals.html",
  "category": "https://dium.io/blog/category/trust-and-health/",
  "authorUrl": "https://dium.io/blog/author/dium-research/",
  "coverImage": "https://cdn.twc.sh/images/igcache/Auto%20Raid%20Detection%204%20Signals/1200_830/blog.jpg",
  "coverImageWide": "https://cdn.twc.sh/images/igcache/Auto%20Raid%20Detection%204%20Signals/1600_900/blog.jpg",
  "coverImageSmall": "https://cdn.twc.sh/images/igcache/Auto%20Raid%20Detection%204%20Signals/600_415/blog.jpg",
  "aeo": {
    "keyClaims": [
      "Catch raids with four combined signals: join-velocity spike + low-trust authors + repeated-content fingerprint + cross-thread pattern within 5 minutes.",
      "Each signal alone misfires. All four combined are reliable. The key is requiring 3 of 4 to trigger an auto-action; 2 of 4 only triggers a mod alert."
    ],
    "prospects": [
      "Trust and safety leads",
      "Community managers fighting moderation queue debt",
      "Marketers shipping AEO-citable content"
    ],
    "stats": [
      {
        "num": "4m",
        "label": "Read time"
      },
      {
        "num": "Trust and health",
        "label": "Category"
      }
    ]
  },
  "related": [
    {
      "slug": "aeo-for-community-platforms",
      "title": "Answer Engine Optimization for Community Platforms: the 9 Schema Patterns ChatGPT Actually Cites",
      "pillar": "P5",
      "pillarLabel": "Trust and health",
      "href": "/blog/posts/aeo-for-community-platforms.html"
    },
    {
      "slug": "moderation-queue-top-of-inbox",
      "title": "Moderation Queue That Actually Gets Cleared: the 'Top of Inbox' Redesign",
      "pillar": "P5",
      "pillarLabel": "Trust and health",
      "href": "/blog/posts/moderation-queue-top-of-inbox.html"
    },
    {
      "slug": "community-health-scorecard",
      "title": "The Community Health Scorecard: 12 Metrics, With Formulas",
      "pillar": "P5",
      "pillarLabel": "Trust and health",
      "href": "/blog/posts/community-health-scorecard.html"
    },
    {
      "slug": "three-suspension-states-not-one",
      "title": "Why Your Community Needs Three Suspension States, Not One",
      "pillar": "P5",
      "pillarLabel": "Trust and health",
      "href": "/blog/posts/three-suspension-states-not-one.html"
    }
  ]
}