
Ransomware groups pose a threat to both the economy and national security, yet little is known about their structural dynamics. This study analyses the Conti group using leaked Jabber encrypted instant messaging chat data (similar to Messenger) and Relational Event Models to examine how preferential attachment and triadic closure mechanisms shape its communication network. Findings show Conti prioritised efficiency through centralisation but mitigated risks via compartmentalisation, creating a hybrid structure that balances speed and secrecy. This adaptive approach enhances both effectiveness and resilience. The research provides new insights into the evolution of ransomware groups and suggests that disruption strategies should target internal cohesion rather than external infrastructure.
Personal network size is a versatile and fundamental structural network measure, capturing the total number of personal connections or specific subgroups within an individual’s social environment. In standard sociological methods, such as surveys, personal network size is often indirectly inferred from name generators, which are used to list alters from the respondents’ personal networks. Implicitly, a higher count of named alters is assumed to indicate a larger personal network. We explicitly test this common assumptionand address this imprecise association between network size and number of listed alters by comparing the results from two very distinct approaches to measuring personal network size: alter counts derived from name generators and size estimates obtained from the network scale-up method (NSUM). Using survey data from over 300 participants in Spain, we compute these two independent network measures for the same respondents and assess the strength, significance and robustness of their association, including potential question-order effects on personal network size. Our analyses conclude that the alter counts from name generators primarily reflect participants’ response behaviour and task constraints rather than the underlying personal network size. Finally, our findings highlight critical limitations in the use of free name generators as proxies for personal network size.
Predicting churn in dynamic groups remains a challenge in the field of social network analysis and group behavior modeling. While previous research has focused predominantly on static networks or individual-level predictors, the complex interplay of group dynamics over time is still underexplored. This work proposes a multidimensional framework for analyzing and predicting member churn in dynamic groups by integrating structural and temporal dimensions. Drawing on theories from social networks, group cohesion, and organizational behavior, we examine how fluctuations in individual behavior, group stability and performance, as well as network characteristics relate to member retention and change. We apply key concepts such as individual engagement, group stability, and performance using a comprehensive set of features derived from a dataset of the massively multiplayer online game (MMOG) Travian, which covers over 4700 groups (alliances) and 18,000 players, providing a rich setting to observe dynamic group processes. By applying machine learning models, we demonstrate the predictive value of these multidimensional features, achieving robust performance across various classifiers. This study contributes to the theoretical understanding of churn as an emergent group-level phenomenon and offers practical insights for designing interventions in online communities and team-based environments.
Why do some social ties endure while others dissolve? Homophily research typically treats similarity as a single mechanism, conflating processes of tie formation and persistence. I develop a framework based on attribute observability, distinguishing between observable characteristics that guide formation under uncertainty and interaction-revealed attributes that shape tie retention. Using three-wave longitudinal friendship network data and Stochastic Actor-Oriented Models, I decompose homophily into creation and endowment effects across 28 grade networks. Observable attributes (gender, ethnicity) show strong formation effects but little persistence advantage. Interaction-revealed attributes show weaker and less precise patterns. These findings demonstrate that homophily is an information-conditional process and that standard models obscure its underlying mechanisms.
This work investigates the co-evolution of cooperation and conflict (violence) among organized crime groups. Using actor-oriented relational event models, we analyze 179 group cooperation and 141 group conflict events from a UK police force (2004–2015). To estimate undirected relational event models for cooperation, we develop a multiple imputation procedure. Cooperation often recurs and follows transitive patterns, likely reducing partner-selection risk. Conflict is characterized by repeated victimization, outdegree activity, and event-level reciprocity. Embeddedness in cooperative triads reduces conflict, as groups avoid losing valuable partners. We find evidence of differential status conflict-wise. Cooperation and conflict tend to be localized.
Triad census is a popular static analysis technique that summarizes topology and triadic behavior in a network. However, traditional static methods for counting triad motifs do not scale for dynamic analysis on large event logs of digital trace data increasingly used in computational social science. Further, tracking triad evolution over time can provide insights into behavioral elements such as information brokerage not captured in static analysis. We propose Dynamic Triad Census (DTC), a dynamic programming algorithm to calculate the triad census procedure efficiently over time. Formal analyses of the correctness and computational complexity of the proposed method are supported by numerical experiments that demonstrate its accuracy and improved efficiency over existing static counting methods. We show how efficient computation and storage of census motifs enables dynamic network analysis of triad transition and brokerage behavior in longitudinal networks by using motifs as covariates in other dynamic techniques and as their own objects of inquiry.
Access to premium buyers represents a critical yet unevenly distributed source of advantage in global supply chains, reflecting firms’ ability to secure valuable exchange relationships rather than merely achieve superior performance. However, extant research offers limited insight into how firms’ network structures and networking behaviors jointly shape such access as a relationally embedded outcome. This study addresses this gap by analyzing contractual transaction data of 36,124 transactions from 385 Vietnamese cashew exporters to 867 international buyers over a 12-month period. Using Necessary Condition Analysis (NCA) and fuzzy-set Qualitative Comparative Analysis (fsQCA), the study examines the conditions under which firms achieve high revenue and high spending share from premium buyers. While NCA provides limited support for individual necessary conditions, fsQCA reveals four robust configurations explaining high access across outcomes, along with two additional pathways for spending share. These results highlight that access to premium buyers arises from the interplay of network structure and agency, characterized by equifinality and compensatory effects. By reframing premium buyer access as a relational resource and adopting a configurational analytical approach, this study advances theoretical understanding of interorganizational networks and offers practical insights for firms seeking to strengthen their positions in global buyer–seller systems.
It is common in both the popular imagination and in scientific research to treat humans as members of distinctive ethnolinguistic groups, populations, or races with different histories. How to best model human diversity has reemerged as a significant issue owing to the prominence of ancient genetic evidence now being used to study the human past. The island of New Guinea, where people speak more than 800 languages or dialects, has served as a test case of competing models of how human biocultural diversity is created and maintained. We present a new test of the degree to which language and material cultural patterning align, using a sample of elaborately decorated bone daggers from museum collections spanning large areas of New Guinea and its surrounds. We compare technological and stylistic variability in these daggers to language as well as a large ethnographically modelled social network. We find that how people socially engage with each other is more predictive of how they make daggers than what language they speak, particularly for daggers dating to the later 19th and early 20th century. While it is often assumed that ancient communities were relatively socially isolated from one another, we argue that there is no reason to assume this default hypothesis about ancient social life. Empirical studies of material culture, and emerging archaeological and genetic understanding of the New Guinean past suggests that language diversity there was developed and maintained within structured social networks linking communities to one another.
We introduce VINA (Visual Interface for Network Assessment), an open-source software tool designed to collect quantitative social network data in an intuitive, engaging, and ethically responsible manner. VINA is developed to remain clear and scalable on small screens, regardless of the number of reported social relations. As a result, it is the first graphical interface that allows researchers to collect cognitive social structures (i.e., perceptions of alter-alter relationships in complete networks) on smartphones. VINA also enables researchers to dynamically integrate participants' self-reported names into the surveys of other participants in real time, eliminating the need to gather name lists prior to informed consent and thereby addressing key ethical concerns. We outline the motivation behind VINA, describe its development process, and highlight its benefits and novel features for social network research. Using large-scale school data collected with VINA (N = 1341), we further examine how design choices influence data quality. Specifically, we assess how completion time varies with network size, how alphabetical name order in name generators affects peer nominations, and the extent to which cognitive social structures correspond meaningfully to self-reported networks. We conclude by discussing practical lessons from this first large-scale deployment, along with directions for future development. Overall, VINA has the potential to make the collection of complete network data more convenient for researchers and more engaging for participants. Moreover, we believe VINA will significantly reduce the practical barriers that have long limited the collection of cognitive social structure data.
We investigate networks represented as hypergraphs and propose a generalizable statistical framework that captures the relationship between their node degrees and hyperedge sizes. We test the presence of such an association in 36 empirical hypergraphs from diverse domains, with a focus on social networks. Using nested model comparisons, we classify each such relationship as linear, monotonic, non-monotonic, or absent. Results reveal that true absence of this relationship is rare, while nearly half exhibit non-monotonic patterns. We evaluate three correlation measures of this association and find that Pearson correlation best aligns with relationship direction. We also consider three ways to capture this relationship (called: bipartite, node-centric or edge-centric) and show that the bipartite one yields most consistent results. Beyond providing empirical evidence, our results lay conceptual groundwork for linking static hypergraph structure to potential dynamical processes, positioning degree-size correlations as a structural bridge between hypergraph topology and function.
This study examines how personal networks respond to two contrasting forms of social experiences: disruptive life events and participation in civic organizations. We theorize that acquaintance networks operate as semi-stable systems, buffering short-term shocks but expanding durably through structured, repeated exposure in organizational settings. Using two waves of nationally representative panel data from Chile, we measure the network size with the Network Scale-Up Method. Our difference-in-differences strategy shows that most life events have limited effects, with only marital reconciliation producing modest increases. In contrast, active participation, especially in educational, labor, political, and sports groups, substantially expands networks, and the effects hold across robustness checks. These findings point to a dual role of personal networks: maintaining stability under short-term shocks while enabling expansion through sustained organizational participation.
This study assesses the stability of egocentric social networks in children aged 5-12, focusing on variation across microsystems such as family, school, and leisure, and examining how relationship resources and burdens are associated with stability. The study included 156 children (59% girls) using a structured interview (SoBeKi-R) over two sessions 5-63 days apart. It evaluated the stability of named individuals (personal stability) and the stability of relationship characteristics (functional stability) within these networks and examined how perceived resources and burdens relate to stability. Results indicated that familial relationships were significantly more stable (92%) compared to extrafamilial relationships (61%). Functional stability showed a differentiated pattern: burdens were more stable in family contexts, whereas resources were relatively more stable in extrafamilial settings, suggesting that children may selectively maintain or adjust social relationships in extrafamilial contexts in line with their social needs. Stability in extrafamilial relationships decreased with increasing time between assessments, whereas familial relationships remained largely stable across varying intervals. These findings highlight the complex interplay between stable and evolving relationships in children's social networks, particularly the distinction between personal and functional stability, suggesting that while stable relationships provide important support, changes in relationships may also contribute to the development and maintenance of social resources.
The basic premise of the security/efficiency trade-off stipulates that criminal networks either prioritize their ability to collaborate efficiently, their ability to protect themselves from risks of legal sanctions, or make some compromise between the two. Although the security/efficiency trade-off is an empirical question, prior studies frequently describe conspirators as "collaborators" who "collaborate" together to perpetrate racketeering. Taking this analogy one step further, only one study has tested whether criminal networks resemble types of collaborative networks in non-criminal domains, such as science, industry, and the arts. In this study, I test the hypothesis that criminal networks prioritize their ability to communicate over their security concerns and, in doing so, resemble these other types of collaborative networks. To do so, I conduct a meta-analysis of eight criminal networks reconstructed from wiretap surveillance of discreet communications. I find that none of them meet all three criteria (triadic closure, assortativity, centralization) that defines collaboration in other types of social networks. Findings therefore suggest that this model does not fully generalize to the discreet communications of the criminal networks that comprise this sample. It is unclear, however, if that is because discreet communication is qualitatively different from other types of collaboration, if groups of conspirators make trade-offs that alter their communication structure, or if non-random sample bias that threatens the validity and reliability of police surveillance distorts the findings.
Everyday mobility data have become a central resource for studying neighborhoods, yet most research still treats mobility networks as collections of dyadic ties rather than complex systems with higher-order structure. This study investigates whether triadic closure operates causally in neighborhood mobility networks: when two neighborhoods (B and C) increasingly share a common destination (A), do direct mobility flows between B and C strengthen? Using longitudinal smartphone traces from SafeGraph, we construct neighborhood-to-neighborhood mobility networks for U.S. census tracts and define triads in which two "alter" tracts jointly visit a focal tract that experiences the opening of a large new employer. We leverage these employer openings as an instrumental variable for exogenous increases in joint visits to A and estimate the local average treatment effect of mutual-destination mobility on subsequent B to C flows, controlling for lagged mobility. Contrary to canonical expectations of triadic closure, we find strong evidence of triadic repulsion: exogenous increases in joint visits to A reduce direct mobility between B and C, with particularly large negative effects for "bridged" dyads whose shortest geodesic paths run through A and null effects for non-bridged dyads. These results suggest that when everyday mobility flows converge on shared hubs, they consolidate activity rather than knitting alters together, challenging standard closure-based intuitions in network theory and underscoring the importance of modeling everyday mobility networks as complex, higher-order structures.
Often motivated by concerns about contamination of control subjects, stepped wedge cluster-randomized trial designs assign interventions to distinct clusters (e.g., hospitals) and protect against confounding by randomizing the timing of intervention delivery. However, when trial units are embedded in professional networks that span clusters, such designs cannot prevent spillover. In this study, we use longitudinal cluster-randomized trial data and contemporaneous physician networks to estimate the direct, indirect and direct-indirect interaction effects of an advance care planning (ACP) intervention. The direct effect reflects the intervention's impact in a counterfactual world absent contamination, the indirect effect captures spillover to control subjects, and the interaction effect assesses whether spillover modifies the intervention's effect, a phenomenon known as contamination. In addition, we exploit the staggered nature of the stepped-wedge design to test whether intervened peers impact the sustainment of the intervention over follow-up and, specifically, of whether spillover reinforces or attenuates the intervention. On a national provider organization's physician network, we find that accounting for spillover and contamination had a profound effect on the direct effect of the intervention. We also found evidence that physician spillover effects reinforced the intervention over followup. These findings suggest that the diffusion of the intervention's effect through the network was primarily driven by a large physician spillover effect that modified the direct effect at the time of intervention and subsequently over follow-up.
We study experimentally the challenges of network coordination in groups that share goals but are subject to local and noisy information. We show that consensus on the correct action declines in larger networks, networks with fewer local connections, and asymmetric networks, where misinformation forms small stubborn pockets of incorrect beliefs. Groups with more exploratory and adaptive participants perform best. Our findings explain persistent societal misconceptions such as vaccine hesitancy or climate denial. They highlight the importance of well-informed, highly connected networks for improving collective decision-making in situations such as committee deliberations, team projects and public goods.
A common interest in social network analysis is to understand the social processes that contribute to network change. While a variety of longitudinal network models are available, it remains unclear how to analyze cases where the estimand differs from the model coefficients, for instance, when the model predicts conditional tie probabilities, but the research question concerns network segregation. To address this gap, this paper introduces two complementary frameworks that apply the micro effects on macro structure approach to discrete longitudinal network data. The immediate effect model (IEM) adapts the Kitagawa-Oaxaca-Blinder decomposition to quantify how the change in micro-level mechanisms between two time points explain the change in macro-level outcomes. The cumulative effect model (CEM) employs the g-formula to capture the long-term impacts of changes in micro-level mechanisms across multiple time points on certain macro-level outcomes. The models can flexibly accommodate varying numbers of time points, different longitudinal network models, various counterfactual designs, and the existence of time-varying covariates. The paper presents the estimands, the identifying equations and assumptions, as well as an estimation algorithm. I also demonstrate the methods with an empirical example that use both models to study whether and how income decline explains the net migration loss of core Rust Belt states to other U.S. states.
Comparative case studies are widely used to answer causal questions in the social sciences, yet applying them to network settings presents a core challenge: how do we define a suitable comparison node when all nodes are structurally interdependent? We introduce an embedding-based synthetic control (EB-SC) framework that combines nonparametric causal inference with graph neural networks to construct plausible counterfactuals for causal network analysis. A graph convolutional autoencoder produces low-dimensional embeddings that encode not only each node’s attributes but also its changing local connectivity, enabling us to construct a synthetic node that mimics the treated node’s trajectory in the network. We demonstrate the robustness of EB-SC in the presence of network spillover through Monte Carlo exercises and a case study of the closure of the University of Arizona during COVID-19 and its effect on organizational resilience in urban neighborhoods. We found that a network-ignorant comparison underestimated the effect, while EB-SC produced estimates robust to network spillover.