Internationally Wrongful Acts in Cyberspace : Allocating State Responsibility for “Below the Threshold” Cyber Operations
Bibliographic record
Abstract
State cyber operations that occur during peacetime and fall below the threshold of prohibited uses of force have become commonplace. Over the past decade, it has been estimated that over a hundred states have acquired the technological capabilities to launch cyber operations against other states, causing damage to critical infrastructure, official databases, or governmental computer systems. Approximately thirty states have been accused of having conducted or supported such malicious cyber activity, a recent example being a series of alleged Russian cyber operations targeting organizations in Canada, the U.K., and the U.S. involved in the development and testing of potential COVID-19 vaccines. Moreover, since the beginning of the novel coronavirus pandemic, the World Health Organization (WHO) has reported a fivefold increase in cyber operations conducted against hospitals and other medical facilities around the world. In the absence of a cyber-specific treaty, the applicability of international law to cyberspace is widely dependent on customary international law. Therefore, by applying existing customary rules of state responsibility, the thesis examines how cyber operations may constitute internationally wrongful acts by violating state sovereignty and the principle on non-intervention into the internal or external affairs of another state. For state responsibility to arise, the conduct must be unlawful and attributable to a state. The majority of the official state positions and national cyber security strategies examined in the thesis affirm that state sovereignty is applicable in cyberspace. Cyber operations causing damage, injury, or a loss of functionality of another state’s governmental or private cyber infrastructure qualify as a violation of sovereignty. Furthermore, cyber operations that interfere with inherently governmental functions also amount to a violation of the target state’s sovereignty. Correspondingly, cyber operations constitute illegal interventions if they intervene in another state’s internal or external affairs by coercive means, such as altering electronic ballots to impact the outcome of another state’s election. The classified nature of state cyber activity makes it challenging to determine the existence of opino juris and state practice. Despite technical leaps and increasing public state attribution, holding states legally responsible for their malicious cyber operations remains difficult. No state has claimed responsibility for a cyber operation or tried to publicly justify their unlawful cyber activity. States seemingly launch cyber operations with impunity, along with the knowledge or suspicion that their behavior will not trigger a response, certainly not a kinetic one. States conducting or supporting cyber operations have consistently denied the allegations or remained silent on the matter. A greater predicament is the failure of the accusing states to condemn malicious cyber operations as violations of international law, instead labelling the activity as flagrant violations of international norms or harmful conduct.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.002 | 0.001 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.001 | 0.000 |
| Bibliometrics | 0.000 | 0.001 |
| Science and technology studies | 0.002 | 0.001 |
| Scholarly communication | 0.000 | 0.001 |
| Open science | 0.001 | 0.001 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".