SLOW BURN: Subversion and Escalation in Cyber Conflict and Covert Action
Bibliographic record
Abstract
This thesis argues that the low intensity of cyber conflict reflects the fact that cyber operations have been primarily useful as means of subversion rather than warfare. Established wisdom that conceives of cyber conflict as a novel form of warfare defined by its speed the escalatory properties of cyber weapons. In practice, it has been marked by persistently low intensity and escalation has not occurred. This mismatch between theory and practice presents a puzzle. Subversion, in contrast, is a slow-burning and low intensity alternative to the use of force that is strategically attractive but operationally limited in effectiveness. It is strategically attractive because it promises to exert influence over competitors at lower costs and risks compared to force projection. These advantages are the result of its indirect and covert mechanism of action, which secretly undermines and manipulates an adversary’s own capabilities to produce detrimental effects against the former and erode its capacity to resist. However, this mechanism comes with three inherent constraints that limits effectiveness: subversion is slow, the intensity of effects is limited and it is unreliable. The strategic role and operational constraints of subversion explain the low intensity of cyber conflict. Cyber operations target new technologies but rely on the same operational mechanism of exploiting vulnerabilities in secret—hence they are expected to face analogous constraints. The thesis develops a grounded theory based on a structured focused comparison of a historical and contemporary case of subversion. The cases chosen are the Soviet campaign to suppress the Prague Spring and the Russian campaign to suppress the Euromaidan movement in Ukraine 2013-2018. These cases are most-similar except for the technology used. This comparison confirms expectations, showing that technological change has not altered the quality of subversion. Counterintuitively, however, the analysis reveals the operational constraints of cyber operations reinforce rather than reform its slow-burning and low intensity character. Contrary to prevailing threat perception of critical infrastructure strikes, cyber operations prove slower, more expensive and less effective than traditional sabotage operations.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.004 | 0.006 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.001 |
| Bibliometrics | 0.003 | 0.002 |
| Science and technology studies | 0.004 | 0.036 |
| Scholarly communication | 0.008 | 0.010 |
| Open science | 0.001 | 0.005 |
| Research integrity | 0.002 | 0.004 |
| Insufficient payload (model declined to judge) | 0.004 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".