Military operations, public governance, and strategic decision-making increasingly face a threat that conventional means struggle to detect. A kinetic attack leaves destruction. A cyberattack sooner or later reveals itself through disruption, data exfiltration, or infrastructure failure. A cognitive attack is different: its aim is that the targeted system should not recognise the attack as an attack, but should experience the imposed change as the natural evolution of its own views.
The new article “A Structural Model of the Human Agent in Cognitive Warfare” continues the research line opened by the same Ukrainian scholars in “Ontological Foundations of Cognitive Warfare”, prepared for the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE). If the first study explained cognitive warfare at the level of socio-technical systems – states, organisations, alliances, and institutions – the new article takes the next step: it shows how such attacks operate at the level of the human agent, that is, the person who makes decisions within these systems.
The central idea of the study is that cognitive warfare is directed not only at what a person thinks, but at how they think. Modern defensive systems work well against information threats: they detect disinformation, verify facts, counter hostile narratives, and analyse data flows. All these are instruments of information warfare: they operate at the level of content, at the level of what is being communicated. Work with narratives is often equated with cognitive warfare; yet narrative remains an element of information confrontation. Cognitive warfare begins one level deeper – where the target is not the message and not the narrative, but the very structure through which a person perceives, evaluates, and makes decisions. That structure cannot be refuted by fact-checking.
The authors propose that the human being should be understood not as a unified “node” in a network, but as a complex multiplex structure. The same officer, analyst, or leader acts in different contexts: at headquarters, within a professional community, in a political environment, and among family or friends. In each context, different ways of assessing data, different levels of responsibility, and different regimes of trust and risk are activated. Yet all this remains one person because of deeper stable structures – personal invariants. These are values, habits of judgement, models of the future, and ways of interpreting the world that allow a person to change without losing inner integrity.
A cognitive attack exploits the natural asymmetries of this structure. Cognitive biases are treated not as defects of thought, but as normal mechanisms of rapid information processing. Under ordinary conditions, they help decisions to be made under pressure, with limited time and incomplete data. But an adversary may direct influence precisely into such a “zone of reduced resistance”, gradually widening the gap between reality and the way it is interpreted. At a certain point, the person is no longer merely mistaken in a particular judgement: the connection between the contexts in which they act – the coherence of their own decisions across different roles – begins to break down, and the very integrity of decision-making comes under threat. The study distinguishes three structurally different forms of such influence: from disorientation, to the gradual rewriting of the criteria of judgement themselves, and finally to the destruction of the stable core of personality.
The systemic conclusion of the article is especially important. Institutions, headquarters, organisations, and states are held together not only by procedures and infrastructure. Their coherence depends on the compatibility of the invariants of key people – on the extent to which they share basic orientations, trust, criteria of acceptable risk, and an understanding of the final aim. If a cognitive attack destroys this compatibility among several structurally significant participants, a system may begin to disintegrate even while its formal features remain unchanged: the same posts, the same procedures, the same channels of communication – but the capacity to reach a common decision has been lost.
This is why the authors propose a transition from the defence of content to topological defence. Its task is to protect not individual messages, but the structure of decision-making: the connections between contexts, the coherence of action, the compatibility of key orientations, and the points of crystallisation – the key people and relations around which an organisation has formed into a whole. Such defence does not replace information security, cybersecurity, or counter-disinformation. It adds a new layer: the early detection of cognitive decoherence before it manifests itself as institutional failure. In its most advanced form, it also permits the logic of attack to be turned back against the attacker: the adversary’s confidence in the picture imposed upon them becomes an instrument of their own disintegration.
The practical result of the study is that cognitive security must include early-warning circuits. Changes in coordination, divergence of assessments, growing mutual inconsistency, and the loss of the capacity to interpret data within a shared purpose may all become indicators of an approaching cognitive vulnerability within the system. At the same time, the authors emphasise that this is not about surveillance of people’s thoughts or psychometric profiling of personnel. The object of analysis should be the structural coherence of decision-making processes, not the private life of the individual.
The mathematical apparatus of the model is developed in a separate mathematical companion paper, where the human agent is described as a multiplex structure stabilised by personal invariants, and cognitive influence is formalised as a perturbation of the connection between contexts. This makes it possible to connect the philosophical depth of the problem with a formal language suitable for the further development of metrics, indicators, and early-warning systems.
Much of the existing literature describes cognitive attacks only after their consequences have become visible. A unified formalism allows a more demanding question to be asked: which structures are vulnerable, which are approaching failure, and which are likely to hold. The vulnerability this model teaches us to recognise lies not in the message, but in the one who receives it.
