THIS EXPLANATION
THE ROOM
MIL·37 Military, Conflict & Strategic Studies 6 MIN · 8 STATIONS

Strategic deception

A Socratic walk-through of strategic deception — reasoned out one step at a time, not lectured.

abcdefgh
a

The question we started with

THE QUESTION #

Why can gathering more independent confirmations of an enemy's plan leave you more certain of a lie?

The rule looks unimpeachable. One source might be wrong, or lying, or repeating gossip; but when an agent's report, an aerial photograph and an intercepted signal all say the same thing, the coincidence is too much to be accident. Yet the most successful deceptions in military history did not defeat that rule — they were built out of it, and the victims were not credulous. They were careful people applying a sound method to a supply of evidence that had been arranged for them.

b

Reasoning it through

REASONING #

Why does corroboration work at all, when it works? Put it in odds. You hold some prior belief about where the attack will fall; each piece of evidence multiplies those odds by a factor — how much likelier that evidence would be if the hypothesis were true than if it were false. Suppose a report is four times likelier under the true hypothesis than under the false one. Five such reports multiply your odds by four to the fifth power: a factor of 1,024. That is why analysts feel a step-change when the third and fourth confirmations land.

Now look at the fine print, because it is doing all the work. That multiplication is valid only if the reports are independent given the hypothesis — if the reasons any one of them might be wrong have nothing to do with the reasons any other might be wrong. And here is the thing worth stopping on: independence is a fact about a channel's causal history, not about your organisation chart. Three agencies filing three reports look independent on your side of the desk. If one person told all three, it is one report wearing three coats, and its likelihood ratio is four, not 1,024. The felt confidence has been multiplied by 256 without a scrap of new information arriving.

So a deception planner's real task is not forging convincing individual items. It is manufacturing correlation while preserving the appearance of independence. Take the strongest historical case: if a counter-intelligence service has quietly turned essentially every agent an adversary runs in a country, then that adversary's headquarters receives many agent reports, from separately recruited people who do not know each other, all sincerely filed — and every one of them written by the same controller. Add staged movements the adversary photographs for himself and radio traffic he intercepts himself, and the most trusted category of all, evidence you obtained rather than were given, becomes the most thoroughly owned.

There is a second engine, and it is what turns a lie into a certainty rather than a suspicion. The story that costs least to install is the one the target already half-believes; reinforcing an existing expectation is far cheaper than replacing it. And once the target begins to act, the deceiver can watch which feeds produced movement and press on those. That closes a loop: the target's own response reveals which channels the target trusts, and the deceiver feeds those harder. The evidence is being tuned, in something close to real time, by the confidence it is producing.

The perverse conclusion follows. Collecting more does not straightforwardly help, because each new channel is one more that can be corrupted, while the analyst's certainty grows with the number of agreeing reports rather than with the number of genuinely separate causes behind them.

Is there a defence? The standard one is to grade a report not by its content or its confidence, but by how expensive it would be for the adversary to fabricate that particular channel — a measurement he does not know you can make, an observation he cannot stage, a source he does not know he has lost. It is sound in principle and thin in practice: you cannot verify from inside that a channel is uncompromised, and after the fact every successful deception looks obvious in a way it never was at the time.

c

The analogy

THE ANALOGY #
THE FIGURE

You collect three quotes for a repair from three firms with different names, different offices, and different letterheads, and all three come in at the same high figure. You take the agreement as evidence of what the work costs. The three firms are owned by the same holding company.

WHERE IT BREAKS DOWN

ownership is a matter of public record you could go and look up, whereas the corresponding fact here is being actively concealed by a professional — and a serious deceiver will also arrange for one genuinely unconnected quote to agree, so no examination of the quotes themselves can settle the question.

d

Clarifying the model

THE MODEL #

The first correction is the important one: corroboration is not evidence of truth. It is evidence of correlation, and truth is only one of the things that produces correlation. A shared cause produces it just as well, and a deliberate shared cause produces it better, because it can be designed to be tidy in exactly the way real evidence rarely is.

The second is that nothing here requires a bad source. Each report may be individually accurate: the turned agent really does report what he was told, the photograph really does show what was there, the intercept really was sent. Every item survives scrutiny; it is the rule for combining them that fails. That is why the failure is invisible to the checks a careful organisation actually runs.

It is worth separating this from two neighbouring problems. It is not that two competent analysts read the same evidence differently — that is a matter of priors. Nor is it that correct information cannot be acted on without exposing how it was obtained. Here the analysts agree, the information is usable, and the collection system is working exactly as designed. That is what makes it dangerous.

e

A picture of it

THE PICTURE #
Strategic deception
Strategic deception Start at the rounded terminal at the top: a single plan, shaped in the hexagon into one story issued down three routes. The three slanted boxes are what actually reaches you, and they arrive separately, which is the whole trick -- the circular junction is the only place they meet, and by then they look like three findings. At the diamond everything turns on one question, and both branches are labelled: count the agreeing reports and you get the left-hand outcome, trace each route back to its origin and you get the right-hand one. The dashed arrow is the feedback loop -- your response tells the planner which channel you trust, so the next round of evidence is tuned to it. {"generator":"mermaid-svg-renderer@3.2.1","source":"../Socrates/.diagram-cache/_src/strategic-deception.md","sourceIndex":1,"sourceLine":4,"sourceHash":"b787b03b0ebee0a77e6f605e25addd4e89c5b1c32cfc3563a3953535621c4018","diagramType":"flowchart-v2","layoutVariant":"source","repairedDuplicateIds":[],"motion":"entrance-with-reduced-motion-fallback","presentation":"editorial","attempt":1,"viewBox":{"x":0,"y":0,"width":888,"height":1191},"qa":{"passed":true,"findings":[]}} No, the reports arecounted Yes, to a shared origin deceiver sees which feedmoved you Deception plan One story, three mouths Agent report Movement observed Signal intercepted Routes converge Analyst's file Are the routes traced back? Certain of a lie One report, not three Force committed elsewhere
KINDSsourceprocessdecisionriskoutcomeconnector

How to readStart at the rounded terminal at the top: a single plan, shaped in the hexagon into one story issued down three routes. The three slanted boxes are what actually reaches you, and they arrive separately, which is the whole trick — the circular junction is the only place they meet, and by then they look like three findings. At the diamond everything turns on one question, and both branches are labelled: count the agreeing reports and you get the left-hand outcome, trace each route back to its origin and you get the right-hand one. The dashed arrow is the feedback loop — your response tells the planner which channel you trust, so the next round of evidence is tuned to it.

f

What became clearer

WHAT CLEARED #
WHAT CLEARED

Corroboration multiplies confidence only in proportion to how separate the causes behind the reports are, and separateness is a property of the world, not of the filing system. A deception manufactures agreement while hiding the shared cause, and it works on careful people because it defeats the aggregation rule rather than any individual judgement. Once it is partly believed, the target's own reactions steer the next round of evidence — which is why the certainty grows exactly as the information stops arriving.

g

Where to go next

ONWARD #
  • How the same failure appears far from intelligence work, wherever many apparently separate sources trace back to one wire service, one dataset, or one original study.
h

Key terms

TERMS #
TermWhat it means
Likelihood ratiohow much likelier a piece of evidence is if a hypothesis is true than if it is false; the factor by which one report should move your odds.
Conditional independencethe condition, required for likelihood ratios to multiply, that the reasons any one report might be wrong are unrelated to the reasons any other might be.
Channelthe route by which a report reached you, as distinct from its content; what a deception has to own, and what a defence has to price.

Every term the collection defines is gathered in the glossary.

Nearby on the shelf

4