顶会论文分配系统可被合谋者利用文本匹配漏洞,绕过投票机制操控评审结果。
Vulnerability of Text-Matching in ML/AI Conference Reviewer Assignments to Collusions
- 利用论文与过往发表物的文本相似性匹配机制,合谋者可诱导系统将目标论文分配给指定审稿人。
- 即使无投票操纵,合谋团队仍可通过文本相似性实现精准操控,成功率超过80%。
- 适用于关注学术评审公平性的研究人员、会议组织者及安全机制设计者。
顶级机器学习与人工智能会议的同行评审中,审稿人通过自动化算法分配。该算法主要考虑两个因素:(1) 审稿人对论文的投稿意愿(投标);(2) 基于其过去发表论文与投稿稿件之间文本相似性的领域专长。当前面临的主要挑战是合谋圈的存在——研究者串通一气,互相评审,无论质量如何均给予正面评价。现有反合谋措施多集中于防范投标操纵,普遍假设文本相似性模块是安全的。本文揭示,即便没有投标行为,合谋的作者与审稿人仍能利用顶级会议所采用的基于机器学习的文本匹配机制,将目标论文成功分配给指定审稿人。我们进一步指出该系统的具体脆弱点,并提出增强鲁棒性的建议。
原文摘要 · Abstract (English)
In the peer review process of top-tier machine learning (ML) and artificial intelligence (AI) conferences, reviewers are assigned to papers through automated methods. These assignment algorithms consider two main factors: (1) reviewers' expressed interests indicated by their bids for papers, and (2) reviewers' domain expertise inferred from the similarity between the text of their previously published papers and the submitted manuscripts. A significant challenge these conferences face is the existence of collusion rings, where groups of researchers manipulate the assignment process to review each other's papers, providing positive evaluations regardless of their actual quality. Most efforts to combat collusion rings have focused on preventing bid manipulation, under the assumption that the text similarity component is secure. In this paper, we demonstrate that even in the absence of bidding, colluding reviewers and authors can exploit the machine learning based text-matching component of reviewer assignment used at top ML/AI venues to get assigned their target paper. We also highlight specific vulnerabilities within this system and offer suggestions to enhance its robustness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。