攻击者可伪造打字时间特征,骗过AI作者身份检测系统。
On the Insecurity of Keystroke-Based AI Authorship Detection: Timing-Forgery Attacks Against Motor-Signal Verification
- 用真实人类打字数据生成虚假时间间隔,伪装成真人输入。
- 三种攻击方式均实现99.8%以上绕过率,检测器误判率超99.8%。
- 打字节奏无法证明文本原创性,需结合语义内容验证来源。
近期研究主张利用打字时间信号(特别是击键间隔变异系数δ)区分人工撰写与AI生成内容。本文证明此类防御机制易受两类实际攻击:一是人类转录大模型生成文本,保留真实运动信号;二是自动化代理从人类实测分布中采样击键间隔。基于SBU语料库13,000个会话及三种伪造变体(直方图采样、统计模仿、生成式LSTM),所有攻击在五种分类器上均实现≥99.8%的逃逸率。尽管检测器对全自动注入达到AUC=1.000,却将≥99.8%攻击样本判定为人类,平均置信度≥0.993。我们形式化证明:当仅观察时间特征时,特征与内容来源间的互信息为零(针对复制类攻击)。虽然创作与转录产生可区分的运动模式(Cohen's d=1.28),但二者δ值均高于检测阈值2-4倍,使区分失去安全意义。这些系统仅确认有人操作键盘,未验证其是否为原文作者。确保来源可信需构建写作过程与语义内容绑定的架构。
原文摘要 · Abstract (English)
Recent proposals advocate using keystroke timing signals, specifically the coefficient of variation ($δ$) of inter-keystroke intervals, to distinguish human-composed text from AI-generated content. We demonstrate that this class of defenses is insecure against two practical attack classes: the copy-type attack, in which a human transcribes LLM-generated text producing authentic motor signals, and timing-forgery attacks, in which automated agents sample inter-keystroke intervals from empirical human distributions. Using 13,000 sessions from the SBU corpus and three timing-forgery variants (histogram sampling, statistical impersonation, and generative LSTM), we show all attacks achieve $\ge$99.8% evasion rates against five classifiers. While detectors achieve AUC=1.000 against fully-automated injection, they classify $\ge$99.8% of attack samples as human with mean confidence $\ge$0.993. We formalize a non-identifiability result: when the detector observes only timing, the mutual information between features and content provenance is zero for copy-type attacks. Although composition and transcription produce statistically distinguishable motor patterns (Cohen's d=1.28), both yield $δ$ values 2-4x above detection thresholds, rendering the distinction security-irrelevant. These systems confirm a human operated the keyboard, but not whether that human originated the text. Securing provenance requires architectures that bind the writing process to semantic content.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。