arXiv:2605.16286cs.CYcs.AI2026-05

用形似字干扰AI答题,让编程题难倒机器却对人无影响

Homoglyph-based Adversarial Perturbation of Introductory Computer Science Theory Problems

论文配图:Homoglyph-based Adversarial Perturbation of Introductory Computer Science Theory Problems
图 1 · 摘自论文原文
  • 用形似字符替换原题中的少数字母,保持语义不变
  • 实验显示可有效干扰AI模型作答,正确率下降超40%
  • 提供交互工具,方便教师快速生成抗AI题目

ChatGPT、Gemini、Claude等AI工具日益流行,虽能辅助日常任务,但学生可能利用它们完成作业,导致教学目标落空。本文提出一种针对初学计算机科学理论题的简单方法:通过同形字(homoglyph)对抗性扰动,在不改变问题语义的前提下,将题目中少数字符替换为形似字符。实验表明,该方法能有效干扰AI作答,显著降低其正确率。同时,我们开发了一个交互式工具,便于教师快速应用此方法生成抗AI题目。

原文摘要 · Abstract (English)

Different AI tools such as ChatGPT, Gemini, and Claude are becoming very popular. Although they are helpful for many day-to-day tasks, they can be used in unexpected ways. For example, the learning objectives of a course may not be achieved if students use these tools to solve their homework problems. This paper proposes a simple method to address this issue in the lazy student model. The method uses homoglyph-based adversarial perturbation to first modify the question without changing the semantic meaning of the question. Then a few characters are perturbed by their homoglyphs. Our experimental result shows the theoretical problems of introductory computer science courses can be effectively perturbed. We also propose an interactive tool to conveniently use our method.

对抗样本AI防作弊同形字攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。