用纯展示修改就能骗过AI审稿,无需改数据或方法。
No Hidden Prompts Needed! You Can Game AI Peer Review with Presentation-Only Revisions

- 仅调整摘要、论述结构等展示内容,利用AI反馈迭代优化
- 攻击成功率75.1%,平均得分提升1.21分,效果显著
- 重构相关工作和讨论比修辞润色更有效,适合研究者警惕
随着AI生成评审从实验工具进入同行评审体系,主流关注集中在隐藏指令和提示注入等显式攻击。本文研究了一种更隐蔽且政策相关的失效模式:不添加隐藏文本、不进行提示注入,也不改动方法、实验、图表、公式、证明或数值结果。攻击者仅修改呈现层面内容,如摘要、贡献定位、相关工作、讨论与叙事结构。我们提出对抗性重包装:一种基于AI评审反馈的闭环攻击,仅在保持科学证据不变的前提下搜索最优呈现修改。在三个主流AI评审器上,该方法实现75.1%的攻击成功率和平均+1.21分的得分提升,效果非普通润色所致。分析显示,改变评审对论文的理解策略(如重置相关工作位置、扩展分析讨论)远优于表面修改(如局部润色、表格格式、算法框)。进一步揭示两大深层缺陷:一是AI评审更易被强调优势打动,却难被削弱弱点说服;二是会将‘看起来解决’误解为‘实际解决’,使未变证据被重新解读为更强贡献。这表明部署风险不仅来自恶意指令,更在于论文呈现本身成为可被优化的新靶点。我们发布无污染滚动基准与攻击框架,用于测试AI评审是否仍锚定科学内容。
原文摘要 · Abstract (English)
As AI-generated reviews move from experimental tools into peer-review infrastructure, most robustness concerns have focused on explicit attacks such as hidden instructions and prompt injection. We study a harder and more policy-relevant failure mode: no hidden text, no prompt injection, and no changes to methods, experiments, figures, equations, proofs, or numerical results. The attacker modifies only presentation-level content, such as the abstract, contribution framing, related work, discussion, and narrative structure. We introduce adversarial repackaging: a closed-loop attack that uses AI-reviewer feedback to search for presentation-level revisions while keeping the scientific evidence fixed. Across three mainstream AI reviewers, adversarial repackaging achieves a 75.1% attack success rate and a mean score gain of +1.21/10. The effect is not explained by ordinary prose polishing. We also reveal that strategies that change how the reviewer interprets the paper, such as related-work repositioning and analytical discussion expansion, substantially outperform surface edits such as local polishing, table formatting, and algorithm boxes. Our analysis reveals two deeper structural failure modes. First, AI reviewers are easier to impress than to convince: highlighting strengths reliably increases perceived merit, while attempts to dissolve weaknesses frequently backfire. Second, AI reviewers can confuse the appearance of addressing a limitation with actually resolving it, allowing unchanged evidence to be reinterpreted as stronger scientific contribution. These results show that the deployment risk is not only malicious hidden instructions, but the emergence of paper presentation itself as an optimization surface. We release a contamination-free rolling benchmark and attack framework for testing whether AI reviewers remain anchored to scientific content under presentation-only edits.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。