发现顶会论文中存在被伪造的参考文献,且人工审稿难以察觉。
Phantom References: Hallucinated Citations That Survive Peer Review at Top-Tier Conferences
- 构建自动验证系统RefChecker,比对引用条目与多个学术数据库
- 2025年近5%的NeurIPS和USENIX安全会议论文含至少两个伪造引用
- 即使获奖论文也出现伪造引用,说明审稿难保引用真实
大型语言模型可生成包含未经支持主张的科学文本,导致幻觉进入学术记录。评估此类风险在技术陈述上困难且需专家判断,但引用提供了更可审计的表面:一个引用要么对应真实学术作品且作者匹配,要么不成立。本文采用保守定义,仅检测身份级失败(不存在的作品或作者列表严重不符),排除常规引用漂移(如会议/年份差异、发表状态更新、姓名微小变体)。为大规模审计引用,我们开发了RefChecker验证管道,将参考文献条目交叉比对多个文献数据库,并将无法解析的条目移交网络搜索复核。该方法应用于ICLR、ICML、NeurIPS及USENIX Security的已接受终稿论文。结果显示,伪造引用已进入学术档案。尽管引用层级错误率通常低于1%,但由于论文体量庞大,论文层级的失败仍显著:2025年约每20篇NeurIPS和USENIX Security论文中就有一篇包含至少两个可能的伪造学术引用。此外,我们观察到ChatGPT发布后多个会议中此类现象上升,部分论文甚至出现单篇5个以上错误引用,且获奖论文中也发现疑似伪造引用。这些结果表明,仅靠同行评审无法可靠保障引用完整性,但审计是可行的(在一次会议规模扫描中,每篇成本约0.04美元)。我们已开源RefChecker,供出版前进行常规、可复现的引用验证(https://github.com/markrussinovich/refchecker)。
原文摘要 · Abstract (English)
Large language models can generate polished scientific text that includes unsupported claims, allowing hallucinations to enter the archival record. Assessing this risk via technical statements is difficult and often requires expert judgment, but citations provide a more auditable surface: a reference either resolves to a real scholarly work with compatible authorship, or it does not. We measure citation hallucination in peer-reviewed proceedings using a conservative definition limited to identity-level failures: non-existent works and substantial author-list mismatches. We explicitly exclude ordinary bibliographic drift (e.g., venue/year differences, publication-status updates, minor name variants). To audit citations at scale, we build RefChecker, a verification pipeline that resolves bibliography entries against multiple bibliographic sources and escalates unresolved cases to web-search re-verification. We apply RefChecker to accepted camera-ready papers from ICLR, ICML, NeurIPS, and USENIX Security. Hallucinated citations have entered the archival record. While reference-level rates are usually below 1%, proceedings are large enough that paper-level failures are visible: in 2025, roughly one in twenty NeurIPS and USENIX Security papers contains at least two likely hallucinated academic-paper-like references under our strict definition. We also observe post-ChatGPT increases in several venues, including a tail of papers with 5+ failures in a single bibliography, and likely hallucinated citations even among award-winning papers. These results suggest peer review alone does not reliably enforce citation integrity, yet auditing is tractable (about 0.04$ per paper in one venue-scale scan). We open-source RefChecker for routine, reproducible citation verification before publication (https://github.com/markrussinovich/refchecker).
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。