{"id":"b5efa4d2-4e8b-4120-8270-3c34bd2671da","arxiv_id":"1908.06173","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":3.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"A comprehensive historical survey of digital spam that distinguishes spam generated with AI and spam directed against AI systems.","lead":"This paper surveys the evolution of digital spam, from 1978 email spam to fake reviews, social bots, and AI-generated content. It frames modern and future threats as spam created with AI and spam aimed at attacking AI systems.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The paper's forward-looking claim rests on the assumption, admitted in §3.2, that AI proof-of-concepts will be abused at scale; Sections 4.1–4.2 offer no evidence of actual AI-spam campaigns.","rationale":"The reader's weakest assumption correctly identifies the load-bearing step: the paper's forward-looking AI-spam categories rely on proof-of-concept attacks becoming real large-scale campaigns. The attack is not manufactured; the paper explicitly concedes in §3.2 that there is no systematic evidence and that researchers operate on the assumption that new AI capabilities will be abused. Sections 4.1 and 4.2 provide no deployment data, only demonstrations. This does not invalidate the historical survey or the taxonomy as a conceptual framing, but it leaves the central predictive claim conditional. The reader's CONDITIONAL verdict is therefore appropriate, and my read does not move it. The proposed audit is a concrete way to test whether the PoC-to-scale assumption has actually held since publication.","tokens_in":13461,"tokens_out":6964,"duration_ms":72108,"concrete_test":"Conduct a post-publication audit: search threat-intelligence reports (e.g., FBI IC3, Sensity AI, Google/Meta transparency reports) and peer-reviewed case studies for documented large-scale spam or abuse campaigns since 2019 that use deepfake video/voice cloning or adversarial-perturbation techniques. If no such campaigns at a scale comparable to historical email or social-bot spam are found, the §3.2 assumption that proof-of-concept AI capabilities will be abused at scale is empirically unsupported, and the two new AI-spam categories lack their main predictive justification.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central forward-looking claim—that AI is creating two new spam categories, 'spamming with AI' and 'spamming into AI'—depends on the assumption that publicly demonstrated AI capabilities will be repurposed for large-scale abuse. The paper itself flags this in §3.2: 'Beyond anecdotal evidence, there is no systematic way to survey the state of AI-fueled spam bots and consequently their capabilities—researchers adjust their expectations based on advancements made public in AI technologies (with the assumptions that these will be abused by spammers with the right incentives and technical means), and based on proof-of-concept tools that are often originally created with other non-nefarious purposes in mind.' Sections 4.1 and 4.2 then build the categories exclusively from proof-of-concept demonstrations: Suwajanakorn et al. lip-sync, Thies et al. Face2Face, and Eykholt et al. adversarial stop signs. No evidence is offered that any of these techniques have been deployed in actual spam campaigns, and no economic model shows that they will be. If the PoC-to-scale transfer fails—because attack cost remains high, because countermeasures such as synthetic-media provenance or adversarial robustness catch up, or because bulk deception is not the dominant use—the empirical payoff of the claimed evolution is unsupported. The historical survey in Sections 2–3 stands on its own, but the two new categories are predictions rather than observations, and the §5 recommendation to 'design technology with abuse in mind' rests on a selected historical pattern that may not extrapolate.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper is a survey of the history of digital spam, from its origins in unsolicited email to modern forms such as web spam, opinion spam, and social-bot spam. It proposes a general definition of digital spam, presents a timeline and a taxonomy in Table 1 and Figure 1, reviews technical and regulatory countermeasures, and introduces two alleged new categories: 'spamming with AI' (using AI to generate deceptive content) and 'spamming into AI' (manipulating AI systems via poisoned training data or adversarial test inputs). The paper concludes with three recommendations: designing technology with abuse in mind, expecting an ongoing arms race, and using blockchain-style authentication to deter spam.","tokens_in":13720,"tokens_out":4083,"duration_ms":41992,"significance":"If the forward-looking parts are accepted, the paper usefully frames an emerging risk landscape: AI-based content generation and adversarial manipulation could plausibly evolve into new forms of large-scale abuse. The historical survey of email, web, and social spam is a competent synthesis of the literature, and the taxonomy is clear enough to be useful to a broad computing audience. The paper is honest in places about the speculative nature of its AI-spam scenario, and it gives concrete pointers to proof-of-concept systems. However, the central claim that AI spam is already an observable category is not empirically supported, and the conceptual extension of the word 'spam' to adversarial machine learning is not adequately justified. The historical sections stand on their own; the AI sections are better read as a risk assessment than as a documented evolution.","major_comments":[{"comment":"The paper presents 'AI spam' as an established category, but all supporting evidence is drawn from proof-of-concept demonstrations (Suwajanakorn et al., Thies et al., Eykholt et al.) rather than from actual spam campaigns. The paper itself concedes in Section 3.2 that 'there is no systematic way to survey the state of AI-fueled spam bots and consequently their capabilities.' Because the claimed successor to email and social-bot spam rests on the transfer from proofs-of-concept to real-world abuse, this is a load-bearing gap. The authors should either (i) relabel Sections 4.1 and 4.2, Table 1's 'Multimedia' row, and Figure 1's 'AI SPAM' milestone as speculative risk scenarios, or (ii) provide documented evidence of AI-generated content or adversarial manipulation being used in real spam campaigns.","section":"Section 4 (including Table 1 and Figure 1)"},{"comment":"The term 'spamming into AI' conflates spam with adversarial machine learning and data poisoning. The definition given in Section 1 emphasizes 'producing and injecting unsolicited, and/or undesired content aimed at steering the behavior of humans or the system itself.' Test-time adversarial perturbations, such as the modified stop sign of Eykholt et al., are not unsolicited messages in the traditional spam sense; they are crafted inputs to an existing system. Training-data poisoning is a security attack rather than a communicative nuisance. The authors should either broaden the definition of spam explicitly and give a principled justification, or differentiate AI-specific abuse (adversarial ML, data poisoning) from spam proper.","section":"Section 4.2"}],"minor_comments":[{"comment":"Several current-volume figures (e.g., 'Billions x day' for email, 'Millions x day' for instant messaging) are given without specific supporting citations; the cited reference [10] is a 1998 article and cannot substantiate present-day volume estimates. Please add explicit sources for each statistic or qualify the numbers as rough estimates.","section":"Table 1"},{"comment":"The paper states that the 1978 ARPANET message was sent to 'over 400 subscribers'; common accounts give the number as 397. Please verify the exact figure and adjust if necessary.","section":"Section 2.1"},{"comment":"The blockchain recommendation is plausible as a directional suggestion, but the main text does not address scalability, user adoption, or the cost of proof-of-work; the footnote on proof-of-work's debated feasibility is helpful, yet the main text would benefit from more balance.","section":"Section 5, recommendation 3"},{"comment":"There is a typo: 'STMP host' should be 'SMTP host'.","section":"Sidebar 'Detecting Spam Emails'"},{"comment":"The phrase 'we flashed out techniques' should likely be 'we fleshed out techniques'.","section":"Section 3.2"},{"comment":"In the provided version, some timeline labels overlap the plotted line; the published figure should be checked for legibility.","section":"Figure 1"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nQuick take: this is a competent and readable survey of spam's history, and its real value is the historical synthesis, not the crystal ball. The 'spamming with AI' versus 'spamming into AI' distinction is a genuinely handy organizing device, and it's likely to stick as vocabulary. But the paper is a review, not a research result, and the speculative sections are exactly that.\n\nWhat's good: Sections 2 and 3 give a fair, compact history of email spam, opinion spam, and social bots, with a sensible taxonomy and decent coverage of detection methods. The citations to classic work (Cranor & LaMacchia, Drucker et al., Jindal & Liu, Mukherjee et al.) are appropriate, and the author's own prior studies on bots are cited where they are actually the relevant source. The discussion of email spam as an arms race, and the note that much detection work is proprietary, is honest and useful.\n\nThe soft spots are mostly in the second half. The two new categories are built from proof-of-concept demonstrations (Face2Face, adversarial stop signs) with no evidence that any of these have been deployed in real spam campaigns. The paper itself admits in §3.2 that researchers are 'adjusting expectations' that public AI advances will be abused—that is an assumption, not a finding. The stress-test note is right not to overstate this; it doesn't sink the historical survey, but it means Sections 4.1–4.2 are agenda-setting, not evidence. The Table 1 statistics are unsourced, which matters less in a CACM review but is still a sloppy detail. And the blockchain recommendation in §5 is a real overreach; the paper cites its own footnote acknowledging proof-of-work for email was debated, yet still presents blockchain as a plausible solution. That's the weakest part of the paper.\n\nThe self-citation pattern is noticeable but not disqualifying. The author's bot work is genuinely central to the social spam section, and the cited studies are peer-reviewed. I wouldn't call it circular—just a bit heavy.\n\nVerdict: this deserves a serious referee if submitted as a review article, and it would be a reasonable fit for a broad-audience venue. I'd suggest the referee push for (a) sourcing or removing the Table 1 numbers, (b) softening the blockchain claim to 'an open question,' and (c) an explicit paragraph separating observed phenomena from predicted ones. For your own work, it's worth citing for the taxonomy and the historical summary, but not for empirical claims about AI spam.\n\nYes, send it to review.\n\n—","headline":"A readable, well-organized survey whose novel 'spamming with AI' vs 'spamming into AI' framing is a useful label but not an empirical result; the historical core holds up, the forward-looking sections are speculative, and the blockchain recommendation outruns the evidence.","tokens_in":14186,"tokens_out":679,"would_cite":true,"duration_ms":9126,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"AI generates the next wave of spam and is itself its target.","keywords":["digital spam","email spam","social bots","opinion spam","fake reviews","spamming with AI","spamming into AI","deepfakes"],"falsifier":"Concrete test: deploy a public AI system as a honeypot and measure, over several years, how often it receives adversarially perturbed inputs or poisoned data; also track whether AI-generated deceptive content becomes a measurable share of reported spam. If both stay near zero while platforms improve detection, the paper's central prediction fails.","tokens_in":13278,"feed_emoji":"🤖","tokens_out":6546,"duration_ms":65539,"temperature":0.7,"pith_summary":"This paper traces digital spam from the first 1978 ARPANET email to social bots and deepfakes, arguing that spam is best understood as abuse of techno-social systems rather than just unwanted email. Its central claim is that artificial intelligence now sits on both sides of the problem: spam made with AI, in which AI fabricates deceptive content, and spam aimed at AI, in which manipulated inputs steer AI systems toward attacker-chosen behavior. The paper organizes four decades of spam into a taxonomy, reviews detection and regulatory responses, and concludes that the cycle of abuse will continue with each new technology. A sympathetic reader should care because the paper names the next battlefront in spam defense before large-scale AI spam campaigns have fully arrived.","feed_headline":"AI creates two new kinds of spam: by AI, at AI","feed_subtitle":"Four decades of digital spam show every new technology gets abused; artificial intelligence is next on both sides.","key_machinery":"The central object is the paper's definition of digital spam and the four-decade timeline of its incarnations, from the Spanish Prisoner scam and early ARPANET email through search-engine link farms, fake reviews, social bots, false news, and AI-generated media. The load-bearing conceptual division is the distinction between spamming with AI and spamming into AI: it places deepfakes and adversarial perturbations under one roof, and it is what allows the author to extend the history of spam into a prediction about AI systems. This division does the argument's work by showing that AI is not merely a new channel for old spam but a new actor-and-target pair.","core_discovery":"The paper proposes a unified definition of digital spam as the attempt to abuse or manipulate a techno-social system by injecting unsolicited or undesired content intended to steer the behavior of humans or the system itself, for the spammer's advantage. It surveys email spam, search-engine spam, opinion and review spam, wiki spam, mobile messaging spam, false news, and social bots, and argues that each appeared soon after its host technology became popular. The forward-looking finding is the category of 'AI spam,' split into two directions: spamming with AI, where generative tools such as deepfakes, real-time facial reenactment, and digital humans create content meant to deceive; and spamming into AI, where attackers poison training data or craft adversarial test inputs, such as a perturbed stop sign misread as a speed-limit sign, to make an AI system misbehave. The paper's thesis is that spam evolves with technology and that AI is the next, already emerging, domain.","pith_inferences":["The two-way split implies that defense will itself split: forensic detection of AI-generated media for 'with AI' spam, and adversarial robustness plus data-integrity checks for 'into AI' spam; these require different tools and may be handled by different communities.","If the paper's abuse-repeats-history premise holds, AI spam toolkits should soon appear for sale on illicit marketplaces, mirroring the fake-review markets of the 2000s; monitoring such markets is a testable extension.","The definition of digital spam as steering human or system behavior could also cover manipulating recommendation and ranking algorithms with fake engagement, a direction the paper leaves implicit.","'Spamming into AI' may extend beyond adversarial images to prompt-based manipulation of conversational agents, which the paper frames as test-data attacks but which is a broader, related vulnerability class."],"forward_implications":["Every new communication or content platform—email, instant messaging, search, social networks, e-commerce reviews—has produced a spam variant within a few years, so AI assistants and virtual spaces should be assumed vulnerable from launch.","Because the fight is an arms race, detection techniques that are fully public can be exploited; effective defenses will need secrecy, constant updating, or structural features that raise the spammer's cost.","Regulation alone will not stop spam, since operations can relocate to less restrictive jurisdictions; the paper's historical cases show legal action helped but did not end the practice.","AI systems used in medicine, autonomous mobility, and finance must treat manipulated inputs as a spam problem, because the paper's 'spamming into AI' examples show real-world consequences.","Proof-of-concept media-manipulation tools are likely to be repurposed for large-scale influence campaigns and automated spam calls, as the paper argues with deepfakes and voice assistants."],"supporting_citations":[{"why":"Establishes the late-1990s framing of email spam as a pressing problem and supplies the starting point for the paper's history.","marker":"[10]"},{"why":"Defines social bots and their capabilities; the paper builds its social spam section on this prior review.","marker":"[16]"},{"why":"Supplies the three-way taxonomy of review spam (fake reviews, brand-only reviews, non-reviews) used throughout the opinion spam discussion.","marker":"[27]"},{"why":"Contributes the finding that spammers often post near-duplicate reviews, which the paper cites as the key to supervised fake-review detection.","marker":"[24]"},{"why":"Provides the bot-detection features and method the paper cites in its account of large-scale political bot operations.","marker":"[35]"},{"why":"Shows false news spreads faster than true news and is more likely to be shared, grounding the paper's claim that misinformation can steer human behavior.","marker":"[36]"},{"why":"Demonstrates lip-sync synthesis from audio, the proof-of-concept behind audio-driven deepfake video.","marker":"[33]"},{"why":"Demonstrates real-time facial reenactment, the proof-of-concept the paper uses to illustrate AI-generated multimedia spam.","marker":"[34]"},{"why":"Represents the next generation of deepfake video-portrait synthesis and the source of the paper's 'DeepFakes' examples.","marker":"[25]"},{"why":"Shows physical-world adversarial perturbations can fool an image classifier, the paper's key example of spamming into AI.","marker":"[14]"}],"fun_headline_variants":["AI spam splits into two fronts: with AI and into AI","Deepfakes and poisoned data: the new spam frontier","From email spam to AI abuse: the history and future","AI is the next spam playground: two directions of attack"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The risk forecast rests on the assumption that new powerful technologies are routinely abused beyond their original scope, so today's proof-of-concept AI attacks will grow into large-scale spam rather than being contained by countermeasures.","fun_headline_variants_meta":{"raw":{"variants":["AI spam splits into two fronts: with AI and into AI","Deepfakes and poisoned data: the new spam frontier","From email spam to AI abuse: the history and future","AI is the next spam playground: two directions of attack"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000453,"raw_usage":{"total_tokens":2270,"prompt_tokens":925,"completion_tokens":1345,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":541,"completion_tokens_details":{"reasoning_tokens":1277}},"tokens_in":541,"tokens_out":1345,"duration_ms":10811,"temperature":1.0,"reasoning_tokens":1277,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T13:28:26.988007+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Concrete test: deploy a public AI system as a honeypot and measure, over several years, how often it receives adversarially perturbed inputs or poisoned data; also track whether AI-generated deceptive content becomes a measurable share of reported spam. If both stay near zero while platforms improve detection, the paper's central prediction fails.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Establishes the late-1990s framing of email spam as a pressing problem and supplies the starting point for the paper's history."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines social bots and their capabilities; the paper builds its social spam section on this prior review."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the three-way taxonomy of review spam (fake reviews, brand-only reviews, non-reviews) used throughout the opinion spam discussion."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Contributes the finding that spammers often post near-duplicate reviews, which the paper cites as the key to supervised fake-review detection."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the bot-detection features and method the paper cites in its account of large-scale political bot operations."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Demonstrates lip-sync synthesis from audio, the proof-of-concept behind audio-driven deepfake video."},{"cited_title":"Thies, M","cited_arxiv_id":null,"evidence_quote":"Demonstrates real-time facial reenactment, the proof-of-concept the paper uses to illustrate AI-generated multimedia spam."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Shows physical-world adversarial perturbations can fool an image classifier, the paper's key example of spamming into AI."}],"review_version":1}