Pith. sign in

REVIEW 2 cited by

Attacking Neural Text Detectors

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2002.11768 v4 pith:F2SE5G5O submitted 2020-02-19 cs.CR cs.CL

classification cs.CRcs.CL
keywords textneuralattacksdetectorsdangerlanguagemodelsother
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Machine learning based language models have recently made significant progress, which introduces a danger to spread misinformation. To combat this potential danger, several methods have been proposed for detecting text written by these language models. This paper presents two classes of black-box attacks on these detectors, one which randomly replaces characters with homoglyphs, and the other a simple scheme to purposefully misspell words. The homoglyph and misspelling attacks decrease a popular neural text detector's recall on neural text from 97.44% to 0.26% and 22.68%, respectively. Results also indicate that the attacks are transferable to other neural text detectors.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Hijacking Text Heritage: Hiding the Human Signature through Homoglyphic Substitution

    cs.CR 2026-04 unverdicted novelty 5.0 of 10

    Replacing characters in at least 37.5% of words with visual homoglyphs degrades authorship verification scores enough to obfuscate style, with diminishing returns past 50%.

  2. GenAI Content Detection Task 3: Cross-Domain Machine-Generated Text Detection Challenge

    cs.CL 2025-01 conditional novelty 4.0 of 10

    Top detectors in the shared task achieved above 99% true positive rate at 5% false positive rate on the RAID benchmark when all domains and models were seen during training.

Pith tools