REVIEW 2 cited by
Attacking Neural Text Detectors
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Machine learning based language models have recently made significant progress, which introduces a danger to spread misinformation. To combat this potential danger, several methods have been proposed for detecting text written by these language models. This paper presents two classes of black-box attacks on these detectors, one which randomly replaces characters with homoglyphs, and the other a simple scheme to purposefully misspell words. The homoglyph and misspelling attacks decrease a popular neural text detector's recall on neural text from 97.44% to 0.26% and 22.68%, respectively. Results also indicate that the attacks are transferable to other neural text detectors.
Forward citations
Cited by 2 Pith papers
-
Hijacking Text Heritage: Hiding the Human Signature through Homoglyphic Substitution
Replacing characters in at least 37.5% of words with visual homoglyphs degrades authorship verification scores enough to obfuscate style, with diminishing returns past 50%.
-
GenAI Content Detection Task 3: Cross-Domain Machine-Generated Text Detection Challenge
Top detectors in the shared task achieved above 99% true positive rate at 5% false positive rate on the RAID benchmark when all domains and models were seen during training.
Discussion (0). Continue with ORCID to comment.