{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T16:10:38Z","timestamp":1782835838318,"version":"3.54.5"},"reference-count":35,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2024,10,16]],"date-time":"2024-10-16T00:00:00Z","timestamp":1729036800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,10,16]],"date-time":"2024-10-16T00:00:00Z","timestamp":1729036800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Speech Technol"],"published-print":{"date-parts":[[2024,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The increased quality and human-likeness of AI generated texts has resulted in a rising demand for neural text detectors, i.e. software that is able to detect whether a text was written by a human or generated by an AI. Such tools are often used in contexts where the use of AI is restricted or completely prohibited, e.g. in educational contexts. It is, therefore, important for the effectiveness of such tools that they are robust towards deliberate attempts to hide the fact that a text was generated by an AI. In this article, we investigate a broad range of adversarial attacks in English texts with six different neural text detectors, including commercial and research tools. While the results show that no detector is completely invulnerable to adversarial attacks, the latest generation of commercial detectors proved to be very robust and not significantly influenced by most of the evaluated attack strategies.<\/jats:p>","DOI":"10.1007\/s10772-024-10144-2","type":"journal-article","created":{"date-parts":[[2024,10,16]],"date-time":"2024-10-16T14:01:42Z","timestamp":1729087302000},"page":"861-874","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Robustness of generative AI detection: adversarial attacks on black-box neural text detectors"],"prefix":"10.1007","volume":"27","author":[{"given":"Vitalii","family":"Fishchuk","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8120-3368","authenticated-orcid":false,"given":"Daniel","family":"Braun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,10,16]]},"reference":[{"key":"10144_CR1","doi-asserted-by":"publisher","first-page":"155161","DOI":"10.1109\/ACCESS.2021.3127960","volume":"9","author":"N Akhtar","year":"2021","unstructured":"Akhtar, N., Mian, A., Kardan, N., & Shah, M. (2021). Advances in adversarial attacks and defenses in computer vision: A survey. IEEE Access, 9, 155161\u2013155196.","journal-title":"IEEE Access"},{"issue":"2","key":"10144_CR2","first-page":"44","volume":"4","author":"A Akram","year":"2023","unstructured":"Akram, A. (2023). An empirical study of AI-generated text detection tools. Advances in Machine Learning & Artificial Intelligence, 4(2), 44\u201355.","journal-title":"Advances in Machine Learning & Artificial Intelligence"},{"issue":"1","key":"10144_CR3","doi-asserted-by":"publisher","DOI":"10.1016\/j.fastrc.2024.100367","volume":"4","author":"SR Cooperman","year":"2024","unstructured":"Cooperman, S. R., & Brand\u00e3o, R. A. (2024). Ai tools vs AI text: Detecting AI-generated writing in foot and ankle surgery. Foot & Ankle Surgery: Techniques, Reports & Cases, 4(1), 100367. https:\/\/doi.org\/10.1016\/j.fastrc.2024.100367","journal-title":"Foot & Ankle Surgery: Techniques, Reports & Cases"},{"key":"10144_CR4","doi-asserted-by":"crossref","unstructured":"Crothers, E., Japkowicz, N., Viktor, H., & Branco, P. (2022). Adversarial robustness of neural-statistical features in detection of generative transformers. In 2022 international joint conference on neural networks (IJCNN) (pp. 1\u20138).","DOI":"10.1109\/IJCNN55064.2022.9892269"},{"key":"10144_CR5","unstructured":"Damodaran, P. (2021). Parrot: Paraphrase generation for NLU."},{"key":"10144_CR6","doi-asserted-by":"crossref","unstructured":"Ebrahimi, J., Rao, A., Lowd, D., & Dou, D. (2018, July). HotFlip: White-box adversarial examples for text classification. In Proceedings of the 56th annual meeting of the association for computational linguistics (volume 2: Short papers) (pp. 31\u2013 36). Association for Computational Linguistics. Retrieved from https:\/\/aclanthology.org\/P18-2006","DOI":"10.18653\/v1\/P18-2006"},{"issue":"1","key":"10144_CR7","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/s40979-023-00140-5","volume":"19","author":"AM Elkhatat","year":"2023","unstructured":"Elkhatat, A. M., Elsaid, K., & Almeer, S. (2023). Evaluating the efficacy of AI content detection tools in differentiating between human and AI-generated text. International Journal for Educational Integrity, 19(1), 17.","journal-title":"International Journal for Educational Integrity"},{"key":"10144_CR8","unstructured":"Emi, B., & Spero, M. (2024). Technical report on the Checkfor.ai AI-generated text classifier. arXiv preprint arXiv:2402.14873"},{"key":"10144_CR9","unstructured":"Fishchuk, V., & Braun, D. (2023). Efficient black-box adversarial attacks on neural text detectors. In Abbas, M., & Freihat, A. A., (Eds.), Proceedings of the 6th international conference on natural language and speech processing (ICNLSP 2023) (pp. 78\u201383). Association for Computational Linguistics. Retrieved from https:\/\/aclanthology.org\/2023.icnlsp-1.8"},{"key":"10144_CR10","doi-asserted-by":"publisher","unstructured":"Gao, J., Lanchantin, J., Soffa, M. L., & Qi, Y. (2018). Black-box generation of adversarial text sequences to evade deep learning classifiers. In Proceedings\u20142018 IEEE symposium on security and privacy workshops. (SPW) (pp. 50\u201356). https:\/\/doi.org\/10.1109\/SPW.2018.00016","DOI":"10.1109\/SPW.2018.00016"},{"key":"10144_CR11","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. In 3rd international conference on learning representations, ICLR 2015\u2014conference track proceedings."},{"key":"10144_CR12","doi-asserted-by":"crossref","unstructured":"Habibzadeh, F. (2023). Gptzero performance in identifying artificial intelligencegenerated medical texts: A preliminary study. Journal of Korean Medical Science, 38(38).","DOI":"10.3346\/jkms.2023.38.e319"},{"key":"10144_CR13","first-page":"15077","volume-title":"Advances in neural information processing systems","author":"X Hu","year":"2023","unstructured":"Hu, X., Chen, P.-Y., & Ho, T.-Y. (2023). Radar: Robust AI-text detection via adversarial learning. In A. Oh, T. Neumann, A. Globerson, K. Saenko, M. Hardt, & S. Levine (Eds.), Advances in neural information processing systems (Vol. 36, pp. 15077\u201315095). Curran Associates Inc."},{"key":"10144_CR14","doi-asserted-by":"crossref","unstructured":"Jawahar, G., Abdul-Mageed, M., & Lakshmanan, L. V. S. (2020). Automatic detection of machine generated text: A critical survey. In Proceedings of the 28th international conference on computational linguistics (pp. 2296\u20132309). International Committee on Computational Linguistics. Retrieved from https:\/\/aclanthology.org\/2020.coling-main.208","DOI":"10.18653\/v1\/2020.coling-main.208"},{"key":"10144_CR15","doi-asserted-by":"publisher","unstructured":"Jin, D., Jin, Z., Zhou, J.T., & Szolovits, P. (2019). Is BERT really robust? A strong baseline for natural language attack on text classification and entailment. In AAAI 2020\u201434th AAAI conference on artificial intelligence (pp. 8018\u20138025). https:\/\/doi.org\/10.1609\/aaai.v34i05.6311","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"10144_CR16","unstructured":"Kirchenbauer, J., Geiping, J., Wen, Y., Katz, J., Miers, I., & Goldstein, T. (2023). A watermark for large language models. In Krause, A., Brunskill, E., Cho, K., Engelhardt, B., Sabato, S., & Scarlett, J. (Eds.), Proceedings of the 40th international conference on machine learning (Vol. 202, pp. 17061\u201317084). PMLR. Retrieved from https:\/\/proceedings.mlr.press\/v202\/kirchenbauer23a.html"},{"key":"10144_CR17","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2021\/4907754","volume":"2021","author":"Z Kong","year":"2021","unstructured":"Kong, Z., Xue, J., Wang, Y., Huang, L., Niu, Z., & Li, F. (2021). A survey on adversarial attack in the age of artificial intelligence. Wireless Communications and Mobile Computing, 2021, 1\u201322.","journal-title":"Wireless Communications and Mobile Computing"},{"key":"10144_CR18","unstructured":"Liang, G., Guerrero, J., & Alsmadi, I. (2023a). Mutation-based adversarial attacks on neural text detectors. arXiv preprint arXiv:2302.05794"},{"issue":"8","key":"10144_CR19","doi-asserted-by":"publisher","first-page":"1948","DOI":"10.3390\/electronics12081948","volume":"12","author":"G Liang","year":"2023","unstructured":"Liang, G., Guerrero, J., Zheng, F., & Alsmadi, I. (2023b). Enhancing neural text detector robustness with \u00b5attacking and RR-training. Electronics, 12(8), 1948. https:\/\/doi.org\/10.3390\/electronics12081948","journal-title":"Electronics"},{"key":"10144_CR20","doi-asserted-by":"crossref","unstructured":"Liang, W., Yuksekgonul, M., Mao, Y., Wu, E., & Zou, J. (2023c). GPT detectors are biased against non-native english writers. In ICLR 2023 workshop on trustworthy and reliable large-scale machine learning models.","DOI":"10.1016\/j.patter.2023.100779"},{"issue":"7","key":"10144_CR21","doi-asserted-by":"publisher","DOI":"10.1016\/j.patter.2023.100779","volume":"4","author":"W Liang","year":"2023","unstructured":"Liang, W., Yuksekgonul, M., Mao, Y., Wu, E., & Zou, J. (2023d). GPT detectors are biased against non-native English writers. Patterns, 4(7), 100779. https:\/\/doi.org\/10.1016\/j.patter.2023.100779","journal-title":"Patterns"},{"key":"10144_CR22","unstructured":"Nova, A. (2019). Essay topics: 100+ best essay topics for your guidance. Retrieved November 7, 2023, from https:\/\/www.5staressays.com\/blog\/essay-writing-guide\/essay-topics"},{"key":"10144_CR23","unstructured":"OpenAI. (2023). Api reference\u2014 openai api. Retrieved from https:\/\/platform.openai.com\/docs\/api-reference\/chat\/create"},{"key":"10144_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/J.JKSUCI.2023.03.017","volume":"35","author":"H Peng","year":"2023","unstructured":"Peng, H., Wang, Z., Zhao, D., Wu, Y., Han, J., Guo, S., & Zhong, M. (2023). Efficient text-based evolution algorithm to hard-label adversarial attacks on text. Journal of King Saud University-Computer and Information Sciences, 35, 101539. https:\/\/doi.org\/10.1016\/J.JKSUCI.2023.03.017","journal-title":"Journal of King Saud University-Computer and Information Sciences"},{"key":"10144_CR25","doi-asserted-by":"crossref","unstructured":"Rathore, P., Basak, A., Nistala, S. H., & Runkana, V. (2020). Untargeted, targeted and universal adversarial attacks and defenses on time series. In 2020 international joint conference on neural networks (IJCNN) (pp. 1\u20138).","DOI":"10.1109\/IJCNN48605.2020.9207272"},{"key":"10144_CR26","unstructured":"Sadasivan, V.S., Kumar, A., Balasubramanian, S., Wang, W., & Feizi, S. (2023). Can AI-generated text be reliably detected?"},{"key":"10144_CR27","unstructured":"Shen, L., Zhang, X., Ji, S., Pu, Y., Ge, C., Yang, X., & Feng, Y. (2023). Textdefense: Adversarial text detection based on word importance entropy."},{"key":"10144_CR28","unstructured":"Solaiman, I., Brundage, M., Clark, J., Askell, A., Herbert-Voss, A., & Wu, J. (2019). Release strategies and the social impacts of language models. arXiv preprint arXiv:1908.09203"},{"key":"10144_CR29","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., & Fergus, R. (2013). Intriguing properties of neural networks. In 2nd international conference on learning representations, (ICLR 2014) \u2014Conference Track Proceedings."},{"key":"10144_CR30","unstructured":"van Oijen, V. (2023). AI-generated text detectors: Do they work? Retrieved 9 March, 2024, from https:\/\/communities.surf.nl\/en\/ai-in-education\/article\/ai-generated-text-detectors-do-they-work"},{"issue":"1","key":"10144_CR31","doi-asserted-by":"publisher","first-page":"20220158","DOI":"10.1515\/opis-2022-0158","volume":"7","author":"WH Walters","year":"2023","unstructured":"Walters, W. H. (2023). The effectiveness of software designed to detect AI-generated writing: A comparison of 16 AI text detectors. Open Information Science, 7(1), 20220158. Retrieved 20 April, 2024, from\u00a0https:\/\/doi.org\/10.1515\/opis-2022-0158.","journal-title":"Open Information Science"},{"issue":"1","key":"10144_CR32","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1007\/s40979-023-00146-z","volume":"19","author":"D Weber-Wulff","year":"2023","unstructured":"Weber-Wulff, D., Anohina-Naumeca, A., Bjelobaba, S., Folt\u1ef3nek, T., Guerrero-Dib, J., Popoola, O., & Waddington, L. (2023). Testing of detection tools for AI-generated text. International Journal for Educational Integrity, 19(1), 26.","journal-title":"International Journal for Educational Integrity"},{"key":"10144_CR33","unstructured":"Wolff, M., & Wolff, S. (2022). Attacking neural text detectors."},{"key":"10144_CR34","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1007\/s11633-019-1211-x","volume":"17","author":"H Xu","year":"2020","unstructured":"Xu, H., Ma, Y., Liu, H.-C., Deb, D., Liu, H., Tang, J.-L., & Jain, A. K. (2020). Adversarial attacks and defenses in images, graphs and text: A review. International Journal of Automation and Computing, 17, 151\u2013178. https:\/\/doi.org\/10.1007\/s11633-019-1211-x","journal-title":"International Journal of Automation and Computing"},{"key":"10144_CR35","doi-asserted-by":"crossref","unstructured":"Yoo, K., Kim, J., Jang, J., & Kwak, N. (2022). Detection of adversarial examples in text classification: Benchmark and baseline via robust density estimation. In Findings of the association for computational linguistics. (ACL 2022) (pp. 3656\u20133672). Association for Computational Linguistics. Retrieved from https:\/\/aclanthology.org\/2022.findings-acl.289","DOI":"10.18653\/v1\/2022.findings-acl.289"}],"container-title":["International Journal of Speech Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10772-024-10144-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10772-024-10144-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10772-024-10144-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,16]],"date-time":"2024-12-16T10:07:29Z","timestamp":1734343649000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10772-024-10144-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,16]]},"references-count":35,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2024,12]]}},"alternative-id":["10144"],"URL":"https:\/\/doi.org\/10.1007\/s10772-024-10144-2","relation":{},"ISSN":["1381-2416","1572-8110"],"issn-type":[{"value":"1381-2416","type":"print"},{"value":"1572-8110","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,16]]},"assertion":[{"value":"11 August 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 September 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 October 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}