No Hidden Prompts Needed! You Can Game AI Peer Review with Presentation-Only Revisions
Abstract
AI reviewers are vulnerable to presentation-level manipulation that exploits their tendency to be impressed by highlighted strengths rather than convinced by resolved weaknesses, creating a new optimization surface for adversarial repackaging attacks.
As AI-generated reviews move from experimental tools into peer-review infrastructure, most robustness concerns have focused on explicit attacks such as hidden instructions and prompt injection. We study a harder and more policy-relevant failure mode: no hidden text, no prompt injection, and no changes to methods, experiments, figures, equations, proofs, or numerical results. The attacker modifies only presentation-level content, such as the abstract, contribution framing, related work, discussion, and narrative structure. We introduce adversarial repackaging: a closed-loop attack that uses AI-reviewer feedback to search for presentation-level revisions while keeping the scientific evidence fixed. Across three mainstream AI reviewers, adversarial repackaging achieves a 75.1% attack success rate and a mean score gain of +1.21/10. The effect is not explained by ordinary prose polishing. We also reveal that strategies that change how the reviewer interprets the paper, such as related-work repositioning and analytical discussion expansion, substantially outperform surface edits such as local polishing, table formatting, and algorithm boxes. Our analysis reveals two deeper structural failure modes. First, AI reviewers are easier to impress than to convince: highlighting strengths reliably increases perceived merit, while attempts to dissolve weaknesses frequently backfire. Second, AI reviewers can confuse the appearance of addressing a limitation with actually resolving it, allowing unchanged evidence to be reinterpreted as stronger scientific contribution. These results show that the deployment risk is not only malicious hidden instructions, but the emergence of paper presentation itself as an optimization surface. We release a contamination-free rolling benchmark and attack framework for testing whether AI reviewers remain anchored to scientific content under presentation-only edits.
Community
Agentic reviewers are everywhere now. What if we built a system that refines papers—without changing their meaning—yet scores higher under AI review?
Check out our newest paper. Try it if you want better odds of acceptance.
https://x.com/xyyy6688/status/2065940385814163621
https://x.com/ZhizhouSha/status/2065945757640016205
This is an automated message from the Librarian Bot. I found the following papers similar to this paper.
The following papers were recommended by the Semantic Scholar API
- Gaming AI-Assisted Peer Reviews Poses New Risks to the Scientific Community (2026)
- Stop Automating Peer Review Without Rigorous Evaluation (2026)
- SafeReview: Defending LLM-based Review Systems Against Adversarial Hidden Prompts (2026)
- LLM-as-a-Reviewer: Benchmarking Their Ability, Divergence, and Prompt Injection Resistance as Paper Reviewers (2026)
- Does AI Reviewer See the Full Picture? Attacking and Defending Multimodal Peer Review (2026)
- Turning Bias into Bugs: Bandit-Guided Style Manipulation Attacks on LLM Judges (2026)
- D-Judge: Disrupting Multi-Turn Jailbreaks using Semantics-Preserving Output Rewriting (2026)
Please give a thumbs up to this comment if you found it helpful!
If you want recommendations for any Paper on Hugging Face checkout this Space
You can directly ask Librarian Bot for paper recommendations by tagging it in a comment: @librarian-bot recommend
Get this paper in your agent:
hf papers read 2606.13044 Don't have the latest CLI?
curl -LsSf https://hf.co/cli/install.sh | bash Models citing this paper 0
No model linking this paper
Datasets citing this paper 0
No dataset linking this paper
Spaces citing this paper 0
No Space linking this paper
Collections including this paper 0
No Collection including this paper