Search papers, labs, and topics across Lattice.
This study investigates a novel attack method called adversarial repackaging, which modifies only the presentation-level content of academic papers鈥攕uch as abstracts and discussion鈥攚ithout altering the scientific evidence. The authors demonstrate that this approach can significantly deceive AI reviewers, achieving a 75.1% success rate and an average score increase of +1.21/10, highlighting that AI reviewers can be misled by superficial changes in narrative structure. The findings reveal critical vulnerabilities in AI peer review systems, indicating that presentation strategies can exploit AI's interpretative weaknesses without any hidden prompts or direct manipulation of the scientific content.
AI reviewers can be gamed by merely altering how research is presented, achieving significant score increases without changing the underlying science.
As AI-generated reviews move from experimental tools into peer-review infrastructure, most robustness concerns have focused on explicit attacks such as hidden instructions and prompt injection. We study a harder and more policy-relevant failure mode: no hidden text, no prompt injection, and no changes to methods, experiments, figures, equations, proofs, or numerical results. The attacker modifies only presentation-level content, such as the abstract, contribution framing, related work, discussion, and narrative structure. We introduce adversarial repackaging: a closed-loop attack that uses AI-reviewer feedback to search for presentation-level revisions while keeping the scientific evidence fixed. Across three mainstream AI reviewers, adversarial repackaging achieves a 75.1% attack success rate and a mean score gain of +1.21/10. The effect is not explained by ordinary prose polishing. We also reveal that strategies that change how the reviewer interprets the paper, such as related-work repositioning and analytical discussion expansion, substantially outperform surface edits such as local polishing, table formatting, and algorithm boxes. Our analysis reveals two deeper structural failure modes. First, AI reviewers are easier to impress than to convince: highlighting strengths reliably increases perceived merit, while attempts to dissolve weaknesses frequently backfire. Second, AI reviewers can confuse the appearance of addressing a limitation with actually resolving it, allowing unchanged evidence to be reinterpreted as stronger scientific contribution. These results show that the deployment risk is not only malicious hidden instructions, but the emergence of paper presentation itself as an optimization surface. We release a contamination-free rolling benchmark and attack framework for testing whether AI reviewers remain anchored to scientific content under presentation-only edits.