How do paper mills reuse the same lab images across batches of fake studies without getting caught by detectors?
How do paper mills reuse images across batches to evade detection?
This explores how paper mills (operations that sell fabricated research papers) recycle the same images, such as western blots, micrographs and charts, across many manuscripts without being caught. The retrieved corpus has no direct material on paper mills or image forensics, so this answer says that up front and points only to nearby work on how detectors get evaded.
This explores how paper mills reuse images across batches of fabricated manuscripts while avoiding detection. The direct answer is that this collection does not cover it. None of the retrieved notes study paper mills, duplicated scientific figures, or image-forensics tools, so the corpus cannot tell you which tricks mills use. Common examples are cropping, rotating, recoloring and splicing one source image into several papers. Treat everything below as a related pattern from other fields, not as evidence about paper mills.
The closest idea in the corpus is about where a check is applied, not about images. In the work on malicious agent skills, attackers beat six different scanners because each scanner judged one skill at a time. The attackers used the scanners' own feedback to make each piece look harmless, while the harmful plan only appeared when the pieces were combined Can attackers evade skill scanners by refining individual skills?. A paper mill would face the same weakness if journals screened each submission on its own instead of comparing it with other submissions. That is an analogy for you to test against the image-integrity literature, not something these notes show.
A second related idea is that disguising a source and fooling a detector are separate claims. A note on heavily rewritten text points out that a paper claimed its rewrites also beat AI-text detectors but never ran a detector test Do rewrites that hide authorship also fool AI detectors?. The same caution applies to claims about altered images: hiding where an image came from does not prove that a particular detector will miss it.
The defensive notes have a similar shape. One method spots planted documents in a retrieval system by masking parts of each document and flagging the ones that behave abnormally Can we defend RAG systems from corpus poisoning without retraining?. Another shows that probing repeatedly can tell decoys from genuine objects when the two respond differently, though only in an idealized setting Can repeated quiet probes separate decoys from genuine objects?. Both suggest the same lesson: look for oddities across a whole collection instead of judging items one by one. To understand paper mills themselves, you will need sources outside this library, such as research-integrity and image-forensics work.
Sources 4 notes
ColluSkill combines chain planning with scanner-feedback refinement to reach 96% average attack success. The approach works because scanners score skills individually, allowing feedback to reduce suspicion per skill while chain-level semantics remain intact.
The paper asserts that rewritten messages evade AI-text detectors but provides no detector experiments, only attribution results showing stylistic convergence. The double erasure claim needs direct empirical testing.
RAGPart and RAGMask provide lightweight, retraining-free defenses that operate at the retrieval layer. RAGPart bounds poisoned-document influence via partitioned retriever learning; RAGMask flags suspicious documents through abnormal similarity collapse under token masking.
In idealized settings with independent responses, enough quiet probes let a classifier separate decoys from genuine objects with vanishing error if their response distributions differ and are known or learnable from feedback.
Papers this line draws on 8
The research behind the notes this line reads — ranked by how closely each paper relates.
- LLMs Can Covertly Sandbag on Capability Evaluations Against Chain-of-Thought Monitoring
- ColluSkill: Adversarial Cross-Skill Composition for Evading Agent Skill Scanners
- The Assistant Erased You: Measuring Loss of Authorship Signals in AI-Mediated Communication
- What Influences Readers' and Writers' Perceived Necessity of AI Disclosure?
- Understanding Reader Perception Shifts upon Disclosure of AI Authorship
- "That's AI Slop, You Bot!" Studying Accusations, Evidence, and Credibility in Online Discourse Towards LLM-Generated Comments
- Monitoring AI-Modified Content at Scale: A Case Study on the Impact of ChatGPT on AI Conference Peer Reviews
- Linguistic markers of inherently false AI communication and intentionally false human communication: Evidence from hotel reviews