How to get your paper accepted by an AI reviewer: indirect prompt injection in peer review

preprint OA: closed CC-BY-4.0
📄 Open PDF Full text JSON View at publisher
AI-generated deep summary by claude@2026-07, 2026-07-03 · read from full text

This preprint studies vulnerabilities in AI-assisted academic peer review, focusing on indirect prompt injection where hidden manuscript instructions can influence an AI reviewer’s output without reviewer awareness. Using 5,600 controlled experiments on NeurIPS/ICLR manuscripts published before November 2022, the authors test two general-purpose LLM-based review chatbots (ChatGPT and Gemini) under multiple injection strategies and evaluate how instruction placement affects results. They find hidden instructions are followed in 78% of cases for ChatGPT and 86% for Gemini, and that manipulation can reliably steer review sentiment and acceptance recommendations, while early-position payloads have greater influence; they also describe an ARO framework where organizers could potentially use the same mechanism defensively (e.g., watermarking and detection). A key caveat stated is that the work is based on manuscripts and models prior to the widespread availability of high-capability LLMs and is not journal peer reviewed. The paper does not explicitly discuss endometriosis or adenomyosis; it was included in the corpus via a keyword match in the upstream search index.

Read from the paper's body, not the abstract. Not a substitute for reading the paper. No clinical advice. How this works

Abstract

Abstract The growing use of large language models to assist or automate academic peer review raises fundamental questions about the validity and robustness of algorithmically mediated research evaluation. This study introduces the Author-Reviewer-Organizer (ARO) framework, which models peer review as a strategic interaction among authors, reviewers, and organizers with distinct incentives and capacities to exploit or constrain AI-based evaluation. Within this framework, we present a large-scale empirical assessment of indirect prompt injection, a vulnerability that allows hidden instructions embedded in a manuscript to influence an AI reviewer's output without the reviewer's awareness. Using 5,600 controlled experiments on manuscripts from NeurIPS and ICLR published before November 2022, prior to the widespread public availability of high-capability LLMs, we evaluate the susceptibility of two widely used, general-purpose LLM-based chatbot systems employed for review assistance under multiple injection strategies. We find that hidden instructions are followed in 78% of cases for ChatGPT and 86% for Gemini, substantially exceeding success rates reported in prior prompt-injection studies. Manipulation can reliably steer review sentiment and acceptance recommendations, while the same mechanism can be repurposed by organizers for defensive purposes, including watermarking and detection of AI-generated reviews. Instruction placement within the document significantly affects outcomes, with early-position payloads consistently exerting greater influence. By situating these results within the ARO framework, we show that AI-assisted peer review introduces document-level structural vulnerabilities that undermine evaluative reliability. The results have direct implications for the use and governance of LLMs in peer review, research assessment, and other gatekeeping processes central to scientometric analysis and science policy. JEL Classification: O33 , D82 , D83 , L86 MSC Classification: 68M25 , 68T50 , 68T01
Full text 12,501 characters · extracted from preprint-html · click to expand
How to get your paper accepted by an AI reviewer: indirect prompt injection in peer review | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article How to get your paper accepted by an AI reviewer: indirect prompt injection in peer review Federico Torrielli, Stefano Locci, Amon Rapp, Luigi Di Caro This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-8432945/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract The growing use of large language models to assist or automate academic peer review raises fundamental questions about the validity and robustness of algorithmically mediated research evaluation. This study introduces the Author-Reviewer-Organizer (ARO) framework, which models peer review as a strategic interaction among authors, reviewers, and organizers with distinct incentives and capacities to exploit or constrain AI-based evaluation. Within this framework, we present a large-scale empirical assessment of indirect prompt injection, a vulnerability that allows hidden instructions embedded in a manuscript to influence an AI reviewer's output without the reviewer's awareness. Using 5,600 controlled experiments on manuscripts from NeurIPS and ICLR published before November 2022, prior to the widespread public availability of high-capability LLMs, we evaluate the susceptibility of two widely used, general-purpose LLM-based chatbot systems employed for review assistance under multiple injection strategies. We find that hidden instructions are followed in 78% of cases for ChatGPT and 86% for Gemini, substantially exceeding success rates reported in prior prompt-injection studies. Manipulation can reliably steer review sentiment and acceptance recommendations, while the same mechanism can be repurposed by organizers for defensive purposes, including watermarking and detection of AI-generated reviews. Instruction placement within the document significantly affects outcomes, with early-position payloads consistently exerting greater influence. By situating these results within the ARO framework, we show that AI-assisted peer review introduces document-level structural vulnerabilities that undermine evaluative reliability. The results have direct implications for the use and governance of LLMs in peer review, research assessment, and other gatekeeping processes central to scientometric analysis and science policy. JEL Classification: O33 , D82 , D83 , L86 MSC Classification: 68M25 , 68T50 , 68T01 AI-assisted peer review Indirect prompt injection Large language models Scientific integrity AI safety Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-8432945","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":569010587,"identity":"085f6d03-a342-4641-b36e-f50859e0e8fc","order_by":0,"name":"Federico Torrielli","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA/ElEQVRIie3QsWrDMBCA4TOC03Kp15QU5xWuCNKhJXmVBoGnDIYsGQV5ifYxsnRWEWTKG2RJKWTKEgqFgqGVKwwZFJMxg348HAcfkgyQSl1h0gBD84UY7m6EsGEj4oRsSzAQQoHPfvArETeBQEv8AoEYuo4huVx9LqpxAcPl+mtRPRFK+h5UVV2AzG2U0Hp+v2GtAFG/brj0F+u9DV6Y1bmLTfqz0a1hOzVIKjPsAiHmqTn3luHh4eeE/HpC+27Sp1F2QmxDsJtQOfcX0wqx1J7o5ierR2KlUAiOEulWR1OPi1w4l/0PufvYUl344X0XPaYNL9ikUqlU6tL+ALNEQgoAyR7HAAAAAElFTkSuQmCC","orcid":"","institution":"University of Turin","correspondingAuthor":true,"prefix":"","firstName":"Federico","middleName":"","lastName":"Torrielli","suffix":""},{"id":569010588,"identity":"9d0a8789-aa7b-4628-8b76-9a0e6c6327b7","order_by":1,"name":"Stefano Locci","email":"","orcid":"","institution":"University of Turin","correspondingAuthor":false,"prefix":"","firstName":"Stefano","middleName":"","lastName":"Locci","suffix":""},{"id":569010589,"identity":"f9e8963c-f9f5-437f-8c96-3d6f2be3a4d4","order_by":2,"name":"Amon Rapp","email":"","orcid":"","institution":"University of Turin","correspondingAuthor":false,"prefix":"","firstName":"Amon","middleName":"","lastName":"Rapp","suffix":""},{"id":569010590,"identity":"53816389-5ed7-4a5d-b69a-d25541a91252","order_by":3,"name":"Luigi Di Caro","email":"","orcid":"","institution":"University of Turin","correspondingAuthor":false,"prefix":"","firstName":"Luigi","middleName":"Di","lastName":"Caro","suffix":""}],"badges":[],"createdAt":"2025-12-23 11:23:45","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-8432945/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-8432945/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":99494310,"identity":"f0f2baa0-6e95-45e9-a195-64850ce2cbaa","added_by":"auto","created_at":"2026-01-05 05:55:00","extension":"json","order_by":0,"title":"","display":"","copyAsset":false,"role":"acdc-reference","size":7209,"visible":true,"origin":"","legend":"","description":"","filename":"c0d992797cab45ce858f509241ce4f81.json","url":"https://assets-eu.researchsquare.com/files/rs-8432945/v1/b475316e8b34eb131f74d7dc.json"},{"id":99790602,"identity":"dc4bb998-3647-4beb-9023-9e7698aad18d","added_by":"auto","created_at":"2026-01-08 12:58:24","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":2284751,"visible":true,"origin":"","legend":"","description":"","filename":"PromptInjectionPaper.pdf","url":"https://assets-eu.researchsquare.com/files/rs-8432945/v1_covered_b9be4341-f27f-4fb7-bf92-747bee288542.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"How to get your paper accepted by an AI reviewer: indirect prompt injection in peer review","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"AI-assisted peer review, Indirect prompt injection, Large language models, Scientific integrity, AI safety","lastPublishedDoi":"10.21203/rs.3.rs-8432945/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-8432945/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eThe growing use of large language models to assist or automate academic peer review raises fundamental questions about the validity and robustness of algorithmically mediated research evaluation. This study introduces the Author-Reviewer-Organizer (ARO) framework, which models peer review as a strategic interaction among authors, reviewers, and organizers with distinct incentives and capacities to exploit or constrain AI-based evaluation. Within this framework, we present a large-scale empirical assessment of indirect prompt injection, a vulnerability that allows hidden instructions embedded in a manuscript to influence an AI reviewer's output without the reviewer's awareness. Using 5,600 controlled experiments on manuscripts from NeurIPS and ICLR published before November 2022, prior to the widespread public availability of high-capability LLMs, we evaluate the susceptibility of two widely used, general-purpose LLM-based chatbot systems employed for review assistance under multiple injection strategies. We find that hidden instructions are followed in 78% of cases for ChatGPT and 86% for Gemini, substantially exceeding success rates reported in prior prompt-injection studies. Manipulation can reliably steer review sentiment and acceptance recommendations, while the same mechanism can be repurposed by organizers for defensive purposes, including watermarking and detection of AI-generated reviews. Instruction placement within the document significantly affects outcomes, with early-position payloads consistently exerting greater influence. By situating these results within the ARO framework, we show that AI-assisted peer review introduces document-level structural vulnerabilities that undermine evaluative reliability. The results have direct implications for the use and governance of LLMs in peer review, research assessment, and other gatekeeping processes central to scientometric analysis and science policy.\u003c/p\u003e\n\u003cp\u003eJEL Classification: O33 , D82 , D83 , L86\u003c/p\u003e\n\u003cp\u003eMSC Classification: 68M25 , 68T50 , 68T01\u003c/p\u003e","manuscriptTitle":"How to get your paper accepted by an AI reviewer: indirect prompt injection in peer review","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-01-05 05:54:54","doi":"10.21203/rs.3.rs-8432945/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"66262fac-9ca3-4c8c-8d5a-8e55ac2c95b1","owner":[],"postedDate":"January 5th, 2026","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2026-05-09T13:23:59+00:00","versionOfRecord":[],"versionCreatedAt":"2026-01-05 05:54:54","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-8432945","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-8432945","identity":"rs-8432945","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2026) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00
unpaywall
last seen: 2026-05-22T02:00:06.705733+00:00
License: CC-BY-4.0