On the Insecurity of Keystroke-Based AI Authorship Detection: Timing-Forgery Attacks Against Motor-Signal Verification
This paper demonstrates that keystroke-based AI authorship detection relying on inter-keystroke interval variability is fundamentally insecure because both human transcription of AI text and automated timing-forgery attacks can achieve near-perfect evasion rates, proving that motor signals alone cannot verify the semantic origin of content.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine a security guard at the door of a library. Their job is to make sure that the person holding the book actually wrote it themselves, rather than copying it from a computer screen.
For a while, experts thought they had a clever way to do this using typing speed. The theory was: "If you type naturally, your fingers pause, speed up, and slow down in a messy, human rhythm. If a robot or a script types the text, it's too perfect and too fast." So, they built detectors that looked at the "heartbeat" of your typing to see if it was human.
This paper, "On the Insecurity of Keystroke-Based AI Authorship Detection," argues that this security guard is being fooled. The author, David Condrey, shows that these detectors are looking at the wrong thing. They can tell if a body is pressing the keys, but they cannot tell if a mind is thinking up the words.
Here is the breakdown of the paper's findings using simple analogies:
1. The "Copy-Paste" Trick (The Copy-Type Attack)
The biggest hole in the security system is a trick the author calls the "Copy-Type Attack."
- The Scenario: A student uses an AI (like ChatGPT) to write an essay. Then, they open the essay on their phone, look at it, and type it out letter-by-letter on the school's computer.
- The Flaw: The security detector sees the typing. It sees the pauses, the speed-ups, and the "messy" rhythm. It says, "Aha! This is a human typing!"
- The Reality: The human didn't write the ideas; they just acted as a "biological printer." Because the detector only looks at the fingers and not the brain, it gets tricked. It's like a bouncer checking your ID to see if you are a real person, but not checking if you actually own the car you are driving.
2. The "Fake Rhythm" Trick (Timing-Forgery Attacks)
Even if a student doesn't type it out themselves, the paper shows that a hacker can fake the typing rhythm using software.
- The Analogy: Imagine a musician who knows exactly how a jazz drummer plays. They can program a robot to hit the drums with the exact same "swing" and "pause" as a human.
- The Result: The researchers built three different types of "fake rhythm" bots. They tested them against the detectors, and the bots fooled the system 99.8% of the time. The detectors thought the fake rhythms were real humans.
3. The "Two Different Jobs" Confusion
The paper argues that the people who built these detectors made a category error. They confused two very different jobs:
- Job A: Identity Verification. "Is this specific person (John) typing?" (This works well. Your typing style is like a fingerprint).
- Job B: Authorship Verification. "Did this person think up the story?" (This is what the detectors are trying to do, and they fail).
The paper says: "We can confirm a human operated the keyboard, but not whether that human originated the text."
4. The "Gap" That Doesn't Matter
The researchers admit that there is a tiny difference between typing your own thoughts and typing someone else's words.
- The Analogy: When you write your own story, you might pause to think, "Hmm, what word should I use next?" When you copy someone else's story, you might pause to read the next line.
- The Problem: The paper shows that this difference is so small (statistically speaking) that you can't use it for security. To catch the "copiers," you would have to set the detector so sensitive that it would also reject 16% of honest students who are just thinking hard. That's too many false alarms to be useful.
5. The Solution: Change the Game
The paper concludes that you cannot fix this by making the typing detectors "smarter." You can't get better at reading the rhythm because the rhythm doesn't tell you where the ideas came from.
Instead, we need completely different tools:
- Revision History: Did the writer delete and rewrite sentences (like a real thinker), or did they just type straight through (like a copier)?
- Challenge Questions: Ask the writer, "Why did you choose this example?" while they are typing. If they are just copying, they won't be able to answer.
- Semantic Binding: Link the typing process to the meaning of the words, not just the timing.
The Bottom Line
The paper warns that schools and companies relying on "typing rhythm" to catch AI cheating are building a castle on sand. A student can easily bypass it by typing out AI text, or a hacker can fake the rhythm entirely.
The takeaway: These systems can prove a human was present, but they cannot prove a human was the author. To know who really wrote the essay, we need to look at the content and the thinking process, not just the speed of the fingers.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.