← Latest papers
💬 NLP

Authorship Impersonation via LLM Prompting does not Evade Authorship Verification Methods

This study demonstrates that despite the accessibility of large language models, current authorship verification systems remain robust against entry-level impersonation attempts because LLM-generated texts fail to replicate specific authorial individuality and often exhibit higher lexical diversity that aids in their detection.

Original authors: Baoyi Zeng, Andrea Nini

Published 2026-04-01
📖 5 min read🧠 Deep dive

Original authors: Baoyi Zeng, Andrea Nini

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Question: Can AI Fake a Person's Writing Style?

Imagine you are a detective trying to solve a crime. You find a suspicious text message or email and need to know: Did the suspect write this, or did someone else write it pretending to be the suspect?

For years, bad guys have tried to "fake" their writing style to trick investigators. But now, with the rise of super-smart AI (like the one you might be talking to right now), there's a new fear: Can an AI be tricked into writing a perfect forgery that even the best forensic experts can't spot?

This paper asks: If a criminal uses an AI to impersonate a victim's writing style, will the AI succeed in fooling the computer systems used by police and courts?

The Experiment: The "Style Swap" Challenge

The researchers set up a digital "heist" to test this. Here's how they played the game:

  1. The Cast: They gathered real writing samples from three different groups of people:
    • Corporate Emails: Serious, formal writing (like a boss writing to an employee).
    • Text Messages: Short, casual, messy chats between friends.
    • Social Media Posts: Tweets and short updates.
  2. The Criminal (The AI): They used a powerful AI (GPT-4o) and gave it a "mission." The mission was: "Here are some texts written by Person A. Now, take this new story written by Person B, and rewrite it so it looks exactly like Person A wrote it."
  3. The Tools (The Detectives): They used six different "detective systems" (computer programs) to check the AI's work. Some were old-school math-based tools, and some were modern, brain-like neural networks.
  4. The Twist: They tried four different ways to ask the AI to do the job:
    • The "Naive" Ask: Just saying "Pretend to be this person."
    • The "Self-Coach" Ask: Asking the AI to first write a plan on how to be that person, then do it.
    • The "Role-Play" Ask: Telling the AI, "You are now a writing assistant who specializes in mimicking people."
    • The "Tree of Thoughts" Ask: Making the AI brainstorm multiple plans, vote on the best one, and then write the text.

The Results: The AI Failed to Fool the Detectives

The results were surprising. Despite the AI's advanced capabilities, it failed to trick the forensic systems.

  • The Verdict: Almost every time, the detective systems looked at the AI-generated text and said, "Nope. This wasn't written by the person you claim."
  • The Score: The systems gave the AI a very low score, meaning they were highly confident the text was a fake.
  • The "Super-Confident" Twist: In some cases, the detective systems were even more sure the text was fake when it was written by the AI than when it was written by a real stranger.

Why Did the AI Fail? The "Too Perfect" Problem

You might think, "If the AI is so smart, why couldn't it copy the style?"

The researchers found a funny reason: The AI was too diverse.

Think of a human writer like a musician who plays a specific instrument. They have a "signature sound." They might always use a specific type of drum beat or a specific chord progression. They are consistent, even if they make mistakes.

The AI, however, is like a musician who has played every instrument in the world. When asked to copy a specific style, the AI tries to be everything at once.

  • Humans repeat certain words and phrases (like a signature).
  • The AI uses a huge variety of words and rarely repeats itself in the same way.

Because the AI's writing was so "rich" and varied (high "entropy"), it actually stood out like a sore thumb. It was like trying to pass off a diamond-encrusted watch as a cheap plastic one; the sheer complexity of the fake gave it away. The forensic systems noticed, "This writing is too perfect and too varied to be a normal human."

The Takeaway for the Real World

  1. Current Systems are Safe: For now, if a criminal tries to use a standard AI to fake a text message or email to frame someone, the forensic tools used in court will likely catch them. The AI isn't "stealthy" enough yet.
  2. The "Human" Factor: While the computers can spot the AI, the paper notes that regular people (like a spouse or a friend) might still be fooled. If you get a text that sounds mostly like your friend, you might believe it, even if a computer knows it's fake.
  3. The Future: The researchers warn that this is just the "beginner level" of hacking. If criminals start using more advanced tricks (like training the AI specifically on one person's data or having the AI learn from its own mistakes), the game might change. But for now, the "AI Impersonation" threat is not as scary as the movies make it look.

In a Nutshell

The paper is like a security test for a bank. They tried to break in using a high-tech robot (the AI). The robot tried to mimic the security guard's voice and walk. But the security cameras (the forensic tools) immediately spotted that the robot's voice was too clear and its walk was too smooth. The robot failed to sneak in.

For now, the digital locks on our authorship are still holding strong.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →