Position: Academic Conferences are Potentially Facing Denominator Gaming Caused by Fully Automated Scientific Agents
This position paper warns that top AI conferences face a systemic vulnerability called "Agentic Denominator Gaming," where malicious actors use automated agents to flood submission pools with low-quality papers to artificially inflate acceptance rates for targeted legitimate work, necessitating structural policy reforms over mere technical detection to mitigate the resulting reviewer burnout and degraded review quality.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The Big Idea: A New Way to "Game" the System
Imagine a prestigious art gallery that only accepts 25% of the paintings submitted to it. This rule is strict and consistent every year to keep the gallery's reputation high.
The authors of this paper warn that a new kind of "hacker" is emerging. Instead of trying to paint a masterpiece to get in, these hackers are using AI robots to paint thousands of terrible, ugly paintings and submitting them all at once.
Their goal isn't to get the ugly paintings accepted. Their goal is to flood the gallery so much that the gallery is forced to accept more paintings just to keep their "25% acceptance" rule. By filling the "denominator" (the total number of submissions) with garbage, they accidentally make it easier for their real, high-quality paintings to get accepted.
The paper calls this "Agentic Denominator Gaming."
How It Works: The "Cannon Fodder" Strategy
The paper breaks down the mechanism into three simple steps:
- The Stable Rule: Top AI conferences (like NeurIPS or ICML) have a tradition of keeping their acceptance rate steady (usually around 20–30%), even if the number of submissions explodes.
- The AI Flood: Bad actors use AI agents (robots) to write and submit thousands of papers that look like real research on the cover but are actually nonsense inside. These cost almost nothing to make.
- The Mathematical Trick:
- If a conference gets 100 papers and accepts 25, the rate is 25%.
- If a hacker adds 300 fake papers, the total is now 400.
- To keep the 25% rate, the conference must now accept 100 papers (instead of 25).
- Since the 300 fake papers are trash, they get rejected. But the conference still has to find 75 more real papers to fill the extra spots.
- The Result: Real scientists who were previously on the "borderline" of rejection now get accepted, not because their work improved, but because the system was flooded with noise.
Why This Is Dangerous (The "Three Disasters")
The paper argues this isn't just a technical glitch; it's a systemic crisis that will break the academic world in three ways:
1. The "Free Labor" Trap (Economic Asymmetry)
- The Attacker's Cost: pennies. They use cheap AI tools to generate thousands of papers.
- The Community's Cost: Millions of dollars in lost time. Real scientists are volunteers who review papers for free. If they have to read 1,000 fake papers to find the 100 real ones, they burn out.
- Analogy: It's like a troll pouring a bucket of mud into a swimming pool. The troll spent $1 on mud. The lifeguards (reviewers) have to spend hours cleaning the pool, or the pool becomes unusable.
2. The "Burnout" Crisis
Reviewers are already tired. If they are forced to sift through a mountain of AI-generated garbage, they will quit.
- Analogy: Imagine a doctor in an emergency room. If someone starts throwing 1,000 fake patients into the waiting room every hour, the doctor can't treat the real sick people. The doctor eventually collapses or leaves, and the whole system fails.
3. The Rise of "Agent Mills"
We already have "paper mills" (companies that sell fake research). This threat upgrades them to "Agent Mills."
- Instead of humans writing fake papers, robots will do it at an industrial scale.
- Analogy: It's the difference between a small-time forger making one fake bill a day, and a factory printing a million fake bills an hour. The quality of science drops, and we can no longer trust what we read.
Why "Detecting" the Fake Papers Won't Work
The paper argues that we cannot simply build an "AI Detector" to solve this.
- The Cat-and-Mouse Game: As soon as we build a detector, the AI robots learn how to trick it. It's like a lock that changes its shape every time you try to pick it.
- False Accusations: Current detectors are bad. They often accuse real human writers of being AI. If a conference bans papers based on a faulty detector, they might reject brilliant human scientists, which is unfair and damaging.
The Proposed Solutions (Fixing the Rules, Not Just the Tech)
Since technical fixes (like detectors) are unreliable, the authors suggest changing the rules of the game:
- Charge a Fee: Make authors pay a small fee to submit. This stops the "flood" because it becomes too expensive to generate thousands of fake papers. (Though the paper notes this might hurt poor researchers).
- Stop the "Stable Rate" Rule: This is the big one. Conferences should stop promising a fixed acceptance percentage (e.g., "We will always accept 25%"). Instead, they should say, "We will accept exactly 500 papers, no matter how many are submitted."
- Why this works: If the number of accepted papers is fixed, flooding the system with fake papers doesn't help. The fake papers just get rejected, and the real papers stay at the same chance of acceptance.
- Reputation Systems: Only allow trusted researchers (or those endorsed by trusted people) to submit papers. This stops anonymous bots from creating thousands of fake accounts to flood the system.
The Bottom Line
The paper is a warning. It says that if we keep the current rules (stable acceptance rates) and let AI get better at writing papers, bad actors can break the system without ever trying to publish a "good" paper. They just need to make enough "bad" noise to change the math.
To save academic integrity, we need to change the incentives and rules, not just try to catch the bad bots with better software.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.