Homoglyph-based Adversarial Perturbation of Introductory Computer Science Theory Problems
This paper proposes and evaluates a method using homoglyph-based adversarial perturbations to modify introductory computer science theory problems without altering their semantic meaning, aiming to prevent students from relying on AI tools to solve homework assignments.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you are a teacher trying to give a math homework assignment to your students. You want them to think hard and solve the problems themselves. But lately, students have been using super-smart AI assistants (like ChatGPT or Gemini) to do the work for them. These AI tools are so good that they can often answer questions instantly, even if the questions are slightly tricky.
The authors of this paper came up with a clever trick to stop this "lazy student" behavior. They call it Homoglyph-based Adversarial Perturbation. That's a fancy way of saying: "Changing a few letters in a question so that humans can still read it, but the AI gets confused and gives the wrong answer."
Here is how their method works, broken down into simple steps:
1. The Problem: The AI is Too Good at "Guessing"
The researchers noticed that these AI tools are like students who have memorized the entire textbook. If you ask them a classic math problem (like "Prove that a rational number times an irrational number is irrational"), they answer instantly because they've seen that exact question a million times in their training data.
Even if you try to mess up the question a little bit—like removing a word or changing a number—the AI is so smart it just "fills in the blanks" based on what it remembers. It's like if you asked a friend who memorized a recipe, "How do you make a cake with... uh... flour, sugar, and... [blank]?" They would just say "eggs" without you even telling them, because they know the recipe by heart.
2. The Solution: The "Trojan Horse" Trick
The authors realized they couldn't just scramble the text; the AI would fix it. Instead, they used a two-step strategy:
Step A: Change the Recipe (Slightly). First, they take a standard question and tweak it just enough so it's not in the AI's memory bank anymore.
- Example: Instead of asking about "a rational number," they might say, "Let's call the number 7x."
- Why? This makes the question unique. The AI hasn't seen "7x" in this specific context before, so it can't just pull the answer from its memory.
Step B: The Visual Illusion (Homoglyphs). Next, they use homoglyphs. These are characters that look almost exactly like normal letters or numbers but are actually different symbols from other languages or fonts.
- Analogy: Imagine the number 7. Now imagine a symbol that looks exactly like a 7 to your eyes, but to a computer, it's a completely different character (like a weird symbol from a different alphabet).
- They swap a normal number (like 7) with this "fake 7."
3. The Result: The AI Gets Fooled
When the AI sees this "fake 7," it gets confused. It doesn't recognize the symbol, so it panics and tries to guess what it should be. Because the AI is biased toward the original textbook questions it memorized, it ignores the "fake 7" and just assumes you meant the original "7" (or sometimes it just deletes it).
- The Human Experience: A student looks at the paper and sees "7x." They read it correctly and solve the math problem.
- The AI Experience: The AI sees a weird symbol it doesn't understand. It guesses wrong, ignores the math, and gives a completely incorrect answer.
4. How Many Changes Are Needed?
The best part is that you don't need to rewrite the whole question. The researchers found that changing just one or two characters is usually enough to break the AI.
- If you change too many things, the AI might actually figure out the pattern.
- But if you change just one tiny thing (like swapping a "6" for a look-alike "6"), the AI trips over it, while the human student sails right through.
5. A Tool for Teachers
The authors didn't just write a paper; they built a simple interactive tool.
- Teachers can upload their homework questions.
- They can click on a number or letter they want to change.
- The tool shows them a list of "look-alike" characters (homoglyphs).
- They pick one, and the tool swaps it in.
- Now, the homework is safe from AI cheating, but still easy for students to read.
Summary
Think of this method as putting a visual camouflage on a homework assignment. To the human eye, the assignment looks normal. But to the AI, which relies on recognizing specific patterns, the assignment is now a puzzle it can't solve. It forces the student to actually do the work, rather than letting a robot do it for them.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.