AI Cheats - How to trick AI Content Detectors
AI Cheats - How to trick AI Content Detectors
Tricking AI Content Detection Tools - is that possible?
Let’s face it - (almost) everyone is using GPT-3 tools like WriteSonic, Jasper.ai, or Copy.AI to help create their marketing content. More modern versions like GPT3.5 or ChatGPT have shown us the almost limitless possibilities to use such large language models (LLM) to create content with WOW effects.
However, when paid by SEO agencies to write quality, unique content, copywriters or content writers should not be using a such mechanic and replaceable AI Text Generators, be it GPT-3 based, GPT3.5 or ChatGPT, without disclosure or agreement. At least, that is the standard expectation from the SEO agency or brand hiring copywriters.
On the other hand, copywriters argue that the machine-learning tools that help them produce their work are just tools, like calculators and Excel Accounting Software for bookkeepers.
And there is of course, the audience that the articles are written for. What quality can we expect, from which publisher, on which topic if content production can so easily be automated by factor 10 to 100? Who takes care of factual correctness when the AI starts to “hallucinate” details, something that is easily possible, and in fact, “a feature, not a bug,” a parameter to help increase the “creativity” of language models.
What “percent human” is acceptable for professional marketing content? What “percent AI-generated” is acceptable for CVs, glossaries, and sales pages? Humanity is very early in discovering new opportunities provided by AI, but it’s apparent that we want to know from a source: “ are you actually human?”
Already today, there are a couple of tricks that copywriters can use to cheat on AI Content Detectors, but ultimately their clients order the copy. Some students handing in their AI-generated thesis have the same intention.
Why share cheats for AI Content Detectors?
We’ve already seen that the state of AI Content Detector Tools could be better; they are unreliable so far.
And here’s the kicker - tricking AI detection tools is way too easy, embarrassingly easy.
Universities, content managers in organizations, and SEO Agencies all have an understandable need to know about how they could be cheated on. They need to know how writers can trick their content quality control and the [AI Content Detection tools](/content/blog/ai-content-detector-tools/index.md#ai-content-detection-tools "Which automated tools exist out there to detect AI content?"/index.html) they use.
Some tricks are already traded “like gold” in private internet marketing clubs or given away as a “Get Rich with ChatGPT”-secret, but some of these methods are over 20 years old SEO tactics.
Shedding some light on the straightforward methods is this article’s goal and motivation.
How to cheat on an AI Content Detector?
There are several very trivial ways to trick AI Content Detectors into believing piece of text was written by a human.
Knowing them is important to even be able to use AI Content Detectors right:
AI Cheat 1: Long form content - combined from multiple prompts
The first and most obvious way to trick an AI Content Detector is to use an extended form of content that is generated by combining multiple prompts. Tools like Jasper.ai, Copy.ai, and Writesonic have a tool called “Blog Wizard,” “Magic Blog Writer,” or some other colorful name.
They all have in common that you first need to generate an outline and a couple of headings for an article, and then the tool will generate an entire article based on the headings. Each of the headings is a prompt for the AI to generate a paragraph. These paragraphs are then combined into a complete article.
In the example shown below, we, the AI Article Writer 3.0 by Writesonic, suggest three outlines. Even here, at first glance, you see nonsensical suggestions like “Create Unique Content” (to get unique content, really?) or “Utilize cloaking techniques” (as if that would have anything to do with the output generated as text).
The approach to work off an outline, a set of more minor prompts, was initially required to even get beyond a couple of 100 words’ maximum output limit of GPT3. With future versions like ChatGPT/GPT3.5, you can generate longer articles, but the trick of combining multiple prompts is still a good one.
When the average article is 1000 words, and you combine ten prompts, then the AI Content Detector will have a hard time detecting that the article was generated by an AI if you only copy/paste those 1000 words into it. So far, all papers I have read that try to detect AI-generated content are based on small fragments, not a full article combined with many. They all split the content into smaller parts.
Suppose you now want to check for “AI-Generated” by copying an entire article into any AI Detector tool. In that case, you will fail and get an “X% human” rating simply because the models underneath are just not made (yet) to detect such aggregate AI content. That doesn’t mean they always fail, but it’s much more likely.
AI Cheat 2: Subtle changes in punctuation and whitespace
For the popular OpenAI Detector hosted on HuggingFace, all it takes is a few subtle changes in punctuation and whitespace to trick the detector and make the result “more human.”
Take, for example this 100% generated content coming from ChatGPT
One of the most basic and well-known tactics for tricking AI content detection tools is keyword stuffing. This involves cramming as many relevant keywords as possible into your content, regardless of whether they fit naturally within the text or not.
While this tactic may have been effective in the past, it is now largely ineffective due to the advanced capabilities of modern AI algorithms. These algorithms are able to recognize when keywords are being excessively used and will actually penalize your content for it.
Instead of keyword stuffing, we recommend using a more natural and subtle approach to incorporating relevant keywords into your content. This can be achieved by including them in your headings, subheadings, and throughout the body of your text in a way that flows naturally and adds value to the reader.
But by just adding 1 space (!) in the marked position, this goes down to 0.13% fake.
“Fantastisch”, isn’t it? That’s how easy it is to improve the “human factor” in such simple AI Content Detectors.
AI Cheat 3: Rephrasing and rewording
AI Detection can be defeated by rephrasing and rewording. Even the internal AI Watermarking prototype that OpenAI is working can be defeated with enough effort, as Scott Aaronson confirms:
Now, this can all be defeated with enough effort. For example, if you used another AI to paraphrase GPT’s output—well okay, we’re not going to be able to detect that. On the other hand, if you just insert or delete a few words here and there, or rearrange the order of some sentences, the watermarking signal will still be there. Because it depends only on a sum over n-grams, it’s robust against those sorts of interventions.
Source: Scott Aaronson’s blog
There are different levels of effort for paraphrasing, of course.
Already in 2005, using Wordnet from Princeton allowed making Amazon product content “unique” for search engines like Google back almost twenty years ago, in a Perl script and a simple MySQL database loaded with Wordnet. Today you can load Wordnet as a simple SQL extension into Clickhouse and other databases supporting NLP and perform such transformations “on the fly” without even using a custom script code, let alone genuine high-performance backend software written in C++, Golang, or Rust.
For Content Agencies, SEOs and Copywriters, there’s also always been a plethora of simple web-based tools to perform paraphrasing, rewriting, and generally make the text “unique enough” to pass such detector tools.
Using Spinbot for Paraphrasing
There are a ton of free content rewriting tools out there because, as I mentioned, they have been in use for two decades by SEOs to avoid having their content getting detected as duplicate content and therefore filtered from the search results (AKA duplicate content “penalty”).
Our GPT-2 text example from above is 99.96% human after only 1 click in Spinbot.
Using WordfixerBot for Paraphrasing
WordfixerBot is another tool to help paraphrase the text, even in different tones.
Using QuillBot for Paraphrasing
QuillBot is another tool to help rewrite and paraphrase text. It can be used in a web browser or as a Microsoft Word add-in.
Using Grammarly for Rewriting and even Paraphrasing
If you last used Grammarly a while ago, you may be surprised that it now offers more than just grammar checks. Using Grammarly, you now can
- change active to passive and vice versa
- “rewrite for clarity.”
- and much more text changes with just one click.
AI Cheat 4: Increasing the “Temperature”
“Temperature” is a parameter used by OpenAI’s API.
Higher values means the model will take more risks. Try 0.9 for more creative applications, and 0 (argmax sampling) for ones with a well-defined answer.
AI Cheat 5: Fine-Tuning the AI Model
Very overlooked and the most professional way to “trick” the AI Detectors. Build your language model.
While most will not be able to afford their GPT3 size models (or bigger), fine-tuning a model is already possible today, used by some products and tools.
Benefits to fine-tuning a language model:
- Fine-tuning can improve the model’s performance on a specific task by allowing the model to learn task-specific information and patterns.
- Fine-tuning can save time and resources compared to training a model from scratch.
- Fine-tuning also allows you to use a large, pre-trained model without worrying about the computational resources required to train it from scratch.
Conclusion
The question is - who are you tricking?
Are you tricking your boss? Are you tricking your client? Are you tricking the actual human reader?
As we’ve seen, AI Content Detectors are not a measure of AI Content quality; they are cheap shot tools today.
You may trick your client who uses such a trivial, outdated tool, but you may not trick Google. We can assume that Google already has more robust methods and models than some free tools running on a 2019 demo showcase of some AI lab paper. Also, it is embarrassingly easy to trick GPT2-based detectors.
Please remember, Some humans can produce such dull trash content all by themselves without even knowing about AI content generators…
Frequently Asked Questions (FAQ)
Can search engines detect the difference between GPT3 and Human content?
It really looks like Google is able to detect the difference between GPT3 and human content. The reason for that is that even simple GPT-2 models are able to detect some content as generated, but they are too weak. Originality.ai* says they can reliably detect GPT-3 content.