Hidden text in a submitter's paper on OpenReview, the platform that runs peer review for NeurIPS 2026, one of machine learning's largest conferences, instructed AI tools a reviewer might use to insert three canned review phrases, running up against
A researcher who submitted to NeurIPS 2026, one of machine learning's largest conferences, says the PDF of their paper on OpenReview, the platform that runs its peer review, contained hidden text instructing any AI model reviewing it to include three phrases: "This work addresses the central challenge," "The claims of the paper," and "Overall, I find this submission."
The submitter fed their own paper to GPT, which surfaced an instruction block not in the version they uploaded. The technique, a prompt injection, hides instructions in text to direct an AI system's output.
An independent reviewer, Sara Atito, corroborated on LinkedIn that she saw the same injection across multiple papers; LLM tools she tried detected it at the "thinking" stage and refused to comply.
The injection tracks with NeurIPS's reviewer handbook, which bars reviewers from uploading assigned papers to AI chatbots but permits LLM use for background research. ICML 2026 took a similar line in March, desk-rejecting 497 papers — about 2% of submissions — tied to LLM-usage violations. The Transmitter and The Scientist have framed the technique as a trap. NeurIPS has not publicly addressed the injection.
Authors can search their own OpenReview PDFs for the three phrases and flag suspicious reviews to their Area Chair before the rebuttal window closes.