Peer Review With AI Assistance: Confidentiality Comes First

Peer Review With AI Assistance: Confidentiality Comes First

AI 辅助同行评审:保密性至上

Most discussion of AI in peer review argues about whether the reviews are any good. That is the second question. The first one is that a manuscript under review is somebody else’s confidential unpublished work, and pasting it into a service is a disclosure you were not entitled to make. 关于 AI 在同行评审中应用的讨论,大多集中在评审质量是否合格上。但这只是第二个问题。首要问题是:待审稿件是他人的机密未发表作品,将其粘贴到某个服务平台中,属于你无权进行的披露行为。

The argument that comes first: When you accept a review invitation you accept a confidentiality undertaking. The manuscript is unpublished, it usually contains results the authors have not yet established priority on, and in the case of grant review it contains an unfunded research plan — arguably the most commercially and academically sensitive document in the whole system. You agreed not to share it. Sending it to a third-party service is sharing it. That is true whether or not the provider trains on it, whether or not it is retained, and whether or not anyone ever reads it. The undertaking was not “do not let this be trained on”; it was “do not disclose this”, and transmission to a party the authors never agreed to is disclosure. Retention and training policies affect how bad the breach is, not whether one occurred. 首要论点在于:当你接受评审邀请时,你就承担了保密义务。稿件尚未发表,通常包含作者尚未确立优先权的成果;若是基金评审,其中还包含尚未获得资助的研究计划——这可以说是整个学术体系中商业和学术敏感度最高的文件。你同意不分享它,而将其发送给第三方服务即是分享。无论服务提供商是否利用数据进行训练、是否保留数据、是否有人阅读,这一事实都不会改变。保密承诺的内容不是“不要让 AI 训练”,而是“不要披露”,将稿件传输给作者未授权的第三方即构成披露。数据保留和训练政策只会影响违规的严重程度,而不会改变违规本身。

Notice what this argument does not depend on. Not model quality, not hallucination, not bias. It would apply identically to a perfect system, which is why it is the argument that has actually driven policy, and why it will not be resolved by better models. It can only be resolved by changing where the computation happens — a model running on infrastructure already covered by the confidentiality arrangement raises a different question from a consumer chat interface, and any serious policy will distinguish them. 请注意,这一论点并不依赖于模型质量、幻觉或偏见等因素。即使是一个完美的系统,这一论点依然成立。正因如此,它成为了推动政策制定的核心逻辑,也注定无法通过改进模型来解决。问题的唯一解决途径是改变计算发生的位置——在已受保密协议覆盖的基础设施上运行模型,与使用消费级聊天界面有着本质区别,任何严肃的政策都必须对此进行区分。

The second argument: accountability. A review is a named expert’s judgement. Its value to an editor is not the prose; it is that a person who knows the field read the paper and formed a view they are willing to stand behind. Generated text can simulate the prose and cannot supply the judgement. Editors describe the resulting artefact recognisably: fluent, correctly structured, superficially thorough, and engaging with nothing specific — no view on whether the control was appropriate, no reaction to the surprising number in table 3, no knowledge of the two other groups working on this. It is a review-shaped object. Worse, it is confidently reasonable, so an editor without domain expertise cannot easily tell it apart from a good review, and its errors carry the reviewer’s name. 第二个论点是:问责制。评审意见是具名专家的判断。对编辑而言,其价值不在于文笔,而在于一位领域内专家阅读了论文并形成了愿意为其背书的观点。生成的文本可以模拟文笔,却无法提供判断。编辑们这样描述此类产物:流畅、结构正确、表面详尽,但内容空洞——对对照组是否合适没有看法,对表 3 中令人惊讶的数据没有反应,对该领域其他研究团队的工作一无所知。这只是一个“评审形状的物体”。更糟糕的是,它看起来头头是道,导致缺乏领域专业知识的编辑难以将其与高质量评审区分开来,而其产生的错误却要由评审人承担责任。

Where it has been prohibited: Several major funders have moved first and moved hardest, because grant applications are the most sensitive documents in the system. The United States National Institutes of Health prohibited peer reviewers from using generative AI tools in analysing and formulating critiques of grant applications, on confidentiality grounds. Other national funders have issued comparable prohibitions for the same reason. Journal and conference policy is more varied and is still moving: some publishers prohibit uploading manuscripts to external tools while permitting limited assistance with the reviewer’s own writing, some require disclosure, some are silent. There is no single rule to quote, and the practical consequence for a reviewer is unavoidable — read the policy of the specific venue before you accept, because the obligations differ and the confidentiality undertaking you signed is theirs, not a general one. 关于禁令:一些主要资助机构行动最早且最为严厉,因为基金申请书是体系中最敏感的文件。美国国立卫生研究院(NIH)出于保密考虑,禁止同行评审人在分析和撰写基金申请评审意见时使用生成式 AI 工具。其他国家的资助机构也出于同样原因发布了类似禁令。期刊和会议的政策则更为多样且处于变动中:一些出版商禁止将稿件上传至外部工具,但允许在评审人撰写自身文字时提供有限辅助;一些要求披露;还有一些保持沉默。目前没有统一的规则可循,评审人必须面对的现实是:在接受邀请前,务必阅读特定平台的政策,因为各方的义务要求不同,你签署的保密协议是针对特定平台的,而非通用的。

Uses that raise neither objection: 无争议的使用场景:

  • Improving your own review text. Once you have written the review, working on its clarity and tone involves your words, not the manuscript. Tone in particular is a real problem in peer review and this is a legitimate use. 润色你自己的评审文本。 一旦你写好了评审意见,对其清晰度和语气进行润色处理的是你自己的文字,而非稿件内容。语气问题在同行评审中确实存在,这是合法的应用场景。
  • Checking your own manuscript before submission. Your own unpublished work is yours to share, subject to your collaborators’ agreement and any institutional or funder rules about where data may go. Running a hostile pre-review on your own paper is one of the more useful applications available. 投稿前检查自己的稿件。 你自己的未发表作品由你决定如何分享,前提是需遵守合作者的协议以及机构或资助方关于数据流向的规定。对自己的论文进行“敌对式预评审”是目前最有用的应用之一。
  • Editorial screening by the publisher. Scope checks, format compliance, statistical reporting checks and reference verification, performed by the party that already holds the manuscript legitimately, raise no confidentiality problem. This is also where the effort is best spent, because it is mechanical work that reviewers currently do badly. 出版商的编辑筛选。 由合法持有稿件的一方进行范围检查、格式合规性检查、统计报告检查和参考文献核实,不会引发保密问题。这也是最值得投入精力的环节,因为这些机械性工作目前评审人做得并不好。
  • Reference verification. Checking that every citation resolves and supports the claim made of it, as described in the integrity checks. Note this needs the reference list, not the manuscript. 参考文献核实。 检查每一处引用是否准确并支持其论点(如诚信检查中所述)。请注意,这只需要参考文献列表,而不需要稿件全文。

What a usable policy has to specify: “No AI in peer review” is not a policy, because it does not tell a reviewer whether they may use a spelling checker with a language model in it. A usable one answers five questions. 一份可行的政策必须明确:简单的“同行评审中禁止使用 AI”并非政策,因为它没有告诉评审人是否可以使用带有语言模型的拼写检查器。一份可行的政策应回答五个问题:

  1. Which stage. Screening, review, editorial decision and post-acceptance production are different, and the confidentiality position differs across them. 哪个阶段。 筛选、评审、编辑决策和录用后的出版阶段各不相同,其保密要求也存在差异。
  2. Whose text. The manuscript, the reviewer’s own comments, and the reference list are three different disclosures. 谁的文本。 稿件、评审人自己的评论以及参考文献列表属于三种不同的披露范畴。
  3. Which systems. A locally hosted model, an enterprise API under contract, and a consumer chat interface have genuinely different disclosure profiles, and a policy that treats them identically will simply be ignored. 哪些系统。 本地部署模型、受合同约束的企业级 API 和消费级聊天界面在披露风险上有着本质区别,一视同仁的政策只会遭到无视。
  4. What is disclosed, and to whom. A reviewer statement to the editor is a different thing from a public note on the paper. 披露了什么,以及披露给谁。 给编辑的评审意见与论文上的公开注释是两码事。
  5. What remains the reviewer’s responsibility. The honest answer is all of it, and saying so is the part that actually changes behaviour. 评审人仍需承担什么责任。 诚实的回答是:全部责任。明确这一点才是真正能改变行为的关键。

It is worth being realistic about enforcement. Detection of generated text is unreliable for the reasons set out in the page on journal integrity, so none of this is a control. It is a norm plus an accountability rule, and norms in peer review have historically done more work than controls. 在执行层面保持现实态度很有必要。由于期刊诚信页面所述的原因,检测生成文本的技术并不可靠,因此这些手段都无法作为有效的管控措施。这本质上是一种规范加上问责规则,而历史上,同行评审中的规范所起的作用远大于管控。