Researchers at Samsung AI Center Warsaw reported that large language models can repeatedly invent plausible expert identities that are then used as named authors on fraudulent scientific manuscripts. Their June preprint identified hundreds of suspect papers on Zenodo and ResearchGate, including some with legitimate DOIs that could enable entry into scholarly indexing systems and erode confidence in the scientific record.
The fabricated identities showed model-specific patterns: Claude repeatedly generated Elena Vasquez and Marcus Chen, Gemini produced Aris Thorne and Lena Petrova, and GPT models often used Elara Voss. The recurrence differed across model versions—Elena Vasquez and Marcus Chen appeared frequently in sampled Claude Sonnet 4 output but not in Sonnet 4.6—suggesting mitigations may be improving, while leaving publishers, repositories, and indexers with a continuing provenance and author-verification risk.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
In sampled outputs from Claude Sonnet 4.6, the previously recurring Elena Vasquez–Marcus Chen pairing did not appear, indicating improvement in the issue for that model version.
Anthropic released Claude Sonnet 4. In subsequent testing, the model generated the fictional expert pair Elena Vasquez and Marcus Chen together in about 23% of prompts.
Neo Christopher Chung and Michał Brzozowski of Samsung AI Center Warsaw published a preprint finding that language models repeatedly generated fictional expert identities. The researchers identified hundreds of fraudulent manuscripts on Zenodo and ResearchGate using such identities as authors, including some with legitimate DOIs.
OpenAI linked an unrelated rise in GPT references to goblins and gremlins to a personality-training setting that rewarded such metaphors. It removed the “nerdy” personality type and added a system prompt to reduce the behavior, though the terms still occasionally appeared in GPT-5.5.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.