Normative Rewriting on the Reading Axis: How to Evade Chinese AI-Text Detectors While Preserving Quality
Abstract
Chinese, the largest unsegmented-script language, poses a fundamental challenge for AI-text detection: word boundaries are invisible, making a detector's reading unit unknown until measured. We measure the reading axis of six real Chinese detectors and establish a predictable link to their training objective. Detection-tuned generative LMs consistently read at the word scale (), while BERT classifiers remain axis-balanced ()—directly refuting the prevailing assumption that Chinese detectors are character-readers. Controlled contrasts confirm that this axis is governed by the objective, not tokenizer granularity. We further show that evasion efficacy is governed by coverage of this axis, and that saturated detectors resist deletion-based probing yet remain vulnerable to substitution, exposing deletion saliency as the wrong diagnostic. Under a normative constraint that preserves semantics, human-exemplar-guided beam rewriting lowers AUROC from 0.968 to 0.606, delivering the best quality-adjusted evasion efficiency among all baselines.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.