Summary
Verdict: Questionable (Yellow), non-fraud-tier descriptive concerns only. The paper by Wu, Hong, Chen, Liu, Liu, and Yang (DOI: 10.14722/ndss.2026.230148) investigates identity confusion via email aliases across 28 providers and 18 platforms, supported by 174 valid out of 304 recruited survey participants and 139 npm abuse cases. Two substantive findings survived human verification: (1) descriptive inconsistency between Section VI.B and Appendix A-C participant demographics (e.g., 55.75% vs 60.81% male; 50.00% vs 48.03% bachelor), most plausibly explained by Section VI.B describing the 174 valid sample and Appendix A-C describing all 304 recruits, but the paper never makes this distinction explicit; (2) Table I's claimed mapping between seven dotted-alias Gmail addresses and seven npm usernames lacks in-table explanation of how the username field was extracted (Appendix A-B indicates _npmUser/author/maintainer, but this is not cited in the table context). Programmatic statistical alerts (Benford, last-digit, copy-move, PRNU, AI-text) were triggered but none of the cited numbers appear in the original paper, and the tests are inapplicable to the paper's discrete tabular/code/screenshot data, so they are not retained as evidence. Overall: description-level issues, not misconduct indicators. Confidence: moderate; final judgment requires institutional review.
Verdict
Questionable (Yellow) — Two descriptive/convenance issues remain after rigorous verification. Neither rises to misconduct; both are remediable by clarifications. The automated statistical alerts (Benford, terminal-digit, copy-move, PRNU, AI-style) produced numbers that cannot be located in the source PDF and are not applicable to the paper's data type, so they are not entered as evidence.
Key findings
- Section VI.B vs. Appendix A–C demographic inconsistency: The paper states it recruited 304 participants with 174 passing the attention check (57.24%). Section VI.B reports demographic figures (55.75% male, 44.25% female; 90.80% aged 18–50; 50.00% bachelor, 35.63% master) that differ from those in Appendix A–C (60.81% male, 39.19% female; 87.50% aged 18–50; 48.03% bachelor, 28.95% master). The most parsimonious explanation is that the two sections report different denominators (174 valid vs. 304 total), but the paper does not state this, creating reader confusion. Severity: 🟡.
- Table I provenance gap for npm usernames: Table I lists seven npm usernames (bujalsokao, nuilaopmei, nualosomuina, ikapikangsua, nikakulpaliindi, limaospoiukas, ukariklaopsiwa) tied to dotted-alias variants of julayera@gmail.com, but the table does not specify which field produced these usernames. Appendix A–B later mentions that npm emails are extracted from
_npmUser/author/maintainer, yet this provenance is not cited in the table context, weakening reproducibility. Severity: 🟡. Evidence highlights
- Section VI.B, exact quote: "Our 174 valid sample exhibited diverse demographic characteristics: 55.75% are male and 44.25% are female. 90.80% participants are 18-50 years old. Most of the participants have a bachelor degree (50.00%) or a master degree (35.63%)."
- Appendix A–C, exact quote: "the sample exhibited diverse demographic characteristics: 60.81% are male and 39.19% are female. 87.50% participants are 18-50 years old. Most of the participants have a bachelor degree (48.03%) or a master degree (28.95%)."
- Table I, exact quote: "An abuser created seven different accounts by adding dots at different positions in the same Gmail address (e.g., julayera@gmail.com), each treated as a separate alias."
- DOI: 10.14722/ndss.2026.230148; venue: NDSS Symposium 2026; source PDF: 2026-s148-paper.pdf.
Notes
- Confidence and limits: Both findings are reproducible from the submitted PDF. The demographic inconsistency is explainable by differing denominators but is not explicitly reconciled by the authors. The Table I gap is a documentation weakness rather than fabrication. Programmatic statistical detectors produced numerical outputs that cannot be matched to the source text and whose assumptions (continuous/visual data) do not hold for this paper's structured artefacts, so they are excluded as evidence. Endorsement of a formal misconduct investigation is not recommended on current evidence; a PubPeer inquiry or author clarification request is appropriate.
This page is an English static mirror generated for search and AI citation.
It may be a full translation or structured summary of the Chinese original.
Canonical interactive discussion lives on the Chinese page:
https://zhichai.net/report/geng_geng_6a81b53b58d434.96843414