I wouldn't say Pangram is broken, but I would say that it's brittle

5 days ago (freddiedeboer.substack.com)

Response: https://substack.com/@maxspero/note/c-297953357

I recently tried Pangram, created an account, wrote a few lines about how my day went, and it was flagged as likely AI-assisted. It clearly doesn't work.

It's especially bad that they keep insisting that it works very well, because thousands of people will probably end up falsely accused of AI usage as a result.

  • Can you share your experiment, so that we can draw our own conclusions? I've been paying for Pangram for a long time and have not seen it misbehave even once. I've seen many people attack it, but when I looked more closely, their claims often evidently boiled down to "I want plausible deniability for my own use of LLMs" - i.e., they were clearly posting AI-generated content on social media and just didn't like the possibility of being called out.

    I'm not saying that's you, but since a proof is easy to produce, it would be nice if you could share.

    • I think most native English speakers are doing well. The one who will face issues are non native ones. I knew English as my third language since about 10 years but I've only truly become somewhat proficient in it in the past 5 or so years, thus it was heavily influenced by LLMs. So who's at fault for this? Me, for speaking like an LLM simply due to my circumstances? Am I now supposed to learn "human" english?

      2 replies →

    • I‘ve seen reports of markdown-tags (##) flipping a pangram result from human to machine (with human written text).

      But I don’t have a license to confirm.

    • >I've been paying for Pangram for a long time and have not seen it misbehave even once.

      How would you know if you just take whatever slop verdict is serves as correct?

  • The problem is likely that you only wrote a few sentences. Pangram clearly needs more text than that to work, which makes sense.

    Pangram should refuse to work with small amounts of text. (Well, I know it already does, but the threshold should clearly be significantly higher.)

  • This issue is, like, exactly what the response from Pangram is talking about.

It frustrates me that AI detection for student essays effectively works as a protection racket: if a student wants to write an essay without AI assistance and reliably get credit for doing so, they still need to pay a company like Pangram for an individual account to ensure their own work isn't accidentally flagged (especially if checking multiple drafts a day).

And even this isn't perfect, nor is it guaranteed that enterprise and individual accounts are tuned the same way. So students also need to proactively use audit/keystroke logging systems to protect themselves against accusations, which creates a type of "panopticon" on one's early/ephemeral drafts, including language of frustration (who among us hasn't typed curses into an unsaved draft at some point?), that can massively stifle creative thought. And if an institution provides such a tool, their centralized access simply worsens the "panopticon" characteristics.

There's no easy solution, here, sadly.

This product does not even have a plausible theory of how it could work.

LLM-generated text does not carry a watermark or other identifying marks. The "theory" is that an LLM trained on human writing, to mimic human writing, can be distinguished from actual human writing in under 100 words.

Notably the first diagram on the research overview page (https://www.pangram.com/research/how-it-works) shows feedback for "misclassified human examples." This is a category error; Pangram will not find out when it has misclassified text in the wild, except in rare cases. Only the "licensed human-written text" in its training data can be used as feedback.

Scams like Pangram also cause real harms, mostly because laypeople do not understand that what is being offered is not possible. Pangram advertises 99.98% accuracy, and they pitch it as a tool for teachers and universities. Translated: if a college like University of Alabama rolled this out, you could expect ~40 students to have their lives upended by this snake oil, every year. (And how can one even prove that an allegation is false, that they did write a given text?) And this is the best case, using the number on Pangram's homepage.

  • Claude, a general-purpose model, can identify me, personally with stylometry in about 200 words. Is it really such a stretch to believe it’s possible for a special-purpose model to identify the ten or so main LLMs crossed with the fifty or so main styles people gave them write in?

    • > Claude, a general-purpose model, can identify me, personally

      It cannot. this is a misconception. A human being is fully capable of writing 200 words that Claude will identify as not being written by them, because human beings are far more complex than Claude. A human can even choose to deliberately write in the style of a different human, even one who does not exist.

      Sometimes people are writing instruction manuals; those are not written like their professional emails, which are not written like their personal emails. It is normal for people to be able to write in different voices/styles/etc. People code switch, people write for different audiences, people change over time, people are hurried or tired or sick, etc.

      So no, an LLM cannot identify you uniquely in 200 words. But more to the point, most human communication is not in training sets. And Pangram has no way of course-correcting on the vast amount of data that is not in its training sets.

      By comparison: the autonomous vehicle companies actually do need their products to verifiably work. So they also feed back human-analyzed data from real trips into their models. They can tell the model where it was right or wrong in the real world. This is the part Pangram cannot do! Pangram deployed at a university may be used to accuse a student of cheating, but then Pangram will never know for sure whether the text in question was written by a human or machine. The feedback loop is missing a critical step!

      1 reply →

> If I want to induce a false positive in TSA's airport scanner, I can put a gun-shaped object in my bag. If I want to induce a false positive in Waymo's stop sign detection system, I can paint my own sign and put it up on a pole.

Holy strawman-batman, not only does the founder of Pangram not have a proper response to the actual criticisms, he feels the need to completely make up very different situations to try to illustrate some completely different point... I guess good job of the founder to engage at all, as deBoer does bring up a lot of valid points and criticisms of why people really shouldn't rely on "tools" like Pangram, too bad the founder failed completely at addressing the more serious points, and instead just chose to say "Well, there will be false-positives, what can you do?".

  • Indeed, that’s not about false positives predominantly. At least for me the key concern is if it’s giving a percentage when it looks like it calculates a Boolean and therefore implies more nuanced analysis than it does. Which explains the nesting behaviour too.

I think the problem is that pangram doesn't actually work on the whole document - it works on chunks of the document.

By analysing a specific piece of prose you probably arent using the same chunk as would otherwise be analysed and can end up with a different result.

Those detectors are even more snake oil shit than some early "AI companies" which had people in like India do the actual work.

And the obvious absolute test that would prove its shit - millions of books and posts written pre-AI would unfortunately be in its training already with some date associated, and thus it would not really detect them, it would just know "x text, written pre 2020".

Adding another anecdote, but Pangram flagged an essay I wrote last week as AI-assisted when it wasn't. I take Pangram results with a grain of salt now.

Even if everyone tacitly agrees Pangram is bullshit, there’s perhaps an opportunity to evolve it into a Yelp-like racket anyway.