r/MachineLearning 2d ago

Discussion NeurIPS accepted papers leaked? [D]

I found this GitHub link, and the HTML file contains ~7k papers. Some are anonymized, and the details seem pretty accurate. It looks like these might actually be the accepted papers.

https://github.com/xll0328/NIPS26-

Can someone confirm whether this list is legit? I’m hoping it’s just a coincidence since it seems way too early.

84 Upvotes

109 comments sorted by

View all comments

48

u/PossiblePossible2571 2d ago edited 2d ago

The list is real, however, the list may not actually be the accepted papers. A lot of sources confirm that the papers are indeed, ones submitted to NeurIPS. However, a lot of sources (some I can confirm personally) also suggest that many of these papers are already desk rejected, withdrawn, or have low scores (while other high scoring papers are not on the list).

What likely happened is that the guy in charge of neurips.cc is testing the code that would eventually export open review papers to the website, and randomly selected papers under the expected acceptance rate to test the system, and forgot to guard it behind permissions etc.

It's highly unlikely that this was some sort of paper scrape, the amount of effort you'd have to go through to check whether an arxiv paper uses the NeurIPS template, and accumulate to some 7000+ without errors is unimaginable. In addition, I know a couple of folks who submitted to NeurIPS and had a different template on arxiv that's also in the list.

11

u/Feuilius 2d ago

Thanks a lot, that explanation was really helpful. That actually makes sense, since some papers with scores >=4 that I know of aren’t on the list, while some with scores <3 are.

3

u/SingleAbroad7985 1d ago

This might be the actual case. With avg rating of 4.67, my paper is not on this list and it scared the hell out of me, lol!

1

u/dante_2701 2d ago

Maybe these are only posters

1

u/we_are_mammals 2d ago

randomly selected papers

How easy would it be for "security researchers" to actually get all the papers, their scores, reviewer identities, etc.?

My guess is that the reason it hasn't happened yet, is that nobody cares about NeurIPS all that much.

3

u/PossiblePossible2571 2d ago

Very hard. It's definitely no HuggingFace level incident but OpenReview is quite an established website. It likely is built on top of popular web frameworks and the same exploit should work for all other websites.

3

u/dante_2701 1d ago

It’s not leaked from openreview though but from dev.neurips.com
Try searching some of the paper ok google. You’ll get the link to this site.

2

u/psayre23 2d ago

Not strictly. They could have opened a security hole through config or infra. But they have mostly open repos, so it might not be challenging to find a hole.

https://github.com/openreview/openreview-web