<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.0 20040830//EN" "journalpublishing.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="2.0" xml:lang="en" article-type="news"><front><journal-meta><journal-id journal-id-type="nlm-ta">J Med Internet Res</journal-id><journal-id journal-id-type="publisher-id">jmir</journal-id><journal-id journal-id-type="index">1</journal-id><journal-title>Journal of Medical Internet Research</journal-title><abbrev-journal-title>J Med Internet Res</abbrev-journal-title><issn pub-type="epub">1438-8871</issn><publisher><publisher-name>JMIR Publications</publisher-name><publisher-loc>Toronto, Canada</publisher-loc></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">v28i1e112019</article-id><article-id pub-id-type="doi">10.2196/112019</article-id><article-categories><subj-group subj-group-type="heading"><subject>News and Perspectives</subject></subj-group></article-categories><title-group><article-title>Participant Fraud: How Imposters and Bots Undermine Health Databases</article-title></title-group><contrib-group><contrib contrib-type="author"><name name-style="western"><surname>Dominy</surname><given-names>Cliff</given-names></name><role>JMIR Correspondent</role></contrib></contrib-group><contrib-group><contrib contrib-type="editor"><name name-style="western"><surname>Clegg</surname><given-names>Kayleigh-Ann</given-names></name></contrib></contrib-group><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>21</day><month>9</month><year>2026</year></pub-date><volume>28</volume><elocation-id>e112019</elocation-id><history><date date-type="received"><day>14</day><month>09</month><year>2026</year></date><date date-type="accepted"><day>14</day><month>09</month><year>2026</year></date></history><copyright-statement>&#x00A9; JMIR Publications. Originally published in the Journal of Medical Internet Research (<ext-link ext-link-type="uri" xlink:href="https://www.jmir.org">https://www.jmir.org</ext-link>), 21.9.2026. </copyright-statement><copyright-year>2026</copyright-year><self-uri xlink:type="simple" xlink:href="https://www.jmir.org/2026/1/e112019"/><abstract><p>Advances in technology are making scientific fraud easier, faster, and harder to detect&#x2014;from fake papers and fake authors to fake participants. In this <italic>News and Perspectives</italic> article, JMIR Correspondent Cliff Dominy reports on the evolving problem of participant fraud, as well as measures that can be taken to detect and prevent it.</p></abstract><kwd-group><kwd>fraud</kwd><kwd>artificial intelligence</kwd><kwd>data integrity</kwd><kwd>research ethics</kwd><kwd>internet</kwd><kwd>computer security</kwd><kwd>bots</kwd></kwd-group></article-meta></front><body><boxed-text id="IB1"><p><bold>Key Takeaways:</bold></p><list list-type="bullet"><list-item><p>Increasingly sophisticated AI-driven technologies have contaminated datasets with fraudulent responses, forcing researchers to spend time and money protecting the integrity of their data.</p></list-item><list-item><p>Addressing participant fraud will require a multipronged approach including both technology and human expert review.</p></list-item></list></boxed-text><p>These days, we are often asked to prove our humanity by, say, counting fire hydrants in a graphical screen known as CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart), designed to block malicious bots from infiltrating websites. Despite initial success, the introduction of optical character recognition capabilities has allowed modern bots to evade CAPTCHA detection, necessitating the development of updated approaches such as <ext-link ext-link-type="uri" xlink:href="https://link.springer.com/article/10.1186/s42400-025-00484-0">iReCAPTCHA</ext-link> to outcompete the new threats. For health researchers collecting data via web-based surveys, CAPTCHA failure can be devastating.</p><sec id="s1"><title>The Long COVID Episodic Disability Study</title><p>The extent of the AI-infiltration problem was highlighted in a recent paper by Kelly O&#x2019;Brien, PhD, and colleagues from the Department of Physical Therapy, Temerty Faculty of Medicine at the University of Toronto. The <ext-link ext-link-type="uri" xlink:href="https://www.jmir.org/2026/1/e88838">Long COVID and Episodic Disability Study</ext-link> was a web-based survey involving two self-reported health questionnaires administered electronically, one week apart, to assess the symptoms and health challenges of people living with long COVID in Canada, Ireland, the United Kingdom, and United States.</p><p>Recruitment was carried out through trusted community organizations, many of which advertised the study, along with its CAD $40 gift card incentive, on their social media channels. These marketing efforts, intended to lower the participation barrier for people with long COVID, ultimately exposed the study to fraud.</p><p>Within 24 hours of launch, the survey received 3638 replies; a response that wasn&#x2019;t just good&#x2014;it was too good. O&#x2019;Brien was suspicious. &#x201C;We knew right away that the link we were using had been compromised,&#x201D; she said, continuing, &#x201C;We really had to shut everything down, and basically we were left with a wealth of data to [manually] sift through to delineate real participant responses from garbage.&#x201D; The result: just 9% of responses came from legitimate participants living with long COVID.</p><p>O&#x2019;Brien&#x2019;s team discovered that the fraudulent responses had left a characteristic trail of clues, including respondents with similar internet addresses or using generic emails that differed by just a single character. Further inspection revealed discrepancies in geolocation, with responses from computers outside the study countries. Another red flag was survey speed&#x2014;bots are simply faster than humans. The team began manually sifting through the questionnaire responses to separate genuine participant responses from fraudulent responses, which took time and wasted precious research dollars.</p><p>The team changed tactics for the relaunch of the survey a few weeks later. This time, fresh weblinks were in place, there was no mention of a gift card incentive, the link was not made openly accessible on social media, and recruitment was contained within networks of community leaders on the team. For successful infiltrators, they added a last trap&#x2014; honeypot questions, invisible to humans but detectable by bots&#x2014;to the new survey.</p><p>The results were better; 482 (47%) of the 1025 respondents made it past the prescreening procedure, with 377 (69%) legitimate participants completing the survey questionnaire and subsequently being compensated for their participation. In trimming the responses, the team prioritized data validity at the risk of excluding genuine participants&#x2014;the price of securing trustworthy data that accurately represented the experiences of persons living with long COVID. It was a tough call, says O&#x2019;Brien, noting &#x201C;we really erred on the side of being able to ensure that we were retaining responses that were true... but in so doing, we most likely removed real participant data.&#x201D;</p></sec><sec id="s2"><title>The Problem: Technology</title><p>The arrival of the internet opened up new opportunities for these medical fraudsters, with O&#x2019;Brien recalling, &#x201C;One of my first experiences conducting a web-based survey was in a study called the <ext-link ext-link-type="uri" xlink:href="https://www.jmir.org/2014/3/e81/">HIV Health and Rehabilitation Survey</ext-link>,&#x201D; a 2014 national study in which multiple fraudulent responses were received from a small group of internet (IP) addresses. Today, AI has enabled the mass harvesting of online rewards&#x2014;a lucrative activity for the ethically challenged. Looking back, she reflects, &#x201C;I feel like over a decade later, we&#x2019;re still experiencing the same issues, but with much more sophistication.&#x201D;</p><p>The unwelcome reality is that the role of health researchers has expanded from improving patient care to playing cybercop. &#x201C;It&#x2019;s really disrupting and detrimental to science... we often talk about protecting participants, protecting individuals,&#x201D; O&#x2019;Brien notes, continuing, &#x201C;I think in this case, we now have to protect the science and the validity of the data itself.&#x201D; Another unrecognized personal cost: <ext-link ext-link-type="uri" xlink:href="https://journals.sagepub.com/doi/10.1177/10497323261417232?url_ver=Z39.88-2003&#x0026;rfr_id=ori:rid:crossref.org&#x0026;rfr_dat=cr_pub%20%200pubmed">fraud fatigue</ext-link>, the emotional consequence of spending time and energy countering malfeasance instead of advancing medical research.</p><fig position="float" id="figureWL1"><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e112019_fig01.png"/></fig></sec><sec id="s3"><title>The Solution: More Technology?</title><p>As is often the case with the abuse of technology, <ext-link ext-link-type="uri" xlink:href="https://onlinelibrary.wiley.com/doi/10.1002/eahr.70017">better technology is needed</ext-link> to compete in the ongoing arms race against the imposters. Multipronged countermeasures will be needed, involving at least partially automated surveillance to reduce the scale of the problem.</p><p><ext-link ext-link-type="uri" xlink:href="https://journals.plos.org/globalpublichealth/article?id=10.1371/journal.pgph.0001452">Researchers</ext-link> at Johns Hopkins in Baltimore have provided <ext-link ext-link-type="uri" xlink:href="https://journals.plos.org/globalpublichealth/article/figure?id=10.1371/journal.pgph.0001452.t004">recommendations</ext-link> for tackling the participation fraud problem, including:</p><list list-type="bullet"><list-item><p>Website security: outdated CAPTCHA screens need augmentation with newer technology (like iReCAPTCHA) to effectively repel bot attacks.</p></list-item><list-item><p>Survey questions: honeypot and corroboration questions between different sections of the survey to look for inconsistencies in the answers.</p></list-item><list-item><p>Web monitoring: ongoing scanning to identify multiple respondents and geolocation discrepancies.</p></list-item></list><p>Bots and humans behave differently when interacting with websites, producing measurably different text-entry signatures; <ext-link ext-link-type="uri" xlink:href="https://technav.ieee.org/topic/user-behavior-analytics/">behavioral</ext-link><ext-link ext-link-type="uri" xlink:href="https://technav.ieee.org/topic/user-behavior-analytics/"> analytics</ext-link> could be informative during the survey phase. <ext-link ext-link-type="uri" xlink:href="https://www.cloudresearch.com/products/fraud-detection/">Biometric</ext-link> services, for example, can monitor mouse track timing and typing rhythm to help detect and deny bots.</p><p>Another clue can be found in the new science of <ext-link ext-link-type="uri" xlink:href="https://gangw.cs.illinois.edu/www22-bot.pdf">bot fingerprinting</ext-link>. Bot technology creates characteristic operating system signatures not typically used by individuals. For example, bots use scripts and cookies to launch automatic responses on multiple accounts using differing internet addresses. That activity can be tracked and added to the <italic>bot index</italic>, the sum total of all the evidence. It&#x2019;s no longer what you say on the questionnaire but rather how it&#x2019;s said that could reveal your true identity.</p></sec><sec id="s4"><title>Finding Balance in a Brave New World</title><p>While many of these approaches can be automated to ease the administrative burden on health researchers, full automation may not be desirable.</p><p>Researchers at UC Davis analyzed over <ext-link ext-link-type="uri" xlink:href="https://www.frontiersin.org/journals/research-metrics-and-analytics/articles/10.3389/frma.2024.1432774/full">31 fraud detection strategies</ext-link> to determine which combination of strategies optimized for dataset integrity with minimum participant loss. To keep pace with increasingly sophisticated attacks, the group recommended a layered strategy combining several complementary detection technologies in combination with expert human review.</p><p>Participant fraud is a significant and growing threat to data integrity in health research. Both automated technology and human oversight will be necessary to safeguard data quality and address that threat.</p></sec></body><back/></article>