September 2, 2026
Research Integrity Infrastructure: Outputs Must Carry Proof

Verify, Don't Trust: Research Outputs Need Their Own Proof
By DecentraSec Team
Scholarly integrity can no longer rest on the word of intermediaries — editors, publishers, platforms, cloud attestations — because each checkpoint they guard fails in ways that compound downstream. Between 2025 and 2026, three events turned optional integrity properties into audited expectations: Biology Open made paid review permanent after an 85% cut in decision time (Nature, DOI: 10.1038/d41586-026-01973-z); MLRC 2026 became an official NeurIPS 2026 track in Sydney (6–13 December); and the EOSC Steering Board recommended sovereign research-data services (17 December 2025). These are early signals of institutional pressure, not yet a single compliance regime. Institutions that treat integrity as editorial assertion accumulate risk: retracted citations entering training corpora, disqualified grants, and a widening gap against peers whose outputs carry their own proof. The artifact must carry its integrity. Verify, don't trust.
Consider the paper your annual report leads with — your most-cited researcher's 2024 publication. A 2026 audit reconstructs its lifecycle: retraction in 2024; citations persisting beyond three years; assistants surfacing the work because the retraction flag never traveled with the artifact. The persistence claim carries direct evidence; the flanking risks are downstream consequences of the same failure. Your ORIC reporting sees none of this, because the retraction flag lives in one mutable publisher database — an assertion that never traveled with the artifact. The same root cause runs through the EOSC recommendations and the new reproducibility track, and the fix is institutional, not editorial.
The Root Cause: Integrity Is Asserted, Not Encoded
Through 2025–2026, five pressures converged: reviewer scarcity pushed journals to pay reviewers; LLM-generated reviews entered editorial workflows; retraction notices failed to propagate across citation graphs; the EOSC Steering Board's Opinion Paper recommended sovereign research-data services whose location institutions must evidence; and MLRC 2026 became an official NeurIPS 2026 track. Once a manuscript, review, or dataset leaves its origin, its status — reviewer identity, machine or human authorship, retraction, physical location — does not travel with it. Each property now conditions procurement, audit, or funding. The failure is structural: institutions assert integrity at the edges instead of encoding it as verifiable metadata in the artifact. More pay, more editors, and stronger AI policies cannot fix a missing integrity layer. The integrity layer has to be a protocol on the artifact itself. ScholarMark's artifact-level proof workflow is one way to encode that protocol from submission through retraction.
Reviewer Scarcity Is Real—But Unverifiable Payment Attracts Bad Actors
Biology Open's Fast & Fair workflow pays reviewers £220 per manuscript, cutting mean time-to-first-decision from 37.7 working days to 5.5 — an 85% reduction with no reported quality loss (Nature, DOI: 10.1038/d41586-026-01973-z). Earlier experiments at two journals showed payments near US$250 accelerate review without lowering quality (Nature, DOI: 10.1038/d41586-025-00968-6). Reviewer economics now work; scarcity, not capability, is the binding constraint. Yet payment without verifiable identity and quality attestation invites fabricated and AI-masquerading referees — a risk the paid-review discussion itself raises. Payment at scale plus unverifiable reviewers creates a fraud surface at the least-instrumented checkpoint in the knowledge supply chain. Every reviewer payment is an institutional reputation transaction without a verifiable receipt.
To scale payment and accreditation safely, bind reviewer identity to an institutional credential and sign each review event with the reviewer's key; commit the reviewer credential, manuscript hash, review hash, and editor's quality attestation to an append-only log before the decision is recorded.
AI Review Is a Provenance Problem, Not a Policy Problem
A survey of reviewer-facing AI policies across 111 venues — 63 AI/NLP conferences and 48 medical journals — finds substantial divergence between communities; evaluations on ICLR 2026 and Nature Communications submissions show LLM reviews reading fluent yet running overly positive, generic, and unevenly evidence-grounded (arXiv:2608.03581; DOI: 10.48550/arXiv.2608.03581). Retroactive detection cannot police that boundary: most existing detectors fail to flag machine-written reviews without unacceptable false-positive rates, and lightly edited machine text evades both inspection and analysis (arXiv:2502.19614; DOI: 10.48550/arXiv.2502.19614).
Design provenance in at the point of creation; do not attempt detection after the fact. At minimum, a review event should carry three signed fields: a reviewer credential binding the review to an identity under an institutional or ORCID-backed key; a machine-or-human contribution declaration, including any LLM assistance; and a content hash of the manuscript version reviewed plus a link to the evidence grounding the review. These fields are appended to a tamper-evident log before the review enters the workflow. The declaration is not a detector; it converts a detection problem into an accountability problem — a false declaration becomes a signed, attributable integrity violation. A dean's office cannot defend an investigation with "we could not tell." It can defend with a tamper-evident origin record that was created before any dispute arose. Provenance is a property of the review event, not a policy layer bolted on after submission.
Retraction and Reproducibility Must Travel With the Artifact
A dataset integrating Wikipedia revision histories with Retraction Watch, Crossref, Altmetric, and OpenAlex metadata identified 1,181 citations of retracted papers persisting beyond a median of 3.68 years (arXiv:2509.18403; DOI: 10.48550/arXiv.2509.18403; Retraction Watch, 18 June 2026). A retraction today is an operator's flag in a mutable database — a Crossref record, an editor's note — an assertion that does not propagate. Retraction should instead be a signed state transition linked to the DOI and content hash of the original artifact. A client can then verify the transition without trusting any single database; indexes, assistants, and training pipelines can refuse stale or superseded artifacts.
Reproducibility is now visible at a flagship venue. MLRC 2026 operates as an official NeurIPS 2026 track for the first time (Sydney, 6–13 December 2026), and its reviewers will verify rather than assume. Seal code, data, and model versions against author departure, lab reorganization, and collaborator churn by pinning hashes and execution environments to the publication record. Deans and ORIC directors own the downside of every non-propagated retraction and every reproducibility failure; both are auditable events.
Data Sovereignty Makes Geolocation a Governance Question—and Exposes Why Centralized Trust Fails
The EOSC Steering Board's Opinion Paper (17 December 2025) recommends sovereign research-data services and closer alignment with European data spaces. It is a recommendation, not a regulation; but for institutions holding EU-collaborative or regulated data, it raises the governance question of evidence: where data resides and who may audit it. Such evidence cannot rest on one cloud's assertions — operator claims, not independent proofs. Sovereign research infrastructure should bind each dataset to a provisioned region at write time, with a platform root-of-trust signing that binding and an independent auditor able to replay the log. This produces geolocation evidence, not a pure mathematical proof of physical geography; the residual physical risk must still be governed.
Centralized registries carry the same flaw: an editor's database, a Crossref flag, and a cloud attestation are mutable single points of trust. The alternative is to make integrity a protocol property. Decentralized Provenance means each state change — review, retraction, reuse, storage relocation — is written as a signed event and committed to an append-only, replicated log; no single operator can silently rewrite history. Mathematical Validation means any party can verify the result locally: signatures prove which actor made a claim, hash commitments prove which content the claim covers, and consistency proofs show the log has not been altered or forked. Algorithmic Integrity is the consequence: the artifact carries the evidence of its lifecycle, and the verification algorithm — not a trusted intermediary's assertion — decides whether the evidence is complete.
This is not a substitute for substantive judgment. Cryptographic validation proves which actor made a claim and that the log is consistent; it does not independently verify the truth of the claim. Institutional governance must still determine which claims are required and what consequences attach to false ones.
Applied to this problem, the infrastructure attaches a signed tuple — reviewer credential, manuscript version hash, review hash, quality attestation — to every artifact, and extends the chain from submission through retraction and reuse. "Verify, don't trust" becomes operational: the verifier asks for proofs, not promises.
The Institutional Decision Point
The choice is binary: keep asserting integrity through failing intermediaries, or instrument every handoff — review, retraction, reuse, storage. Pilot one submission-to-publication workflow, or one funded cross-border dataset, end to end, and make it your office's reference case. Reviewer accreditation, retraction propagation, sovereign-data storage, and reproducibility sealing belong at ORIC or dean level, not with any single PI or journal.
First movers set the template; institutions that pilot verifiable provenance now define the standards their peers will follow. Apply for the Institutional Pilot Grant: co-funding to instrument one end-to-end research workflow, with implementation and compliance-review support. This quarter's cohort also qualifies for the Early Adopter Subsidy. This is a research partnership — co-ownership of the compliance template — not a vendor transaction.
The five pressures are not coming; they are here. The question is whether your outputs carry their own proof before the next audit asks for it.
--- ScholarMark by DecentraSec is building the pre-submission infrastructure that academic publishing has never had — AI-powered integrity checks, paid peer review via the GEAR Network, and immutable provenance-based authorship seals. Start here →
References
- Nature. "Publishers trial paying peer reviewers — what did they find?" 28 March 2025. DOI: 10.1038/d41586-025-00968-6.
- Naddaf, M. "Why paying peer reviewers works, according to a journal's editor-in-chief." Nature 655, 290–291 (2026). DOI: 10.1038/d41586-026-01973-z.
- Fichtl, A. M. et al. "AI-Assisted Peer Review Across Research Communities." arXiv:2608.03581 (2026). DOI: 10.48550/arXiv.2608.03581.
- Yu, S. et al. "Is Your Paper Being Reviewed by an LLM? Benchmarking AI Text Detection in Peer Review." arXiv:2502.19614 (2025). DOI: 10.48550/arXiv.2502.19614.
- Shi, H. et al. "The Persistence of Retracted Papers on Wikipedia." arXiv:2509.18403 (2025). DOI: 10.48550/arXiv.2509.18403.
- Retraction Watch. "Some Wikipedia citations to retracted papers persist for years, study finds." 18 June 2026.
- European Commission, EOSC Steering Board. Opinion Paper on Research Data Sovereignty. 17 December 2025.
- NeurIPS Blog / MLRC. "MLRC 2026: Reproducibility as an Official Track at NeurIPS." April–May 2026.
Related posts

August 26, 2026
LLM4SE Reproducibility Crisis: 86.7% of Papers Fail Audit
First 640-paper audit of LLM4SE research finds 86.7% reproducibility failure modes. ScholarMark replaces badges with tamper-evident, mathematically verifiable infrastructure — proof, not presence.

August 4, 2026
Peer Review Bottleneck: An Infrastructure Problem — and Fix
Median peer-review times stretch to 198 days; payment and AI triage cannot scale. The fix is a portable, cryptographically verifiable review-provenance layer institutions can use to accelerate research and prove integrity.

August 1, 2026
Provenance Infrastructure: Why Detection Can't Save Research
Detection is archaeology. Provenance is engineering. Why integrity-by-design infrastructure must replace retrospective screening to protect the research record.
About us
Latest updates
News and milestones from DecentraSec.
Blog
From the team

September 2, 2026
Research Integrity Infrastructure: Outputs Must Carry Proof
Institutions that assert integrity through intermediaries accumulate risk. Research outputs need signed, tamper-evident lifecycle proof before the next audit.

September 1, 2026
AI Reproducibility Ceiling: 21% Derived, 79% Not Verified
The strongest tested agent re-derived only 21% of tasks from top-venue AI papers. The institutional remedy is verifiable provenance infrastructure—not another checklist.

August 26, 2026
LLM4SE Reproducibility Crisis: 86.7% of Papers Fail Audit
First 640-paper audit of LLM4SE research finds 86.7% reproducibility failure modes. ScholarMark replaces badges with tamper-evident, mathematically verifiable infrastructure — proof, not presence.
Institutional intake
Formal onboarding & strategic inquiries.
DecentraSec works with universities, investors, Tier-1 reviewers, and Open Access contributors through a structured intake process — not a generic contact form. Select your pathway below.
QuantumOSX briefing
Request QuantumOSX Security Briefing
Institutional pilot
Request Institutional Pilot Access (Deans/VCs/HEC)
GEAR reviewer
Join the GEAR Network (Tier-1 Reviewers)
Investor relations
Investor Relations & Pre-Seed Inquiry

