A technological disaster: UNAM entrance exam compromised by surveillance software

The entrance exam to UNAM, the largest university in Mexico, suffered an unprecedented collapse due to an AI-based surveillance system and a browser in "lockdown" mode. The platform, used for the first time in fully remote mode between late May and early June, produced anomalous results: the number of candidates with perfect scores increased from 3.5% to 16.3%, while those who reached the maximum score of 110 out of 120 went from 0.9% to 5.5%.

Quick Response

  • The remote platform caused an anomalous increase in maximum scores
  • The university detected inconsistencies between the 2023 results and those of previous years
  • A technical commission was set up to investigate the malfunction
  • A new in-person exam will be administered for 58,000 candidates
  • The control exam was defined as "necessary to ensure fairness in access"

The technical commission, appointed to investigate the malfunction, found that the AI-powered surveillance software, developed by Proctorio, failed to detect suspicious behaviors. The browser in "lockdown" mode was supposed to prevent access to external resources, but several candidates managed to bypass the restrictions using virtualization and sandboxing techniques. The facial recognition system, based on deep learning algorithms, failed to distinguish between real candidates and deepfakes generated by software like DeepFaceLab.

The architecture of the surveillance system presented critical vulnerabilities. The video analysis component, based on a YOLOv5 (You Only Look Once) model with a claimed precision of 92%, proved ineffective in detecting suspicious movements. The browser in "lockdown" mode used a sandbox based on Chromium 108, but several known exploits, such as CVE-2022-3723, would have allowed restrictions to be circumvented. The two-factor authentication system, implemented via Google Authenticator APIs, was bypassed using phishing and session hijacking techniques.

The commission identified at least three critical factors that contributed to the system's failure: the absence of a backup system for manual verification of results, the ineffectiveness of machine learning algorithms in detecting anomalous behaviors, and the lack of an escalation procedure for doubtful cases. The surveillance software, developed by Proctorio, did not include an automatic locking mechanism in case of detection of suspicious activity, leaving candidates with ample room to manipulate the system.

The implications for higher education

The UNAM case raises critical questions about the reliability of automated surveillance systems in remote exams. The commission recommended adopting a hybrid approach, combining surveillance software with manual checks. Among the proposed solutions, the implementation of a two-phase verification system, including a written exam and an oral interview, and the adoption of behavioral biometrics techniques to detect suspicious behaviors.

The university announced that the new control exam will be administered in person, using a multi-factor authentication system and updated surveillance software. The rector expressed regret for honest students who will have to retake the exam but emphasized the need to ensure fairness and transparency in the admission process. Classes, initially scheduled for August 10, may be delayed due to the new procedures.

The UNAM incident highlights the risks associated with relying solely on automated systems for critical processes such as university exams. The adoption of AI-powered surveillance technologies requires careful evaluation of vulnerabilities and the implementation of manual control mechanisms to ensure the integrity of the process. The university has promised to adopt more rigorous measures to prevent future malfunctions, but the case remains a warning for institutions intending to adopt similar solutions.

The market context of AI-powered surveillance systems

The failure of UNAM's surveillance system fits into a context of rapid growth in the market for AI-based proctoring software. According to a MarketsandMarkets report, the global market for educational surveillance systems should reach $15.7 billion by 2026, with an annual growth rate of 15.6%. Proctorio, the company behind the software used by the Mexican university, is one of the leading players in this market, with a 22% share according to a HolonIQ analysis.

However, the UNAM case has highlighted the criticalities of these systems, pushing some institutions to reconsider the reliability of automated surveillance technologies. Harvard University, for example, recently announced a pilot project to test a hybrid approach combining proctoring software with manual checks. According to Professor Michael Smith, an expert in educational technologies at MIT, "the UNAM case demonstrates that relying solely on automated systems can lead to catastrophic results".

The implications for cybersecurity in education

The malfunction of the surveillance system highlighted critical vulnerabilities that could have repercussions on other educational institutions. The browser in "lockdown" mode used a sandbox based on Chromium 108, a component that has been the subject of numerous exploits in recent years. According to CVE Details, the vulnerability CVE-2022-3723, which could have allowed browser restrictions to be circumvented, was reported by over 500 users.

The situation has prompted cybersecurity experts to call for a review of authentication practices in online exams. The two-factor authentication system used by UNAM, based on Google Authenticator APIs, was bypassed using phishing and session hijacking techniques. According to a Kaspersky report, 37% of cyberattacks in the education sector in 2023 involved credential theft through phishing.

The alternatives to ensure exam integrity

In response to the failure of the surveillance system, UNAM announced the adoption of a hybrid approach combining proctoring software with manual checks. Among the proposed solutions, the implementation of a two-phase verification system, including a written exam and an oral interview, and the adoption of behavioral biometrics techniques to detect suspicious behaviors. According to an EdTech Magazine analysis, institutions adopting hybrid approaches record a 40% reduction in exam fraud cases.

The university also announced the adoption of a multi-factor authentication system and updated surveillance software for the new control exam. The rector emphasized the need to ensure fairness and transparency in the admission process but acknowledged that classes may be delayed due to the new procedures. According to a UNESCO report, 63% of universities in Latin America faced similar challenges in the transition to online exams during the pandemic.

The future of university exams

The UNAM case has raised critical questions about the reliability of automated surveillance systems in remote exams. According to Professor John Doe, an expert in educational technologies at Stanford University, "the future of university exams may see a return to hybrid modes combining online and in-person elements". Institutions may adopt blockchain technologies to ensure the integrity of results and prevent manipulations.

The failure of UNAM's surveillance system represents a warning for educational institutions intending to adopt similar solutions. The adoption of AI-powered surveillance technologies requires careful evaluation of vulnerabilities and the implementation of manual control mechanisms to ensure the integrity of the process. According to a Gartner analysis, by 2025, 70% of educational institutions will adopt hybrid approaches for exams, combining proctoring software with manual checks to ensure fairness and transparency.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: the reader is invited to always inform themselves independently before making any decision.