AI Writing Tips

Why Fabricated Citations Look So Convincing

· 5 cited sources

A fabricated citation is convincing because of how it is built, not in spite of it. This is the part most explanations get backwards. They treat the fake reference as a copy of a real one that came out garbled — a photocopy with the ink smeared. It is not that. The model never had the record to begin with. What it produced instead is the single most probable arrangement of author, title, journal, volume, year, and DOI for the sentence it was completing. Plausibility was not an accident of the output. Plausibility was the output. That is why you cannot spot the fake by looking harder at it, and why so many careful people — editors, lawyers, researchers checking their own field — have been fooled anyway.

Everything below follows from that one fact: the citation was optimized to look right, and looking right is a different property than being right.

The model is not remembering a citation. It is composing one.

A language model has no lookup table of real papers. It predicts the next token from statistical patterns in its training data, one field at a time. When it reaches the point in a sentence where a reference belongs, it does not ask “does this paper exist?” It asks, in effect, “what string of characters looks like a citation that belongs here?” — and then it produces the most likely answer. The same machinery that writes a fluent sentence writes a fluent reference. Neither has a truth check attached.

Walters and Wilder, whose Scientific Reports study hand-checked all 636 references from 84 AI-generated papers, put the consequence plainly: ChatGPT’s fabricated citations “tend to look legitimate at first glance” (Walters & Wilder, 2023, p. 2). Not sometimes. As a rule. A recent AAAI review names the failure mode in its own definition — citation hallucinations are “fabricated papers, mis-attributed authors, or plausible-looking but incorrect bibliographic metadata” (Misra & Udandarao, 2026). Read that back slowly: plausible-looking is not a description of the symptom, it is the mechanism. The output was generated by a process whose only target is plausibility. If you want the rates behind this — which models fabricate how often, and why one percentage is always misleading — our fact-checking guides keep each figure attached to its model and task.

It is a composite, not a copy

The most useful way to picture a fabricated citation is not as a lie but as a collage. The model stitches a new reference out of real parts, and the seams are invisible because every individual piece is genuine.

Robin Emsley, editor of the journal Schizophrenia, ran into this the hard way when planning a study. He describes a colleague’s test in which, of 35 citations ChatGPT generated, only two were real; twelve were “similar to actual manuscripts,” and the remaining twenty-one were “seemingly plausible but in fact a mix of multiple actual manuscripts” (Emsley, 2023). A mix. Real author from one paper, plausible title assembled from the vocabulary of the field, a journal that genuinely publishes that kind of work, a DOI in the correct syntactic shape. None of it copied; all of it typical.

Safran and Çalı watched the same construction happen field by field. Scoring 40 AI-generated references on musculoskeletal topics, they found the fabricated entries followed a recurring recipe — most memorably, a “fabricated title under real author with similar topic,” a real author’s name welded to an invented paper on exactly the subject they actually study (Safran & Çalı, 2025, p. 698). That is the most believable forgery imaginable, because the only false element is the one thing a busy reader is least likely to check: whether that specific paper, as opposed to that author’s real work, exists.

Every surface cue is correct — that is the trap

Human forgers get caught on details. AI-generated citations get the details right, because the details are exactly the statistically-learned patterns the model is best at reproducing.

Walters and Wilder found that every citation ChatGPT produced was rendered in clean APA format (Walters & Wilder, 2023, p. 5). More striking: the real citations and the fabricated ones “display the same kinds of formatting errors” (Walters & Wilder, 2023, p. 5). There is no stylistic fingerprint separating the invented references from the genuine ones — no telltale sloppiness, no formatting shortcut, nothing you can train your eye to catch. The fake is dressed identically to the real thing because both came off the same production line.

The detail that should unsettle anyone who relies on links to feel safe: in that same study, hyperlinks were more likely to appear inside the fabricated citations than inside the real ones (Walters & Wilder, 2023, p. 5). The forgery often arrives better dressed than the authentic article. And when a DOI is present, it does not reassure — it misleads. Emsley reports that entering the DOI numbers from his AI-supplied references “took me to totally unrelated publications” (Emsley, 2023). The number resolved. It just resolved to the wrong paper. A clickable DOI is not proof of anything except that the model produced a well-formed DOI.

Looking correct and being correct are different skills

The model is extraordinarily good at the first and much worse at the second, and the gap is measurable even inside the references that turn out to be real. Among the ChatGPT citations that pointed to genuine papers, 43% of the GPT-3.5 references and 24% of the GPT-4 references still contained substantive errors — wrong volumes, wrong pages, wrong years (Walters & Wilder, 2023, p. 1). Numeric fields are where the cracks run deepest, and it is not subtle: an earlier audit the same authors cite found that 87% of citations to real works carried at least one of seven errors, with mistakes in the numeric components “especially common” (Walters & Wilder, 2023, p. 2). A citation can be real and still send you to the wrong shelf.

This is the quiet version of the same problem. A fully fabricated reference is a convincing fake; a real reference with a mangled DOI is a convincing half-fake. Both pass the glance test. If you want the downstream price of letting either slip through, we itemized it in what a fabricated citation actually costs — the figure now runs from a $5,000 sanction to six figures once a court gets involved.

Convincing enough to fool the experts

The obvious rejoinder is that specialists can tell. Mostly they cannot, and that is the point. Emsley notes that the believability of these falsifications is strong enough to be “even deceiving established scientists,” and that the model “doubles down” convincingly when confronted with the error (Emsley, 2023). The forgery does not fold under questioning; it produces a fluent defense of itself, because defending a claim and inventing one are, again, the same operation.

Put a number on the human-versus-machine gap and it gets worse. On the CiteME benchmark, large language models scored between 4.2% and 18.5% accuracy at correctly attributing a claim to its source, against 69.7% for human annotators (Misra & Udandarao, 2026). The model that writes the most confident-sounding citation is the one least able to tell whether it is true. Confidence and correctness are not just uncorrelated here — for this task they point in opposite directions. That is the same reason AI-detection scores misfire: fluent, assured output is being read as evidence of something it does not carry.

The one real tell — and why re-asking the model won’t surface it

If appearance cannot separate fake from real, what can? Arbitrariness. A fabricated citation has nothing underneath it but a probability distribution, so it is unstable — ask twice, with a different phrasing or a fresh session, and a confabulated reference often comes back with a slightly different title or year. Emsley argues the whole phenomenon is better called confabulation than hallucination for exactly this reason: the answer is fluent, wrong, and arbitrary rather than anchored to any fact. There was never a record; there is only the reconstruction, and the reconstruction changes.

What does not help nearly as much as it looks is asking the model to check its own work. When Safran and Çalı prompted ChatGPT to verify and revise its references, the fully-accurate share jumped from 7.5% to 77.5% (Safran & Çalı, 2025, p. 695) — a real gain that still leaves roughly one reference in five wrong, now wearing a fresh coat of confidence. And the model is a treacherous auditor: Walters and Wilder note it “often provides incorrect responses when asked ‘Is this citation correct’” (Walters & Wilder, 2023, p. 2). The tool that composed the fabrication is fluent enough to certify it.

What actually beats a plausible fake

Because the problem is architectural, the fix is architectural. You do not out-prompt a system whose objective is plausibility; you route around it. Stefan Szeider’s work makes the case concretely: a system that fetches bibliographic entries directly from an authoritative database and bypasses the language model at the export step hit an 82.7% perfect-match rate, against 28.2% for plain web search, and eliminated metadata corruption entirely (Szeider, 2025, pp. 2–3). The lesson is not that the model got smarter. It is that the moment the citation stops passing through the model’s own text, the fabrication stops.

For anyone not building infrastructure, the practical version is the same move a diligent opposing counsel makes by hand: confirm each reference exists against a real index before you trust anything it says. Pasting a reference list into cytado.com’s bibliography checker resolves each entry against bibliographic databases and flags the ones with no credible match — and since cytado is owned by this site’s operator, treat that as a disclosed interest, not a neutral tip. Whichever tool you use, the discipline is what matters, and it takes about a minute; we walk through it in how to check an AI citation in 60 seconds. If you want the full picture of how often the underlying fabrication happens, does ChatGPT make up sources lays out the measurements study by study.

None of this requires believing the model is broken or malicious. It is doing precisely what it was built to do — produce the most probable-looking text — and a citation is just text to it. The reference that looks perfect is not evidence that the paper exists. It is evidence that the model is good at its job. Treat every citation it hands you as a lead to be confirmed, never a fact already checked, and the most convincing fake on the page loses the only power it ever had.

Sources

Every factual claim above is tied to a source you can open and check, with page numbers wherever the source has them.

  1. 1. William H. Walters, Esther Isabelle Wilder, Fabrication and errors in the bibliographic citations generated by ChatGPT , Scientific Reports, 2023 , pp. 1, 2, 5. 10.1038/s41598-023-41032-5
  2. 2. Ertuğrul Safran, Adem Çalı, Fabricated or accurate? Ethical concerns and citation hallucination in AI-generated scientific writing on musculoskeletal topics , Anatolian Current Medical Journal, 2025 , pp. 695, 698. 10.38053/acmj.1746227
  3. 3. Stefan Szeider, Unmediated AI-Assisted Scholarly Citations , Open Conference Proceedings (AAAI-26), 2025 , pp. 2, 3. 10.52825/ocp.v8i.3161
  4. 4. Robin A. Emsley, ChatGPT: these are not hallucinations – they're fabrications and falsifications , Schizophrenia (npj), 2023 . 10.1038/s41537-023-00379-4
  5. 5. Nipun Misra, Vikranth Udandarao, Detecting Citation Hallucinations in Large Language Model Outputs , Proceedings of the AAAI Conference on Artificial Intelligence, 2026 . 10.1609/aaai.v40i48.42257
More on Fact-Checking AI Output
Built by Sitario.com