Academic integrity guide
How to Catch Students Cheating in Online Exams
You catch students cheating in online exams by collecting corroborating signals from the device during the session and reviewing them together, rather than relying on a webcam feed or a plagiarism score after the fact. The signals that matter most — hidden AI assistants, overlay windows, remote control, injected input, and secondary displays — all live outside the browser. ScreenComply captures those signals at the operating-system level and packages them into a timestamped report a reviewer can defend.
The signals that actually indicate assistance
Isolated anomalies are weak evidence. A student glancing away means little on its own; a student glancing away in the same seconds an always-on-top window appears and typing cadence shifts to paste-and-modify is a very different picture. Catching cheating well means correlating independent signals in time.
Practically, that means treating the session as a stream of events rather than a video to skim. The strongest cases come from several independent signal families lining up around the same moments of the assessment.
- A restricted AI application or browser extension running during the session.
- Transparent or always-on-top windows appearing while questions are on screen.
- Focus loss to another application immediately before answer entry.
- Typing cadence that indicates transcription or paste-and-modify rather than composition.
- Additional displays reported by the operating system that were not declared.
- Remote-access sessions, virtualization, or non-local input sources.
Why browser-based proctoring misses modern AI assistants
Most proctoring tools are built as browser extensions or lockdown browsers. They can see the tab, the page, and sometimes the webcam, but their visibility ends at the edge of the browser process. Modern AI assistance does not live inside the browser.
Tools such as invisible interview copilots and always-on-top answer overlays run as native desktop applications. They render above every other window, are frequently excluded from screen capture and screen share, and never touch the exam tab. A lockdown browser can be perfectly locked down while an assistant quietly reads the question and displays an answer on the same screen.
The same gap applies to remote-control software, virtual machines, injected keyboard input, and a second device sitting off camera. None of these leave a trace inside the browser, which is why a session can look clean in a browser-only tool and still be assisted end to end.
- Native overlay applications draw above the browser and are often invisible to screen sharing and screen recording.
- Remote-access tools let another person drive the machine without any browser-visible signal.
- Virtual machines and sandboxes let a candidate run the assessment in a controlled environment with helpers outside it.
- Synthesized or injected keyboard input can type answers that were never physically typed.
- A second phone, tablet, or monitor off camera leaves nothing at all in the browser.
What device-level detection actually sees
Detecting AI assistance reliably requires observation at the layer where the assistance runs: the operating system. ScreenComply pairs a browser-based API with an optional desktop agent that inspects the environment around the assessment rather than only the page inside it.
The agent enumerates running processes and browser extensions against a continuously updated list of AI assistants, answer overlays, and interview-copilot tools. It looks for always-on-top and transparent windows, remote-access sessions, virtualization, screen-capture drivers, additional connected displays, and USB storage events. It checks whether keyboard input originates from local physical hardware, and it records focus changes, clipboard events, and typing cadence patterns that distinguish composition from paste-and-modify behavior.
No detection system is perfect, and ScreenComply does not claim to catch every form of assistance. The goal is different and more useful: gather corroborating, timestamped signals so a human reviewer can make an informed, defensible decision instead of guessing from a webcam thumbnail.
- Process and extension enumeration against a maintained AI-assistant list.
- Overlay and always-on-top window detection, including windows excluded from screen share.
- Remote access, virtual machine, and screen-capture detection.
- Multi-monitor enumeration queried from the operating system, not inferred from gaze alone.
- Input-source integrity, clipboard and paste events, and typing-cadence analysis.
- Network and secondary-device signals on the local network.
How audit-ready integrity reports work
A detection is only useful if it can be explained to someone who was not in the room. Every ScreenComply session produces a structured integrity report: an executive verdict with a risk level, a chronological evidence timeline, and the underlying signal detail behind each entry.
Each entry is timestamped and tied to the specific observation that produced it, so a reviewer can see what was detected, when it happened, and how strong the signal was. Reports are written in non-accusatory, factual language, because the institution or employer makes the decision, not the software.
Reports can be exported to PDF and shared with a secure link, which is what makes them usable in academic-integrity hearings, HR reviews, and compliance audits. Retention is configurable, including tiers that minimize or eliminate stored artifacts for privacy-sensitive programs.
- Executive verdict with a graded risk level rather than a pass/fail guess.
- Chronological, timestamped evidence timeline linked to underlying signals.
- Human-review-by-design framing: factual observations, not accusations.
- PDF export and secure sharing for hearings, HR files, and audits.
- Configurable retention, up to zero-retention operating modes.
Reviewing a flagged session without overreaching
Detection systems produce signals, not conclusions. Some flags have innocent explanations: a notification stealing focus, an accessibility tool synthesizing input, an unusual but legitimate hardware setup. Treating every flag as misconduct erodes trust in the process and produces cases that collapse under appeal.
The workflow that holds up is straightforward: read the executive verdict, walk the evidence timeline, look for corroboration across independent signals, check whether an accommodation or environmental explanation covers the finding, and only then apply the institution's academic-integrity process. ScreenComply writes reports in non-accusatory language for exactly this reason.
Where to go next
Frequently asked questions
How can teachers tell if a student used AI on an exam?
Text-based AI detectors are unreliable on their own. Session-level evidence is stronger: a restricted assistant running on the device, an overlay window appearing during questions, focus loss before answers, or input that did not originate from local physical hardware.
Can you detect a second monitor or a phone?
Additional displays are enumerated directly from the operating system rather than inferred from gaze. Secondary devices on the local network can also produce detectable signals, though a fully offline device off camera remains difficult for any system to observe.
Is webcam monitoring enough?
No. A webcam shows a face and a room. It cannot see what runs on the machine, and modern assistance is designed to be silent and on-screen, which is why device-level signals matter more than video alone.
Does ScreenComply record the exam screen?
Capture behavior depends on the privacy tier the institution selects, including modes that minimize or eliminate stored artifacts. Retention is configurable, and the report remains usable without maximal capture.
Can a flagged session be appealed?
Yes. Reports are built for review: every finding is timestamped and linked to the observation behind it, so a student, instructor, or integrity board can examine the same evidence rather than argue over an opaque score.
ScreenComply is under contract with the State of Montana. SOC 2 Type 2 examination in progress.
See a session, a detection, and a report
A short walkthrough of live detection, Detect versus Prevent mode, and the integrity report your reviewers would actually receive.