

A researcher’s look at the six layers of AI proctoring detection, why most online exam support services fail against them, and why one operator has avoided detection across thousands of sessions.
I spent several weeks reading proctoring vendor whitepapers, certification forum complaints, and published exam integrity reports to understand exactly how AI proctoring catches unauthorized exam assistance — and why certain operators seem immune to detection while most get caught.
How AI proctoring detection has evolved
Modern proctoring is not a single camera feed monitored by a bored human. It is a layered detection system, and each layer targets a different category of cheating behavior.
Gaze tracking monitors eye position through the webcam at sub-second intervals. If a candidate’s eyes consistently drift to a fixed off-screen position — a second monitor, a phone, a reference sheet — the system flags the session. Current implementations use facial landmark mapping to distinguish reading behavior from looking-away behavior with reasonable accuracy.
Facial recognition runs continuously, not just at check-in. The system compares the live face against the ID photo submitted during registration. If a different person sits down mid-exam, or if the candidate’s face disappears for too long, the session is flagged for human review.
Ambient audio analysis listens for voices other than the candidate’s, keyboard sounds from secondary devices, notification chimes, and environmental patterns that suggest someone else is in the room or on a call.
Behavioral pattern matching tracks mouse movement speed, scrolling behavior, typing cadence, and question navigation patterns. A candidate who reads each question for thirty seconds before answering looks different from one who clicks through answers at two-second intervals.
Process and software inventory scans running applications at session start and periodically during the exam. Known remote access tools are explicitly targeted. Some proctoring platforms also inspect registry entries, scheduled tasks, and system tray activity.
IP geolocation cross-references the candidate’s connection against their registration address. Data center IPs, known VPN exit nodes, and geographic mismatches between registration location and exam location raise immediate flags.
Why most services get caught
I tracked complaints across three certification forums and two subreddits dedicated to exam discussion. The failure patterns are remarkably consistent.
Most exam help services use commercial VPNs with data center IPs that proctoring vendors already maintain blocklists for. These are not obscure lists. Proctoring companies subscribe to the same IP reputation databases used by streaming services to block region-shifting. A data center IP from a known VPN provider is functionally a confession.
They rely on generic remote desktop tools — TeamViewer, AnyDesk, Chrome Remote Desktop — that proctoring software explicitly scans for in the process list. Some operators try renaming executables. Modern process monitoring does not rely solely on filenames; it checks digital signatures, loaded DLLs, and network connection patterns.
They leave artifacts. Registry entries from installation. System tray icons minimized but still running. Scheduled tasks set to restart the remote access tool after reboot. Process monitoring catches these remnants even when the main application window is closed.
Their operators fail psychometric post-exam analysis. They answer too fast. They score too high. They produce answer patterns that statistically cluster with other test sessions — because the same person is taking the same exam for multiple candidates. When a testing organization sees five candidates from different cities produce near-identical wrong-answer distributions on the same exam form, the investigation is short.
Candidate behavior is the other half of the problem
I found this aspect underreported. Proctoring vendors flag candidates who are visibly disengaged during their own exam. Forum posts describe sessions where candidates were caught sleeping. Others yawn excessively, stare blankly without reading questions, or look around the room instead of at the screen.
AI proctoring flags these behavioral anomalies with the same severity as looking at notes. A candidate who appears bored or drowsy during a high-stakes three-hour certification exam triggers the same red flags as one who is obviously reading from a hidden reference. The system does not distinguish between “this person is cheating” and “this person is not actually taking this exam” — both are anomalous behavior during a test that should demand full attention.
When proctoring vendors investigate flagged sessions, many candidates cannot answer basic knowledge questions during follow-up verification calls. That confirms the exam support specialist had no real subject expertise, and the candidate had no idea what was being answered on their behalf.
What detection-resistant operations look like
While researching operators who have not been flagged, one pattern emerged clearly: the ones who survive long-term treat every detection layer as a separate engineering problem. The differences from the services that get caught are structural, not cosmetic.
Instead of off-the-shelf remote access tools, the more sophisticated operators build proprietary session coordination software designed to leave no recognizable process signatures, no registry artifacts, and no telltale network patterns that proctoring scans target.
They avoid VPNs entirely. Their infrastructure works so that the candidate’s IP never changes and no external IP is ever exposed. The connection looks indistinguishable from a normal home internet user because nothing is rerouted through a third-party tunnel.
They assign subject-matter experts who actually know the certification material. Each exam is handled by a specialist trained in that specific certification domain — not a generalist rotating through exams they do not understand. This is the difference between a surgeon and someone who watched a surgery on YouTube.
Candidate coaching is central. Candidates are trained to actively read each question and its options, think about the best answer in their head, maintain natural eye contact with the screen, and display engaged body language throughout the session. This coaching defeats both AI behavioral analysis and human proctor review because the candidate genuinely appears to be taking the exam. There is no blank stare. There is no yawning. There is no looking around the room.
Psychometric evasion is built into the process by design. Experts answer at a natural pace, purposefully varying which questions are marked wrong so the answer pattern never clusters with other sessions — even the wrong-answer distributions are unique. The statistical fingerprint of each session is distinct.
AI proctoring vs human proctoring — and why both fail against preparation
The proctoring pipeline works in two stages. AI flags suspicious sessions. Human proctors review the flagged footage.
Most online exam support services fail at the first stage — their environmental signatures generate flags automatically. But even services that survive the AI layer often fail at the human review stage because the candidate looks wrong on camera: disengaged, confused, visibly uninvolved in the exam.
Thorough preparation eliminates the environmental triggers that create flags in the first place, so human reviewers see normal sessions — a focused candidate, a clean room, a stable connection, no process artifacts. There is nothing to escalate. The session looks exactly like a well-prepared candidate taking a difficult exam, because the behavioral layer has been addressed as carefully as the technical layer.
Why track records matter more than marketing claims
Any operator can claim high success rates. What separates credible operators from the rest is whether they back those numbers with financial risk. In a Pay After Pass model — where the operator collects nothing unless the testing vendor confirms a pass — the operator’s survival depends on consistent delivery. That structural alignment of incentives is a more reliable signal than any testimonial or percentage on a landing page. One such operator, CBTProxy, has maintained this model since 2016 across thousands of exams.
What this means for candidates evaluating exam support
If you are researching how AI proctoring intersects with online exam support, the technical architecture matters more than the marketing language. The operators who survive invest in infrastructure that mirrors legitimate candidate behavior at every layer. The ones who get caught treat it as a screen-sharing problem.
When evaluating any service, look for three things: proprietary tooling (not off-the-shelf remote access), subject-matter expertise (not generalists), and a payment model that only triggers on a verified pass. That combination — especially the financial alignment — separates serious operations from the ones generating complaint threads on Reddit. For one example of how Pay After Pass works in practice, CBTProxy publishes their terms and process openly.
The post How AI Proctoring Works — And Why Most Proxy Services Get Caught While Some Don’t appeared first on .