Skip to content
Ideas

Idea · 2026

3 min read

Playable

An exam you cannot leak

The NEET leaks were not a cheating problem. They were a distribution problem wearing a cheating costume, and distribution problems have architectures.

Every time a national exam leaks, the conversation goes the same way. Stricter invigilation. More CCTV. Harsher penalties for the candidates caught with a phone.

All of which addresses the last hundred metres of a failure that happened weeks earlier, somewhere in a supply chain that moves a secret through printers, couriers, storerooms and district officials, and asks every one of them to be trustworthy on the same day.

You cannot fix that with invigilators. It is a distribution problem. We know how to build distribution systems that do not require every participant to be honest. We just have not pointed that knowledge at exams.

Run it yourself

Below is the architecture as a model. Pick how the leak is attempted, then switch individual controls off to see what each one was actually doing. That second part is the point: a design that claims to stop everything is marketing. A design worth having tells you precisely which failure it converts into a smaller failure.

1 · Choose a leak vector
2 · Switch controls off to see what they were doing
  1. 01Authored
  2. 02Sealed
  3. 03Distributed
  4. 04Unsealed
  5. 05Live
  6. 06Scored

Set a vector and the controls, then run the exam to see what happens.

The four controls

Per-copy sealing. Every printed paper carries an invisible variant (spacing, ordering, imperceptible marks) so a photograph identifies its source copy. This is traitor tracing, and it is old, well-understood technology. It does not stop the photograph. It removes the anonymity that makes leaking rational.

Time-locked centre keys. The packet is not merely sealed with wax, it is cryptographically unopenable until its key releases at T. A centre that tries to open early does not get a paper and a broken seal nobody notices. It gets nothing, and generates an alert. This converts the most common vector into a non-event.

In-hall attestation. Attested devices and RF monitoring, so capture-and-transmit is caught while it happens. This one is genuinely invasive and deserves a real argument about proportionality; I have put it in the model because pretending it is free would be dishonest.

Answer-pattern correlation. The backstop. Improbable answer agreement, clustered by centre or by time, catches what everything else missed. It is always too late to protect the sitting. It exists so that a leak cannot also be invisible.

The property that actually matters

Run the model with everything on and you will notice the interesting result is not "no leaks". It is that every remaining failure is small and known.

That is the realistic goal. Not an unleakable exam, but an exam where a leak affects one centre instead of six hundred, where you find out in seconds instead of after scoring, and where "we did not know" stops being an available answer.

Prevented
Early unsealing at a centre. The packet simply cannot open.
Contained
In-hall capture, caught during transmission, one candidate.
Traced only
Insider at the press: identified, not prevented.
Never
A leak that is both undetected and unattributable. That is the outcome this design removes.

Why I keep thinking about this

I build measurement systems. Measurement is the discipline of knowing what actually happened when everyone involved has an incentive to tell you something else, and exam integrity is exactly that problem with much higher stakes than an ad campaign.

Two and a half million candidates sat NEET. When it leaks, the cost is not statistical. It lands on specific people who did the work and lost the year.