Back to BlogTroubleshooting

Students Are Cheating the Online Exam: Integrity Fixes That Work

Rupak Amin

Founder & Lead Engineer, RAITHub

8 min read

RAITHub ships and tests production software. See QA as a Service or talk to us.

When students are cheating your online exam, work out how before spending on tools. Most cheating is one of four things: shared answers, extra attempts, a tampered clock, or help from a second device. The fixes that work reduce what cheating gains: randomise papers from pools, enforce the timer and one-attempt rule on the server, and log everything. Lockdown browsers and AI proctoring help far less than vendors claim.

If you would rather have RAITHub diagnose and harden your exam engine, see how below.

This post is for EdTech teams, coaching centres and institutes whose online exams are being gamed. It is engineering guidance. RAITHub's education build is PadhAI, an AI tutoring platform. The build details for a new exam engine, including the timer and SEB code, are in online exam software: question banks, timers and anti-cheating that works; this post is the incident case, fixing an exam that is already being cheated.

How are students actually cheating the exam?

Diagnose before you defend. The right fix depends entirely on the method, and logs usually tell you which one it is.

MethodSign in the dataWhat stops it
Sharing answers between studentsIdentical answers, same wrong options, same orderQuestion pools and per-student randomisation
Extra or restarted attemptsMultiple attempt rows per student; suspicious retriesOne attempt per student, enforced as a database constraint
Clock or refresh tricks for more timeSubmissions after the deadline; timers that resetA server-owned deadline checked on every save
Help from a phone or second deviceLittle in your logs; it happens off-screenSupervision, pools, parameterised questions; not a browser
Impersonation (someone else sits it)Hard to see without identity checksSupervised identity checks; proctoring with human review

Pull the attempt and answer logs for the suspect exam first. Identical papers point to sharing; late submissions point to a timer that the browser, not the server, controls.

Which fixes actually reduce cheating?

The ones that change what a cheater can gain, and they are mostly cheap engineering, not expensive tools. Moodle's own documentation is blunt about the ceiling here: "There is a limit to what the quiz, which runs on a web server, can do to restrict what the student sitting at their computer can do while attempting the quiz" (Moodle: quiz settings). Within that limit, these work.

  • Draw each paper from a pool. "Pick 5 from 30 of similar difficulty" gives each student a different paper, so a shared answer key is worth little. A fixed paper in a shuffled order is not enough.
  • Parameterise numeric questions. Generate the numbers per student and compute the answer on the server, so a shared final answer is useless to the next student.
  • Own the clock on the server. Store the deadline when the attempt starts and check every save and submit against server time. Changing the laptop clock or refreshing does nothing.
  • Enforce one attempt as a constraint. A unique key on exam and student means two tabs or a double-click cannot create a second attempt.
  • Fix the paper at start and log everything. Draw questions and order once, store them on the attempt, and keep an audit trail of every answer and event, so a dispute is decided by evidence. The pattern is in designing an audit log customers trust.

Which anti-cheating measures are mostly theatre?

The ones that try to watch the student's room through a browser. They cost more, produce false alarms, and miss the phone under the desk.

MeasureWhat it stopsWhat it misses
Disabling copy, paste, right-clickCasual copying of question textA phone camera
Tab-switch / focus-loss detectionRecords that focus left the pageA second device; it also fires on notifications
Webcam / AI proctoringSome obvious behaviour and impersonationDetermined cheating; it produces flags a human must review
Browser lockdown aloneOther apps on that one computerA phone, a second device, another person in the room

Browser lockdown is useful in the right place. Safe Exam Browser is software that "controls access to resources like system functions, other websites and applications and prevents unauthorized resources being used during an exam" (Safe Exam Browser overview), and your server can reject exam requests that do not come from a correctly configured instance. But it does not see a phone, so it belongs in supervised rooms and on managed laptops, not as a cure on its own.

How do I harden an exam that is already being cheated?

Work in order of impact, and do the free changes before buying anything.

StepChangeEffort
1Audit the logs: identify the method from attempt and answer dataHours
2Move the timer and one-attempt rule to the server if they are not alreadyDays
3Convert fixed papers to pools; parameterise numeric questionsDays to weeks, mostly question authoring
4Add full attempt and answer logging for disputesDays
5Add SEB checks and supervision for high-stakes exams onlyWeeks; policy as much as code

Test the clock edges deliberately: a save one second before the deadline, one after, after the grace period, and from two tabs. These bugs only show under real conditions, so keep the tests in CI, as in regression testing on every deploy. If the exam also slows or times out at the start, that is a separate problem, covered in surviving the exam-season concurrency spike.

What about high-stakes exams?

For exams that gate a qualification, no remote browser measure substitutes for supervision. Use in-person invigilation or a reputable proctoring provider with human review, clear consent, and a data-protection check, and keep your server-side controls underneath. Remote proctoring records students, often minors, in their homes, and consent, retention and privacy rules vary by country. This is general information; confirm with your adviser before you switch it on.

How RAITHub would fix this

Scope:

  • A log audit to identify how the exam is being cheated, from attempt and answer data.
  • Server-owned timer and a one-attempt-per-student database constraint, if not already in place.
  • Question pools and parameterised numeric questions, so shared answers lose their value.
  • Full attempt and answer logging for defensible dispute resolution.
  • Optional Safe Exam Browser request checks for supervised exams, and clock-edge tests in CI.

Timeline: hardening an existing exam engine is a 2–4 week code rescue engagement; a new or heavily rebuilt assessment platform follows the SaaS development path. You receive: automated tests and CI, handover docs and an exam-day runbook, and full IP under an NDA signed before detailed discussion. Student data stays in your own cloud account; development uses synthetic data. This is application-level hardening, not a certified security or compliance assessment. Next step: a free 15-minute technical audit, then a written fixed quote; RAITHub publishes no rates. See what RAITHub builds for education on the EdTech industry page, and book the free audit with the exam logs and how exams are supervised today.

Frequently asked questions

How do I know how students are cheating my online exam?

Start with the attempt and answer logs. Identical answers and option orders point to shared keys; multiple attempt rows point to reused attempts; submissions after the deadline point to a browser-controlled timer. The data usually names the method, and the method decides the fix.

What actually stops online exam cheating?

Measures that reduce what cheating gains: draw each paper from a question pool, parameterise numeric questions, enforce the timer and one-attempt rule on the server, and log everything. These are cheap engineering, and they beat expensive tools that try to watch the student's room through a browser.

Does a lockdown browser stop cheating?

Partly, in the right place. Safe Exam Browser locks down the one computer it runs on, which helps in supervised rooms and on managed laptops, and your server can reject requests that do not come from a configured instance. It cannot see a phone, a second device or another person, so it is not a cure on its own.

Is AI proctoring worth it?

Only with care and human review. AI proctoring produces flags, not proof, so a person must review them, and it records students in their homes, raising consent and privacy questions. For most exams, better question design and a server-enforced timer buy more integrity per unit of cost.

How do I stop students getting extra time?

Store the deadline on the server when the attempt starts and check every save and submit against server time, with a short grace period for a save in flight. The browser countdown is display only, and a server job auto-submits attempts once the deadline passes. Changing the device clock or refreshing changes nothing.

How should high-stakes exams be protected?

With supervision, not just browser tools. Use in-person invigilation or a reputable proctoring provider with human review, clear consent and a data-protection check, kept on top of server-side controls. Confirm consent, retention and privacy obligations with your adviser, as they vary by country.

online exam cheatingexam integrityanti-cheatingquestion randomisationproctoringassessment security

Ready to discuss your project?

Book a free 15-minute technical audit with our engineering team.