If you don’t want AI scrapers training themselves on your website, there’s a new way to stop them that doesn’t involve server-side blocking or praying they respect your instructions in robots.txt. A team of creatives have teamed up with a typography company to create a new type of font that’ll trick LLM scrapers into ingesting poisoned gibberish.
Dubbed ShieldFont, the open-source project almost seems like magic if you’re not familiar with the ins and outs of computer fonts. Look at a web page written using a ShieldFont font and it’ll appear exactly as one would expect: All the content words (the nouns, verbs, adjectives and adverbs that give a sentence meaning) are the same as the writer originally wrote.
Inspect the raw HTML that a scraper reads from a ShieldFonted page, however, and you’ll see a sentence that’s essentially gibberish. Typing “good luck reading this, you useless robot” in the online demo version, for example, turns it into “good comfort reading this, you yellow barrier.”
The goal, as outlined in the ShieldFont white paper, is not to get a scraping bot to reject the text as garbage, but to convince it that the text on the page is unusual but sensible. A noun will never be swapped for a verb, for example, and a verb will never be swapped for an adjective: Swaps only come from the same grammatical pool.
Yeah, because fuck accessibility, right?
It’s amazing how many people who work in web are clueless about WCAG. Screen readers weren’t even an afterthought here.
Clever, but disabled people using screen readers shouldn’t be ignored or considered just collateral damage. 🙁
Yup. This project is cutting off the nose to spite the face. So easily worked around by any scraper, but makes the website worse for actual users. Accessibility is usability.
Unfortunately, any tools a screen reader can use to read the page are tools a LLM can use. Without challenge-based solutions like Anubis, I’m not sure what can really be done that isn’t IP whack-a-mole.
If it comes down to losing accessibility or losing the website due to scrapers obliterating the hosting costs, then I think most website admins would rather just put a “use OCR” message at the top of their skip nav.
As much as I hate using JS for this, I wonder if there’s a JS-based solution that gets the best of both worlds while killing off scraping. Serve this obfuscated trash initially, then swap it out after completing some challenge sometime after FCP.
I assume a screen reader that used OCR instead of just copying the text would work (for example, being able to read text in images)
Yes, but this is not typical and the experience is degraded compared to traditional screen readers. There are some that have limited OCR capabilities, but they’re typically used for images without alt text or PDFs that are images.
This is a horrible idea. Accessibility is fairly complicated. Websites are difficult enough to navigate without this.
pointless and easily worked around. these fonts would have a unique signature that can be detected and decoded same way the browser is doing it. basically its relying on obscurity to work.
Though it does change the landscape and introduce additional computation for those scraping.
If they make a mistake and don’t account for all the ways the model can be poisoned they risk significant capital training only to identify an issue causing degraded results.
Imagine if everyone did this differently on many websites. It would cause a re-evaluation of scraping costs.
Ultimately, things like this may well change human behavior through changed LLM behavior.
Human language evolves through use and social context. People use LLMs.
Much like youth speak becoming mainstream, people may eventually use words or formulations inspired by LLM use.
very rose colored glasses. the extra work to identify such sites is trivial less than even the hashing approach anubis uses.
risks are minimal for data pipelining on the training side. you can bootstrap a classifier that errors towards reject to sweep 99% of the weirdness this thing is doing in a few days. we already have clean datasets we can use to baseline such systems.
on top of that its fairly easy to detect if a run is failing due to collapse. the capital costs are small.
Yes, rose coloured. But I’d rather be in an environment where there are a million ways to make the life of a scraping AI company hard so it’s impossible for them to account for everything.
More options, are more better especially when they are otherwise meanlessly different for users.
Also there is evidence that poisoning an AI’s training set does not require much data.
top contributor to repo: Claude







