TensorX
返回文献探索

Paper · arXiv 2306.04634

On the Reliability of Watermarks for Large Language Models

John Kirchenbauer, Jonas Geiping, Yuxin Wen, Manli Shu, Khalid Saifullah, Kezhi Kong, Kasun Fernando, Aniruddha Saha, Micah Goldblum, Tom Goldstein

6 upvotesJune 7, 2023arXiv 预印本
AI 摘要

Watermarking LLM-generated text is reliable and effective, especially in scenarios involving human paraphrasing and multiple text sources, with evidence compounding as more samples are observed.

large language modelsLLMsmachine-generated textwatermarkingspearphishing attackssocial media botsdetection schemeshuman paraphrasingsample complexity

Abstract

Large language models (LLMs) are now deployed to everyday use and positioned to produce large quantities of text in the coming decade. Machine-generated text may displace human-written text on the internet and has the potential to be used for malicious purposes, such as spearphishing attacks and social media bots. Watermarking is a simple and effective strategy for mitigating such harms by enabling the detection and documentation of LLM-generated text. Yet, a crucial question remains: How reliable is watermarking in realistic settings in the wild? There, watermarked text might be mixed with other text sources, paraphrased by human writers or other language models, and used for applications in a broad number of domains, both social and technical. In this paper, we explore different detection schemes, quantify their power at detecting watermarks, and determine how much machine-generated text needs to be observed in each scenario to reliably detect the watermark. We especially highlight our human study, where we investigate the reliability of watermarking when faced with human paraphrasing. We compare watermark-based detection to other detection strategies, finding overall that watermarking is a reliable solution, especially because of its sample complexity - for all attacks we consider, the watermark evidence compounds the more examples are given, and the watermark is eventually detected.

北京市昌平区探索星信息技术及软件开发工作室

京ICP备2026059466号
On the Reliability of Watermarks for Large Language Models | TensorX