arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.10103cs.CRcs.CL

大语言模型水印:理论与部署综述

LLM Watermarking as Big Data Provenance: A Deployment-Oriented Systematization

  • Truman State University(特伦特州立大学)
  • University at Albany, State University of New York(纽约州立大学阿尔巴尼分校)

机构由 AI 辅助整理,请以论文原文为准。

Huy Phan, Kieu Dang, Ojaswi Dulal, Aiham AL Shukairi, Abby Shine, Chase Garner, Phung Lai

AI总结:

综述大语言模型水印技术,通过从业者核心问题组织内容,综合技术家族并分析安全效用权衡,回顾攻击策略、评估协议等,为LLM水印设计提供实际指导,明确可靠部署的研究方向。

AI中文摘要:

大语言模型(LLMs)越来越多地嵌入到高影响力工作流程中,但其大规模生成流畅文本的能力增加了出处模糊、模型滥用和大规模内容清洗的风险。LLM水印作为一种有前景的技术层,可在模型输出中嵌入不可见签名用于溯源、审计和下游信任决策。然而,相关文献增长迅速且不均衡。本文进行了系统的、面向部署的LLM水印综述。通过从业者必须回答的核心问题组织相关内容,包括水印嵌入位置、检测方、假设条件和针对的威胁模型等。综合了主要技术家族,分析其安全效用权衡,还回顾了攻击和规避策略、评估协议和指标以及开放挑战等。最后提供了实际指导并确定了可靠、可问责的LLM部署所需的研究方向。

英文摘要:

As large language models (LLMs) become widely deployed, their outputs can be copied, transformed, and redistributed at scale without reliable evidence of origin, creating risks for trust, accountability, intellectual property (IP) protection, and high-stakes decision-making. LLM watermarking addresses this problem by embedding detectable signals into text during or after generation. However, existing methods vary in design assumptions, threat models, and evaluation criteria, while deployment choices such as watermark placement, detection authority, and key management affect reliability, security, and scalability. This paper systematizes LLM watermarking as provenance infrastructure for large-scale data ecosystems. We organize existing approaches along four deployment dimensions: insertion point, verification authority, operational state, and transformation threat model, and relate them to the big data requirements of Volume, Velocity, Variety, Veracity, and Value. We further introduce a Big Data Watermarking Readiness framework centered on four deployment workloads: online generation, streaming detection, transformation pipelines, and ecosystem governance. The framework connects these workloads to system-level requirements including throughput, false-positive control, robustness, cross-domain reliability, governance, and downstream utility. Our analysis highlights a gap between benchmark performance and deployment readiness: false positives accumulate at scale, repeated transformations weaken watermark signals, computational overhead can limit online deployment, and centralized verification can create governance bottlenecks. We conclude with an evaluation blueprint and research directions for scalable, trustworthy provenance in big data ecosystems.

↑