arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.03844cs.CRcs.CLcs.LG

翻转而非打乱:以推理速度对大语言模型(LLM)加水印

Flip, Don't Shuffle: Watermarking LLMs at the Speed of Inference

Simone Ceppi, Ignacio Sanchez

首次发表
浏览论文内容

中文总结 AI 辅助

该研究提出SBW水印方法,复杂度为O(1),开销低于1%,速度远快于现有方法,可兼容分布式推理,哈希函数优化后性能提升且文本更多样。

中文摘要 AI 辅助

我们提出无状态伯努利水印(Stateless Bernoulli Watermark, SBW),一种针对大语言模型的新型统计水印,通过逐词独立的伯努利试验确定绿色列表成员资格。与KGW的词汇置换或SynthID的多层锦标赛不同,SBW仅需将每个词与基于计数器的随机数生成器进行一次比较,将成员资格复杂度降至O(1),并支持单内核执行且无中间分配。我们证明该公式保留了与固定大小绿色列表相同的检测保证:在原假设下,z分数检验服从标准正态分布N(0,1)。无状态架构具备现有方法无法实现的能力:全词汇自加盐水印(尽管通过候选相关种子对整个词汇进行偏置,速度仍比KGW的自加盐快6000倍以上,比SynthID快2倍),以及与分布式推理的架构兼容性。在端到端生成基准测试中,SBW在所有批量大小下添加的开销均低于1%。我们还确定哈希函数设计是水印质量的一个此前未被探索的维度,表明GPU原生的Jenkins哈希将原假设校准提升1.8倍,同时生成更多样的文本。对两种种子方案和八种(γ, δ)配置的实验证实其与统计等效性,ROC-AUC差异低于0.01。

英文摘要

We introduce Stateless Bernoulli Watermarking (SBW), a new statistical watermark for Large Language Models that determines green list membership through independent per-token Bernoulli trials. Unlike KGW's vocabulary permutation or SynthID's multi-layer tournament, SBW requires only a single comparison per token against a counter-based random number generator, reducing membership complexity to $O(1)$ and enabling single-kernel execution with zero intermediate allocations. We prove that this formulation preserves the same detection guarantees as fixed-size green lists: the z-score test remains $\mathcal{N}(0,1)$ under the null. The stateless architecture enables capabilities unavailable to existing methods: full-vocabulary self-salt watermarking (over 6000$\times$ faster than KGW's self-salt and 2$\times$ faster than SynthID despite biasing the entire vocabulary with candidate-dependent seeding) and architectural compatibility with distributed inference. In end-to-end generation benchmarks, SBW adds less than 1\% overhead at all batch sizes. We additionally identify hash function design as a previously unexplored axis for watermark quality, showing that a GPU-native Jenkins hash improves null calibration by 1.8$\times$ while producing more diverse text. Experiments across two seeding schemes and eight $(γ, δ)$ configurations confirm statistical equivalence with ROC-AUC differences below 0.01.

发表机构

  • European Commission(欧洲委员会)
  • Joint Research Centre(联合研究中心)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑