DenMark:用于扩散语言模型的鲁棒语义水印
DenMark: Robust Semantic Watermarking for Diffusion Language Models
浏览论文内容
中文总结 AI 辅助
DenMark通过将密钥信号注入扩散模型去噪过程,利用临时展开进行语义前瞻,实现鲁棒语义水印,在多种模型和攻击下检测性能最优。
中文摘要 AI 辅助
语义文本水印将信号编码在语义中而非表面的词元选择上,从而对释义和其他保持语义的编辑具有鲁棒性。现有的语义水印方法主要针对自回归语言模型(ARLMs)设计,在生成进行之前,可以生成并评分完整的候选单元。这种范式不能自然地扩展到扩散语言模型(DLMs),因为在中间去噪步骤中语义单元保持不完整,且词元可以以灵活的顺序更新。我们提出DenMark,一种语义水印框架,直接将密钥相关信号注入DLM去噪过程。DenMark将输出划分为固定的词元区域,并使用临时展开作为语义前瞻:条件补全估计不完整区域的最终语义,使DenMark能够选择具有更高估计语义水印分数的局部更新。在去噪步骤中重复此过程,逐步在最终输出中累积水印证据。对于检测,DenMark使用校准扫描覆盖候选单元大小,以保持对语义攻击引入的边界偏移的鲁棒性。在四个DLM、三个数据集和四种语义攻击中,DenMark在所有48种骨干-数据集-攻击组合的所有报告检测指标上均达到最佳结果。这些结果表明,DenMark为DLM中的鲁棒语义水印提供了一种有效机制。
英文摘要
Semantic text watermarks encode signals in meaning rather than surface token choices, offering robustness to paraphrasing and other semantic-preserving edits. Existing semantic watermarking methods are primarily designed for autoregressive language models (ARLMs), where completed candidate units can be generated and scored before generation proceeds. This paradigm does not naturally extend to diffusion language models (DLMs), where semantic units remain incomplete during intermediate denoising steps and tokens may be updated in flexible orders. We propose DenMark, a semantic watermarking framework that injects key-dependent signals directly into the DLM denoising process. DenMark partitions the output into fixed token regions and uses temporary rollouts as semantic lookahead: conditional completions estimate the eventual semantics of an incomplete region, enabling DenMark to select local updates with higher estimated semantic watermark scores. Repeating this procedure across denoising steps progressively accumulates watermark evidence in the final output. For detection, DenMark uses calibrated scanning over candidate unit sizes to remain robust to boundary shifts introduced by semantic attacks. Across four DLMs, three datasets, and four semantic attacks, DenMark achieves the best results across all reported detection metrics in all 48 backbone-dataset-attack combinations. These results demonstrate that DenMark provides an effective mechanism for robust semantic watermarking in DLMs.
发表机构
- The University of Tokyo(东京大学)
- RIKEN Center for Advanced Intelligence Project(理化学研究所先进智能研究中心)
机构由 AI 辅助整理,请以论文原文为准。