arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

SimpleMark: 在 f-散度约束下的快速多比特文本水印

SimpleMark: Fast Multi-Bit Text Watermarking under f -Divergence Constraints

Benjamin D. Kim, Wanrong Zhang, Weitong Ruan, Lav R. Varshney, Daniel Alabi

arXiv 2610.05712首次发表:更新:

发表机构

Massachusetts Institute of Technology; Amazon; Stony Brook University; University of Illinois Urbana-Champaign(麻省理工学院; 亚马逊; 石溪大学; 伊利诺伊大学厄巴纳-香槟分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

我们提出一个基于 f-散度约束的多比特文本水印框架,通过最优偏置词元分布实现低可检测性,同时保持消息恢复性能和生成质量。

AI 中文摘要

我们提出了一种多比特文本水印框架,其安全性直接通过基础语言模型分布的 f-散度来定义。与先前关注平均密钥失真无关性或特定统计距离的方法不同,我们的公式支持一般的 f-散度,包括全变差和 KL 散度,并为每个实现的密钥和嵌入消息强制执行保证。我们开发了一种基于编码的水印方案,在规定的散度预算下最优地偏置下一个词元分布,并刻画了嵌入率、解码可靠性和统计安全性之间的权衡。在实验中,我们将我们的方法与先前的多比特水印方案在现代语言模型和载荷场景下进行了比较。我们的方法在保持竞争力的消息恢复性能和生成质量的同时,实现了显著更低的水印可检测性。我们的结果提供了安全多比特水印的统一视角,并将几种常用的安全概念作为特例恢复。

英文摘要

We introduce a framework for multi-bit text watermarking with security defined directly through $f$-divergence from the base language model distribution. Unlike prior approaches that focus on average-key distortion-freeness or a particular statistical distance, our formulation supports general $f$-divergences, including total variation and KL divergence, and enforces the guarantee for each realized key and embedded message. We develop a coding-based watermarking scheme that optimally biases next-token distributions subject to a prescribed divergence budget, and characterize the resulting tradeoff between embedding rate, decoding reliability, and statistical security. Experimentally, we compare our method against prior multi-bit watermarking schemes across modern language models and payload regimes. Our approach achieves substantially lower watermark detectability while maintaining competitive message-recovery performance and generation quality. Our results provide a unified view of secure multi-bit watermarking and recover several commonly used security notions as special cases.

Comments39 pages, 10 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑