arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

水印:从不可能性到可审计合规

Watermarking: from Impossibility to Auditable Compliance

Fernando Delbianco, Fernando Tohmé, Hugo Acciarri

arXiv 2610.06317首次发表:更新:

发表机构

Universidad Nacional del Sur (UNS); CONICET–UNS(国立南方大学; 国家科学与技术研究理事会-国立南方大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对生成式文本水印在对抗移除下的不可能性,本文提出一种可审计合规方案,通过定义描述长度鲁棒性剖面和标签条件共形预测集,实现有限样本保证的检测与报告,并操作化欧盟AI法案的合规要求。

AI 中文摘要

欧盟人工智能法案第50条第2款要求生成式系统的提供者使合成输出具有机器可读性和可检测性,同时根据技术可行性、成本、内容特定限制和现有技术水平来限定有效性、互操作性、鲁棒性和可靠性。对于自由格式文本,一个重要的实现途径是实施生成式水印程序,这带来了一个难以解决的合规问题。强水印在对抗自适应移除时是不可能的,而普通编辑会削弱统计证据,且未标记的人类文本可能与机器输出在分布上重叠。本文开发了一种可审计的替代方案。首先,它定义了一个描述长度鲁棒性剖面。一个有限样本界表明可检测偏差会衰减,且所需样本量随衰减率的平方倒数增长。这用碰撞熵替代了未识别的香农熵常数。其次,它构建了标签条件共形预测集,具有独立的错误归因和错误排除水平,报告“水印支持”、“不支持”或“不确定”。覆盖率作为有限样本结果获得,并在可交换性下具有类别条件性。一个可复现的小型锦标赛水印模拟证实了这两个主张,并表明幸存令牌规则将可容忍编辑率高估了约两倍。由此产生的上市前证书、签名检测器报告和上市后重新校准协议,使委员会2026年实践准则得以操作化,而不声称具有普遍鲁棒性。

英文摘要

Article 50 (2) of the EU Artificial Intelligence Act requires providers of generative systems to make synthetic outputs machine-readable and detectable, while qualifying the effectiveness, interoperability, robustness, and reliability by technical feasibility, cost, content-specific limits, and the state of the art. For free-form text, one important implementation route is the implementation of a generative watermarking procedure, which poses a compliance problem that is hard to address. Strong watermarking is impossible against adaptive removal, while ordinary edits attenuate statistical evidence, and unmarked human text may overlap distributionally with machine output. This article develops an auditable alternative. First, it defines a description-length robustness profile. A finite-sample bound shows that detectable bias decays and that the required sample size grows with the inverse square of the decay rate. This replaces an unidentified Shannon-entropy constant with collision entropy. Second, it constructs label-conditional conformal prediction sets with separate false-attribution and false-exclusion levels, reporting ``watermark supported,'' ``not supported,'' or ``inconclusive''. Coverage is obtained as a finite-sample result and is class-conditional under exchangeability. A small reproducible simulation of a tournament watermark confirms both claims and shows that the surviving-token rule overstates the tolerable edit rate roughly twofold. The resulting premarket certificate, signed detector report, and postmarket recalibration protocol operationalize the Commission's 2026 Code of Practice without claiming universal robustness.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑