发表机构
FAIR, Meta Superintelligence Labs; University of Maryland, College Park(Meta超级智能实验室; 马里兰大学帕克分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对LLM水印检测器未公开的问题,提出分钥公私水印方法,经实验验证其可在小编辑预算下提升水印移除效果,还能识别伪造,平衡了公开性与安全性。
AI 中文摘要
大型语言模型(LLM)水印技术常用于追踪聊天机器人和智能体的输出,但检测器仍未公开,因为暴露检测器可能让攻击者利用其反馈进行针对性编辑。不过,水印已易受不知情篡改攻击。因此,我们首先量化在不同访问级别(从 token 级分数到二元判定)下,公开检测器是否会成为部署环境中的额外风险。其次,我们提出一种分钥公私水印方法,该方法通过公开检测器暴露一把密钥,同时保留另一把密钥用于完整验证和取证。知情攻击者只能移动公开信号,造成公开分数与私有分数之间的不平衡;我们针对这种不平衡引入统计检验,并将其与完整密钥判定结合为两阶段机制。第三,我们在广泛的移除和伪造攻击上评估分钥方法,对比不知情设置与检测器知情设置。公开检测仅在小编辑预算下提升移除效果,因为单纯改写已能以更低质量成本去除水印,但它确实会启用伪造,而私有流程可识别伪造。总体而言,公开一半水印可实现透明度和互操作性,且对公开部分的篡改仍可检测,这限制了提供者的责任,并质疑是否需要将检测器完全保密。
英文摘要
Watermarking large language models is popular for tracing chatbot and agentic outputs, yet detectors remain unreleased since exposing them could let attackers do targeted edits with the detector's feedback. However, watermarks are already vulnerable to uninformed tampering attacks. We thus first quantify whether a public detector would be an additional liability in a deployment setting at varying levels of access, from token-level scores to a binary verdict. Second, we introduce a split-key public-private watermarking method that exposes one key through a public detector while keeping the other for full verification and forensics. An informed attacker can only move the public signal, creating an imbalance between public and private scores. We introduce a statistical test for this imbalance, and combine it with the full key verdict in a two-stage mechanism. Third, we evaluate the split-key method on a wide range of removal and forgery attacks, comparing the uninformed to detector-informed settings. Public detection improves removal only at small edit budgets, since plain rephrasing already strips the watermark at a lower quality cost, but it does enable forgery, which the private pipeline can identify. Overall, releasing half of the watermark enables transparency and interoperability, and tampering with the released half stays detectable. This bounds the provider's liability and questions the need to keep detectors fully private.