arXiv:2411.19563cs.CL2024-11ACL被引 8

用多重水印组合提升大模型文本识别率,防篡改能力强。

Ensemble Watermarks for Large Language Models

  • 将三种水印特征融合成集成水印,增强鲁棒性。
  • 经改写攻击后仍保持95%检测率,远超单一水印的49%。
  • 适配多场景需求,检测方法统一无需调整。

随着大语言模型(LLMs)达到类人流畅度,区分其生成文本与人类写作愈发困难。现有水印方法灵活性差,易受改写攻击影响。为此,我们提出一种多特征集成水印方法,融合首字母诗(acrostica)、感官运动规范(sensorimotor norms)与经典的红绿水印。实验显示,三者组合在多种模型与水印强度下均实现98%检测率;经改写攻击后仍保持95%检测率,而红绿水印单独使用仅49%。所有组合中,三者集成表现最优。该方法支持灵活配置,且检测函数无需适配不同组合,适用于促进责任追究与防范社会危害。

原文摘要 · Abstract (English)

As large language models (LLMs) reach human-like fluency, reliably distinguishing AI-generated text from human authorship becomes increasingly difficult. While watermarks already exist for LLMs, they often lack flexibility and struggle with attacks such as paraphrasing. To address these issues, we propose a multi-feature method for generating watermarks that combines multiple distinct watermark features into an ensemble watermark. Concretely, we combine acrostica and sensorimotor norms with the established red-green watermark to achieve a 98% detection rate. After a paraphrasing attack, the performance remains high with 95% detection rate. In comparison, the red-green feature alone as a baseline achieves a detection rate of 49% after paraphrasing. The evaluation of all feature combinations reveals that the ensemble of all three consistently has the highest detection rate across several LLMs and watermark strength settings. Due to the flexibility of combining features in the ensemble, various requirements and trade-offs can be addressed. Additionally, the same detection function can be used without adaptations for all ensemble configurations. This method is particularly of interest to facilitate accountability and prevent societal harm.

水印技术大模型安全文本检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。