arXiv:2502.10673cs.CRcs.CL2025-02被引 15

用嵌入水印的伪装文档保护文本数据集版权

Dataset Protection via Watermarked Canaries in Retrieval-Augmented LLMs

  • 在数据集嵌入特制伪装文档,内容为合成生成
  • 通过查询检测响应中的水印信号,识别未经授权使用
  • 不影响原模型性能,适合数据版权方使用

检索增强生成(RAG)虽能提升大语言模型的时效性知识,但也存在恶意模型未经授权将受版权保护的数据集纳入知识库的风险。为保护数据所有权,本文提出新方法CanaryTrace,通过在原始数据集中插入具有合成内容和水印的伪装文档来实现版权保护。这些伪装文档完全保留原始数据结构,仅通过水印确保唯一性与可验证性。检测时,通过查询伪装文档并分析RAG模型输出中的水印统计特征,即可识别未授权使用。实验表明该方法具有高检测效率、强一致性及低扰动,且不损害RAG系统性能。

原文摘要 · Abstract (English)

Retrieval-Augmented Generation (RAG) has become an effective method for enhancing large language models (LLMs) with up-to-date knowledge. However, it may pose a risk of copyright infringement, as IP datasets may be incorporated into the knowledge database by malicious Retrieval-Augmented LLMs (RA-LLMs) without authorization. To protect the rights of the dataset owner, an effective dataset membership inference algorithm for RA-LLMs is needed. In this work, we introduce a novel approach, \textit{CanaryTrace}, to safeguard the ownership of text datasets and effectively detect unauthorized use by RA-LLMs. Our approach preserves the original data completely unchanged while protecting it by inserting specifically designed canary documents into the IP dataset. These canary documents are created with synthetic content and embedded watermarks to ensure uniqueness, consistency, and statistical provability. During the detection process, unauthorized usage is identified by querying the canary documents and analyzing the responses of RA-LLMs for statistical evidence of the embedded watermark. Our experimental results demonstrate high query efficiency, detectability, and consistency, along with minimal perturbation to the original dataset, all without compromising the performance of the RAG system.

数据版权RAG水印隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。