主张在硬件层用加密签名为真实内容打标,比纯AI水印更可信。
On-Device Watermarking: A Socio-Technical Imperative For Authenticity In The Age of Generative AI
- 从物理传感器层面为音视频内容加密签名,实现可信溯源
- 提出类HTTPS与Blu-Ray的认证框架,提升系统级可信度
- 适合关注内容真实性、政策落地的技术决策者
随着生成式AI输出越来越逼真,学术界和产业界正聚焦于检测内容是否由AI生成。尽管已有诸多进展,现有水印与AI检测技术仍存在严重局限。本文认为当前路径错误,应转向通过可信赖的加密签名来标记真实内容,而非仅依赖AI生成内容的水印。尤其对于音视频内容,其真实来源均源于物理世界并通过硬件传感器采集,这为在硬件层进行水印提供了独特机遇。本文提出一种社会技术框架,并类比HTTPS证书与Blu-Ray验证协议。尽管存在实施挑战,但硬件级认证在政策层面更具可行性。当生成模型接近感知不可区分时,研究社区应警惕对AI水印的过度乐观,建议将研究资源更多投向文本与大语言模型领域,因这些内容无法追溯至物理传感器。
原文摘要 · Abstract (English)
As generative AI models produce increasingly realistic output, both academia and industry are focusing on the ability to detect whether an output was generated by an AI model or not. Many of the research efforts and policy discourse are centered around robust watermarking of AI outputs. While plenty of progress has been made, all watermarking and AI detection techniques face severe limitations. In this position paper, we argue that we are adopting the wrong approach, and should instead focus on watermarking via cryptographic signatures trustworthy content rather than AI generated ones. For audio-visual content, in particular, all real content is grounded in the physical world and captured via hardware sensors. This presents a unique opportunity to watermark at the hardware layer, and we lay out a socio-technical framework and draw parallels with HTTPS certification and Blu-Ray verification protocols. While acknowledging implementation challenges, we contend that hardware-based authentication offers a more tractable path forward, particularly from a policy perspective. As generative models approach perceptual indistinguishability, the research community should be wary of being overly optimistic with AI watermarking, and we argue that AI watermarking research efforts are better spent in the text and LLM space, which are ultimately not traceable to a physical sensor.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。