arXiv:2506.15975cs.CRcs.CL2025-06被引 3

同一水印同时用于检测与识别会引发误判,新方法有效降低误报率。

Multi-use LLM Watermarking and the False Detection Problem

  • 设计双水印机制,分离检测与用户识别功能
  • 实验显示误报率显著下降,检测准确率保持高位
  • 适合需要高可信度水印验证的生成文本场景

数字水印是缓解自动文本滥用风险的有前景方案。现有方法或嵌入通用水印以检测特定采样器生成的内容,或嵌入特定密钥以识别LLM用户。但若同一嵌入同时用于检测和识别,随着用户容量增加,未加水印的文本将更易被误判为带水印。通过理论分析,我们揭示了该现象的根本原因。基于此,提出双水印机制,将检测与识别水印联合编码至生成文本中,在显著降低误报率的同时保持高检测精度。实验结果验证了理论发现,并证明了方法的有效性。

原文摘要 · Abstract (English)

Digital watermarking is a promising solution for mitigating some of the risks arising from the misuse of automatically generated text. These approaches either embed non-specific watermarks to allow for the detection of any text generated by a particular sampler, or embed specific keys that allow the identification of the LLM user. However, simultaneously using the same embedding for both detection and user identification leads to a false detection problem, whereby, as user capacity grows, unwatermarked text is increasingly likely to be falsely detected as watermarked. Through theoretical analysis, we identify the underlying causes of this phenomenon. Building on these insights, we propose Dual Watermarking which jointly encodes detection and identification watermarks into generated text, significantly reducing false positives while maintaining high detection accuracy. Our experimental results validate our theoretical findings and demonstrate the effectiveness of our approach.

水印大模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。