arXiv:2510.20075cs.AIcs.CL2025-10被引 1

用大模型将秘密文本藏入等长的表面文本中,实现隐形信息传递。

LLMs can hide text in other text of the same length

  • 利用大模型生成表面文本,隐含真实信息,保持语义连贯。
  • 80亿参数模型即可在秒级完成编码解码,本地可运行。
  • 适用于隐蔽传播敏感内容,挑战AI可信性与知识定义。

有意义的文本可以被隐藏在另一段完全不同但依然通顺可信的等长文本中。例如,一条严厉的政治批评可嵌入赞美同一政治人物的推文,或普通产品评论中可隐藏秘密手稿。这一现象得益于大语言模型,本文提出名为Calgacus的简单高效协议来实现。我们证明,即使使用仅80亿参数的开源大模型,也能获得高质量结果,且该摘要长度的消息可在笔记本电脑上秒级完成编码与解码。该技术揭示了文本与作者意图的彻底分离,进一步削弱人们对书面交流的信任,而这一信任本已因大模型聊天机器人兴起而动摇。我们以具体场景为例:公司可暗中部署未经过滤的大模型,将其回答编码进安全模型的合规回应中。这引发关于AI安全的紧迫问题,并挑战我们对大模型‘知道’某事的定义。

原文摘要 · Abstract (English)

A meaningful text can be hidden inside another, completely different yet still coherent and plausible, text of the same length. For example, a tweet containing a harsh political critique could be embedded in a tweet that celebrates the same political leader, or an ordinary product review could conceal a secret manuscript. This uncanny state of affairs is now possible thanks to Large Language Models, and in this paper we present Calgacus, a simple and efficient protocol to achieve it. We show that even modest 8-billion-parameter open-source LLMs are sufficient to obtain high-quality results, and a message as long as this abstract can be encoded and decoded locally on a laptop in seconds. The existence of such a protocol demonstrates a radical decoupling of text from authorial intent, further eroding trust in written communication, already shaken by the rise of LLM chatbots. We illustrate this with a concrete scenario: a company could covertly deploy an unfiltered LLM by encoding its answers within the compliant responses of a safe model. This possibility raises urgent questions for AI safety and challenges our understanding of what it means for a Large Language Model to know something.

隐写术LLM安全信息隐藏对抗样本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。