提出最优多比特生成水印方案,解决最坏情况误报问题。
Optimal Multi-bit Generative Watermarking Schemes Under Worst-Case False-Alarm Constraints
- 将水印设计建模为线性规划,推导出最优结构条件。
- 证明此前方案次优,新方案达到理论下界。
- 适合关注生成模型水印安全性的研究人员。
本文研究在最坏情况误报约束下,大语言模型的多比特生成水印问题。已有工作在有限令牌范围内建立了可实现漏检概率的下界,并提出一个声称达到该下界的方案。我们发现该方案实际上次优。随后,我们提出了两种新的编码-解码构造,实现了先前建立的下界,从而完全刻画了最优多比特水印性能。我们的方法将水印设计问题形式化为线性规划,并推导出达到最优性的结构条件。此外,我们识别了此前构造的失效机制,并比较了两种新方案之间的权衡。
原文摘要 · Abstract (English)
This paper considers the problem of multi-bit generative watermarking for large language models under a worst-case false-alarm constraint. Prior work established a lower bound on the achievable miss-detection probability in the finite-token regime and proposed a scheme claimed to achieve this bound. We show, however, that the proposed scheme is in fact suboptimal. We then develop two new encoding-decoding constructions that attain the previously established lower bound, thereby completely characterizing the optimal multi-bit watermarking performance. Our approach formulates the watermark design problem as a linear program and derives the structural conditions under which optimality can be achieved. In addition, we identify the failure mechanism of the previous construction and compare the tradeoffs between the two proposed schemes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。