TextSeal为大模型生成可定位水印,防篡改且无性能损失。
TextSeal: A Localized LLM Watermark for Provenance & Distillation Protection
- 基于Gumbel-max采样设计双密钥生成,恢复输出多样性。
- 在6000次A/B测试中,多语言下人眼无法察觉质量差异。
- 水印可随模型蒸馏传递,能追踪未经授权的使用。
我们提出TextSeal,一种先进的大语言模型水印技术。基于Gumbel-max采样,TextSeal引入双密钥生成以恢复输出多样性,并采用熵加权评分与多区域定位提升检测能力。支持推测解码和多标记预测等服务优化,且不增加推理开销。在检测强度上严格优于SynthID-text等基线,对稀释具有鲁棒性,即使在高度混合的人类与AI文本中仍可实现可靠定位检测。该方案理论上无失真,推理基准测试表明其保持下游性能;多语言人类评估(6000次A/B对比,5种语言)显示无感知质量下降。除溯源检测外,TextSeal具备“放射性”特性:水印信号可经模型蒸馏传递,从而实现对非法使用的检测。
原文摘要 · Abstract (English)
We introduce TextSeal, a state-of-the-art watermark for large language models. Building on Gumbel-max sampling, TextSeal introduces dual-key generation to restore output diversity, along with entropy-weighted scoring and multi-region localization for improved detection. It supports serving optimizations such as speculative decoding and multi-token prediction, and does not add any inference overhead. TextSeal strictly dominates baselines like SynthID-text in detection strength and is robust to dilution, maintaining confident localized detection even in heavily mixed human/AI documents. The scheme is theoretically distortion-free, and evaluation across reasoning benchmarks confirms that it preserves downstream performance; while a multilingual human evaluation (6000 A/B comparisons, 5 languages) shows no perceptible quality difference. Beyond its use for provenance detection, TextSeal is also ``radioactive'': its watermark signal transfers through model distillation, enabling detection of unauthorized use.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。