为大模型身份识别提供统一框架,解决指纹与水印混乱问题。
Implicit Identity Technologies for LLMs: Fingerprinting and Watermarking across Datasets, Models, and Generated Content
- 提出隐式身份新概念,统一区分指纹与水印
- 构建覆盖数据、模型、生成内容的生命周期分类体系
- 适合关注模型版权与内容溯源的研究者和开发者
本文系统梳理了大语言模型(LLMs)在身份认证、所有权验证、来源追溯和生成内容归属方面的指纹与水印技术。由于大模型需投入大量数据、计算资源与专业知识,且在高风险场景中广泛应用,保护其资产并追踪起源至关重要。现有研究虽快速扩展至数据溯源、模型所有权与生成内容检测等领域,但方法分散、术语不一,常局限于特定资产场景。为此,本文提出‘隐式身份’作为可验证但不可直接观测的身份信号的统一抽象。区分非侵入式指纹(基于内在特征)与侵入式水印(人为嵌入)。进一步构建基于生命周期的分类体系,涵盖数据、模型与生成内容,并按验证语义分为相似性归因与密钥验证两类。最后建立以可识别性、鲁棒性与可部署性为核心的评估框架,总结真实访问与变换条件下的代表性指标。通过统一术语、生命周期与评估目标,本综述为研究大模型身份技术提供了结构化基础,助力开发更可靠的资产保护与溯源机制。
原文摘要 · Abstract (English)
This paper presents a survey and taxonomy of LLM fingerprinting and watermarking for identity, ownership verification, provenance, and generated-content attribution. Large language models (LLMs) require substantial investments in data, computation, and expertise, and are increasingly deployed in high-stakes settings, making it critical to protect LLM-related assets and trace their origins. Existing work has rapidly expanded across dataset provenance, model ownership, and generated-content detection, but the field remains fragmented: fingerprinting and watermarking are often used inconsistently, and methods are typically studied within isolated asset-specific settings. To address this gap, we introduce implicit identity as a unifying abstraction for verifiable but not directly observable identity signals in LLM systems. We distinguish fingerprinting as non-intrusive identity derived from intrinsic characteristics, and watermarking as intrusive identity deliberately embedded into data, models, or generated content. We then propose a lifecycle-based taxonomy that organises techniques across datasets, models, and generated content, and further separates them by verification semantics: similarity-based attribution and keyed verification. Finally, we establish an evaluation framework centred on identifiability, robustness, and deployability, summarising representative metrics under realistic access and transformation regimes. By unifying terminology, lifecycle stages, and evaluation objectives, this survey provides a structured foundation for studying LLM identity technologies and for developing more reliable mechanisms for asset protection and provenance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。