多模型平均可轻松消除文本水印,暴露当前检测机制的致命弱点。
Linear Ensembles Wash Away Watermarks: On the Fragility of Distributional Perturbations in LLMs

- 通过平均多个模型输出分布,还原未加水印的原始分布。
- 仅3-5个模型平均即可使检测z值从5-300降至2以下。
- 适用于对抗水印检测的研究者或需提升生成效率的开发者。
水印通过在生成文本中嵌入统计签名以实现检测与溯源。我们揭示了一个根本性漏洞:当用户访问多个模型(当今常态)时,水印会轻易失效。水印会使输出分布偏离原分布,而在竞争市场中,各提供方的扰动通常相互独立。理论上证明,平均输出概率分布可恢复未水印分布,误差最多为二阶项。实验表明,仅平均3-5个模型即可消除扰动。我们提出WASH(水印衰减的统计融合),解决异构模型间词汇不匹配和分词差异等实际问题。在六种水印方案和三个LLM上的实验显示,平均3个模型可使检测z值从5-300降至2以下(低于4的检测阈值),在5%假阳性率下真阳性率降至50%以下,同时提升生成质量27.5%,速度比最优基线快6倍,适用于长序列生成。
原文摘要 · Abstract (English)
Watermarking embeds statistical signatures in AI-generated text for detection and attribution. We reveal a fundamental vulnerability: when users access multiple models (today's reality), watermarks trivially fail. Watermarks perturb output distributions away from the original, and in competitive markets, these perturbations are typically independent across providers. We theoretically prove that averaging output probability distributions recovers the unwatermarked distribution with up to a second-order error term. Empirically, simply averaging 3-5 models cancels out these perturbations. We introduce WASH (Watermark Attenuation via Statistical Hybridisation), which solves practical challenges in ensemble generation: vocabulary misalignment and tokenisation differences across heterogeneous models. Experiments across six watermarking schemes and three LLMs show that averaging across 3 models suppresses detection z-scores from 5-300 to below 2 (below the detection threshold of 4) and reduces TPR at 5% FPR to below 50%, while improving quality by 27.5% and running 6 times faster than the best baseline on the long sequence generation. Our results suggest that robust AI-text detection via watermarking requires either accepting this fundamental vulnerability or unprecedented coordination among model providers.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。