An Unforgeable Publicly Verifiable Watermark for Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liu, Aiwei, Pan, Leyi, Hu, Xuming, Li, Shu'ang, Wen, Lijie, King, Irwin, Yu, Philip S.
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911887602483200
author Liu, Aiwei
Pan, Leyi
Hu, Xuming
Li, Shu'ang
Wen, Lijie
King, Irwin
Yu, Philip S.
author_facet Liu, Aiwei
Pan, Leyi
Hu, Xuming
Li, Shu'ang
Wen, Lijie
King, Irwin
Yu, Philip S.
contents Recently, text watermarking algorithms for large language models (LLMs) have been proposed to mitigate the potential harms of text generated by LLMs, including fake news and copyright issues. However, current watermark detection algorithms require the secret key used in the watermark generation process, making them susceptible to security breaches and counterfeiting during public detection. To address this limitation, we propose an unforgeable publicly verifiable watermark algorithm named UPV that uses two different neural networks for watermark generation and detection, instead of using the same key at both stages. Meanwhile, the token embedding parameters are shared between the generation and detection networks, which makes the detection network achieve a high accuracy very efficiently. Experiments demonstrate that our algorithm attains high detection accuracy and computational efficiency through neural networks. Subsequent analysis confirms the high complexity involved in forging the watermark from the detection network. Our code is available at \href{https://github.com/THU-BPM/unforgeable_watermark}{https://github.com/THU-BPM/unforgeable\_watermark}. Additionally, our algorithm could also be accessed through MarkLLM \citep{pan2024markllm} \footnote{https://github.com/THU-BPM/MarkLLM}.
format Preprint
id arxiv_https___arxiv_org_abs_2307_16230
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle An Unforgeable Publicly Verifiable Watermark for Large Language Models
Liu, Aiwei
Pan, Leyi
Hu, Xuming
Li, Shu'ang
Wen, Lijie
King, Irwin
Yu, Philip S.
Computation and Language
68T50
I.2.7
Recently, text watermarking algorithms for large language models (LLMs) have been proposed to mitigate the potential harms of text generated by LLMs, including fake news and copyright issues. However, current watermark detection algorithms require the secret key used in the watermark generation process, making them susceptible to security breaches and counterfeiting during public detection. To address this limitation, we propose an unforgeable publicly verifiable watermark algorithm named UPV that uses two different neural networks for watermark generation and detection, instead of using the same key at both stages. Meanwhile, the token embedding parameters are shared between the generation and detection networks, which makes the detection network achieve a high accuracy very efficiently. Experiments demonstrate that our algorithm attains high detection accuracy and computational efficiency through neural networks. Subsequent analysis confirms the high complexity involved in forging the watermark from the detection network. Our code is available at \href{https://github.com/THU-BPM/unforgeable_watermark}{https://github.com/THU-BPM/unforgeable\_watermark}. Additionally, our algorithm could also be accessed through MarkLLM \citep{pan2024markllm} \footnote{https://github.com/THU-BPM/MarkLLM}.
title An Unforgeable Publicly Verifiable Watermark for Large Language Models
topic Computation and Language
68T50
I.2.7
url https://arxiv.org/abs/2307.16230