A Robust Semantics-based Watermark for Large Language Model against Paraphrasing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ren, Jie, Xu, Han, Liu, Yiding, Cui, Yingqian, Wang, Shuaiqiang, Yin, Dawei, Tang, Jiliang
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910393590349824
author Ren, Jie
Xu, Han
Liu, Yiding
Cui, Yingqian
Wang, Shuaiqiang
Yin, Dawei
Tang, Jiliang
author_facet Ren, Jie
Xu, Han
Liu, Yiding
Cui, Yingqian
Wang, Shuaiqiang
Yin, Dawei
Tang, Jiliang
contents Large language models (LLMs) have show great ability in various natural language tasks. However, there are concerns that LLMs are possible to be used improperly or even illegally. To prevent the malicious usage of LLMs, detecting LLM-generated text becomes crucial in the deployment of LLM applications. Watermarking is an effective strategy to detect the LLM-generated content by encoding a pre-defined secret watermark to facilitate the detection process. However, the majority of existing watermark methods leverage the simple hashes of precedent tokens to partition vocabulary. Such watermark can be easily eliminated by paraphrase and correspondingly the detection effectiveness will be greatly compromised. Thus, to enhance the robustness against paraphrase, we propose a semantics-based watermark framework SemaMark. It leverages the semantics as an alternative to simple hashes of tokens since the paraphrase will likely preserve the semantic meaning of the sentences. Comprehensive experiments are conducted to demonstrate the effectiveness and robustness of SemaMark under different paraphrases.
format Preprint
id arxiv_https___arxiv_org_abs_2311_08721
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle A Robust Semantics-based Watermark for Large Language Model against Paraphrasing
Ren, Jie
Xu, Han
Liu, Yiding
Cui, Yingqian
Wang, Shuaiqiang
Yin, Dawei
Tang, Jiliang
Cryptography and Security
Large language models (LLMs) have show great ability in various natural language tasks. However, there are concerns that LLMs are possible to be used improperly or even illegally. To prevent the malicious usage of LLMs, detecting LLM-generated text becomes crucial in the deployment of LLM applications. Watermarking is an effective strategy to detect the LLM-generated content by encoding a pre-defined secret watermark to facilitate the detection process. However, the majority of existing watermark methods leverage the simple hashes of precedent tokens to partition vocabulary. Such watermark can be easily eliminated by paraphrase and correspondingly the detection effectiveness will be greatly compromised. Thus, to enhance the robustness against paraphrase, we propose a semantics-based watermark framework SemaMark. It leverages the semantics as an alternative to simple hashes of tokens since the paraphrase will likely preserve the semantic meaning of the sentences. Comprehensive experiments are conducted to demonstrate the effectiveness and robustness of SemaMark under different paraphrases.
title A Robust Semantics-based Watermark for Large Language Model against Paraphrasing
topic Cryptography and Security
url https://arxiv.org/abs/2311.08721