Permute-and-Flip: An optimally stable and watermarkable decoder for LLMs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhao, Xuandong, Li, Lei, Wang, Yu-Xiang
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912275441385472
author Zhao, Xuandong
Li, Lei
Wang, Yu-Xiang
author_facet Zhao, Xuandong
Li, Lei
Wang, Yu-Xiang
contents In this paper, we propose a new decoding method called Permute-and-Flip (PF) decoder. It enjoys stability properties similar to the standard sampling decoder, but is provably up to 2x better in its quality-stability tradeoff than sampling and never worse than any other decoder. We also design a cryptographic watermarking scheme analogous to Aaronson (2023)'s Gumbel watermark, but naturally tailored for PF decoder. The watermarking scheme does not change the distribution to sample, while allowing arbitrarily low false positive rate and high recall whenever the generated text has high entropy. Our experiments show that the PF decoder (and its watermarked counterpart) significantly outperform(s) naive sampling (and its Gumbel watermarked counterpart) in terms of perplexity, while retaining the same stability (and detectability), hence making it a promising new approach for LLM decoding. The code is available at https://github.com/XuandongZhao/pf-decoding
format Preprint
id arxiv_https___arxiv_org_abs_2402_05864
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Permute-and-Flip: An optimally stable and watermarkable decoder for LLMs
Zhao, Xuandong
Li, Lei
Wang, Yu-Xiang
Computation and Language
Cryptography and Security
Machine Learning
In this paper, we propose a new decoding method called Permute-and-Flip (PF) decoder. It enjoys stability properties similar to the standard sampling decoder, but is provably up to 2x better in its quality-stability tradeoff than sampling and never worse than any other decoder. We also design a cryptographic watermarking scheme analogous to Aaronson (2023)'s Gumbel watermark, but naturally tailored for PF decoder. The watermarking scheme does not change the distribution to sample, while allowing arbitrarily low false positive rate and high recall whenever the generated text has high entropy. Our experiments show that the PF decoder (and its watermarked counterpart) significantly outperform(s) naive sampling (and its Gumbel watermarked counterpart) in terms of perplexity, while retaining the same stability (and detectability), hence making it a promising new approach for LLM decoding. The code is available at https://github.com/XuandongZhao/pf-decoding
title Permute-and-Flip: An optimally stable and watermarkable decoder for LLMs
topic Computation and Language
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2402.05864