Black-Box Detection of Language Model Watermarks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Gloaguen, Thibaud, Jovanović, Nikola, Staab, Robin, Vechev, Martin
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866929728148996096
author Gloaguen, Thibaud
Jovanović, Nikola
Staab, Robin
Vechev, Martin
author_facet Gloaguen, Thibaud
Jovanović, Nikola
Staab, Robin
Vechev, Martin
contents Watermarking has emerged as a promising way to detect LLM-generated text, by augmenting LLM generations with later detectable signals. Recent work has proposed multiple families of watermarking schemes, several of which focus on preserving the LLM distribution. This distribution-preservation property is motivated by the fact that it is a tractable proxy for retaining LLM capabilities, as well as the inherently implied undetectability of the watermark by downstream users. Yet, despite much discourse around undetectability, no prior work has investigated the practical detectability of any of the current watermarking schemes in a realistic black-box setting. In this work we tackle this for the first time, developing rigorous statistical tests to detect the presence, and estimate parameters, of all three popular watermarking scheme families, using only a limited number of black-box queries. We experimentally confirm the effectiveness of our methods on a range of schemes and a diverse set of open-source models. Further, we validate the feasibility of our tests on real-world APIs. Our findings indicate that current watermarking schemes are more detectable than previously believed.
format Preprint
id arxiv_https___arxiv_org_abs_2405_20777
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Black-Box Detection of Language Model Watermarks
Gloaguen, Thibaud
Jovanović, Nikola
Staab, Robin
Vechev, Martin
Cryptography and Security
Machine Learning
Watermarking has emerged as a promising way to detect LLM-generated text, by augmenting LLM generations with later detectable signals. Recent work has proposed multiple families of watermarking schemes, several of which focus on preserving the LLM distribution. This distribution-preservation property is motivated by the fact that it is a tractable proxy for retaining LLM capabilities, as well as the inherently implied undetectability of the watermark by downstream users. Yet, despite much discourse around undetectability, no prior work has investigated the practical detectability of any of the current watermarking schemes in a realistic black-box setting. In this work we tackle this for the first time, developing rigorous statistical tests to detect the presence, and estimate parameters, of all three popular watermarking scheme families, using only a limited number of black-box queries. We experimentally confirm the effectiveness of our methods on a range of schemes and a diverse set of open-source models. Further, we validate the feasibility of our tests on real-world APIs. Our findings indicate that current watermarking schemes are more detectable than previously believed.
title Black-Box Detection of Language Model Watermarks
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2405.20777