Waterfall: Framework for Robust and Scalable Text Watermarking and Provenance for LLMs

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Lau, Gregory Kang Ruey, Niu, Xinyuan, Dao, Hieu, Chen, Jiangwei, Foo, Chuan-Sheng, Low, Bryan Kian Hsiang
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866910676122861568
author Lau, Gregory Kang Ruey
Niu, Xinyuan
Dao, Hieu
Chen, Jiangwei
Foo, Chuan-Sheng
Low, Bryan Kian Hsiang
author_facet Lau, Gregory Kang Ruey
Niu, Xinyuan
Dao, Hieu
Chen, Jiangwei
Foo, Chuan-Sheng
Low, Bryan Kian Hsiang
contents Protecting intellectual property (IP) of text such as articles and code is increasingly important, especially as sophisticated attacks become possible, such as paraphrasing by large language models (LLMs) or even unauthorized training of LLMs on copyrighted text to infringe such IP. However, existing text watermarking methods are not robust enough against such attacks nor scalable to millions of users for practical implementation. In this paper, we propose Waterfall, the first training-free framework for robust and scalable text watermarking applicable across multiple text types (e.g., articles, code) and languages supportable by LLMs, for general text and LLM data provenance. Waterfall comprises several key innovations, such as being the first to use LLM as paraphrasers for watermarking along with a novel combination of techniques that are surprisingly effective in achieving robust verifiability and scalability. We empirically demonstrate that Waterfall achieves significantly better scalability, robust verifiability, and computational efficiency compared to SOTA article-text watermarking methods, and showed how it could be directly applied to the watermarking of code. We also demonstrated that Waterfall can be used for LLM data provenance, where the watermarks of LLM training data can be detected in LLM output, allowing for detection of unauthorized use of data for LLM training and potentially enabling model-centric watermarking of open-sourced LLMs which has been a limitation of existing LLM watermarking works. Our code is available at https://github.com/aoi3142/Waterfall.
format Preprint
id arxiv_https___arxiv_org_abs_2407_04411
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Waterfall: Framework for Robust and Scalable Text Watermarking and Provenance for LLMs
Lau, Gregory Kang Ruey
Niu, Xinyuan
Dao, Hieu
Chen, Jiangwei
Foo, Chuan-Sheng
Low, Bryan Kian Hsiang
Cryptography and Security
Artificial Intelligence
Computation and Language
Protecting intellectual property (IP) of text such as articles and code is increasingly important, especially as sophisticated attacks become possible, such as paraphrasing by large language models (LLMs) or even unauthorized training of LLMs on copyrighted text to infringe such IP. However, existing text watermarking methods are not robust enough against such attacks nor scalable to millions of users for practical implementation. In this paper, we propose Waterfall, the first training-free framework for robust and scalable text watermarking applicable across multiple text types (e.g., articles, code) and languages supportable by LLMs, for general text and LLM data provenance. Waterfall comprises several key innovations, such as being the first to use LLM as paraphrasers for watermarking along with a novel combination of techniques that are surprisingly effective in achieving robust verifiability and scalability. We empirically demonstrate that Waterfall achieves significantly better scalability, robust verifiability, and computational efficiency compared to SOTA article-text watermarking methods, and showed how it could be directly applied to the watermarking of code. We also demonstrated that Waterfall can be used for LLM data provenance, where the watermarks of LLM training data can be detected in LLM output, allowing for detection of unauthorized use of data for LLM training and potentially enabling model-centric watermarking of open-sourced LLMs which has been a limitation of existing LLM watermarking works. Our code is available at https://github.com/aoi3142/Waterfall.
title Waterfall: Framework for Robust and Scalable Text Watermarking and Provenance for LLMs
topic Cryptography and Security
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2407.04411