Multi-Designated Detector Watermarking for Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Huang, Zhengan, Zeng, Gongxian, Mu, Xin, Wang, Yu, Yu, Yue
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910626415116288
author Huang, Zhengan
Zeng, Gongxian
Mu, Xin
Wang, Yu
Yu, Yue
author_facet Huang, Zhengan
Zeng, Gongxian
Mu, Xin
Wang, Yu
Yu, Yue
contents In this paper, we initiate the study of \emph{multi-designated detector watermarking (MDDW)} for large language models (LLMs). This technique allows model providers to generate watermarked outputs from LLMs with two key properties: (i) only specific, possibly multiple, designated detectors can identify the watermarks, and (ii) there is no perceptible degradation in the output quality for ordinary users. We formalize the security definitions for MDDW and present a framework for constructing MDDW for any LLM using multi-designated verifier signatures (MDVS). Recognizing the significant economic value of LLM outputs, we introduce claimability as an optional security feature for MDDW, enabling model providers to assert ownership of LLM outputs within designated-detector settings. To support claimable MDDW, we propose a generic transformation converting any MDVS to a claimable MDVS. Our implementation of the MDDW scheme highlights its advanced functionalities and flexibility over existing methods, with satisfactory performance metrics.
format Preprint
id arxiv_https___arxiv_org_abs_2409_17518
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Multi-Designated Detector Watermarking for Language Models
Huang, Zhengan
Zeng, Gongxian
Mu, Xin
Wang, Yu
Yu, Yue
Cryptography and Security
Artificial Intelligence
In this paper, we initiate the study of \emph{multi-designated detector watermarking (MDDW)} for large language models (LLMs). This technique allows model providers to generate watermarked outputs from LLMs with two key properties: (i) only specific, possibly multiple, designated detectors can identify the watermarks, and (ii) there is no perceptible degradation in the output quality for ordinary users. We formalize the security definitions for MDDW and present a framework for constructing MDDW for any LLM using multi-designated verifier signatures (MDVS). Recognizing the significant economic value of LLM outputs, we introduce claimability as an optional security feature for MDDW, enabling model providers to assert ownership of LLM outputs within designated-detector settings. To support claimable MDDW, we propose a generic transformation converting any MDVS to a claimable MDVS. Our implementation of the MDDW scheme highlights its advanced functionalities and flexibility over existing methods, with satisfactory performance metrics.
title Multi-Designated Detector Watermarking for Language Models
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2409.17518