SoK: Are Watermarks in LLMs Ready for Deployment?

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Dang, Kieu, Lai, Phung, Phan, NhatHai, Shen, Yelong, Jin, Ruoming, Khreishah, Abdallah, Thai, My T.
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915691969380352
author Dang, Kieu
Lai, Phung
Phan, NhatHai
Shen, Yelong
Jin, Ruoming
Khreishah, Abdallah
Thai, My T.
author_facet Dang, Kieu
Lai, Phung
Phan, NhatHai
Shen, Yelong
Jin, Ruoming
Khreishah, Abdallah
Thai, My T.
contents Large Language Models (LLMs) have transformed natural language processing, demonstrating impressive capabilities across diverse tasks. However, deploying these models introduces critical risks related to intellectual property violations and potential misuse, particularly as adversaries can imitate these models to steal services or generate misleading outputs. We specifically focus on model stealing attacks, as they are highly relevant to proprietary LLMs and pose a serious threat to their security, revenue, and ethical deployment. While various watermarking techniques have emerged to mitigate these risks, it remains unclear how far the community and industry have progressed in developing and deploying watermarks in LLMs. To bridge this gap, we aim to develop a comprehensive systematization for watermarks in LLMs by 1) presenting a detailed taxonomy for watermarks in LLMs, 2) proposing a novel intellectual property classifier to explore the effectiveness and impacts of watermarks on LLMs under both attack and attack-free environments, 3) analyzing the limitations of existing watermarks in LLMs, and 4) discussing practical challenges and potential future directions for watermarks in LLMs. Through extensive experiments, we show that despite promising research outcomes and significant attention from leading companies and community to deploy watermarks, these techniques have yet to reach their full potential in real-world applications due to their unfavorable impacts on model utility of LLMs and downstream tasks. Our findings provide an insightful understanding of watermarks in LLMs, highlighting the need for practical watermarks solutions tailored to LLM deployment.
format Preprint
id arxiv_https___arxiv_org_abs_2506_05594
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle SoK: Are Watermarks in LLMs Ready for Deployment?
Dang, Kieu
Lai, Phung
Phan, NhatHai
Shen, Yelong
Jin, Ruoming
Khreishah, Abdallah
Thai, My T.
Cryptography and Security
Computation and Language
Large Language Models (LLMs) have transformed natural language processing, demonstrating impressive capabilities across diverse tasks. However, deploying these models introduces critical risks related to intellectual property violations and potential misuse, particularly as adversaries can imitate these models to steal services or generate misleading outputs. We specifically focus on model stealing attacks, as they are highly relevant to proprietary LLMs and pose a serious threat to their security, revenue, and ethical deployment. While various watermarking techniques have emerged to mitigate these risks, it remains unclear how far the community and industry have progressed in developing and deploying watermarks in LLMs. To bridge this gap, we aim to develop a comprehensive systematization for watermarks in LLMs by 1) presenting a detailed taxonomy for watermarks in LLMs, 2) proposing a novel intellectual property classifier to explore the effectiveness and impacts of watermarks on LLMs under both attack and attack-free environments, 3) analyzing the limitations of existing watermarks in LLMs, and 4) discussing practical challenges and potential future directions for watermarks in LLMs. Through extensive experiments, we show that despite promising research outcomes and significant attention from leading companies and community to deploy watermarks, these techniques have yet to reach their full potential in real-world applications due to their unfavorable impacts on model utility of LLMs and downstream tasks. Our findings provide an insightful understanding of watermarks in LLMs, highlighting the need for practical watermarks solutions tailored to LLM deployment.
title SoK: Are Watermarks in LLMs Ready for Deployment?
topic Cryptography and Security
Computation and Language
url https://arxiv.org/abs/2506.05594