Embarrassingly Simple Text Watermarks
arxiv.org
arxiv.org
This is true, of course, but also vacuous. The problem is that there is no sense of the computational complexity or difficulty of implementing the Erase function. The proof holds even if the watermark can only be removed in O(e^n) or some similarly absurd time span. A good watermark, like a good encryption scheme or a good password, is one that can be verified quickly but must be reversed slowly.
The paper's stance is no different from saying "since any watermark can be reversed, none of them matter, and we should just use THIS WAS WRITTEN BY CHATGPT".
Which is why you should never assume that a paper makes sense merely because it is technically correct.
I’m not sure we shouldn’t do this; at least people wouldn’t put false stock in watermark detection methods. As it is now, what a watermark not being detected says is that this wasn’t copy-pasted directly from an LLM, but what lay people will understand is that “this was not produced by an LLM.” That’s a dangerous muddying of the waters in my opinion.
That code is long lost, and I was a kid, so never characterized it in any meaningful way. But it was interesting and seemed to work. The downside was that you had to have a fairly lengthy text to encode anything but very short messages.
The authors appear to be entirely aware that this sort of substitution can be trivially stripped out by normalizing down to a simplified character set ("The critical limitation of Whitemark is that it can be bypassed by replacing all whitespaces with the basic whitespace U+0020, then the validator can no longer detect the watermark"), but believe that it still has value because the typical student using an LLM to write their essay won't know anything about Unicode.
This seems a bit naive to me. Implementing the necessary "watermark remover" normalization as a simple webapp would be an easy afternoon project for most of us here, and if this approach reached any sort of widespread use there would be many such sites. Students who intend to cheat by using an LLM to write their essays are entirely capable of learning "there's some secret data hidden in the text so copy-paste it through this other site to strip that out before turning it in". Even without access to such a tool they could simply...retype the text themselves?
Arguably this still has some value. In most contexts there is minimal downside to watermarking the generated text in this way, and a slight possibility of catching some cases in which people lazily present LLM generated text as human written. However this might give people a misplaced belief that the absence of such a watermark means the text is authentically human authored, which might outweigh the benefits of catching the occasional lazy or ignorant user.
Or copy the text using an OCR app.
There are so many ways you could catch leakers of sensitive information this way. Look at how often government agencies react information in PDFs by writing black blocks over the text.
Note it could be used for authentication in the opposite direction, only accepting text with the unusual spaces in it.
So far as catching the indolent and the ignorant, making an example here or their works wonders.
In fact there is precedent for this. When I was at school a lot of kids would start writing an essay by copy and pasting the most relevant Wikipedia article into Microsoft Word, and then edit it to sound different, but this resulted in a subtle light-blue background being inserted into the resulting printed page, which made it very obvious that they had copied from Wikipedia. They quickly learnt that they had to paste it through Notepad or similar first to get rid of the background colour.
I could hardly comprehend, at that time, how much this was preparation for a career in software development.
We're still in the early stages of it, but AI is and will continue to force us to re-explore our relationships with work, productivity, authenticity and what really matters to us about the "human element" in anything.
Come to think of it, the current socioeconomic equilibrium where students take out loans (or pull on their parents' purse strings) to fund their own education to provide more value to future employers than they ultimately get back seems woefully inefficient, not just for software engineering, but for most academic and industrial fields more generally.
Why not run application cycles or even scout students directly out of high school and enroll them in professional programs run by the organizations themselves in exchange for some number of months or years of discounted labor? Obviously, this isn't happening because it transfers risk from individuals to organizations, but it also seems obvious that, were it subsidized or enforced in some way (insurance?), it might lead to better, more equitable outcomes.
Has anyone else had similar thoughts? Or thoughts to the contrary?
It's usually Ctrl-Shift-V to not include formatting (or get a menu of options, of which that's one), by the way.
This specific scheme is also not remotely novel; I once saw it implemented, something like six or eight years back, in an effort to quell leaks to an industry rag with a habit of posting paragraph-length excerpts verbatim. They also did this with some of the watermarked emails, having stripped the watermarking whitespace before publication.
This would be a glaring stylistic inconsistency in every text produced with a watermark. You could just as well implement a watermark by doing automated thesaurus replacements on certain of the words and using the index of the selected entry as a code.
A watermark that deeply unnerves everyone who reads the text can carry information, but it tends to render the tool itself unfit for purpose.
No need to waste all that time watching a TikTok video - just ask ChatGPT to do it for you.
There was a story I remember hearing, I think from an older student during highschool or during college from another student's highschool, where some kid was cheating by copying a hand-written paper from another student, and the paper had two names on it. They had put their name in the corner then just blindly wrote all text on the other paper, including the other student's name.
That observation told us that we were on the right track of both predicting and explaining the spectra of atoms.
Of course, this paper is likely nothing like Bohr's work. But sometimes very simple ideas have far reaching consequences.
Not this one.
Yes many people can circumvent this simple watermark technique but for those who don't, it is essentially guaranteed that they used a LLM if their text has clearly atypical unicode marks (Whether U+2004, ligatures, or variant selectors). Thus an organization can feel confident in taking action against the individual who submitted the document.
Whereas right now there are a bunch of dubious "LLM detector" models that output a confidence score that may or may not correspond to whether the person used an LLM. This low precision technique leads to people getting incorrectly accused of using LLM content.
So in my opinion, a world of high precision (but potentially low recall) LLM watermarks using simple techniques is way better than this current high-noise low precision black box world of low quality "LLM detector models"
For PR? It's not a degradation for legitimate uses of AI. It only degrades output being used in an attempt to mislead people. Someone using an LLM to e.g. translate would usually be fine admitting they used it. I'm working under the assumption this isn't intended for something like a code model where it would break things, but only for output being used as readable text.
Just spitballing here.
1. Identify the ~N most common tokens (let's say N is 5), and call this set S.
2. Restrict the model so that every T tokens it emits, the Tth token must be from the set S.
Maybe you can be clever and say T must be a prime number or something.
Anyway, the quality of the output should suffer minimally, since even though you are constraining the model to pick "sub-par" tokens every T tokens, it still gets to pick from the N most common ones anyway.
And to validate, you simply scan the text and see if every T tokens is always from the set S. If yes, there's a high probability it has the watermark (similar to a Bloom filter, adjust the values to adjust the probability). If no, then it's 100% guaranteed to not have the watermark.
Of course, there are pitfalls. What if you ask the model to generate code? Which is full of uncommon symbols. If you happen to get unlucky, then maybe the only token that makes sense at a given position is '}', and if you force the model to select from ['the', 'a', 'not'] etc then it simply cannot produce a good output. Still, the approach is interesting if you ask me.
echo "a string with funny unicode spaces" | iconv -f utf8 -t ascii//TRANSLIT
Though for languages that cannot be represented as ascii, such as Japanese as they paper is discussing, it's perhaps less trivial.
If they cannot be distinguished, then there is no need to distinguish them. Seriously.
Worried about someone having an LLM do their work? Why? Ad long as the work us good, does it matter?
Teachers worried that students will have LLMs do their assignments? You need different assignments and better tests.
LLMs are a tool. There were typewriters, then word processors, then spelling and grammar checkers. Now we have LLMs. Progress is great!
Also, I think 3.1 and the following proof is pseudo-formalism. A simple sentence that explains the reason is enough.