PVMark: Enabling Public Verifiability for LLM Watermarking Schemes
Haohua Duan, Liyao Xiang, Xin Zhang, Baochun Li, Bo Li
摘要
Watermarking schemes for large language models (LLMs) have been proposed to identify the source of the generated text. However, current watermarking solutions hardly resolve the trust issue: the watermark detection often relies on the secret key and thus remains opaque to the public; otherwise any adversary may launch removal attacks if the secret key is exposed. To resolve the dilemma, we propose PVMark, a plugin based on zero-knowledge proof (ZKP), enabling the watermark detection process to be publicly verifiable by third parties without disclosing any secret key. PVMark novelly hinges upon the proof of `correct execution' of watermark detection on which a set of constraints are built, and is optimized according to the structural nature of the detection process. Developed for three representative watermarking schemes, we implement multiple variants of PVMark in Python, Rust and Circom, covering combinations of three hash functions and four ZKP protocols, showing our approach effectively works under a variety of circumstances. By experimental results, PVMark efficiently enables public verifiability on the state-of-the-art LLM watermarking schemes yet without compromising the watermarking performance, and hence is promising for practical deployment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper17
- DetectGPT: Zero-Shot Machine-Generated Text Detection using Probability CurvatureEric Mitchell, Yoonho Lee, Alexander Khazatsky, Christopher D. Manning 等ICML 2023 · 被引用 988 次
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz 等ICML 2023 · 被引用 854 次
- Paraphrasing evades detectors of AI-generated text, but retrieval is an effective defenseKalpesh Krishna, Yixiao Song, Marzena Karpinska, John Wieting 等NeurIPS 2023 · 被引用 657 次
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy 等USENIX Security 2021 · 被引用 410 次
- Provable Robust Watermarking for AI-Generated TextXuandong Zhao, Prabhanjan Vijendra Ananth, Lei Li, Yu-Xiang WangICLR 2024 · 被引用 312 次
相关 Paper
- An Unforgeable Publicly Verifiable Watermark for Large Language ModelsAiwei Liu, Leyi Pan, Xuming Hu, Shuang Li 等ICLR 2024 · 被引用 63 次
- WaterMax: breaking the LLM watermark detectability-robustness-quality trade-offEva Giboulot, Teddy FuronNeurIPS 2024 · 被引用 76 次
- De-mark: Watermark Removal in Large Language ModelsRuibo Chen, Yihan Wu, Junfeng Guo, Heng HuangICML 2025
- IPMark: A Sentence-Level Watermark for LLMs with Hierarchical Personalization and Efficient DetectionWenbo An, Lianwei Wu, Zehao WangICML 2026
- Black-Box Detection of Language Model WatermarksThibaud Gloaguen, Nikola Jovanovic, Robin Staab, Martin T. VechevICLR 2025
