Black-Box Detection of Language Model Watermarks
Thibaud Gloaguen, Nikola Jovanovic, Robin Staab, Martin T. Vechev
摘要
Watermarking has emerged as a promising way to detect LLM-generated text. To apply a watermark an LLM provider, given a secret key, augments generations with a signal that is later detectable by any party with the same key. Recent work has proposed three main families of watermarking schemes, two of which focus on the property of preserving the LLM distribution. This is motivated by it being a tractable proxy for maintaining LLM capabilities, but also by the idea that concealing a watermark deployment makes it harder for malicious actors to hide misuse by avoiding a certain LLM or attacking its watermark. Yet, despite much discourse around detectability, no prior work has investigated if any of these scheme families are detectable in a realistic black-box setting. We tackle this for the first time, developing rigorous statistical tests to detect the presence of all three most popular watermarking scheme families using only a limited number of black-box queries. We experimentally confirm the effectiveness of our methods on a range of schemes and a diverse set of open-source models. Our findings indicate that current watermarking schemes are more detectable than previously believed, and that obscuring the fact that a watermark was deployed may not be a viable way for providers to protect against adversaries. We further apply our methods to test for watermark presence behind the most popular public APIs: GPT4, CLAUDE 3, GEMINI 1.0 PRO, finding no strong evidence of a watermark at this point in time.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- Watermarking Diffusion Language ModelsThibaud Gloaguen, Robin Staab, Nikola Jovanović, Martin VechevICLR 2026 · 被引用 13 次
- Human Texts Are Outliers: Detecting LLM-generated Texts via Out-of-distribution DetectionCong Zeng, Shengkun Tang, Yuanzhou Chen, Zhiqiang Shen 等NeurIPS 2025 · 被引用 10 次
- LLM Fingerprinting via Semantically Conditioned WatermarksThibaud Gloaguen, Robin Staab, Nikola Jovanovic, Martin T. VechevICLR 2026 · 被引用 8 次
- SAEMark: Steering Personalized Multilingual LLM Watermarks with Sparse AutoencodersZhuohao Yu, Xingru Jiang, Weizheng Gu, Yidong Wang 等NeurIPS 2025 · 被引用 6 次
- Safeguarding Multimodal Knowledge Copyright in the RAG-as-a-Service EnvironmentTianyu Chen, Jian Lou, Wenjie WangICLR 2026 · 被引用 2 次
它引用的顶会 Paper7
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz 等ICML 2023 · 被引用 854 次
- On the Reliability of Watermarks for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Manli Shu 等ICLR 2024 · 被引用 202 次
- Stealing part of a production language modelNicholas Carlini, Daniel Paleka, Krishnamurthy Dj Dvijotham, Thomas Steinke 等ICML 2024 · 被引用 157 次
- A Semantic Invariant Robust Watermark for Large Language ModelsAiwei Liu, Leyi Pan, Xuming Hu, Shiao Meng 等ICLR 2024 · 被引用 108 次
- Unbiased Watermark for Large Language ModelsZhengmian Hu, Lichang Chen, Xidong Wu, Yihan Wu 等ICLR 2024 · 被引用 103 次
相关 Paper
- PostMark: A Robust Blackbox Watermark for Large Language ModelsYapei Chang, Kalpesh Krishna, Amir Houmansadr, John Wieting 等EMNLP 2024 · 被引用 4 次
- StealthInk: A Multi-bit and Stealthy Watermark for Large Language ModelsYa Jiang, Chuxiong Wu, Massieh Kordi Boroujeny, Brian L. Mark 等ICML 2025
- Segmenting Watermarked Texts From Language ModelsXingchi Li, Guanxun Li, Xianyang ZhangNeurIPS 2024 · 被引用 5 次
- Protecting Language Generation Models via Invisible WatermarkingXuandong Zhao, Yu-Xiang Wang, Lei LiICML 2023 · 被引用 117 次
- A Resilient and Accessible Distribution-Preserving Watermark for Large Language ModelsYihan Wu, Zhengmian Hu, Junfeng Guo, Hongyang Zhang 等ICML 2024 · 被引用 50 次
