3 ms·
There are obviously ways it can be "watermarked" easily, put some zero-width unicode characters in the output and you'll notice right away when it's copy and pa
by EMM_386 3y ago
There are obviously ways it can be "watermarked" easily, put some zero-width unicode characters in the output and you'll notice right away when it's copy and pasted.
But clearly, that can be stripped out easily by anyone who knows it's there.
This process, too, would seem to be easily reversible. Just have it run through another model and tell it to slightly reword it or rephrase it.
I don't think there is a technically solvable way of watermarking output like this.
- mach1ne 3y agoI, for one, do believe watermarking solutions exist. One thing you cannot escape with LLMs is content meaning. As a simple example, the secret watermark could be hidden in the embeddings of the sequence of words. To make the watermark more robust against rephrasings, it could be hidden in the meaning of sentences or paragraphs. At the minimum, I think this could be possible.
- schrodinger 3y agoHow about you output in Spanish, then google translate to English?
- ShamelessC 3y agoThis research presents a technically solvable way for just that. Although I will admit it’s far too complex for me to understand.
- yomlica8 3y agoIt's actually pretty crazy that people are trying to solve this problem. "How can we install DRM and tracking into a block of text?"
- JohnFen 3y agoI don't think it's about DRM and tracking as much as proving authenticity.
- mk_stjames 3y agoI now have a habit of copying and pasting things I receive in emails or generate with certain tools into a ascii-only notepad before recopying and pasting out, anything that I am posting or sending to others. Because I've thought about how easy certain services could track origin of content across platforms with non printing unicode or using unicode for homograph attacks. Makes me want a systemwide right click > "Paste and strip all but ASCII" command.