12 ms·
The academic paper: https://www.nature.com/articles/s41586-024-08025-4 https://www.nature.com/articles/s41586-024-08025-4 They use the last N prefix tokens, ha
by espadrine 2y ago
The academic paper: https://www.nature.com/articles/s41586-024-08025-4 https://www.nature.com/articles/s41586-024-08025-4
They use the last N prefix tokens, hash them (with a keyed hash), and use the random value to sample the next token by doing an 8-wise tournament, by assigning random bits to each of the top 8 preferred tokens, making pairwise comparisons, and keeping the token with a larger bit. (Yes, it seems complicated, but apparently it increases the watermarking accuracy compared to a straightforward nucleus9 sampling.)
The negative of this approach is that you need to rerun the LLM, so you must keep all versions of all LLMs that you trained, forever.
- mmoskal 2y agoThey actually run 2^30-way tournament (they derive an equivalent form that doesn't requires 2B operations). You do not need to run the LLM, it only depends on the tokenizer.
- espadrine 2y agoYou’re right. I understood it to require taking the top 2^30 tokens, but instead they sample 2^30 times with replacement. Too bad they only formulate the detection positive rate empirically. I am curious what the exact probability would be mathematically.
- jkhdigital 2y agoWhy do you need to rerun the LLM? Watermark detection only requires the hash functions (equation (1) from the paper).