posted in Technology
How AI text watermarking works: a visual guide
declaude.org/watermarking/posted in Technology
How AI text watermarking works: a visual guide
declaude.org/watermarking/But it doesn’t work. It looks like only the owner of the text generator is able to check if some text is written with this concrete generator (with some probability). I see no use of this technique.
It works for them not scraping their own slop back into training data. I assume that is actually the real purpose of the system. They don’t want to share the key with the public. But they probably will with other llm companies in exchange for theirs.
Hmm, yes. I just thought about outside usage, somehow haven’t thought about it as an inner LLM maintenance tool.
The article seemed to claim that some models allow outsiders to submit text for detection if I read it right. That seems like a decent way of doing it. If you “open source” the raw data, it means people can do things to try and get around it - same reason most websites don’t reveal their anti-spam techniques.
Yeah, but you’ll have to submit to every known provider and hope the user used one of the ones that provide this checking service, and didn’t do something like ask a local model to just randomize synonyms in a text.
Replying to @fluxx@mander.xyz
That would only work for their own slop though. Anthropic cannot recognize Google’s watermark, only theirs.
I assumed the goal might be so they could check whether other models have been trained on their output. Like anthropic using that as a “proof” when they start whining again about Chinese “distillation attacks”.
Of course, since they’re the only ones able to check their watermark, it would be rather shit as evidence anyway. “We’ve run the numbers, and we know you can’t, but trust us, this chatbot is totally copying ours!”