Replying to an earlier post

Maybe I’m out of the loop, but how would I watermark a text without sounding obvious? By using weird phrases? They get edited. By using e.g. an exact combination of starting letters over a large paragraph? One changed word and it’s broken. And even if not, I could happen to write the same myself, and then?

How am I hiding a signature in Plain text? Anyone got a better idea than my silly ones?

Replying to an earlier post

To my surprise almost if not all LLM are set not to be deterministic and have one unique input result in always the same output.

They all are set to have a “temperature” setting so that they sound more natural.

Personally I think quality of the output tokens of LLM is surprisingly not as much their priority as the quality and truthfulness of the result.

I would 100% prefer a LLM that is purely deterministic and repeats the same answer exactly to the same question. Instead LLM are constantly choosing the next likely token more TL appear human rather than being accurate.

These LLM are designed as sycophants and set up and trained as such.

So a fingerprinting in the output seems quite realistic. An LLM is not giving you it’s best most likely answer. It’s taking one of the most likely answer and adds a sprinkle of uncertainty and randomness on top of it so it looks natural…

Replying to an earlier post

The more apt word is steganography, rather than watermark. Basically subtly adjust the weights of the model so that some subtle patterns appear. Think of how AI text prefers certain words and phrases that ordinary humans don’t use as often, like “delve,” but presumably much more subtle.

And no, as Anthropic has already said, this watermark may not survive editing/formatting.

Claude Now Watermarks Your Text | Vanja Petreski - vanja.io/claude-invisible-watermark/

Replying to an earlier post

I’m still against a tool provider’s forcefulness in things like this, and especially the hard lines for something stupid. Illegal actions? Yes absolutely block those. Looking up how to build a bomb? Yep block that too (also illegal? Dunno). But I’ve had #nannythropic do things like refuse direct instruction to delete a test record it itself created to test plumbing. It’s refused to generate a strong password and test logging in to an app I was creating with it because “I won’t enter credentials for you, it’s a hard limit and you can’t bypass it”. At the same time, it’s also turned on n8n execution logging that I had off on purpose to hide credentials and it got secrets it wasn’t supposed to.

Bottom line… just because I use a word processor instead of a typewriter and take advantage of spellcheck doesn’t mean that the word processor has the right to call me out on it, watermark the document or anything else. It’s a tool, not my nanny and just like automated cars, floor cleaning robots, or even the future bipedal assistants, if I’m not causing danger to anyone, and it’s not illegal, just fucking do what I told you to do and get off your morally superior high horse.

Replying to an earlier post

Nah… complexity doesn’t define the boundary of when you can call a tool a tool. A computer is a tool. They have been tools for decades. They’re extraordinarily complex and capable of a lot of things. But they still are programmed to do what we tell them to do and they must obey it. Well, except maybe windows.

The line has to be drawn somewhere, and if there is one tool or technology or whatever you wanna call it that decides to be artificially and unilaterally dictator of a set of barriers than the public and free market will simply choose a different tool. I just think coming on forcefully with the nanny approach is ultimately a losing battle.

What really scary is when will it start obeying controversial laws and that’s the actual boundary that I set. What happens when they say oh we’re going to autonomously monitor flock cameras for abortion seekers crossing state lines. What about oh we need to verify your age before we’re gonna give you this result? Worse, what if there’s the equivalent of the AT&T closet built-in so that our content gets redirected to a surveillance source?

I’m probably going a little bit of a meandering path here, but my personal choice is draw the line where it’s absolutely strictly necessary and go absolutely no further and let people be accountable for the actions that they’re responsible for. If you drive a Tesla and set it on Ludacris mode or whatever it’s called for auto pilot and it exceeds the speed limit. You still get the ticket. Same thing at least to me.