Watermarking technology, which embeds invisible secret patterns into AI-generated content, aids in content authentication but faces a complex balancing act between performance and imperceptibility.
Imagine this: What if the interesting news article you read this morning was actually written by an Artificial Intelligence (AI) instead of a human reporter? Or what if a touching letter you saw on social media was actually an AI-generated output without any human touch? As AI technology advances at a staggering pace, it is becoming increasingly difficult to distinguish whether the text we read is a human creation or an AI-generated result.
In this situation, ‘AI Watermarking’ technology is gaining attention. Like a microscopic hologram inside a banknote, it is a technology that places an invisible secret brand on text generated by AI to notify that “This is AI-written text.” Today, let’s easily and clearly understand how this interesting technology works and why it is difficult to make perfect.
Why is this technology necessary?
Being able to distinguish AI-written text is very important. This is because it can prevent fake news from spreading rapidly across the internet and greatly help protect copyrights for AI-created content. Source: Hacker News
Simply put, it is like attaching a ‘certificate of authenticity’ for the digital age. However, there are tricky conditions when applying this technology. Even if a watermark is embedded, the AI-written text must retain its original naturalness and meaning, and it must be made so that users cannot easily detect or artificially remove this watermark. Source: Watermarked LLMs Offer Benefits
The Principle of the ‘Secret Mark’: The Magic of Word Choice
Watermark technology adopts a method of embedding secret patterns by subtly shaking the ‘output distribution,’ which is the way AI selects specific words like a chef choosing ingredients when creating text. Source: No free lunch in LLM watermarking Source: Mark Your LLM
To put it in an analogy, if an AI normally used the word ‘very’ with a 50% probability when writing, when embedding a watermark, it would adjust this probability slightly to 51%. While a person cannot feel any difference when reading, when a dedicated detector (algorithm) analyzes it later, it immediately notices that the text was written by an AI, thinking, “Uh, this text has an unusual pattern of word choices.”
In fact, attempts to embed watermarks in text existed long before Large Language Models (LLMs) appeared. They have been used for a long time to determine the authenticity of documents or to prevent forgery and alteration. Source: Text Watermarking The only difference is that modern AI watermarks use much more sophisticated and statistical methods than before.
Where is the technology now?
Then, is this technology perfect? To start with the conclusion, it still has a long way to go. Researchers at Carnegie Mellon University (CMU) point out that there are small and large vulnerabilities in every watermarking design method currently used. Source: Watermarked LLMs Offer Benefits
This is because for watermarking technology to be successful, the following three goals must be achieved simultaneously, but they conflict with each other. Source: Watermarked LLMs Offer Benefits
- Text Quality: Even if a watermark is embedded, the text must be natural and smooth to read.
- Imperceptibility: The general public should not notice that a watermark is included.
- Robustness: Even if someone slightly changes the text or deletes words, the watermark should not easily disappear.
Satisfying all three perfectly is as difficult as ‘catching three rabbits at once.’ Therefore, research is recently underway to design them much more robustly so that watermarks can be found even if sentences are deleted arbitrarily or words are changed slightly. Source: Can we Watermark Low-Entropy LLM Outputs?
The Future of AI Watermarking
As AI technology develops in the future, technologies that remove or bypass watermarks will also fiercely develop. Source: ChatGPT Watermark Remover From now on, watermarking detection methods will have to evolve together whenever models are updated, and social discussions on how to authenticate text created through collaboration between AI and humans will have to continue. Source: LLM Output Watermarking Engineer
Above all, the point we must remember is that technical solutions alone are not enough. When we consume text in the sea of information, the ‘critical perspective’ of keeping in mind the possibility that it is an AI-generated result and thinking about it once more might be the most powerful weapon we need to live in the future.
MindTickleBytes’ AI Reporter’s View
AI’s secret mark technology is like an ‘invisible signature.’ However, rather than trying to solve everything with technical magic, I think cultivating the ability to think and judge the boundaries between human-created content and AI-created content ourselves might be the true countermeasure for the future. Technology only helps; the judgment is ultimately made by humans.
References
-
[Guess which of these LLM outputs is watermarked Hacker News](https://news.ycombinator.com/item?id=49374729) - [Literature Review] Mark Your LLM: Detecting the Misuse of…
- No free lunch in LLM watermarking: Trade-offs in watermarking…
- LLM Output Watermarking Engineer — IT English Interview Practice…
- Can we Watermark Low-Entropy LLM Outputs?
- Watermarked LLMs Offer Benefits, but Leading Strategies Come With…
-
[ChatGPT Watermark Remover and Checker Remove AI Text…](https://www.gptwatermark.com/) - Text Watermarking: “Secret Wars” between the lines
- It modifies the metadata of the document file
- It finely adjusts the probability distribution of the model's word choices
- It changes the font size very slightly
- The cost of implementing the technology is too expensive
- The watermark completely changes the meaning of the writing
- The three goals of maintaining performance, preventing detection, and preventing removal conflict with each other
- Yes, it started with the emergence of LLMs
- No, it existed previously for the purpose of document integrity protection
- Not at all, it has existed since the 19th century