In plain words: Easymark tags AI-written text with tiny changes that leave the meaning untouched, needing just a few lines of code and no access to the language model. It was detected more reliably than leading watermarking tricks while keeping text quality unchanged.
Abstract
We propose Easymark, a family of embarrassingly simple yet effective watermarks. Text watermarking is becoming increasingly important with the advent of Large Language Models (LLM). LLMs can generate texts that cannot be distinguished from human-written texts. This is a serious problem for the credibility of the text. Easymark is a simple yet effective solution to this problem. Easymark can inject a watermark without changing the meaning of the text at all while a validator can detect if a text was generated from a system that adopted Easymark or not with high credibility. Easymark is extremely easy to implement so that it only requires a few lines of code. Easymark does not require access to LLMs, so it can be implemented on the user-side when the LLM providers do not offer watermarked LLMs. In spite of its simplicity, it achieves higher detection accuracy and BLEU scores than the state-of-the-art text watermarking methods. We also prove the impossibility theorem of perfect watermarking, which is valuable in its own right. This theorem shows that no matter how sophisticated a watermark is, a malicious user could remove it from the text, which motivate us to use a simple watermark such as Easymark. We carry out experiments with LLM-generated texts and confirm that Easymark can be detected reliably without any degradation of BLEU and perplexity, and outperform state-of-the-art watermarks in terms of both quality and reliability.
Ryoma Sato, Yuki Takezawa, Han Bao, Kenta Niwa, Makoto Yamada
arXiv:2310.08920 · cs.LG, cs.AI, cs.CR · submitted Oct 13, 2023
abstract · pdf · html
This is true, of course, but also vacuous. The problem is that there is no sense of the computational complexity or difficulty of implementing the Erase function. The proof holds even if the watermark can only be removed in O(e^n) or some similarly absurd time span. A good watermark, like a good encryption scheme or a good password, is one that can be verified quickly but must be reversed slowly.
The paper's stance is no different from saying "since any watermark can be reversed, none of them matter, and we should just use THIS WAS WRITTEN BY CHATGPT".
Which is why you should never assume that a paper makes sense merely because it is technically correct.