Pith. sign in

REVIEW 2 cited by

Watermarking Text Data on Large Language Models for Dataset Copyright

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2305.13257 v4 pith:JT2GF5YQ submitted 2023-05-22 cs.CR

classification cs.CR
keywords datamodelstextmarkerdatasetinformationtrainingcopyrightinference
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Substantial research works have shown that deep models, e.g., pre-trained models, on the large corpus can learn universal language representations, which are beneficial for downstream NLP tasks. However, these powerful models are also vulnerable to various privacy attacks, while much sensitive information exists in the training dataset. The attacker can easily steal sensitive information from public models, e.g., individuals' email addresses and phone numbers. In an attempt to address these issues, particularly the unauthorized use of private data, we introduce a novel watermarking technique via a backdoor-based membership inference approach named TextMarker, which can safeguard diverse forms of private information embedded in the training text data. Specifically, TextMarker only requires data owners to mark a small number of samples for data copyright protection under the black-box access assumption to the target model. Through extensive evaluation, we demonstrate the effectiveness of TextMarker on various real-world datasets, e.g., marking only 0.1% of the training dataset is practically sufficient for effective membership inference with negligible effect on model utility. We also discuss potential countermeasures and show that TextMarker is stealthy enough to bypass them.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. STAMP Your Content: Proving Dataset Membership via Watermarked Rephrasings

    cs.LG 2025-04 conditional novelty 7.0 of 10

    STAMP detects dataset membership in LLMs by comparing model perplexity on a publicly released watermarked rephrasing against private watermarked rephrasings of the same documents.

  2. Data Watermarking for Sequential Recommender Systems

    cs.IR 2024-11 conditional novelty 6.0 of 10

    Inserting short consecutive item sequences into user interaction histories lets a data owner detect whether a sequential recommender was trained on the protected dataset.

Pith tools