Pith. sign in

REVIEW 2 cited by

No Free Lunch in LLM Watermarking: Trade-offs in Watermarking Design Choices

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2402.16187 v3 pith:E2IHPRD3 submitted 2024-02-25 cs.CR cs.CLcs.LG

classification cs.CRcs.CLcs.LG
keywords watermarkingtrade-offsai-generatedchoicescommoncontentdesignsystems
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Advances in generative models have made it possible for AI-generated text, code, and images to mirror human-generated content in many applications. Watermarking, a technique that aims to embed information in the output of a model to verify its source, is useful for mitigating the misuse of such AI-generated content. However, we show that common design choices in LLM watermarking schemes make the resulting systems surprisingly susceptible to attack -- leading to fundamental trade-offs in robustness, utility, and usability. To navigate these trade-offs, we rigorously study a set of simple yet effective attacks on common watermarking systems, and propose guidelines and defenses for LLM watermarking in practice.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Beyond Easy Wins: A Text Hardness-Aware Benchmark for LLM-generated Text Detection

    cs.CL 2025-07 conditional novelty 6.0 of 10

    SHIELD shows that standard AUROC overstates AI-text detector quality, and that six zero-shot detectors collapse under a controllable word-replacement humanification.

  2. Modification and Generated-Text Detection: Achieving Dual Detection Capabilities for the Outputs of LLM by Watermark

    cs.CR 2025-02 conditional novelty 4.0 of 10

    A discarded-token count over the δ-reweight watermark detects text modifications while a modified detection score still confirms machine generation.

Pith tools