Pith. sign in

REVIEW 2 cited by

Bypassing LLM Watermarks with Color-Aware Substitutions

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2403.14719 v1 pith:V6GAP655 submitted 2024-03-19 cs.CR cs.CVcs.LG

classification cs.CRcs.CVcs.LG
keywords sctstexttokenswatermarkingattackcolorcolor-awaredetection
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Watermarking approaches are proposed to identify if text being circulated is human or large language model (LLM) generated. The state-of-the-art watermarking strategy of Kirchenbauer et al. (2023a) biases the LLM to generate specific (``green'') tokens. However, determining the robustness of this watermarking method is an open problem. Existing attack methods fail to evade detection for longer text segments. We overcome this limitation, and propose {\em Self Color Testing-based Substitution (SCTS)}, the first ``color-aware'' attack. SCTS obtains color information by strategically prompting the watermarked LLM and comparing output tokens frequencies. It uses this information to determine token colors, and substitutes green tokens with non-green ones. In our experiments, SCTS successfully evades watermark detection using fewer number of edits than related work. Additionally, we show both theoretically and empirically that SCTS can remove the watermark for arbitrarily long watermarked text.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SoK: On the Role and Future of AIGC Watermarking in the Era of Gen-AI

    cs.CR 2024-11 conditional novelty 5.0 of 10

    A systematization of AI-generated content watermarking that introduces a formal supply-chain definition and a property-based taxonomy.

  2. I'm Spartacus, No, I'm Spartacus: Measuring and Understanding LLM Identity Confusion

    cs.CR 2024-11 reject novelty 5.0 of 10

    Seven of 27 tested LLMs (25.93%) exhibited identity confusion, which the authors link to hallucination and show reduces user trust, especially in critical tasks.

Pith tools