Pith. sign in

REVIEW 1 cited by

Black-Box Detection of Language Model Watermarks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2405.20777 v3 pith:AGM7ER3K submitted 2024-05-28 cs.CR cs.LG

classification cs.CRcs.LG
keywords watermarkingschemesblack-boxworkcurrentdetectdetectablefamilies
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Watermarking has emerged as a promising way to detect LLM-generated text, by augmenting LLM generations with later detectable signals. Recent work has proposed multiple families of watermarking schemes, several of which focus on preserving the LLM distribution. This distribution-preservation property is motivated by the fact that it is a tractable proxy for retaining LLM capabilities, as well as the inherently implied undetectability of the watermark by downstream users. Yet, despite much discourse around undetectability, no prior work has investigated the practical detectability of any of the current watermarking schemes in a realistic black-box setting. In this work we tackle this for the first time, developing rigorous statistical tests to detect the presence, and estimate parameters, of all three popular watermarking scheme families, using only a limited number of black-box queries. We experimentally confirm the effectiveness of our methods on a range of schemes and a diverse set of open-source models. Further, we validate the feasibility of our tests on real-world APIs. Our findings indicate that current watermarking schemes are more detectable than previously believed.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. WaterMoE: Expert-Routing-based Watermarking for High Fidelity and Efficiency

    cs.CR 2026-07 conditional novelty 7.0 of 10

    WaterMoE watermarks MoE LLMs by adding a small secret bias to router expert selection, claiming near-zero quality loss, ~1% latency overhead, and strong detection.

Pith tools