A Statistical Framework of Watermarks for Large Language Models: Pivot, Detection Efficiency and Optimal Rules
arXiv:2404.01245 · doi:10.1214/24-AOS2468
Abstract
Since ChatGPT was introduced in November 2022, embedding (nearly) unnoticeable statistical signals into text generated by large language models (LLMs), also known as watermarking, has been used as a principled approach to provable detection of LLM-generated text from its human-written counterpart. In this paper, we introduce a general and flexible framework for reasoning about the statistical efficiency of watermarks and designing powerful detection rules. Inspired by the hypothesis testing formulation of watermark detection, our framework starts by selecting a pivotal statistic of the text and a secret key -- provided by the LLM to the verifier -- to enable controlling the false positive rate (the error of mistakenly detecting human-written text as LLM-generated). Next, this framework allows one to evaluate the power of watermark detection rules by obtaining a closed-form expression of the asymptotic false negative rate (the error of incorrectly classifying LLM-generated text as human-written). Our framework further reduces the problem of determining the optimal detection rule to solving a minimax optimization program. We apply this framework to two representative watermarks -- one of which has been internally implemented at OpenAI -- and obtain several findings that can be instrumental in guiding the practice of implementing watermarks. In particular, we derive optimal detection rules for these watermarks under our framework. These theoretically derived detection rules are demonstrated to be competitive and sometimes enjoy a higher power than existing detection approaches through numerical experiments.
Accepted by Annals of Statistics
References in corpus (18)
- Exploring the Limits of Transfer Learning with a Unified Text-to-Text Transformer
- Categorical Reparameterization with Gumbel-Softmax
- Language Models are Few-Shot Learners
- Robust Speech Recognition via Large-Scale Weak Supervision
- Testing of Detection Tools for AI-Generated Text
- Distributionally Robust Optimization: A Review
- Paraphrasing evades detectors of AI-generated text, but retrieval is an effective defense
- Random Utility Theory for Social Choice
- On the Partition Function and Random Maximum A-Posteriori Perturbations
- Near-Optimal Algorithms for Minimax Optimization
- Intrinsic Dimension Estimation for Robust Detection of AI-Generated Texts
- On the Reliability of Watermarks for Large Language Models
- Sheared LLaMA: Accelerating Language Model Pre-training via Structured Pruning
- Robust Distortion-free Watermarks for Language Models
- Provable Robust Watermarking for AI-Generated Text
- Undetectable Watermarks for Language Models
- Unbiased Watermark for Large Language Models
- Adaptive Text Watermark for Large Language Models