We study statistical watermarking by formulating it as a hypothesis testing problem, a general framework which subsumes all previous statistical watermarking methods. Key to our formulation is a coupling of the output tokens and the rejection region, realized by pseudo-random generators in practice, that allows non-trivial trade-off between the Type I error and Type II error. We characterize the Uniformly Most Powerful (UMP) watermark in this context. In the most common scenario where the output is a sequence of $n$ tokens, we establish matching upper and lower bounds on the number of i.i.d. tokens required to guarantee small Type I and Type II errors. Our rate scales as $\Theta(h^{-1} \log (1/h))$ with respect to the average entropy per token $h$ and thus greatly improves the $O(h^{-2})$ rate in the previous works. For scenarios where the detector lacks knowledge of the model's distribution, we introduce the concept of model-agnostic watermarking and establish the minimax bounds for the resultant increase in Type II error. Moreover, we formulate the robust watermarking problem where user is allowed to perform a class of perturbation on the generated texts, and characterize the optimal type II error of robust UMP tests via a linear programming problem. To the best of our knowledge, this is the first systematic statistical treatment on the watermarking problem with near-optimal rates in the i.i.d. setting, and might be of interest for future works.
翻译:我们通过将统计水印问题形式化为假设检验框架来研究该问题,该通用框架涵盖了所有先前的统计水印方法。这一形式化过程的核心在于输出令牌与拒绝域之间的耦合(实践中通过伪随机生成器实现),使得第一类错误与第二类错误之间能够实现非平凡权衡。在此框架下,我们刻画了均匀最优势(UMP)水印的特征。针对最常见的输出为$n$个令牌序列的场景,我们建立了在保证第一类和第二类错误率较小的前提下所需独立同分布令牌数量的匹配上下界。该速率关于每个令牌的平均熵$h$呈$\Theta(h^{-1} \log (1/h))$标度,较先前工作中$O(h^{-2})$的速率有显著提升。针对检测器无法获知模型分布的场景,我们提出了模型无关水印概念,并建立了由此导致的第二类错误率增加的极小化极大界。此外,我们构建了鲁棒水印问题框架——允许用户对生成文本施加特定扰动类别,并通过线性规划问题刻画了鲁棒UMP检验的最优第二类错误率。据我们所知,这是首个在独立同分布设定下具有近最优速率的系统性统计水印处理方法,有望为未来研究提供重要参考。