We construct pseudorandom error-correcting codes (or simply pseudorandom codes), which are error-correcting codes with the property that any polynomial number of codewords are pseudorandom to any computationally-bounded adversary. Efficient decoding of corrupted codewords is possible with the help of a decoding key. We build pseudorandom codes that are robust to substitution and deletion errors, where pseudorandomness rests on standard cryptographic assumptions. Specifically, pseudorandomness is based on either $2^{O(\sqrt{n})}$-hardness of LPN, or polynomial hardness of LPN and the planted XOR problem at low density. As our primary application of pseudorandom codes, we present an undetectable watermarking scheme for outputs of language models that is robust to cropping and a constant rate of random substitutions and deletions. The watermark is undetectable in the sense that any number of samples of watermarked text are computationally indistinguishable from text output by the original model. This is the first undetectable watermarking scheme that can tolerate a constant rate of errors. Our second application is to steganography, where a secret message is hidden in innocent-looking content. We present a constant-rate stateless steganography scheme with robustness to a constant rate of substitutions. Ours is the first stateless steganography scheme with provable steganographic security and any robustness to errors.
翻译:我们构造了伪随机纠错码(或简称为伪随机码),这类纠错码具有以下性质:任意多项式数量的码字对于任何计算有界的敌手均呈现伪随机性。借助解码密钥,可以对受损码字进行高效解码。我们构建了对替换和删除错误具有鲁棒性的伪随机码,其伪随机性基于标准密码学假设。具体而言,伪随机性要么基于LPN问题的 $2^{O(\sqrt{n})}$ 难度,要么基于LPN问题的多项式难度和低密度植入XOR问题。作为伪随机码的主要应用,我们提出了一种针对语言模型输出的不可检测水印方案,该方案对裁剪及恒定比率的随机替换和删除具有鲁棒性。该水印的不可检测性体现在:任意数量的水印文本样本与原始模型输出的文本在计算上不可区分。这是首个能够容忍恒定错误率的不可检测水印方案。我们的第二个应用是隐写术,即将秘密消息隐藏在看似无害的内容中。我们提出了一种恒定比率的无状态隐写方案,对恒定比率的替换具有鲁棒性。这是首个具有可证明隐写安全性且具备任何错误鲁棒性的无状态隐写方案。