We study statistical watermarking by formulating it as a hypothesis testing problem, a general framework which subsumes all previous statistical watermarking methods. Key to our formulation is a coupling of the output tokens and the rejection region, realized by pseudo-random generators in practice, that allows non-trivial trade-offs between the Type I error and Type II error. We characterize the Uniformly Most Powerful (UMP) watermark in the general hypothesis testing setting and the minimax Type II error in the model-agnostic setting. In the common scenario where the output is a sequence of $n$ tokens, we establish nearly matching upper and lower bounds on the number of i.i.d. tokens required to guarantee small Type I and Type II errors. Our rate of $\Theta(h^{-1} \log (1/h))$ with respect to the average entropy per token $h$ highlights potentials for improvement from the rate of $h^{-2}$ in the previous works. Moreover, we formulate the robust watermarking problem where the user is allowed to perform a class of perturbations on the generated texts, and characterize the optimal Type II error of robust UMP tests via a linear programming problem. To the best of our knowledge, this is the first systematic statistical treatment on the watermarking problem with near-optimal rates in the i.i.d. setting, which might be of interest for future works.
翻译:我们将统计水印问题形式化为一个假设检验问题,该通用框架涵盖了所有先前的统计水印方法。我们构建的关键在于输出令牌与拒绝域之间的耦合(实践中通过伪随机生成器实现),这使得第一类错误与第二类错误之间能够实现非平凡的权衡。我们在一般假设检验场景中刻画了均匀最优势(UMP)水印,并在模型无关场景中刻画了极小化第二类错误。在常见场景中,输出为$n$个令牌的序列时,我们建立了确保第一类与第二类错误较小的独立同分布令牌数量的近乎匹配的上下界。关于每个令牌的平均熵$h$,我们的速率$\Theta(h^{-1} \log (1/h))$凸显了相较于先前工作中$h^{-2}$速率的改进潜力。此外,我们提出了鲁棒水印问题(允许用户对生成文本施加一类扰动),并通过线性规划问题描述了鲁棒UMP测试的最优第二类错误。据我们所知,这是首次在独立同分布场景下对水印问题进行系统性统计处理并给出近最优速率的研究,可能对未来工作具有参考价值。