Watermarking of language model outputs enables statistical detection of model-generated text, which has many applications in the responsible deployment of language models. Existing watermarking strategies operate by altering the decoder of an existing language model, and the ability for a language model to directly learn to generate the watermark would have significant implications for the real-world deployment of watermarks. First, learned watermarks could be used to build open models that naturally generate watermarked text, allowing for open models to benefit from watermarking. Second, if watermarking is used to determine the provenance of generated text, an adversary can hurt the reputation of a victim model by spoofing its watermark and generating damaging watermarked text. To investigate the learnability of watermarks, we propose watermark distillation, which trains a student model to behave like a teacher model that uses decoding-based watermarking. We test our approach on three distinct decoding-based watermarking strategies and various hyperparameter settings, finding that models can learn to generate watermarked text with high detectability. We also find limitations to learnability, including the loss of watermarking capabilities under fine-tuning on normal text and high sample complexity when learning low-distortion watermarks.
翻译:语言模型输出的水印技术能够实现对模型生成文本的统计检测,这在语言模型负责任部署中具有广泛应用。现有水印策略通过修改语言模型的解码器来实现,而语言模型直接学习生成水印的能力将对水印的实际部署产生重要影响。首先,可学习的水印可用于构建自然生成水印文本的开放模型,使开源模型能够受益于水印技术。其次,若水印用于确定生成文本的溯源,攻击者可能通过伪造水印并生成具有破坏性的水印文本,损害目标模型的声誉。为探究水印的可学习性,我们提出水印蒸馏技术,该方法训练学生模型模仿采用解码式水印的教师模型行为。我们在三种不同的解码式水印策略及多种超参数设置下进行测试,发现模型能够学习生成具有高检测性的水印文本。同时我们也发现可学习性的局限性,包括在常规文本微调时水印能力的丧失,以及在学习低失真水印时需较高样本复杂度。