This is not a SFW instance. NSFW communities will be tagged, and efforts will be made to keep SFW communities clean, but proceed at your own comfort level.
It says this works also for text copied from Claude and pasted into other applications. How is that possible? What degree of metadata storage is possible in text?
LLMs are big statistical networks that determine the following word in a sentence. If two words are just as likely to follow, Claude is gonna pick the next word based on a secret key and somehow this can be looked up later. That appears to be the gist of it if I understood it correctly.
Yep, also my understanding of the mechanism. For small texts it’s probably not that hard to modify it enough to disguise it but the larger the text is, the harder it gets to remove the statistical watermark.
The mechanism happens in the way LLMs generate text sequentially. So as the LLM generates text, each time the LLM encounters a choice between two or more equally probable words and has to pick one, it chooses from a known pseudorandom key instead of its previous practice of actually relying on a source of randomness.
If you run the text through a checker script that tries to predict the next word, and takes note of every choice made in any given fork in the probabilistic flowchart, you can see that whole sequence of choices and compare to whether it matches a known key.
You’d need to know the model itself well enough to know when the text reaches a particular fork, and what the choices are in that fork, and the key itself, so even OpenAI/Google/Anthropic may not be able to run this watermark detection on their competitors’ models. But they’d be able to know it themselves, for their own models.
They said it’d even work if the text was substantially edited by the user, though. Maybe there’s multiple layers of redundancy so it just degrades the watermark but it takes a lot of editing to completely dilute it.
I think the first person was right. It’s probably just a pattern based on this part:
It may also survive certain edits. However, the company warned that extensive rewriting, paraphrasing, translation, or mixing the content with human-written material could weaken or remove the detectable signal.
It says this works also for text copied from Claude and pasted into other applications. How is that possible? What degree of metadata storage is possible in text?
LLMs are big statistical networks that determine the following word in a sentence. If two words are just as likely to follow, Claude is gonna pick the next word based on a secret key and somehow this can be looked up later. That appears to be the gist of it if I understood it correctly.
Yep, also my understanding of the mechanism. For small texts it’s probably not that hard to modify it enough to disguise it but the larger the text is, the harder it gets to remove the statistical watermark.
It’s like a style, except it changes every word. If you know how, you can see when text is written in-style.
The mechanism happens in the way LLMs generate text sequentially. So as the LLM generates text, each time the LLM encounters a choice between two or more equally probable words and has to pick one, it chooses from a known pseudorandom key instead of its previous practice of actually relying on a source of randomness.
If you run the text through a checker script that tries to predict the next word, and takes note of every choice made in any given fork in the probabilistic flowchart, you can see that whole sequence of choices and compare to whether it matches a known key.
You’d need to know the model itself well enough to know when the text reaches a particular fork, and what the choices are in that fork, and the key itself, so even OpenAI/Google/Anthropic may not be able to run this watermark detection on their competitors’ models. But they’d be able to know it themselves, for their own models.
Fontsize 0pt :)
Pattern matching, maybe an extra space every 5 word, ensure the 3rd sentence starts with a T and ends with a P, etc.
They said it’d even work if the text was substantially edited by the user, though. Maybe there’s multiple layers of redundancy so it just degrades the watermark but it takes a lot of editing to completely dilute it.
I can’t think of any pattern that is supposed to survive edits that wouldn’t create a ton of false positives in existing works.
So an average AI and plagiarism detector that already exists.
I think the first person was right. It’s probably just a pattern based on this part: