应用科学学报 ›› 2025, Vol. 43 ›› Issue (3): 361-369.doi: 10.3969/j.issn.0255-8297.2025.03.001
宋轶旻, 刘功申
收稿日期:2024-10-30
出版日期:2025-05-30
发布日期:2025-06-23
通信作者:
刘功申,教授,博士生导师,研究方向为人工智能安全、自然语言理解、内容安全。E-mail:lgshen@sjtu.edu.cn
E-mail:lgshen@sjtu.edu.cn
基金资助:SONG Yimin, LIU Gongshen
Received:2024-10-30
Online:2025-05-30
Published:2025-06-23
摘要: 本文主要针对文本水印技术在中文语境下研究的不足,使用修改式水印与生成式水印两种方案对于中英文文本水印技术进行了实现。利用针对英文的Bert模型和针对中文的WoBert模型,设计了可移植的词替换水印模块,通过替换源文本中指定词元的方式在源文本中嵌入水印信息。对于生成式水印,采用对抗生成式文本水印模型,在中文语料上进行了针对性地修改与迁移,以适应中文文本的语义结构和语言习惯。使用中英文下的人类-ChatGPT对比语料库进行实验,结合准确与语义两方面的文本水印评估指标对2个数据集下不同模型的水印质量进行了评估,以说明水印在多种语料下的有效性。
中图分类号:
宋轶旻, 刘功申. 基于文本水印的AIGC用户溯源技术[J]. 应用科学学报, 2025, 43(3): 361-369.
SONG Yimin, LIU Gongshen. AIGC Users Traceability Technology Based on Text Watermarking[J]. Journal of Applied Sciences, 2025, 43(3): 361-369.
| [1] Vaswani A, Shazeer N, Parmar N, et al. Attention is all you need [J]. Advances in Neural Information Processing Systems, 2017, 30: 5997-6008. [2] Radford A, Wu J, Child R, et al. Language models are unsupervised multitask learners [EB/OL]. [2024-10-30]. https://cdn.openai.com/better-language-models/language_models_ are_unsupervised_multitask_learners.pdf. [3] Bai Y, Jones A, Ndousse K, et al. Training a helpful and harmless assistant with reinforcement learning from human feedback [DB/OL]. (2022-04-22) [2024-10-30]. http://arxiv.org/abs/2204.05862. [4] Touvron H, Lavril T, Izacard G, et al. Llama: open and efficient foundation language models [DB/OL]. (2023-02-27) [2024-10-30]. http://arxiv.org/abs/2302.13971. [5] Black S, Biderman S, Hallahan E, et al. GPT-Neox-20B: an open-source autoregressive language model [DB/OL]. (2022-04-14) [2024-10-30]. http://arxiv.org/abs/2204.06745. [6] Firdhous M F M, Elbreiki W, Abdullahi I, et al. WormGPT: a large language model Chatbot for criminals [C]//202324th International Arab Conference on Information Technology (ACIT). IEEE, 2023: 1-6. [7] Liu A, Pan L, Lu Y, et al. A survey of text watermarking in the era of large language models [J]. ACM Computing Surveys, 2024, 57(2): 1-36. [8] Brassil J T, Low S, Maxemchuk N F, et al. Electronic marking and identification techniques to discourage document copying [J]. IEEE Journal on Selected Areas in Communications, 1995, 13(8): 1495-1504. [9] Por L Y, Wong K S, Chee K O. UniSpaCh: a text-based data hiding method using Unicode space characters [J]. Journal of Systems and Software, 2012, 85(5): 1075-1082. [10] Sato R, Takezawa Y, Bao H, et al. Embarrassingly simple text watermarks [DB/OL]. (2023- 10-13) [2024-10-30]. http://arxiv.org/abs/2204.06745. [11] 刘豪, 孙星明, 刘晋飚. 基于字体颜色的文本数字水印算法[J]. 计算机工程, 2005, 31(15): 129-131. Liu H, Sun X M, Liu J B. Color-based watermarking algorithm for text documents [J]. Computer Engineering, 2005, 31(15): 129-131.(in Chinese) [12] Topkara U, Topkara M, Atallah M J. The hiding virtues of ambiguity: quantifiably resilient watermarking of natural language text through synonym substitutions [C]//8th Workshop on Multimedia and Security, 2006: 164-174. [13] Munyer T, Tanvir A, Das A, et al. DeepTextMark: a deep learning-driven text watermarking approach for identifying large language model generated text [DB/OL]. (2023-05-09) [2024-10- 30]. http://arxiv.org/abs/2305.05773. [14] Abdelnabi S, Fritz M. Adversarial watermarking transformer: towards tracing text provenance with data hiding [C]//2021 IEEE Symposium on Security and Privacy (SP). IEEE, 2021: 121-140. [15] Sun Z, Du X, Song F, et al. Coprotector: protect open-source code against unauthorized training usage with data poisoning [C]//ACM Web Conference, 2022: 652-660. [16] Kirchenbauer J, Geiping J, Wen Y, et al. A watermark for large language models [C]//International Conference on Machine Learning, 2023: 17061-17084. [17] Christ M, Gunn S, Zamir O. Undetectable watermarks for language models [C]//The Thirty Seventh Annual Conference on Learning Theory, 2024: 1125-1139. [18] Guo B, Zhang X, Wang Z, et al. How close is ChatGPT to human experts? comparison corpus, evaluation, and detection [DB/OL]. (2023-01-18) [2024-10-30]. http://arxiv.org/abs/ 2301.07597. |
| [1] | 陈昱胤, 李贯峰, 秦晶, 肖毓航. 基于改进Transformer的复杂逻辑查询模型[J]. 应用科学学报, 2026, 44(1): 34-49. |
| [2] | 江泽涛, 杨建琛, 李孟桐, 程留明, 张路豪. 一种基于边缘特征引导的低照度图像细节增强方法[J]. 应用科学学报, 2025, 43(6): 948-961. |
| [3] | 李依静, 闻建刚, 邹园萍, 华惊宇, 盛彬. OFDM系统中基于遗传算法的SR-NYQ脉冲成形滤波器设计[J]. 应用科学学报, 2025, 43(5): 730-739. |
| [4] | 卢菁, 葛聪. 结合通用轨迹图和多偏好的兴趣点推荐方法[J]. 应用科学学报, 2025, 43(5): 771-784. |
| [5] | 张庆玲, 倪翠, 王朋, 巩慧. 一种基于改进深度确定性策略梯度的移动机器人路径规划算法[J]. 应用科学学报, 2025, 43(3): 415-436. |
| [6] | 金彦亮, 方洁, 高塬, 周嘉豪. 基于对比学习的半监督加密流量分类模型[J]. 应用科学学报, 2025, 43(3): 437-450. |
| [7] | 汪婉灵, 熊邦书, 欧巧凤, 余磊, 饶智博. 基于暗区域引导的低照度图像增强[J]. 应用科学学报, 2025, 43(2): 245-256. |
| [8] | 成佳, 陈玲姣, 吴岳忠. 基于相对信任增强的推荐算法[J]. 应用科学学报, 2025, 43(1): 110-122. |
| [9] | 王华, 何群, 谭如超, 武冬, 方一诺, 马跃辉, 严开全, 牟成博. 基于锁模激光器的FBG电流传感器高速解调系统[J]. 应用科学学报, 2024, 42(6): 903-911. |
| [10] | 江泽涛, 黄景帆, 朱文才, 黄钦阳, 金鑫. 基于CRTNet的低照度图像增强方法[J]. 应用科学学报, 2024, 42(6): 934-946. |
| [11] | 卢菁, 尤晨璐, 盖祺凯, 刘丛. 利用邻近度与内容特征的用户识别方法[J]. 应用科学学报, 2024, 42(6): 1064-1077. |
| [12] | 鹿靖, 李游. 基于稳态集-射极饱和电压的IGBT功率模块疲劳失效模型的研究[J]. 应用科学学报, 2024, 42(6): 1078-1088. |
| [13] | 施智罡, 黄建华, 李天琪. 一种面向车联网的区块链模型[J]. 应用科学学报, 2024, 42(4): 549-568. |
| [14] | 刘凯, 王佳鑫, 毛谦昂, 陈煜菲, 颜嘉麒. 区块链游戏生态的角色动态识别与演化分析——以Axie Infinity为例[J]. 应用科学学报, 2024, 42(4): 642-658. |
| [15] | 吴锴, 龚华平, 倪凯, 毛邦宁, 赵春柳. 基于光纤光栅的多点拉锥光纤柔性曲率传感器[J]. 应用科学学报, 2024, 42(2): 237-247. |
| 阅读次数 | ||||||
|
全文 |
|
|||||
|
摘要 |
|
|||||