Watermarking Conditional Text Generation for AI Detection: Unveiling Challenges and a Semantic-Aware Watermark Remedy

Yu FuDeyi XiongYue Dong

article2024AAAI63 citations

Presents a semantic-aware watermarking algorithm for conditional text generation that preserves output quality in summarization and data-to-text tasks by aligning green-list vocabulary partitions with input context embeddings.

Listen

As artificial intelligence language models generate increasingly realistic text, organizations face mounting risks from misinformation, factual hallucinations, and unauthorized automated writing. Watermarking—a technique that embeds hidden mathematical patterns into generated vocabulary to identify AI origins—has emerged as a primary compliance and safety tool. However, current watermarking methods designed for open-ended text generation fail when applied to conditional text generation tasks, such as document summarization and data-to-text generation, where the output must closely reflect input source text. The article evaluates why existing watermarks degrade task performance and introduces a context-aware watermarking remedy to solve this issue.

To address this limitation, the authors developed a semantic-aware watermarking algorithm that links vocabulary selection directly to the input context. Rather than randomly splitting words into permitted (green) and restricted (red) lists at each step, the proposed method uses word embedding similarity to identify tokens closely related to the input source and prioritizes their inclusion on the green list. The researchers evaluated this approach across multiple model architectures, including BART and Flan-T5, using standard benchmarks for text summarization (CNN/DailyMail and XSum) and data-to-text generation (DART and WebNLG). They complemented automated quality and statistical detection metrics with blinded human evaluations.

The findings demonstrate that applying standard, unadapted watermarks causes severe performance drops in conditional generation—reducing quality scores by up to 96.99% under strict watermark constraints and up to 27.54% under softer settings—because crucial source words are randomly banned, triggering hallucinations. In contrast, the semantic-aware watermark restored generation quality across all models and tasks, recovering substantial performance (for instance, improving data-to-text BLEU scores by up to 21.67 times over standard watermarks). In human evaluations, judges preferred the semantic-aware watermarked summaries by a margin of 55.33% to 44.67%. The investigation also revealed a detection paradox: while the proposed method achieves high statistical detection confidence (z-scores), overall classification accuracy (measured by area under the curve, or AUC) slightly decreased because human writers also naturally rely heavily on source-related words.

These insights are critical for organizations implementing AI governance, safety controls, and content compliance. Deploying standard watermarks in conditional workflows introduces unacceptable operational risks, including severe factual distortion and degraded task output. The semantic-aware approach demonstrates that watermarking can be integrated into high-fidelity conditional generation systems without crippling performance, though decision-makers must account for the slight trade-off in absolute detection accuracy.

Organizations deploying AI watermarks in production should adopt semantic-aware constraints rather than generic random partitioning when performing summarization, translation, or structured reporting. Moving forward, engineering and research teams should conduct pilot implementations to balance the hyperparameter controlling the volume of included semantic tokens against detection requirements. Further research is recommended to refine detection classifiers, specifically addressing the overlapping vocabulary naturally shared between human writers and source texts.

arXiv: 2307.13808
Cover for Watermarking Conditional Text Generation for AI Detection: Unveiling Challenges and a Semantic-Aware Watermark Remedy

Abstract

To mitigate potential risks associated with language models (LMs), recent AI detection research proposes incorporating watermarks into machine-generated text through random vocabulary restrictions and utilizing this information for detection. In this paper, we show that watermarking algorithms designed for LMs cannot be seamlessly applied to conditional text generation (CTG) tasks without a notable decline in downstream task performance. To address this issue, we introduce a simple yet effective semantic-aware watermarking algorithm that considers the characteristics of conditional text generation with the input context. Compared to the baseline watermarks, our proposed watermark yields significant improvements in both automatic and human evaluations across various text generation models, including BART and Flan-T5, for CTG tasks such as summarization and data-to-text generation. Meanwhile, it maintains detection ability with higher z-scores but lower AUC scores, suggesting the presence of a detection paradox that poses additional challenges for watermarking CTG.

Table of Contents

  • Introduction
  • Related Work
  • Method
  • Semantic-Aware Watermark
  • Experiments and Results
  • Datasets and Models
  • Main Results
  • Watermark Strength and Detection
  • Analysis
  • Semantic k Analysis
  • γ and δ Analysis
  • Conclusion
  • References

Knowls

  1. Knowl 1 — Random vocabulary watermarks can severely damage conditional generation

    empirical result

    Applying the original random-list watermark designed for unconditional language-model generation directly to conditional text generation (CTG) causes large task-quality losses because tokens required by the source context may be placed in the red list. Across summarization and data-to-text generation with BART and Flan-T5 models, the paper reports performance drops of up to 96.99% with hard watermarks and 27.54% with soft watermarks. In a DART data-to-text example, the original watermark placed a source entity that needed to be reproduced into the red list; the resulting 30-token output contained 12 hallucinated words. The central empirical finding is that CTG watermarks must account for the relationship between the input and output rather than randomly partitioning the vocabulary alone.

  2. Knowl 2 — Semantic-aware watermarking preserves source-related generation tokens

    model/method

    The semantic-aware watermark (SW) adapts vocabulary partitioning to the input source in a conditional text generation task. Source tokens are used as pivots, and tokens semantically related to those source tokens according to the generation model’s token embeddings are preferentially placed in the green list. Only the remaining vocabulary is randomly partitioned into green and red lists using a hash-seeded random generator. Green-list logits are then increased by the watermark strength, allowing source-related words to remain easy for the conditional model to generate while retaining randomized detection information. The method uses the green-list fraction γ∈(0,1)\gamma\in(0,1), logit-boost parameter δ>0\delta>0, and semantic-neighborhood parameter k∈{1,2,5,10}k\in\{1,2,5,10\}. Its design exploits the high lexical or semantic overlap typical of CTG outputs with their inputs, thereby reducing the quality degradation caused by random watermarking.

  3. Knowl 3 — Conditional watermark generation rule

    equation

    Let VV be a vocabulary, let Gt⊂VG_t\subset V and Rt=V∖GtR_t=V\setminus G_t be the green and red lists at generation step tt, and let lk(t)l_k^{(t)} be the conditional model’s logit for token k∈Vk\in V. With watermark strength δ>0\delta>0, the soft-watermark distribution is

    p~t(k)={exp⁡ ⁣(lk(t)+δ)∑i∈Rtexp⁡ ⁣(li(t))+∑i∈Gtexp⁡ ⁣(li(t)+δ),k∈Gt,exp⁡ ⁣(lk(t))∑i∈Rtexp⁡ ⁣(li(t))+∑i∈Gtexp⁡ ⁣(li(t)+δ),k∈Rt.\widetilde p_t(k)= \begin{cases} \displaystyle\frac{\exp\!\left(l_k^{(t)}+\delta\right)}{\displaystyle\sum_{i\in R_t}\exp\!\left(l_i^{(t)}\right)+\sum_{i\in G_t}\exp\!\left(l_i^{(t)}+\delta\right)}, & k\in G_t,\\[1.2em] \displaystyle\frac{\exp\!\left(l_k^{(t)}\right)}{\displaystyle\sum_{i\in R_t}\exp\!\left(l_i^{(t)}\right)+\sum_{i\in G_t}\exp\!\left(l_i^{(t)}+\delta\right)}, & k\in R_t. \end{cases}

    The next token is sampled from p~t\widetilde p_t. A hard watermark is the limiting high-δ\delta case in which red-list tokens are effectively forbidden. The original watermark forms GtG_t and RtR_t randomly from a hash of previously generated tokens, whereas the semantic-aware watermark first reserves source-related tokens for GtG_t and randomizes only the remaining vocabulary.

  4. Knowl 4 — Semantic-aware watermark algorithm

    algorithm

    The procedure below is the complete semantic-aware watermarking process. It takes a source sequence, a conditional generation model, vocabulary fraction γ\gamma, watermark strength δ\delta, and neighborhood size kk; it returns a watermarked output sequence.

    Input: source token sequence x, vocabulary V, conditional model pθ, green-list fraction γ, strength δ, semantic-neighborhood size k
    Output: watermarked output sequence y
    Precompute the token-embedding matrix E and pairwise similarity matrix M for V.
    For every source token in x, retrieve its k most similar vocabulary tokens from M.
    Take the union of the retrieved tokens as the semantic set S and insert S into the green list G.
    For each generation step t:
        Run pθ on x and the generated prefix y<t to obtain logits l(t) over V.
        Hash the previously generated token y(t-1) and use the hash to seed a random-number generator.
        Randomly partition the remaining vocabulary into enough green-list tokens to make |G| = γ|V| and a red list R of size (1 − γ)|V|.
        Add δ to every logit of a token in G.
        Renormalize the modified logits over G ∪ R to obtain the watermarked distribution.
        Sample the next token y(t) from that distribution.
    Return y.

    The embedding similarity matrix has dimensions ∣V∣×∣V∣|V|\times|V|; the paper describes cosine similarity as one possible similarity measure. The semantic tokens are selected before the random partition, so the green list contains both deterministic source-related coverage and hash-dependent randomness.

  5. Knowl 5 — Experimental evaluation across CTG tasks and models

    experimental setup

    The evaluation covers two conditional text generation tasks and four datasets: CNN/DailyMail and XSUM for summarization, and DART and WebNLG for data-to-text generation. The evaluated architectures and sizes include BART-base, BART-large, Flan-T5-small, and Flan-T5-base. Summarization quality is measured with ROUGE-1, ROUGE-2, and ROUGE-L; data-to-text quality is measured with BLEU. The comparisons use no watermark (NW), the original random watermark (OW), and the semantic-aware watermark (SW). In the main comparisons, both watermark families use γ=0.5\gamma=0.5; hard settings use δ=10\delta=10, soft settings use δ=2\delta=2, and SW uses semantic neighborhood sizes k∈{1,2,5,10}k\in\{1,2,5,10\}. The no-watermark system is the quality baseline, so degradation relative to NW measures the cost of detection-oriented watermarking.

  6. Knowl 6 — Semantic-aware watermarking substantially improves summarization quality

    data/table

    The following ROUGE results compare no watermark (NW), original hard and soft watermarks (OW), and semantic-aware hard and soft watermarks (SW). Higher values are better. The semantic-aware method remains close to or occasionally exceeds the no-watermark baseline, whereas the original hard watermark causes the largest losses, especially for ROUGE-2.

    Could not parse LaTeX table

    For example, on CNN/DailyMail with Flan-T5-base, SW hard obtains ROUGE-1/2/L of 41.80/19.80/38.72, nearly matching or exceeding NW at 41.78/19.57/38.66, while OW hard falls to 24.47/5.60/22.48. On XSUM with BART-large, SW hard improves over OW hard by 12.84 ROUGE-1 points, 11.49 ROUGE-2 points, and 13.08 ROUGE-L points.

  7. Knowl 7 — Semantic-aware watermarking substantially improves data-to-text quality

    data/table

    The following BLEU results compare no watermark (NW), original watermark (OW), and semantic-aware watermark (SW) on DART and WebNLG. The percentages in the watermarked rows are the reported relative drops from the corresponding NW baseline. SW consistently reduces the quality loss caused by watermarking, with especially large gains over the original hard watermark.

    Could not parse LaTeX table

    The most extreme case is WebNLG with Flan-T5-base: OW hard falls from 59.77 BLEU without a watermark to 1.80 BLEU, while SW hard achieves 40.89 BLEU. The paper describes this as a 39.09-point improvement and a 21.67-fold improvement over the original hard watermark.

  8. Knowl 8 — Human judges prefer semantic-aware summaries

    empirical result

    A human evaluation compared BART-base summaries generated with the original soft watermark and the semantic-aware watermark on 100 randomly sampled XSUM examples. Three native English-speaking judges saw the reference summary and anonymized, randomly ordered system outputs; reading the source article was optional when the comparison was otherwise difficult. The semantic-aware output was preferred by Judge 1 on 58% of examples, by Judge 2 on 54%, and by Judge 3 on 54%, for an average preference of 55.33%; the original watermark received the remaining 44.67%. A one-sided A/B test at 95% confidence gave p=0.0358p=0.0358, supporting a significant preference for the semantic-aware watermark. Pairwise agreement was 70%, 66%, and 54% for the three evaluations, with average pairwise agreement of 63.33%.

  9. Knowl 9 — Watermark strength and detection exhibit a CTG detection paradox

    empirical result

    Detection was evaluated using average z-scores and area under the ROC curve (AUC), with generated-length effects taken into account by penalizing the z-score according to the ratio between the average watermarked-output length and the average length of the corresponding unwatermarked output. Increasing δ\delta increases the green-list bias and generally raises the z-score, making hard watermarks easier to detect but more damaging to CTG quality. The semantic-aware watermark produces substantially higher z-scores than the original watermark across the tested semantic settings. However, the original watermark obtains higher AUC scores. The reason proposed by the paper is that semantic-aware green lists contain more input-similar tokens, which human CTG writing also tends to use; therefore, human text contains more green-list tokens and becomes harder to separate by AUC. Thus SW improves ROUGE or BLEU and raises z-score-based watermark strength while slightly reducing AUC, creating a detection trade-off. The paper reports quality improvements of up to approximately 2167% against the original watermark compared with an average AUC decrease of approximately 12.6%.

  10. Knowl 10 — Larger semantic neighborhoods improve quality through greater target coverage

    empirical result

    The semantic-neighborhood parameter kk controls how many embedding-nearest tokens are added for each source token. On DART with BART-base, δ=2\delta=2, and the listed green-list fractions, increasing kk improves BLEU because more target tokens are covered by the semantic green list.

    Could not parse LaTeX table

    The measured fraction of the total vocabulary occupied by semantically related tokens remains small, so the semantic set does not exhaust the intended green list:

    Could not parse LaTeX table

    Target-token coverage rises as kk increases. The quality improvement from larger kk is stronger for data-to-text generation, particularly DART and WebNLG, than for summarization, consistent with the larger BLEU gains shown above.

  11. Knowl 11 — Green-list fraction and logit strength govern the quality–detection trade-off

    limitation

    The soft watermark has two inherited controls: γ\gamma, the fraction of the vocabulary assigned to the green list, and δ\delta, the amount added to green-list logits. Increasing γ\gamma generally places more usable tokens in the green list and reduces the quality cost. Increasing δ\delta moves the method from a soft watermark toward a hard watermark, increasing detection strength but excluding more red-list tokens. Across the tested settings δ∈{2,5,10}\delta\in\{2,5,10\}, the semantic-aware watermark generally outperforms the original watermark, except at δ=2\delta=2 with relatively small γ\gamma. When γ=0.05\gamma=0.05 and δ≤4\delta\leq4, the soft watermark produces almost no quality trade-off, which the paper interprets as an ineffective watermark for detection rather than a free improvement. These findings limit the method’s operating range: strong detection and faithful conditional generation cannot generally be optimized independently.

Coverage note — No substantial contributed material was omitted; the extracted knowls cover the proposed watermark, baseline formulation, algorithm, experiments, quality and human results, detection behavior, hyperparameter analyses, and stated trade-offs.

References

  1. 1.Alkaissi, H.; and McFarlane, S. I. 2023. Artificial hallucinations in ChatGPT: implications in scientific writing. Cureus, 15(2).
  2. 2.Bakhtin, A.; Gross, S.; Ott, M.; Deng, Y.; Ranzato, M.; and Szlam, A. 2019. Real or Fake? Learning to Discriminate Machine from Human Generated Text. arXiv:1906.03351.
  3. 3.Bender, E. M.; Gebru, T.; McMillan-Major, A.; and Shmitchell, S. 2021. On the Dangers of Stochastic Parrots: Can Language Models Be Too Big? In Proceedings of the 2021 ACM conference on fairness, accountability, and transparency, 610–623.
  4. 4.Bian, N.; Han, X.; Sun, L.; Lin, H.; Lu, Y.; and He, B. 2023. Chatgpt is a knowledgeable but inexperienced solver: An investigation of commonsense problem in large language models. arXiv preprint arXiv:2303.16421.
  5. 5.Chen, Y.; Liu, P.; Zhong, M.; Dou, Z.-Y.; Wang, D.; Qiu, X.; and Huang, X. 2020. CDEvalSumm: An Empirical Study of Cross-Dataset Evaluation for Neural Summarization Systems. In Findings of the Association for Computational Linguistics: EMNLP 2020, 3679–3691. Online: Association for Computational Linguistics.
  6. 6.Chung, H. W.; Hou, L.; Longpre, S.; Zoph, B.; Tay, Y.; Fedus, W.; Li, Y.; Wang, X.; Dehghani, M.; Brahma, S.; Webson, A.; Gu, S. S.; Dai, Z.; Suzgun, M.; Chen, X.; Chowdhery, A.; Castro-Ros, A.; Pellat, M.; Robinson, K.; Valter, D.; Narang, S.; Mishra, G.; Yu, A.; Zhao, V.; Huang, Y.; Dai, A.; Yu, H.; Petrov, S.; Chi, E. H.; Dean, J.; Devlin, J.; Roberts, A.; Zhou, D.; Le, Q. V.; and Wei, J. 2022. Scaling Instruction-Finetuned Language Models. arXiv:2210.11416.
  7. 7.Deshpande, A.; Murahari, V.; Rajpurohit, T.; Kalyan, A.; and Narasimhan, K. 2023. Toxicity in chatgpt: Analyzing persona-assigned language models. arXiv preprint arXiv:2304.05335.
  8. 8.Dong, Y.; Jiang, X.; Jin, Z.; and Li, G. 2023. Self-collaboration Code Generation via ChatGPT. arXiv:2304.07590.
  9. 9.Frohling, L.; and Zubiaga, A. 2021. Feature-based detection of automated language models: tackling GPT-2, GPT-3 and Grover. PeerJ Computer Science, 7: e443.
  10. 10.Gardent, C.; Shimorina, A.; Narayan, S.; and Perez-Beltrachini, L. 2017. The WebNLG Challenge: Generating Text from RDF Data. In Proceedings of the 10th International Conference on Natural Language Generation, 124–133. Santiago de Compostela, Spain: Association for Computational Linguistics.
  11. 11.Jawahar, G.; Abdul-Mageed, M.; and Lakshmanan, L., V.S. 2020. Automatic Detection of Machine Generated Text: A Critical Survey. In Proceedings of the 28th International Conference on Computational Linguistics, 2296–2309. Barcelona, Spain (Online): International Committee on Computational Linguistics.
  12. 12.Kirchenbauer, J.; Geiping, J.; Wen, Y.; Katz, J.; Miers, I.; and Goldstein, T. 2023. A Watermark for Large Language Models. arXiv:2301.10226.
  13. 13.Lee, T.; Hong, S.; Ahn, J.; Hong, I.; Lee, H.; Yun, S.; Shin, J.; and Kim, G. 2023. Who Wrote this Code? Watermarking for Code Generation. arXiv:2305.15060.
  14. 14.Lewis, M.; Liu, Y.; Goyal, N.; Ghazvininejad, M.; Mohamed, A.; Levy, O.; Stoyanov, V.; and Zettlemoyer, L. 2020. BART: Denoising Sequence-to-Sequence Pre-training for Natural Language Generation, Translation, and Comprehension. In Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics, 7871–7880. Online: Association for Computational Linguistics.
  15. 15.Lin, C.-Y. 2004. ROUGE: A Package for Automatic Evaluation of Summaries. In Text Summarization Branches Out, 74–81. Barcelona, Spain: Association for Computational Linguistics.
  16. 16.Liu, J.; Xia, C. S.; Wang, Y.; and Zhang, L. 2023. Is Your Code Generated by ChatGPT Really Correct? Rigorous Evaluation of Large Language Models for Code Generation. arXiv:2305.01210.
  17. 17.Mitchell, E.; Lee, Y.; Khazatsky, A.; Manning, C. D.; and Finn, C. 2023. DetectGPT: Zero-Shot Machine-Generated Text Detection using Probability Curvature. arXiv:2301.11305.
  18. 18.Mitrovic, S.; Andreoletti, D.; and Ayoub, O. 2023. ChatGPT or Human? Detect and Explain. Explaining Decisions of Machine Learning Model for Detecting Short ChatGPT-generated Text. arXiv:2301.13852.
  19. 19.Nan, L.; Radev, D.; Zhang, R.; Rau, A.; Sivaprasad, A.; Hsieh, C.; Tang, X.; Vyas, A.; Verma, N.; Krishna, P.; Liu, Y.; Irwanto, N.; Pan, J.; Rahman, F.; Zaidi, A.; Mutuma, M.; Tarabar, Y.; Gupta, A.; Yu, T.; Tan, Y. C.; Lin, X. V.; Xiong, C.; Socher, R.; and Rajani, N. F. 2021. DART: Open-Domain Structured Data Record to Text Generation. In Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, 432–447. Online: Association for Computational Linguistics.
  20. 20.Narayan, S.; Cohen, S. B.; and Lapata, M. 2018. Don’t Give Me the Details, Just the Summary! Topic-Aware Convolutional Neural Networks for Extreme Summarization. In Proceedings of the 2018 Conference on Empirical Methods in Natural Language Processing, 1797–1807. Brussels, Belgium: Association for Computational Linguistics.
  21. 21.OpenAI. 2021. Chatgpt: Optimizing language model for dialogue. https://www.openai.com/blog/chatgpt/. Accessed: 2023-01-10.
  22. 22.OpenAI. 2023. GPT-4 Technical Report. arXiv:2303.08774.
  23. 23.Papineni, K.; Roukos, S.; Ward, T.; and Zhu, W.-J. 2002. Bleu: a Method for Automatic Evaluation of Machine Translation. In Proceedings of the 40th Annual Meeting of the Association for Computational Linguistics, 311–318. Philadelphia, Pennsylvania, USA: Association for Computational Linguistics.
  24. 24.Sadasivan, V. S.; Kumar, A.; Balasubramanian, S.; Wang, W.; and Feizi, S. 2023. Can AI-Generated Text be Reliably Detected? arXiv:2303.11156.
  25. 25.Schuster, T.; Schuster, R.; Shah, D. J.; and Barzilay, R. 2020. The Limitations of Stylometry for Detecting Machine-Generated Fake News. Computational Linguistics, 46(2): 499–510.
  26. 26.See, A.; Liu, P. J.; and Manning, C. D. 2017. Get To The Point: Summarization with Pointer-Generator Networks. In Proceedings of the 55th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), 1073–1083. Vancouver, Canada: Association for Computational Linguistics.
  27. 27.Solaiman, I.; Brundage, M.; Clark, J.; Askell, A.; Herbert-Voss, A.; Wu, J.; Radford, A.; Krueger, G.; Kim, J. W.; Kreps, S.; McCain, M.; Newhouse, A.; Blazakis, J.; McGuffie, K.; and Wang, J. 2019. Release Strategies and the Social Impacts of Language Models. arXiv:1908.09203.
  28. 28.Tan, Y.; Min, D.; Li, Y.; Li, W.; Hu, N.; Chen, Y.; and Qi, G. 2023. Can ChatGPT Replace Traditional KBQA Models? An In-depth Analysis of GPT family LLMs’ Question Answering Performance. arXiv:2303.07992.
  29. 29.Wang, L.; Yang, W.; Chen, D.; Zhou, H.; Lin, Y.; Meng, F.; Zhou, J.; and Sun, X. 2023. Towards Codable Text Watermarking for Large Language Models. arXiv:2307.15992.
  30. 30.Yang, X.; Chen, K.; Zhang, W.; Liu, C.; Qi, Y.; Zhang, J.; Fang, H.; and Yu, N. 2023. Watermarking Text Generated by Black-Box Language Models. arXiv:2305.08883.
  31. 31.Yoo, K.; Ahn, W.; Jang, J.; and Kwak, N. 2023. Robust Multi-bit Natural Language Watermarking through Invariant Features. In Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), 2092–2115. Toronto, Canada: Association for Computational Linguistics.
  32. 32.Zhao, X.; Wang, Y.-X.; and Li, L. 2023. Protecting Language Generation Models via Invisible Watermarking. arXiv:2302.03162.

Citation

MLA
Fu, Y., et al. “Watermarking Conditional Text Generation for AI Detection: Unveiling Challenges and a Semantic-Aware Watermark Remedy”. arXiv, 2023, http://arxiv.org/abs/2307.13808v2.
APA
Fu, Y., Xiong, D., & Dong, Y. (2023). Watermarking Conditional Text Generation for AI Detection: Unveiling Challenges and a Semantic-Aware Watermark Remedy. arXiv. http://arxiv.org/abs/2307.13808v2
Chicago
Fu, Y., D. Xiong, and Y. Dong. 2023. “Watermarking Conditional Text Generation for AI Detection: Unveiling Challenges and a Semantic-Aware Watermark Remedy”. arXiv. http://arxiv.org/abs/2307.13808v2.
Harvard
Fu, Y., Xiong, D. and Dong, Y. (2023) “Watermarking Conditional Text Generation for AI Detection: Unveiling Challenges and a Semantic-Aware Watermark Remedy”, arXiv [Preprint]. Available at: http://arxiv.org/abs/2307.13808v2.
Vancouver
1. Fu Y, Xiong D, Dong Y (2023) Watermarking Conditional Text Generation for AI Detection: Unveiling Challenges and a Semantic-Aware Watermark Remedy. arXiv

BibTeX

@article{fu2023watermarking,
  title = {Watermarking Conditional Text Generation for AI Detection: Unveiling Challenges and a Semantic-Aware Watermark Remedy},
  author = {Fu, Yu and Xiong, Deyi and Dong, Yue},
  year = {2023},
  journal = {arXiv},
  url = {http://arxiv.org/abs/2307.13808v2},
  eprint = {2307.13808}
}
Metadata:arXiv

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF