问HN:Anthropic的水印可能比我们想象的要简单得多吗?
Anthropic最近表示,他们正在对Claude的输出进行水印处理,同时也表示这不会影响生成质量。我在想这是否只是哈希指纹识别。
例如,将生成的文本分割成重叠的片段:
```
"公司报告了强劲的增长..."
"报告了收入的强劲增长..."
"在第二季度期间收入的强劲增长..."
...
```
对每个片段进行哈希处理并存储哈希值。当提交文本进行检测时,进行相同的处理并计算有多少片段哈希已经在数据库中。
即使有人编辑了几个词,许多重叠的片段仍然可能匹配。
搜索本身并不是问题。使用256位哈希时,您处理的是一个2^256的空间,但您只搜索实际存储的哈希值。二分搜索将在256次迭代中搜索任何哈希。
这也满足了Anthropic的要求:*在生成令牌的过程中不需要进行任何更改*,因此没有质量上的折衷。
显而易见的问题是,他们如何在其规模下处理假阳性率。
这是否能解释他们的方法,还是我遗漏了什么?
查看原文
Anthropic recently said they're working on watermarking Claude output, while also saying it won't interfere with generation quality.<p>I'm wondering if is just hash-fingerprinting.<p>For example, take the generated text and split it into overlapping chunks:<p><pre><code> "The company reported strong growth..."
"reported strong growth in revenue..."
"strong growth in revenue during Q2..."
...
</code></pre>
Hash each chunk and store the hashes. When text is submitted for detection, do the same thing and count how many chunk hashes are already in the database.<p>Even if someone edits a few words, many overlapping chunks could still match.<p>The search itself isn't really a problem. With 256-bit hashes you're dealing with a 2^256 space, but you only search the hashes you've actually stored. Binary search would search any hash in 256 iterations.<p>This also satisfies the Anthropic requirements: *nothing needs to be changed during token generation*, so there's no quality tradeoff: https://x.com/i/status/2088343978873966687<p>The obvious question is how they handle false-positive rate works at their scale.<p>Could this explain their approach, or is there something I'm missing?