This approach feels wrong. For code, it's obvious now that Claude is adding watermarks through comments because they are way too long. I keep asking Claude to remove and reduce its comments.
Also, I don't think it's useful because AI involvement in the work is a spectrum, not a binary true or false. If I ask Claude to go over my code and fix up typos and clean up and it starts adding comments with hidden watermarks everywhere it makes the tiniest adjustment, it's essentially appropriating my code. Its contribution may be trivial and superficial.
When I use AI on my own projects, the code it generates basically looks like auto-complete to me; exactly what I would have written by hand. So I don't see why it needs to be marked as AI. It's just saving me time. It's very much my own work.
show comments
LudwigNagasena
It’s obvious that such boneheaded methods don’t work. So what’s next? First, we need to deal with basic word substitution, which seems theoretically feasible. Then we need to deal with encodings such as Caesar cipher, replacing spaces with zero-width spaces, Base64, etc. Your account will be flagged and reported for outputting obfuscated text. What’s next after that? Ooops, you output too many vim commands instead of outputting text directly, your account is flagged and reported to Europol. You think you can bypass that with Deepseek? No, it will be banned alongside VPN.
Aerroon
Could this technique be theoretically used to track users themselves? It would be quite ironic if the EU forced tech companies to implement extra tracking, wouldn't it?
show comments
mgax
This is such a waste of time.
If someone wants to bypass this it will be rather simple. Just change the words. If someone wants to avoid fingerprinting they will.
Can’t we just focus on building rather than spending brainpower on these ridiculous sidequests
show comments
m-hodges
> Starting today, API customers globally will be able to opt in to text watermarking for select models. Text watermarking will remain off by default in the API.
> Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union.
GardenLetter27
I wish we could vote out the EU!
andriamanitra
1% false positive rate is completely unacceptable, and if you can bypass it by changing some of the words what's even the point? This is only going to catch low effort slop.
athrowaway3z
>> Editing can weaken the watermark. In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% of words reduced it to 17%.
> Claude/codex/deepseek, please replace 25% of words with synonyms or slight rephrasing because i dont like the current version.
Not sure if that counts as: `a solution that's robust against "common alterations and adversarial attacks"`. Is there a sort of adversarial attack that is more common?
show comments
smokel
Why use watermarking, and not simply add a signature?
show comments
k__
Is watermarking part of a model architecture or is it something added by the inference engine?
show comments
greatgib
My personal opinion is that they cheated evaluations to be able to release this pretending that it has no meaningful impact.
Otherwise, I don't see any logical explanation that some of their benchmark results would be higher when watermarked. Except if benchmark results are so unstable that they are an useless metric.
show comments
pembrook
Good to know, will exclusively move to Chinese models for non-coding tasks.
The idea that producing text with AI needs to be watermarked as if it's a crime by default is backwards nonsense.
To me this would actually be a counter signal.
If you're NOT primarily writing with AI (at least mildly being informed by all of human knowledge distilled), then I will assume your ideas are emotional opinion-based nonsense, like most comments on hackernews, including my own.
aenis
Another cookie consent-grade success of the EU.
show comments
richwater
Just make the models worse for the EU. Don't accept this nonsense that's holdingg back actual work and progress.
This approach feels wrong. For code, it's obvious now that Claude is adding watermarks through comments because they are way too long. I keep asking Claude to remove and reduce its comments.
Also, I don't think it's useful because AI involvement in the work is a spectrum, not a binary true or false. If I ask Claude to go over my code and fix up typos and clean up and it starts adding comments with hidden watermarks everywhere it makes the tiniest adjustment, it's essentially appropriating my code. Its contribution may be trivial and superficial.
When I use AI on my own projects, the code it generates basically looks like auto-complete to me; exactly what I would have written by hand. So I don't see why it needs to be marked as AI. It's just saving me time. It's very much my own work.
It’s obvious that such boneheaded methods don’t work. So what’s next? First, we need to deal with basic word substitution, which seems theoretically feasible. Then we need to deal with encodings such as Caesar cipher, replacing spaces with zero-width spaces, Base64, etc. Your account will be flagged and reported for outputting obfuscated text. What’s next after that? Ooops, you output too many vim commands instead of outputting text directly, your account is flagged and reported to Europol. You think you can bypass that with Deepseek? No, it will be banned alongside VPN.
Could this technique be theoretically used to track users themselves? It would be quite ironic if the EU forced tech companies to implement extra tracking, wouldn't it?
This is such a waste of time. If someone wants to bypass this it will be rather simple. Just change the words. If someone wants to avoid fingerprinting they will. Can’t we just focus on building rather than spending brainpower on these ridiculous sidequests
> Starting today, API customers globally will be able to opt in to text watermarking for select models. Text watermarking will remain off by default in the API.
> Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union.
I wish we could vote out the EU!
1% false positive rate is completely unacceptable, and if you can bypass it by changing some of the words what's even the point? This is only going to catch low effort slop.
>> Editing can weaken the watermark. In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% of words reduced it to 17%.
> Claude/codex/deepseek, please replace 25% of words with synonyms or slight rephrasing because i dont like the current version.
Not sure if that counts as: `a solution that's robust against "common alterations and adversarial attacks"`. Is there a sort of adversarial attack that is more common?
Why use watermarking, and not simply add a signature?
Is watermarking part of a model architecture or is it something added by the inference engine?
My personal opinion is that they cheated evaluations to be able to release this pretending that it has no meaningful impact.
Otherwise, I don't see any logical explanation that some of their benchmark results would be higher when watermarked. Except if benchmark results are so unstable that they are an useless metric.
Good to know, will exclusively move to Chinese models for non-coding tasks.
The idea that producing text with AI needs to be watermarked as if it's a crime by default is backwards nonsense.
To me this would actually be a counter signal.
If you're NOT primarily writing with AI (at least mildly being informed by all of human knowledge distilled), then I will assume your ideas are emotional opinion-based nonsense, like most comments on hackernews, including my own.
Another cookie consent-grade success of the EU.
Just make the models worse for the EU. Don't accept this nonsense that's holdingg back actual work and progress.