LLM Output Detectability and Task Performance Can be Jointly Optimized
Detecting machine-generated text is essential for transparency and accountability when deploying LLMs. Watermarking enables statistically reliable detection by biasing token distributions to embed detectable signals into LLM outputs. However, it has been reported that watermarked LLMs often perform worse on downstream tasks. We propose PUPPET, a framework that fine-tunes an LLM via DPO to generate text that is both more detectable by a target detector and better performing on downstream tasks. We use two rewards: a detector that outputs a machine-class likelihood and an evaluator that measures a task-specific metric. Just as a watermark is verified with its secret key, this detector-specific design lets an LLM provider track how its published model is used. Experiments on long-form QA, summarization, and essay writing show that LLMs trained with PUPPET achieve detectability competitive with watermarking methods---even at strict low FPRs---while outperforming them on downstream tasks. Moreover, this optimization requires only a few thousand samples and 1--2 GPU hours, and its gains hold across out-of-domain tasks, six detectors of diverse architectures, and different LLM families and sizes, and are even robust to paraphrasing attacks.
Code (0)
등록된 구현이 없습니다.
Tasks
Reinforcement LearningSimilar Papers 제목 키워드 기반
WaterSearch: Exploring Seed Pooling for Improving the Quality-Detectability Trade-off in LLM Watermarking
Watermarking acts as a critical safeguard in text generated by Large Language Models (LLMs). By embedding identifiable signals into model outputs, watermarking enables reliable attribution and enhances the security of ma…
Text GenerationSample-based nonlinear detectability for discrete-time systems
This paper introduces two sample-based formulations of incremental input/output-to-state stability (i-IOSS), a suitable detectability notion for general nonlinear systems. In this work we consider the case of limited out…
Robust LLM Watermarking with Minimal Semantic Distortion for IP Protection
Proprietary large language models (LLMs) face risks of intellectual property (IP) violation, as adversaries can replicate an LLM by collecting input-output pairs to train a surrogate model, causing financial setbacks. Wa…
Adaptive LPD Radar Waveform Design with Generative Deep Learning
We propose a learning-based method for adaptively generating low probability of detection (LPD) radar waveforms that blend into their operating environment. Our waveforms are designed to follow a distribution that is ind…
Deep LearningRadar waveform designNonlinear Functional Estimation: Functional Detectability and Full Information Estimation
We consider the design of functional estimators, i.e., approaches to compute an estimate of a nonlinear function of the state of a general nonlinear dynamical system subject to process noise based on noisy output measure…