AliMark: 문장 수준 워터마킹의 강건성 향상 – 텍스트 재구성 공격에 대한 대응
AliMark: Enhancing Robustness of Sentence-Level Watermarking Against Text Paraphrasing
기존의 문장 수준 워터마킹 방법은 워터마크를 문장의 의미론적 요소에 고정하여 재구성 공격에 대한 강건성을 높입니다. 그러나 이러한 방법들은 주로 접두사 기반으로 설계되어 있어, DIPPER나 GPT-3.5와 같은 강력한 재구성 도구에서 발생하는 문장 분리 및 병합과 같은 구조적인 변경에 취약합니다. 이러한 문제를 해결하기 위해, 우리는 AliMark라는 프레임워크를 제안합니다. AliMark는 문장 수준 워터마킹을 잠재적으로 워터마크가 포함된 텍스트와 비밀 비트 시퀀스 간의 비트 시퀀스 인코딩 및 정렬 문제로 재구성합니다. 특히, 우리의 접근 방식은 두 단계의 검출 전략을 채택합니다. 우리는 여러 개의 재구성된 텍스트 변형을 생성하고, 추출된 비트 시퀀스를 비밀 비트 시퀀스와 정렬하여 정렬 비용을 최소화합니다. 이러한 다중 후보 정렬 설계는 문장 병합 및 분리에 대한 강건성을 자연스럽게 향상시킵니다. 광범위한 실험 결과, AliMark가 다양한 재구성 공격에 대해 최첨단 기준 모델보다 현저히 우수한 성능을 보임을 보여줍니다.
Existing sentence-level watermarking methods enhance robustness to paraphrasing by anchoring watermarks in sentence semantics. However, their prefix-based designs remain vulnerable to structural perturbations, such as sentence splitting and merging, which commonly arise under strong paraphrasers like DIPPER and GPT-3.5. To mitigate this issue, we propose AliMark, a framework that reformulates sentence-level watermarking as a bit sequence encoding and alignment problem between a potentially watermarked text and a secret bit sequence. Notably, our approach adopts a two-stage detection strategy: we generate multiple restructured text variants and adaptively align their extracted bit sequences with the secret bit sequence to minimize alignment cost. This multi-candidate alignment design naturally improves robustness to sentence merges and splits. Extensive experiments demonstrate that AliMark substantially outperforms state-of-the-art baselines under diverse paraphrasing attacks.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.