4 Comments
User's avatar
Simon's avatar

This article is overstating the issue in a way that it s very misleading. Text watermarking works by changing the source of randomness that is an inherent aspect of token generation. A succession of random choices that match the models own randomness have a higher probability of having been generated by that model.

By definition, then, you need a large number of such choices to have high confidence that AI made them. Anthropic themselves admit that "detecting a watermark.. doesn’t work well on small samples, where there are fewer word choices and thus less information to go on"

In other words, neither a single fixed comma nor a corrected spelling mistake is rich enough to be watermarked.

A translation of a substantial piece of text would be susceptible to watermarking, but that's entirely valid. As any translator will tell you, translation is a form of interpretation. Offloading that interpretation to AI is a significant decision that is worth flagging.

More here:

https://www.anthropic.com/news/claude-text-watermark

Denis Stetskov's avatar

Fair on the mechanism, and the piece says as much: a mark that fails on a comma measures length, not origin. That's the case, not the counter.

Simon's avatar

The post claims that a comma being altered by AI will show AI authorship via the watermark. It won't, because it can't. The fact is that only text which has been substantively generated or changed by AI can be watermarked, which undermines most of your argument.

Denis Stetskov's avatar

The comma is yours, too little text to mark. But you already made my case: you said a translated passage gets watermarked and that's valid because the interpretation was offloaded. The words were the user's, Claude touched them, the output carries the mark. That's contact, not authorship. And the C2PA file mark ignores length entirely, it tags the whole file. Metered either way.