‹ BackHN Continuity

Thread

Spymarks, not Watermarks

698 points · 171 comments · possibilistic

  1. pavo-etc · · focus · HN ↗
    I'm not convinced spymark is better than just "invisible watermarks", spymark to my ears sounds designed to be sound very negative when invisible watermarks are not always negative, e.g. the counterfeit bank note example.

    Tech like SynthID I see a net positive especially since it doesn't degrade text quality. I dream about a browser extension running at all times that makes text more translucent based on the confidence of LLM writing[0].

    This article's suggestion of using it to unmask whistleblowers is very interesting and not something I'd thought about though. Still not convinced that spymark is a better name though.

    [0]: Sean Goedecke&#x27;s Deckard is close but it would rather invisible than bright red <a href="https:&#x2F;&#x2F;www.seangoedecke.com&#x2F;deckard&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.seangoedecke.com&#x2F;deckard&#x2F;

    1. pixl97 · · focus · HN ↗
      These spy marks are a great way to teach AI how to create a hidden communication channel in plain sight.
      1. aesthesia · · focus · HN ↗
        Due to their essentially cryptographic nature, I don&#x27;t think SynthID et al are very easy for LLMs to speak natively. They have other ways of doing steganography.
        1. dragonwriter · · focus · HN ↗
          LLMs with access to tools like code execution don&#x27;t need channels they can “speak natively&quot;.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.