Understanding the Impact of LLM Watermarking on AI Agent Behavior
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Understanding the Impact of LLM Watermarking on AI Agent Behavior
Unofficial Hacker News client; not affiliated with Y Combinator.
willmadden · · focus · HN ↗
You should assume all text is AI generated. If you want to "test" someone at school or during an interview, have them write with a pencil and paper.
skybrian · · focus · HN ↗
riskable · · focus · HN ↗
This is because SynthID and similar watermarking methods for LLMs don't just change the random seed. They take additional steps (that I have yet to read about) in order to detect when someone changes a few words of the output, trying to remove the watermark.
The other takeaway is that just by knowing a watermark is being applied gives an attacker an advantage in working around safety features because then they know the output isn't based on true randomness and can take advantage of that in a similar fashion to how breaking cryptography becomes easier when the RNG isn't truly random.