logoalt Hacker News

Our approach to EU text provenance rules

60 points • by tosh • today at 3:38 PM • 51 comments • view on HN

Comments

socketcluster • today at 9:48 PM

This approach feels wrong. For code, it's obvious now that Claude is adding watermarks through comments because they are way too long. I keep asking Claude to remove and reduce its comments.

Also, I don't think it's useful because AI involvement in the work is a spectrum, not a binary true or false. If I ask Claude to go over my code and fix up typos and clean up and it starts adding comments with hidden watermarks everywhere it makes the tiniest adjustment, it's essentially appropriating my code. Its contribution may be trivial and superficial.

When I use AI on my own projects, the code it generates basically looks like auto-complete to me; exactly what I would have written by hand. So I don't see why it needs to be marked as AI. It's just saving me time. It's very much my own work.

➕ show 1 reply
LudwigNagasena • today at 9:41 PM

It’s obvious that such boneheaded methods don’t work. So what’s next? First, we need to deal with basic word substitution, which seems theoretically feasible. Then we need to deal with encodings such as Caesar cipher, replacing spaces with zero-width spaces, Base64, etc. Your account will be flagged and reported for outputting obfuscated text. What’s next after that? Ooops, you output too many vim commands instead of outputting text directly, your account is flagged and reported to Europol. You think you can bypass that with Deepseek? No, it will be banned alongside VPN.

Aerroon • today at 9:46 PM

Could this technique be theoretically used to track users themselves? It would be quite ironic if the EU forced tech companies to implement extra tracking, wouldn't it?

➕ show 2 replies
mgax • today at 5:41 PM

This is such a waste of time. If someone wants to bypass this it will be rather simple. Just change the words. If someone wants to avoid fingerprinting they will. Can’t we just focus on building rather than spending brainpower on these ridiculous sidequests

➕ show 4 replies
m-hodges • today at 5:29 PM

> Starting today, API customers globally will be able to opt in to text watermarking for select models. Text watermarking will remain off by default in the API.

> Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union.

GardenLetter27 • today at 9:43 PM

I wish we could vote out the EU!

athrowaway3z • today at 6:33 PM

>> Editing can weaken the watermark. In an evaluation of 400-token passages, replacing 10% of words with synonyms reduced detection from about 92% to 66%. Replacing 25% of words reduced it to 17%.

> Claude/codex/deepseek, please replace 25% of words with synonyms or slight rephrasing because i dont like the current version.

Not sure if that counts as: `a solution that's robust against "common alterations and adversarial attacks"`. Is there a sort of adversarial attack that is more common?

➕ show 1 reply
smokel • today at 6:08 PM

Why use watermarking, and not simply add a signature?

➕ show 2 replies
k__ • today at 6:55 PM

Is watermarking part of a model architecture or is it something added by the inference engine?

➕ show 1 reply
andriamanitra • today at 9:56 PM

1% false positive rate is completely unacceptable, and if you can bypass it by changing some of the words what's even the point? This is only going to catch low effort slop.

pembrook • today at 9:34 PM

Good to know, will exclusively move to Chinese models for non-coding tasks.

The idea that producing text with AI needs to be watermarked as if it's a crime by default is backwards nonsense.

To me this would actually be a counter signal.

If you're NOT primarily writing with AI (at least mildly being informed by all of human knowledge distilled), then I will assume your ideas are emotional opinion-based nonsense, like most comments on hackernews, including my own.

greatgib • today at 6:14 PM

My personal opinion is that they cheated evaluations to be able to release this pretending that it has no meaningful impact.

Otherwise, I don't see any logical explanation that some of their benchmark results would be higher when watermarked. Except if benchmark results are so unstable that they are an useless metric.

➕ show 2 replies
aenis • today at 6:13 PM

Another cookie consent-grade success of the EU.

➕ show 1 reply
richwater • today at 6:59 PM

Just make the models worse for the EU. Don't accept this nonsense that's holdingg back actual work and progress.