Skip to content
InfoResearchPreprintLLM-specific

Could LLM Watermark Detection be Public?

Published
Record updated
View JSON

Summary

This research asks whether a public LLM watermark detector would add risk, given that exposed detectors could let attackers make targeted edits. The authors propose a split-key public-private watermarking method, where one key is exposed through a public detector and the other is kept for full verification and forensics. They report that public detection mainly helps forgery, which the private pipeline can identify, while tampering with the released half stays detectable.