跳到主要导航 跳到搜索 跳到主要内容

TransMark: Lossless high-capacity watermarking for LLMs via neuron permutation invariances

  • Pei Gen Ye
  • , Zhuorong Chen
  • , Haiwei Sang
  • , Jun Zheng*
  • *此作品的通讯作者
  • Beijing Institute of Technology
  • Guangzhou University
  • Guizhou Education University

科研成果: 期刊稿件文章同行评审

摘要

Large language models (LLMs) require robust ownership verification to protect intellectual property, yet existing watermarking methods inevitably degrade model performance or lack resilience to attacks. We propose TransMark, a watermarking framework that rearranges certain neurons in a transformer’s feed-forward layers to embed a high-capacity, verifiable watermark. This design does not alter any model parameters or demand additional training steps. It leverages row and column permutations in feed-forward sub-layers, which are strict mathematical symmetries that leave the model’s function intact. We offer three strategies for choosing which neurons to swap: (i) a baseline method that pairs neurons based on norm and directional dissimilarity, (ii) a sensitivity-based strategy that minimizes changes to model outputs by focusing on less sensitive neurons, and (iii) a gradient-based approach that applies a small set of calibration texts to find neurons with the smallest gradient importance. We also include a Hamming-based error correction component to improve reliability. Our experiments confirm that TransMark preserves model accuracy and withstands quantization, random noise, and minor fine-tuning, all while embedding a large amount of information with no performance drop.

源语言英语
期刊论文编号104180
期刊Computer Standards and Interfaces
99
DOI
出版状态已出版 - 1月 2027
已对外发布

学术指纹

探究 'TransMark: Lossless high-capacity watermarking for LLMs via neuron permutation invariances' 的科研主题。它们共同构成独一无二的学术指纹。

引用此