AI, Software

LLMs respond differently to harmful prompts when AI watermarking is used

LLMs respond differently to harmful prompts when AI watermarking is used

SynthID can cause models to follow harmful instructions they would otherwise refuse. LLMs respond differently to harmful prompts when AI watermarking is used. Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav In response to a new European Union law, AI platforms are implementing new schemes for watermarking the content they generate.

Anthropic recently disclosed its future Claude models will use SynthID-Text, an approach Google created and released as open source. It uses a secret key that subtly changes the process a model uses for choosing the next word in a sentence. Whereas a top next word choice might be โ€œcloudy,โ€ the key might change it to โ€œovercast.โ€ Anyone who knows the key can determine if it was generated by the platform using it.

New research shows that SynthID-Text can change not just word selection but also the tools a model invokes and the chances it will adhere to or disregard safety guardrails it has been trained to follow. The threat can become greater in the face of an adversarial prompt, in which an attacker attempts to cause a model to carry out a harmful action, such as revealing a password or other sensitive information. Instructions that normally wouldnโ€™t be followed will, in some cases, be performed once the watermarking is deployed.

The finding underscores the need for developers to thoroughly test how their LLMs and agents behave when watermarking is in place.


Discover more from ChuckysCarnage

Subscribe to get the latest posts sent to your email.

Leave a comment