2,914 research outputs found

    Watermarks in the Sand: Impossibility of Strong Watermarking for Generative Models

    Full text link
    Watermarking generative models consists of planting a statistical signal (watermark) in a model's output so that it can be later verified that the output was generated by the given model. A strong watermarking scheme satisfies the property that a computationally bounded attacker cannot erase the watermark without causing significant quality degradation. In this paper, we study the (im)possibility of strong watermarking schemes. We prove that, under well-specified and natural assumptions, strong watermarking is impossible to achieve. This holds even in the private detection algorithm setting, where the watermark insertion and detection algorithms share a secret key, unknown to the attacker. To prove this result, we introduce a generic efficient watermark attack; the attacker is not required to know the private key of the scheme or even which scheme is used. Our attack is based on two assumptions: (1) The attacker has access to a "quality oracle" that can evaluate whether a candidate output is a high-quality response to a prompt, and (2) The attacker has access to a "perturbation oracle" which can modify an output with a nontrivial probability of maintaining quality, and which induces an efficiently mixing random walk on high-quality outputs. We argue that both assumptions can be satisfied in practice by an attacker with weaker computational capabilities than the watermarked model itself, to which the attacker has only black-box access. Furthermore, our assumptions will likely only be easier to satisfy over time as models grow in capabilities and modalities. We demonstrate the feasibility of our attack by instantiating it to attack three existing watermarking schemes for large language models: Kirchenbauer et al. (2023), Kuditipudi et al. (2023), and Zhao et al. (2023). The same attack successfully removes the watermarks planted by all three schemes, with only minor quality degradation.Comment: Blog post: https://www.harvard.edu/kempner-institute/2023/11/09/watermarking-in-the-sand

    Watermarks in the Sand: Impossibility of Strong Watermarking for Generative Models

    Get PDF
    Watermarking generative models consists of planting a statistical signal (watermark) in a model’s output so that it can be later verified that the output was generated by the given model. A strong watermarking scheme satisfies the property that a computationally bounded attacker cannot erase the watermark without causing significant quality degradation. In this paper, we study the (im)possibility of strong watermarking schemes. We prove that, under well-specified and natural assumptions, strong watermarking is impossible to achieve. This holds even in the private detection algorithm setting, where the watermark insertion and detection algorithms share a secret key, unknown to the attacker. To prove this result, we introduce a generic efficient watermark attack; the attacker is not required to know the private key of the scheme or even which scheme is used. Our attack is based on two assumptions: (1) The attacker has access to a “quality oracle” that can evaluate whether a candidate output is a high-quality response to a prompt, and (2) The attacker has access to a “perturbation oracle” which can modify an output with a nontrivial probability of maintaining quality, and which induces an efficiently mixing random walk on high-quality outputs. We argue that both assumptions can be satisfied in practice by an attacker with weaker computational capabilities than the watermarked model itself, to which the attacker has only black-box access. Furthermore, our assumptions will likely only be easier to satisfy over time as models grow in capabilities and modalities. We demonstrate the feasibility of our attack by instantiating it to attack three existing watermarking schemes for large language models: Kirchenbauer et al. (2023), Kuditipudi et al. (2023), and Zhao et al. (2023). The same attack successfully removes the watermarks planted by all three schemes, with only minor quality degradation

    Spontaneous symmetry breaking in strong-coupling lattice QCD at high density

    Full text link
    We determine the patterns of spontaneous symmetry breaking in strong-coupling lattice QCD in a fixed background baryon density. We employ a next-nearest-neighbor fermion formulation that possesses the SU(N_f)xSU(N_f) chiral symmetry of the continuum theory. We find that the global symmetry of the ground state varies with N_f and with the background baryon density. In all cases the condensate breaks the discrete rotational symmetry of the lattice as well as part of the chiral symmetry group.Comment: 10 pages, RevTeX 4; added discussion of accidental degeneracy of vacuum after Eq. (35

    Effect of the irrigation regime on the susceptibility of pepper and tomato to post-harvest proliferation of Salmonella enterica

    Get PDF
    Raw produce is increasingly recognized as a vehicle of human gastroenteritis. Non-typhoidal Salmonella, pathogenic Escherichia coli, and other human pathogens have been isolated from fruits and vegetables in the field and in the marketplace, which led to the hypothesis that these microbes can use plants as alternate hosts. However, environmental and physiological factors that facilitate persistence of these bacteria in the crop production environment and make produce more vulnerable to post-harvest contamination have not been fully delineated. This study tested the effect of irrigation regimes on the susceptibility of peppers and tomatoes to post-harvest proliferation of Salmonella. The experiments were carried out over three experimental seasons in two locations using seven strains of Salmonella. The irrigation regime per se did not affect susceptibility of tomatoes and peppers to post-harvest proliferation of Salmonella; however, in some of the seasons, irrigation regime-dependent differences were observed. Red peppers and tomatoes were more conducive to proliferation of Salmonella than green fruit in all seasons. Inter-seasonal differences were the strongest factors affecting proliferation of Salmonella in peppers

    Severe hypoxaemic hypercapnia compounds cerebral oxidative–nitrosative stress during extreme apnoea: Implications for cerebral bioenergetic function

    Get PDF
    We examined the extent to which apnoea-induced extremes of oxygen demand/carbon dioxide production impact redox regulation of cerebral bioenergetic function. Ten ultra-elite apnoeists (six men and four women) performed two maximal dry apnoeas preceded by normoxic normoventilation, resulting in severe end-apnoea hypoxaemic hypercapnia, and hyperoxic hyperventilation designed to ablate hypoxaemia, resulting in hyperoxaemic hypercapnia. Transcerebral exchange of ascorbate radicals (by electron paramagnetic resonance spectroscopy) and nitric oxide metabolites (by tri-iodide chemiluminescence) were calculated as the product of global cerebral blood flow (by duplex ultrasound) and radial arterial (a) to internal jugular venous (v) concentration gradients. Apnoea duration increased from 306 ± 62 s during hypoxaemic hypercapnia to 959 ± 201 s in hyperoxaemic hypercapnia (P ≤ 0.001). Apnoea generally increased global cerebral blood flow (all P ≤ 0.001) but was insufficient to prevent a reduction in the cerebral metabolic rates of oxygen and glucose (P = 0.015–0.044). This was associated with a general net cerebral output (v > a) of ascorbate radicals that was greater in hypoxaemic hypercapnia (P = 0.046 vs. hyperoxaemic hypercapnia) and coincided with a selective suppression in plasma nitrite uptake (a > v) and global cerebral blood flow (P = 0.034 to <0.001 vs. hyperoxaemic hypercapnia), implying reduced consumption and delivery of nitric oxide consistent with elevated cerebral oxidative–nitrosative stress. In contrast, we failed to observe equidirectional gradients consistent with S-nitrosohaemoglobin consumption and plasma S-nitrosothiol delivery during apnoea (all P ≥ 0.05). Collectively, these findings highlight a key catalytic role for hypoxaemic hypercapnia in cerebral oxidative–nitrosative stress

    Lack of Pericytes Leads to Endothelial Hyperplasia and Abnormal Vascular Morphogenesis

    Get PDF
    The association of pericytes (PCs) to newly formed blood vessels has been suggested to regulate endothelial cell (EC) proliferation, survival, migration, differentiation, and vascular branching. Here, we addressed these issues using PDGF-B– and PDGF receptor-β (PDGFR-β)–deficient mice as in vivo models of brain angiogenesis in the absence of PCs. Quantitative morphological analysis showed that these mutants have normal microvessel density, length, and number of branch points. However, absence of PCs correlates with endothelial hyperplasia, increased capillary diameter, abnormal EC shape and ultrastructure, changed cellular distribution of certain junctional proteins, and morphological signs of increased transendothelial permeability. Brain endothelial hyperplasia was observed already at embryonic day (E) 11.5 and persisted throughout development. From E 13.5, vascular endothelial growth factor-A (VEGF-A) and other genes responsive to metabolic stress became upregulated, suggesting that the abnormal microvessel architecture has systemic metabolic consequences. VEGF-A upregulation correlated temporally with the occurrence of vascular abnormalities in the placenta and dilation of the heart. Thus, although PC deficiency appears to have direct effects on EC number before E 13.5, the subsequent increased VEGF-A levels may further abrogate microvessel architecture, promote vascular permeability, and contribute to formation of the edematous phenotype observed in late gestation PDGF-B and PDGFR-β knock out embryos
    • …
    corecore