Live data from Hacker News

Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing

daringfireball.net

451–460 of 776 posts

Re: Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing

#451

Earlier quoted context omitted.

Thank you for stating clearly situation. I fully agree with your assessment. For almost 10 years now I have been saying that we need to virtually watermark reality. By "virtual" I mean store the metadata about the digital capture on a public blockchain. Then my devices could have a built-in "fake vs real" detector. Artists, photographers, journalist, etc. are going to want and need this.

a lot of cameras do have an in camera hardware based cryptographic signing (i think it runs off its own chip on them?) but any modifications to the image immediately break that. so for stuff like journalism etc where youd hopefully have a lot of settings dialed in on camera for quick turn around would keep that fingerprint intact.

Editing is fine as long as you keep the signed original for validation purposes.

Re: Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing

#452

Earlier quoted context omitted.

The paper for it is open. The technique isn't really hiding information in the text itself, but by forcing some of the rolls to follow a specific pattern. LLMs work by estimating the most likely next token, so there's sometimes a list of possible candidates that would all work in the text (e.g. synonyms). At low "temperature", the output is a bit more deterministic and otherwise it's a weighted dice roll of which tok…

A way to think of it is that any time the model faces a choice, it leaks some fractional bits of information. Instead of making the choice randomly, you can put information in those bits. But unless you know the prompt, you don't fully know which choice the model faces. Surely a lot of coding space is wasted compensating for that uncertainty. Exotic prompts ("Use no more than five E's in four consecutive words anywhe…

In fact such ‘arbitrary’ constraints uniformly improve composition. Thus eg if I force a - largely arbitrary - technical glossary to be unrelentingly applied to a translation, every single sentence improves in quality.

Re: Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing

#453

Gruber shows here that he really doesn’t understand the basics of how LLM text generation works. It’s weird he picked this battle about the quality of writing in LLMs. Was he planning to use LLMs to write his articles? Well, not that weird actually. He just has a hard-on against anything that comes from the EU since Apple got in trouble. If the EU said tomorrow that they want peace in the world he’d be in Fox News th…

Yes, I decided to stop reading his blog relatively recently after some extremely hot takes on EU policy. I don't feel his thoughts on the matter are particularly well-thought-out, and I feel like he's just stanning for Apple from his priors rather than from any grounding in reality. I dunno, I guess that's what you should expect from Gruber but these EU-bashing articles lowered the enjoyment I got from his blog under…

As an EU citizen I've found myself in agreement with everything he's written regarding EU policy

Re: Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing

#456

Earlier quoted context omitted.

You are one person. The corporation is not. Scale matters

> You are one person. The corporation is not. Scale matters Correct, if you violate it too often to count, you have to pay around less than ~2.5ct per violation. So the lesson here is: Create a company to do torrenting professionally, and resell its values for higher prices. Then get sued and pay a dime on the dollar you made. edit: Actually it's 2.5ct per violation.

Anthropic settled for $3,000 per book(1) in the settlement, so it provably depends of whether the government likes you or not.

(1) https://apnews.com/article/ai-anthropic-copyright-settlement...

Re: Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing

#457
They chose the wrong word "watermarking." Perhaps they find the statistics _after_ a certain amount of text is generated at scale, so that it doesn't affect the fidelity or integrity of the LLMs output.

There is evidence this exists already, and it's why "I have to be honest..." and "This is the right lens, ..." keep popping up.

Probably would be cheaper too. Maybe I am missing something?

Re: Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing

#458
Sorry, this article's argument just doesn't hold water. Yes, we want Claude to write "the best text" and having its word choice even very slightly varied could arguably be construed as "not the best." But "best" is highly subjective, always has been. Claude has never, and will never, write what _you_ consider the best version of a piece of text. It has many choices, influenced by all kinds of random, context-dependent weights and environmental settings. Slightly tweaking weights to prefer certain phrasings might even tilt it toward your idea of "best."

Re: Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing

#459

Translation: No one can ever again use Claude for proofreading their own prose unless they’re willing to risk that the whole thing might be flagged as having been generated by Claude. I think that was intended, yes.

You know, back in the era when proofreaders were human, I never one met a proofreader who rewrote my text afresh, rather than annotating the text with a pen. It's still possible to use Claude to proofread - highlight grammatical, flow, structure, logic errors and make simple suggestions for you to pick and choose or adapt as you wish. No watermarking will flag your text. No flaw accusations of LLM authorship will hau…

Anthropic's own explanation (https://www.anthropic.com/news/claude-text-watermark) is not that clear-cut:

"When Claude proofreads text written by a person, what it gives back has generally only been lightly edited; because nearly all the words are the person’s, there’s very little (if anything) for the watermark to attach to. Depending on the length of the text and how heavily Claude has edited it, those changes might not be enough to make Claude’s involvement detectable."

(emphasis added)

Re: Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing

#460
post #51

>I want any LLM I use to choose the very best, most precise words at every single decision point. Does the author think he is currently getting T=0 output from Claude? Is he under the impression that T=0 produces the "best" writing? This entire article just seems so detached from the basics of how LLMs work.

I think the author is just mad people will be able to detect and filter out their AI slop writing in the future.

I don't think you know the author very well
Post reply on HN