少点错误 11月06日 19:52
区分真伪内容:为何水印难以解决AI生成内容难题
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

随着深度伪造技术的发展,辨别AI生成内容变得愈发困难。文章探讨了为AI生成内容添加水印的方案,并指出其局限性。无论是为AI生成内容打水印,还是要求所有数码相机强制添加数字水印,都面临技术挑战、被规避的风险以及可能引发的“水印军备竞赛”。作者认为,与其依赖难以实现的防伪技术,不如接受不可区分的伪造内容已是技术现实,并提出构建去中心化的信任网络,通过追踪内容来源和数字签名来帮助用户判断可信度。

💧 **AI生成内容的水印困境**:为AI生成的内容添加水印,无论是在图像、声音还是文本上,都可能引发一场“水印军备竞赛”,即一方设计水印,另一方设法破解。这种对抗性环境使得水印的长期有效性难以保证,且存在非合规行为者(如不加水印的模型发布者)规避检测的风险。

📸 **强制数码相机水印的挑战**:要求数码相机强制添加数字水印或签名,同样面临多重阻碍。这包括谁有权决定和控制水印系统、软件的安全性以及如何确保水印在“合法”编辑(如裁剪、格式转换)后依然存在,而在恶意篡改后失效。历史上的类似尝试(如Clipper Chip)都曾因安全漏洞而失效,且该技术不适用于文本。

💡 **构建去中心化信任网络**:鉴于技术上的困难,文章提出接受“不可区分的伪造内容”已是技术现实。更可行的方案是建立一个去中心化的、仅可追加的系统,允许用户发布其生成内容的数字签名。通过信任链和自动化工具,用户可以根据自己信任的来源(如可信的记者)来评估内容的真实性,从而构建一个分布式的信任网络。

Published on November 6, 2025 11:44 AM GMT

epistemic status: my thoughts, backed by some arguments

With the advent of deep fakes, it has become very hard to know which image / sound / video is authentic and which is generated by an AI. In this context, people have proposed using software to detect generated content, usually aided by some type of watermarking. I don't think this type of solution would work.

Watermarking AI-generated content

One idea is to add a watermark to all content produced by a generative model. The exact technique would depend on the type of media - e.g. image, sound, text.

We could discuss various techniques with their advantages and shortcomings, but I think this is beside the point. The fact is that this is an adversarial setting - one side is trying to design reliable, robust watermarks and the other side is trying to find ways to break them. Relying on watermarks could start a watermarking arms race. There are strong incentives for creating fakes so hoping that those efforts would fail seems like wishful thinking.

Then there is the issue of non-complying actors. One company could still decide not to put watermarks or release the weights of its model. This is next to impossible to prevent on a worldwide scale. Whoever wants to create fakes can simply use any generative model which doesn't add watermarks.

I don't think watermarking AI-generated content is a reasonable strategy.

Mandatory digital watermark system for all digital cameras

Another idea is to make digital cameras add a watermark (or a digital signature) to pictures and videos. Maybe digital microphones can even do something similar for sound, although this would likely significantly increase the price of the cheapest ones. We should not that this technique cannot be applied for text.

I see several objections to this proposal:

Is there a solution?

I think we may need to accept that indistinguishable fakes are part of what's technologically possible now.

In such case, the best we could do is track the origin of content and then each person could decide which origins to trust. I am thinking of some decentralized append-only system where people can publish digital signatures of content they have generated.

If you trust your journalist friend Ron Burgundy, you could verify the digital signature of the photo in his news article against his public key. You could also assign some level of trust to the people Ron trusts. This creates a distributed network of trust.

With the right software, I can imagine this whole process being automated: I click on an article from a site and one of my browser plugins shows the content is 65% trustworthy (according to my trusted list). When I publish something, a hash of it signed with my private key is automatically appended to a distributed repository of signatures. Anybody can choose run nodes of the repository software in a way similar to how people can run blockchain or tor nodes. Platforms with user-generated content could choose to only allow signed content and the signer could potentially be held responsible. It's not a perfect idea, but it's the best I have been able to come up with.

I have seen attempts at something similar, but usually controlled by some company and requiring paid subscription (both of which defeat the whole purpose for wide adoption).



Discuss

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

AI生成内容 深度伪造 水印技术 数字签名 信任网络 AI Deepfakes Watermarking Digital Signatures Trust Networks
相关文章