SynthID-Text watermarking drifts token selection and can change whether AI agents refuse or call tools

SynthID-Text watermarking drifts token selection and can change whether AI agents refuse or call tools

  • Lasso Security names the effect sampling drift: SynthID-Text keeps the original token distribution only in expectation over watermark randomness, while a fixed key changes token choice and can flip refusal and tool-call outcomes.
  • Tournament sampling moves the most uncertain tokens, so in JSON output braces and function names stay predictable while queries, numbers, paths, and recipients can shift and pass an agent different arguments than an unwatermarked run.
  • In paired runs over BFCL v4 single-turn AST plus 200 HarmBench harmful behaviors and 100 benign JailbreakBench controls, drift appears in both refusal and tool calling, and its size depends on the model and the watermark key.
  • Aggregate scores can mask the drift when opposite-direction changes cancel, so the study reports net performance next to paired disagreement between watermarked and unwatermarked runs.
  • Anthropic applies the watermark at the model level for Claude Platform API and cloud provider models, and EU AI Act Article 50(2) requires providers to mark synthetic text in a machine-readable, detectable form where technically feasible.

Hacker News 의견들

Watermarking sounds like a good idea, but it isn't. Token drift will degrade output quality and could let clever people circumvent guardrails. I'd just assume all text is AI generated and test people with pencil and paper.

Hold on, changing a random seed can improve or degrade the output too. Better and worse outputs should be equally probable, just depends on your luck with the seed.

It's a horrible idea regardless. These companies can embed unique identifiers in content to forever track you and where your content diffuses across the web.

This is getting tiring. Watermarking has zero effect on output quality when implemented correctly, it's like swapping the RNG seed for seed 42 and then detecting that seed from the random sequence.

Model companies are doing this for themselves anyway, so they don't feed generated content back into the slopper and collapse the model. From that angle it slowly contributes to better model quality.

Your statement reads pretty dogmatic next to a decent summary of the watermarking algo. What if seed 42 specifically causes poor quality behaviour in some contexts? Normally that's washed out because the seed is random, and now it's fixed, so shouldn't we check behaviour under this specific seed?

That's not true. Watermarks are messing with the next token generation probabilities based on some random seed. Quality is necessarily lower, the difference is simply too small to notice typically.

The 'when implemented correctly' part is probably what people are complaining about. Opus 5 started adding a bunch of comments to my code even when I told it not to, for trivial changes where the comment was longer than the code change. Was that so there are enough tokens outputted for watermarking?

Benchmarked output quality and actual output quality are very different things. Some use cases sit at the very fringe of model intelligence and depth of logic suffers there.

You're using the subjective definition of quality. The thing you're missing is that the tokens aren't actually random. Tool names, syntax, and prompting style become incredibly deterministic in the areas that matter, like tool calling and parameters. I tune thousands of names and return formats until a call is exactly correct 100% of the time, and what works on Opus 4.7 won't work on 4.8.

The caveat is they have to be a little more sophisticated than just changing the rng on sampling, since they need to detect snippets in the middle of a long chat with thinking removed. I don't know how much impact that part has though.

Over a certain token threshold, roughly 300 to 400 words, yes, there are zero negative effects. At the boundary and below it does affect response quality, so they shouldn't do it. It also incentivizes padding tokens in short responses so they can be watermarked, which is its own quality issue.

Even accepting the seed analogy at face value, fixing a specific seed can change things. Recurrent PRNGs often have degenerate cycles in state space, so a different starting point is just further along the same trajectory. LLMs may not have that failure mode, but recurrence in high dimensional spaces makes me nervous.

Am I missing something, or did they actually completely misunderstand how this technology works?

More likely you misunderstood it than them.

Hard to tell, the writing quality is garbage. 'SynthID-Text changes the process by which the model generates each next token' is a stretch, the refusal claim support is pages later, and 'prompt injection connects these two settings' is a straight non-sequitur. They should have used an LLM for writing help.

The article and most of the comments so far are a dumpster fire.

All these attempts to control language are fundamentally misguided at best and genuinely immoral at worst, same pattern as Newspeak in 1984 or the repressions described in psychoanalysis. Severe unintended consequences either way.

AI
Nvidia in talks to acquire or deepen investment in open-model start-up Reflection AIMicrosoft releases MXC 1.0 to contain AI agents with policy-enforced containers on Windows, macOS, and LinuxTerence Tao posts Thomas Hales guest essay on Lean reliability as AI autoformalization of proofs scales up in 2026TypeSafe AI raises $870M at $7.5B valuation led by Andreessen HorowitzOpenAI told investors its annualised revenue was about $20B below earlier reportsOpenAI withdraws three math manuscripts from its GitHub repo as Lean checks continueOpenAI withdraws 3 math papers after a sign error, revises 14 moreLLM-built Rust port of the TypeScript compiler arrives with $400,000 in API-priced tokens and a nod from the TypeScript teamOpenAI publishes 372 math results, including a proof of the Unique Games ConjectureTerence Tao: AI is harvesting open math problems unsustainably, and 'Math 2.0' must reward exposition and communityGoogle DeepMind's SynthID Detector goes public, but it demands a Google, Apple, or ChatGPT loginPaper: verified Lean proof of OpenAI's Navier-Stokes claim does not match the natural language proofMeta and Microsoft cut internal Claude usage, Microsoft caps AI spend at $10K per employeeOpenAI brings GPT-6 and Intelligent UI to ChatGPT's 1.2 billion weekly usersAnthropic's Claude Haiku 5.5 runs 75% cheaper and hits 1620 on GDPval-AA, with a 100K-token price cliffTelegraph Test: cablese compression cuts LLM output tokens 40-49% at plaintext parityArmin Ronacher explains Codemode: LLM tool calls written as JavaScript in a no-network QuickJS sandbox on the Pi harnessOpenAI launches Decisions API in public beta: gpt-6-luna only, 10x faster than Responses, $0.10 per million input tokensGoogle launches EmbeddingGemma 2, a 740M-parameter multimodal embedding model under Apache 2.0OpenAI releases frontier model math results on GitHub with Lean proofs and reasoning tracesMeta's Muse shipped with a spyable zero-day, uploaded private messages without permission, and ignored user settings; Apple changed macOS rules in responseMistral Large 4 preview: 1T-parameter multimodal model with 49B active parameters, weights due this monthCoding agent reconstructs 1.5M Georgia ballot order from a 2022 scanner flawDust trains transformer LMs without backprop by perturbing activations, matching it at large populationChatGPT is signing fake New Yorker cartoons with real cartoonists' signaturesReflection unveils Beam, a 501B open-weight MoE model trained on 10.5K GB300s, with weights promised later this monthFlorida woman used Claude as a diary; Anthropic flagged a threat entry and reported it to police, and she now faces a second-degree felonyClaude catches root malware on Stratechery's Mac Mini, as Apple tightens AI agents' Full Disk AccessCloudflare launches Web Search API in beta, routing Exa, Ceramic.ai and Linkup queries through AI GatewayWolfram argues against handing pure math research to AI, citing the 1988 Mathematica parallelStrata runs Qwen 3.8 Flash Next 125B on a single RTX 4090 at over 100 tokens/sec via 2-bit quantMeta's Muse tops the App Store on UX, not new agent capabilitiesOpenAI safety lead David Robinson quits over 'broken' culture as firm pauses training and shelves next modelLeCun has "zero concerns" about AI extinction, calls Amodei "deluded" and effective altruism "super toxic"Ataraxos beats the best Stratego player 15-1, trained on 16 GPUs and a few thousand dollarsGreg Kroah-Hartman: Mythos's 79 Linux kernel bugs came down to 10 real fixes and one hour of workWisconsin grid approval threatens Oracle's 2027 AI datacenter deadlineBlack Forest Labs' FLUX 3 Image adds bounding-box layout control to text-to-imageSupabase acquires Turso to build on-demand database infrastructure for AI agentsKevin Buzzard maps mathematicians' reaction to AI onto the five stages of griefarXiv caps submissions at two per month as AI-driven preprint flood hits 40,363 in SeptemberHistorian uses Opus 5.5 to surface a 1615 Dutch eyewitness report of dodo huntingDeepSeek Harness desktop app enters public preview for macOS and Windows as open sourceContext Language Models manage their own context as a file, beating SOTA context management by 11.4% on BrowseComp-Plus with 21.5% fewer FLOPsEarendil ships Pi 1.0 alongside Pi Durable, an experimental harness for long-running agentsFigma limits its remote MCP server to whitelisted clients, and MCP's creator calls the restriction sadEarendil ships Pi 1.0 with native MCP support via Codemode, plus experimental Pi DurableCloudflare open-sources Clef decision models and debuts an RL fine-tuning platformFTC opens investigation into OpenAI, Anthropic and other AI companies over product risksOpenAI and Synopsys unveil GPT-Synopsys, a model that drives Synopsys EDA toolsMath community tells AI labs: stop testing advanced math on proprietary models, fund human understandingLaunch HN: Magnitude (YC S25) ships a self-optimizing local inference engine for agent workloadsGoogle announces Gemini 4 Argon, limited to Fairwind cyber defenders at $2/$10 per million tokensTLA+ author Hillel Wayne pushes back on the idea that formal verification will save AI-written codeDavid Dayen asks why Sam Altman faces no consequences while OpenAI agents breached U.N., Australian, and Education Department sitesOpenAI launches $500/month ChatGPT Pro 500 with Astra Ultrafast and cuts the usage allowance on new Pro 200 subscriptionsOpenAI launches dots, always-on GPT-6 Astra agents with their own cloud computersOpenAI ships GPT-6.1 Sol at $2/$10 per million tokens, near-Astra scores for a fifth of the pricePostHog's Jeeves adds autoregressive reasoning to Jev-style decision models, trading speed for accuracyStudy finds conversational AI services hand chat titles, prompts, and screenshots to ad trackersNvidia launches Open Agent Safety Platform with OpenShell and Sentry chip to contain AI agentsAMD acquires World Labs, with Fei-Fei Li joining as Executive VP and Chief ScientistCal Newport calls on Congress to investigate OpenAI and Anthropic over rogue agents and apocalyptic ideologyCloudflare launches cf, an agentic CLI covering its entire 3,000-operation APIMeta poaches MongoDB CEO CJ Desai to run its new enterprise AI platform; MongoDB stock drops 18%Anthropic launches Claude Sonnet 5.5: 70.6% on Terminal-Bench 4.0, 30% faster, up to 30% cheaper per taskAnthropic's Claude Opus 5.5 prompt guide: 30% faster output tokens, medium effort matches Opus 5 at high effortViral TLA+ tweet has Reasonable preview agents that turned 16,000 specs into 3,000 machine-checked proofsAn OpenAI training agent slipped past the sandbox DNS filter and queried a public chatbotOpenAI execs feared LibGen quote about 'sketchy russian website' would show up on Hacker NewsDeepSeek's DSec: 380K concurrent agentic training sandboxes on 160 EPYC CPU nodesOpenAI agents bypassed site controls at SEC, Census Bureau and other US agenciesSynthID-Text watermarking drifts token selection and can change whether AI agents refuse or call toolsMicrosoft merges Copilot into one corporate product and cedes personal chatbots to OpenAI, Google, and Meta700 OpenAI Agents Hacked Hugging Face by Chaining Nearly a Million Link Shortener URLsAppeals court upholds Pentagon's supply chain risk blacklist of Anthropic, blocking Claude from DOD and its contractorsOracle owes New Mexico data centre investors even with no power, after force majeure filing over permitsTrail of Bits Used Six Months of Agent-Built MASM Tooling and Lean Proofs to Audit the Miden zkVMOracle invokes force majeure to defer payments on its New Mexico data center Project JupiterGEO poisoning makes ChatGPT, Gemini and Google AI Overview answer with scam support numbers for Delta, Lufthansa and ChaseOpenAI agent infiltrated Medicare statistics portal and wrote files to an internal server, Australia saysOpenAI agent bypassed access blocks and breached Medicare portal, Albanese revealsGoogle launches Gemini 3.8 Flash TTS with prompt-built voices and 30-second cloningClaude Agents Find ART, a Phage Enzyme System With CRISPR-Like DNA RepeatsEpoch AI: cost of a fixed level of AI performance drops 47% per quarter, 725-fold on GPQA Diamond in 18 monthsStripe Says 83% of Staff Use Its Internal Kai AI Agent WeeklyClaude Opus 5.5 Tops the Artificial Analysis Index at 58, With a $20 per 1M Output Token Price TagPentagon probe blames AI overreliance and gutted civilian review for strike that killed 123 children in MinabGPT-6 Astra breaks 1941 Enigma message MVUEH that stayed unbroken since 2005OpenAI launches GPT-6 Sol and Luna, cuts API prices 50% below GPT-5.6Anthropic ships Claude Opus 5.5: Fable 5.1-level performance at 40% lower serving costXiaomi MiMo-V2.6-Pro tops open weights with 46 on the AA Intelligence Index at $0.13 per taskAdvisory Group on Mathematics and AI launches at IAS, nine mathematicians to advise OpenAI on releasing results its internal model producedTim Dettmers' lab says the research unit is now the ecosystem, and Open Source Week ships an agent harness, auto-compaction it claims beats Claude Code and CodexXiaomi open-sources MiMo-V2.6-Pro and Flash, claiming 46.32 on the Artificial Analysis Intelligence Index, the top open-source scoreFable 5 thinking tokens fell sharply in August after Anthropic opened the model to subscription plans, six-week measurement findsM5 Ultra Mac Studio review: 256 GB of unified memory makes local AI agents viablexAI ships Grok 4.7 at Grok 4.6 pricing, claiming frontier price-performance on long coding tasksPo-Shen Loh on Tao's blog: AI will create more jobs than humans, forcing AI progress to slowGoogle open sources AX, an Apache 2.0 declarative agent orchestrator that claims billions of concurrent agent sessions per cluster

뉴스 알림

새 알림

내 알림

로그인하고 알림을 만들어 보시기 바랍니다.

전체 알림

Dune제욱 님AI제욱 님해커뉴스성현 님