Anthropic announced this week that the invisible watermark will be added to the text created by Claude. According to external sources, this approach quickly led to the warming of another type of tool: applications and services called the cleanup of AI watermarks.
According to the article, the problem lies not only in rising demand, but also in the fact that a large number of products are taking the opportunity to exaggerate. Some tools claim to be stable in removing watermarks, while others confuse “to recognize” with “to rewrite” “to drop AI traces”, possibly even with malicious software, using users to profit from their eagerness to avoid detection.
Watermarks are hidden in word selection.
According to Anthropic, the text watermarks do not insert special characters or add visible marks to the body, but adjust the choice of words during generation to form statistical models that can be identified by specific tools. The text appears to be normal and the reader is generally unable to make a direct determination as to whether it contains a watermark.
For example, the article states that a sentence is often expressed in a number of terms. When the model is generated, a particular type of alternative expression may be selected according to a given probability. It is difficult to detect anomalies in a single sentence, but this pattern may be identified by placing the entire text together for analysis.
Rewriting and spelling weaken.
According to external sources, the text watermark is different from the photo watermark, and stability is more dependent on the original structure. As long as the user rewriting the content, replacing the words, spelling the text longer, or rewrite it again to another AI, the original statistical feature may be dispersed.
This means that many of the “de-watermarks” do not necessarily depend on know-how. Common editing, local rewrite and even secondary generation can reduce detection results. This is also why some vendors have packaged common rewriting functions as “professional watermarks”, which are not commensurate with their real capacity.
Ash's got an expansion.
According to the article, as more model service providers try to mark AI output, the grey service around "go to watermark" will continue to grow. There are three main types of risk:
- A false promise that all model watermarks could be completely removed.
- Confusion of concepts. Packing the rewrite tool into a detection circumvention tool.
- Use of software for downloading or installing plugins for the placement of malicious programs
The core judgement of the external media is that the text watermark is not in itself unbreakable and that the marketing and fraud surrounding it may spread more quickly than the technology itself. The more realistic question for users now is not “can it be completely eliminated”, but how to identify exaggerated propaganda and suspect software.
