Comment by kingstnap

3 days ago

It's security through obscurity. I'm sure with the technical details or even just sufficient access to a predictive oracle you could break this.

But I suppose it ads friction so better than nothing.

Watermarking text without affecting it is an interesting seemingly weird idea. Does it work any better than (with knowledge of the model used to produce said text), just observing the perplexity is low because its "on policy" generated text.