Watermarking for Proprietary Dataset Protection

July 01, 2026 ยท Grace Period ยท ๐Ÿ› the ICML 2026 Workshop on Trustworthy AI for Good

โณ Grace Period
This paper is less than 90 days old. We give authors time to release their code before passing judgment.
Authors John Kirchenbauer, Brian R. Bartoldson, Bhavya Kailkhura, Tom Goldstein arXiv ID 2607.00325 Category cs.LG: Machine Learning Cross-listed cs.CL Citations 0 Venue the ICML 2026 Workshop on Trustworthy AI for Good
Abstract
A growing body of literature suggests that training data membership inference problems are fundamentally hard tasks in modern language modeling settings. We argue that output watermarking techniques are the right gadget to make training membership tests for generative models more tractable, based on prior results showing that language models exhibit residual watermark "radioactivity" under partially watermarked training datasets. We pit a watermark-based dataset inference approach head-to-head against traditional loss-based membership inference methods and show that watermarking can achieve comparable membership detection performance when subset exposure is high enough, under an alternate set of assumptions.
Community shame:
Not yet rated
Community Contributions

Found the code? Know the venue? Think something is wrong? Let us know!

๐Ÿ“œ Similar Papers

In the same crypt โ€” Machine Learning