{"id":"W4417064600","doi":"10.1145/3773028","title":"Securing Large Language Models: A Survey of Watermarking and Fingerprinting Techniques","year":2025,"lang":"en","type":"review","venue":"ACM Computing Surveys","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"Artificial Intelligence in Medicine (Canada)","funders":"National Natural Science Foundation of China","keywords":"Digital watermarking; Fingerprint (computing); Intellectual property; Sophistication; Ingenuity; Adversarial system; Digital Watermarking Alliance; Security token","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002290684,0.001257523,0.00132693,0.002698109,0.0004430957,0.001809266,0.001443419,0.001581908,0.003225625],"category_scores_gemma":[0.007535678,0.000730817,0.0008533034,0.002583365,0.001273181,0.00494688,0.001363583,0.002164976,0.002500204],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0007705083,"about_ca_system_score_gemma":0.001272085,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0008852585,"about_ca_topic_score_gemma":0.0006561608,"domain_scores_codex":[0.9986579,0.000273236,0.0001370924,0.0002330328,0.0006101538,0.00008846318],"domain_scores_gemma":[0.9939307,0.004350196,0.0003504389,0.0005944113,0.0006944231,0.00007973655],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"not_applicable","study_design_scores_codex":[0.00004768991,0.00006634565,0.0005821557,0.003395283,0.00008094144,0.0001137557,0.0001166588,0.005196326,0.00181143,0.02918469,0.01122517,0.9481797],"study_design_scores_gemma":[0.00004421598,0.0005993837,0.00251279,0.007014532,0.0003035989,0.004623229,0.0004504485,0.04756039,0.01544847,0.07830308,0.8429385,0.0002013658],"study_design_candidate":"not_applicable","study_design_consensus":null,"genre_codex":"review","genre_gemma":"review","genre_scores_codex":[0.002390904,0.9073457,0.07648014,0.002284818,0.0004864611,0.00008255852,0.000106643,0.0003232793,0.01049955],"genre_scores_gemma":[0.03480951,0.9263493,0.03214086,0.0009020474,0.001099781,0.00009142262,0.0002285529,0.00008396271,0.004294517],"genre_candidate":"review","genre_consensus":"review","teacher_disagreement_score":0.003225625,"threshold_uncertainty_score":0.01211441,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.04331983216852198,"score_gpt":0.3479031577032387,"score_spread":0.3045833255347167,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}