跳到主要內容

ChatGPT浮水印評測:textGrain技術多脆弱 | ChatGPT Watermark Review: How Fragile Is textGrain?

By Kit 小克 | AI Tool Observer | 2026-10-07

🇹🇼 ChatGPT浮水印評測:textGrain技術多脆弱

ChatGPT浮水印上線了。OpenAI本週宣布,歐盟的 ChatGPT、Codex 使用者,往後收到的 AI 文字會被打上看不見的記號,技術代號textGrain,用來因應歐盟 AI 法案的透明度條款。這浮水印到底多可靠?

textGrain 怎麼運作?

模型生成每個字時,都在幾個機率相近的候選詞裡挑一個,textGrain 用只有 OpenAI 持有的密鑰動手,累積成統計上可偵測的訊號,藏在字詞本身,複製貼上也不會消失。只有歐盟預設開,API 開發者全球可手動開啟,但預設關閉。

老實看數字

  • 200 token 短文,偵測率約80%(1% 誤判率下)
  • 400 token 長文,升到約95%
  • 改寫10% 字詞,準確率就從 92% 掉到 66%

textGrain 擋得住整段不改一字的複製貼上,擋不住貼上後順手改幾句。想靠它解決學生用 AI 寫作業,先別太興奮。

對你有什麼實際影響?

人在歐盟,文字會被標記,但偵測器只開放認可的研究單位,自己查不到。是開發者,浮水印選配、預設關閉,能證明內容來源,但訊號脆弱,別當成防作弊萬靈丹。

OpenAI 說效果跟 DeepMind 的 SynthID for Text 相當,但兩者有同一硬傷:誰握有偵測器,誰就決定文字算不算 AI 寫的。

好不好用,試了才知道。


🇺🇸 ChatGPT Watermark Review: How Fragile Is textGrain?

ChatGPT watermark is now live in the EU. OpenAI announced this week that text generated by ChatGPT and Codex for EU users will carry an invisible mark, under a system called textGrain. It'''s OpenAI'''s response to the EU AI Act'''s transparency rules, which took effect in August and require AI-generated content to be machine-identifiable. How reliable is this watermark, really?

How textGrain Actually Works

Every time a model picks the next word, it'''s choosing among several near-equally likely candidates. textGrain uses a secret key — held only by OpenAI — to quietly bias which near-equal choice gets picked across hundreds of micro-decisions in a single response, building up a statistical signal that lives in the words themselves and survives copy-paste. It'''s default-on only in the EU, rolling out across all ChatGPT and Codex plans; API developers worldwide can turn it on manually for select models, but it stays off by default.

The Honest Numbers

  • On 200-token passages, detection accuracy is about 80% (at a 1% false-positive rate)
  • On 400-token passages, accuracy rises to about 95%
  • Replacing just 10% of the words drops accuracy from 92% to 66%
  • A light paraphrase pass degrades the signal fast enough to become unreliable

textGrain catches an unedited copy-paste, not a copy-paste followed by a few tweaked sentences. If you hoped this would solve AI-written homework for good, don'''t celebrate yet.

What It Actually Means for You

If you'''re in the EU, your ChatGPT text now carries a mark you can'''t check yourself — detector access is currently limited to vetted researchers, not the public. If you'''re a developer, watermarking via the API is opt-in and off by default; it can help prove content provenance to customers, but it'''s fragile, and don'''t treat it as an anti-cheating or copyright silver bullet.

OpenAI says textGrain performs on par with or better than Google DeepMind'''s SynthID for Text in its own tests. But both systems share the same structural flaw: trust depends entirely on trusting the company holding the detector keys — whoever controls detection controls what counts as "AI-written."

You won'''t know until you try it.

Sources / 資料來源

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Google Ironwood TPU v7 推理專用晶片解析:效能追平 NVIDIA、成本低 44%,AI 晶片戰爭正式開打 | Google Ironwood TPU v7 Explained: Matching NVIDIA Performance at 44% Lower Cost — The AI Chip War Heats Up

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code