Sounds like a great opportunity for the AI labs (American, of course,
because who else?) to train their AIs to embed hidden social signals
in their outputs, for targeting purposes.

On Wed, Jul 22, 2026 at 11:43 AM Matt Mahoney <[email protected]> wrote:
>
> This paper describes how to use open weight LLMs to hide text messages inside 
> other messages of the same length. https://arxiv.org/abs/2510.20075
>
> The technique is to use the LLM to rank the tokens of the hidden message by 
> their probabilities, then generate an unrelated cover text using a secret 
> prompt and the same list of token ranks. To read the hidden message you use 
> the secret prompt to recover the list of token ranks and then generate the 
> hidden message by omitting the prompt. This requires that the sender and 
> receiver both have access to the same weights, a model small enough to run 
> locally (they use Llama 3 8B), and know the secret prompt.
>
> One problem they note is that the cover text looks less plausible and has 
> lower probability than natural text. The most interesting thing I found from 
> the paper is that LLMs can guess the next token on the first try 40% of the 
> time, similar to how Shannon found in 1950 that humans can guess the next 
> character 80% of the time. In both cases, the actual probability is much 
> higher than 40% or 80%, sometimes close to 100%. Shannon estimated the 
> entropy of written English between 0.6 and 1.3 bits per character. The 
> uncertainty comes from only knowing the ranking and not the true 
> probabilities that led to them, but with LLMs we have both. I still don't 
> know exactly because the figure on page 5 is hard to interpret, but I think 
> it shows that random posts on Reddit have 40% as much entropy as random words.
>
> So it seems obvious to me that the cover text plausibility problem could be 
> fixed by skipping or combining high probability tokens, but the authors 
> didn't try it. More generally I find it difficult to think of a use case. We 
> can already hide arbitrary encrypted messages inside images or video by 
> twiddling the low bits without visibly changing the appearance, but the 
> message has to be much smaller than the cover image. In any case, if you have 
> to send a secret key to read the message, why not send the message directly? 
> One use case is time stamping, proving that you knew something when the cover 
> was posted publicly by later revealing the key. But I think that guessing a 
> secret prompt would be more vulnerable to attack than conventional 
> cryptography.
>
> -- Matt Mahoney, [email protected]
> Artificial General Intelligence List / AGI / see discussions + participants + 
> delivery options Permalink

------------------------------------------
Artificial General Intelligence List: AGI
Permalink: 
https://agi.topicbox.com/groups/agi/T90d65db8ef43a62b-M4108f74d66030e62caf4ed54
Delivery options: https://agi.topicbox.com/groups/agi/subscription

Reply via email to