acceptodds
Under review as a conference paper at ICLR 2027

What Does a Copyright Budget Certify? An Exact Threshold for Per-Token Meters, and a Length-Independent Certificate for Selection

Abstract

Certified inference-time copyright defences publish a divergence budget between the served distribution and a safe model, the anchor, trained without the protected works. First, a budget of nats says nothing about a work whose surprisal under the safe model is at most , at every R\'enyi order. Anchored decoding charges its budget per token, so it grows with the output, and at its authors' setting it is vacuous for all protected passages. Second, spent on choosing among draws from the safe model, by any rule, an adversary's included, the budget is a pathwise certificate of exactly nats at any output length, small enough that a rights-holder can bound near-verbatim copying by sampling the safe model alone. Third, with the risky model served as a text continuer at temperature , neither of two judges separates the one metered budget that covers a -token window, , from the safe model. At matched certificates, best-of- and its blockwise variant beat every meter we ran there, under one of two judges once empty answers count as losses; at the authors' temperature the meter at ties selection. Where a meter's certificate is void, selection wins against the authors' B pair and against their byte-level decoder, whose base model is weak on instruction prompts, but loses to the B at their temperature or served as a chat assistant. Against the chat assistant a windowed meter wins too, at window budgets too large to audit by sampling, and leaks near-verbatim text at nats, where both judges prefer it. With no judge, majority vote lifts GSM8K from to . Selection never consults the risky model, so no rescues an anchor that cannot do the task; served from the anchor alone its draws cost a metered decode, and it loses at matched compute. Its leakage, zero at any or at , is relative to the anchor, which must be vetted, as must the scorer unless queries are capped.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.