{
 "cells": [
  {
   "cell_type": "code",
   "execution_count": 1,
   "metadata": {},
   "outputs": [],
   "source": [
    "# in this notebook, we will do abaltion study on the effectiveness of the adaptive thresholding method on the selective watermarking.\n",
    "# as well as the impact of watermark strength on our method.\n",
    "\n",
    "\n",
    "wm_strength=[1.5,2,2.5,3,3.5,4]\n",
    "\n",
    "z_value={\n",
    "    \"with\":{},\n",
    "    \"without\":{}\n",
    "}\n",
    "\n",
    "perplexity={\n",
    "    \"with\":{},\n",
    "    \"without\":{}\n",
    "}\n",
    "\n",
    "\n",
    "cossim={\n",
    "    \"with\":{},\n",
    "    \"without\":{}\n",
    "}\n",
    "\n",
    "\n",
    "for key in wm_strength:\n",
    "    for category in [\"with\", \"without\"]:\n",
    "        z_value[category][key] = []\n",
    "        perplexity[category][key] = []\n",
    "        cossim[category][key] = []\n",
    "\n",
    "\n"
   ]
  },
  {
   "cell_type": "code",
   "execution_count": null,
   "metadata": {},
   "outputs": [
    {
     "data": {
      "application/vnd.jupyter.widget-view+json": {
       "model_id": "e5364e0b64c84899b582ac206b9db821",
       "version_major": 2,
       "version_minor": 0
      },
      "text/plain": [
       "Loading checkpoint shards:   0%|          | 0/2 [00:00<?, ?it/s]"
      ]
     },
     "metadata": {},
     "output_type": "display_data"
    },
    {
     "name": "stderr",
     "output_type": "stream",
     "text": [
      "/data3/LTW/watermark.py:49: FutureWarning: You are using `torch.load` with `weights_only=False` (the current default value), which uses the default pickle module implicitly. It is possible to construct malicious pickle data which will execute arbitrary code during unpickling (See https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models for more details). In a future release, the default value for `weights_only` will be flipped to `True`. This limits the functions that could be executed during unpickling. Arbitrary objects will no longer be allowed to be loaded via this mode unless they are explicitly allowlisted by the user via `torch.serialization.add_safe_globals`. We recommend you start setting `weights_only=True` for any use case where you don't have full control of the loaded file. Please open an issue on GitHub for any issues related to this experimental feature.\n",
      "  self.selector_network.load_state_dict(torch.load(checkpoint_path))\n",
      "/data3/LTW/watermark_ablation.py:49: FutureWarning: You are using `torch.load` with `weights_only=False` (the current default value), which uses the default pickle module implicitly. It is possible to construct malicious pickle data which will execute arbitrary code during unpickling (See https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models for more details). In a future release, the default value for `weights_only` will be flipped to `True`. This limits the functions that could be executed during unpickling. Arbitrary objects will no longer be allowed to be loaded via this mode unless they are explicitly allowlisted by the user via `torch.serialization.add_safe_globals`. We recommend you start setting `weights_only=True` for any use case where you don't have full control of the loaded file. Please open an issue on GitHub for any issues related to this experimental feature.\n",
      "  self.selector_network.load_state_dict(torch.load(checkpoint_path))\n",
      "/data3/LTW/utils/detect_utils.py:106: FutureWarning: You are using `torch.load` with `weights_only=False` (the current default value), which uses the default pickle module implicitly. It is possible to construct malicious pickle data which will execute arbitrary code during unpickling (See https://github.com/pytorch/pytorch/blob/main/SECURITY.md#untrusted-models for more details). In a future release, the default value for `weights_only` will be flipped to `True`. This limits the functions that could be executed during unpickling. Arbitrary objects will no longer be allowed to be loaded via this mode unless they are explicitly allowlisted by the user via `torch.serialization.add_safe_globals`. We recommend you start setting `weights_only=True` for any use case where you don't have full control of the loaded file. Please open an issue on GitHub for any issues related to this experimental feature.\n",
      "  self.selector_network.load_state_dict(torch.load(checkpoint_path))\n"
     ]
    }
   ],
   "source": [
    "from watermark import Detector,Watermark\n",
    "from watermark_ablation import Watermark_ablation,Detector_ablation\n",
    "from datasets import load_dataset, Dataset\n",
    "from transformers import AutoTokenizer, AutoModelForCausalLM,AutoModel,OPTForCausalLM\n",
    "from sentence_transformers import SentenceTransformer, util\n",
    "import torch\n",
    "\n",
    "torch.cuda.set_device(1)\n",
    "device = torch.device('cuda' if torch.cuda.is_available() else 'cpu')\n",
    "\n",
    "dataset = load_dataset(\"json\", data_files=\"./LTW/c4_subset_500.jsonl\")\n",
    "dataset=dataset[\"train\"]\n",
    "\n",
    "\n",
    "\n",
    "model_path=\"./LTW/models/opt-6.7b\"\n",
    "\n",
    "\n",
    "model= AutoModelForCausalLM.from_pretrained(model_path,torch_dtype=torch.float16).to(device)\n",
    "tokenizer=AutoTokenizer.from_pretrained(model_path)\n",
    "model.eval()\n",
    "\n",
    "\n",
    "def get_first_n_words(text, n=200):\n",
    "    words = text.split()  \n",
    "    return ' '.join(words[:n])  \n",
    "\n",
    "\n",
    "model_name = \"./LTW/models/opt-1.3b\"\n",
    "ppl_model = OPTForCausalLM.from_pretrained(model_name).to(device)\n",
    "ppl_tokenizer = AutoTokenizer.from_pretrained(model_name)\n",
    "\n",
    "def calculate_perplexity(text):\n",
    "\n",
    "    inputs = ppl_tokenizer(text, return_tensors=\"pt\", truncation=True, padding=True).to(device)\n",
    "\n",
    "    with torch.no_grad():\n",
    "\n",
    "        outputs = ppl_model(**inputs, labels=inputs[\"input_ids\"])\n",
    "        \n",
    "\n",
    "        loss = outputs.loss \n",
    "        \n",
    "\n",
    "    perplexity = torch.exp(loss)  \n",
    "    return perplexity.item()\n",
    "\n",
    "\n",
    "semantic_model = SentenceTransformer('./hf_models/all-mpnet-base-v2') \n",
    "\n",
    "def calculate_sim(text1,text2):\n",
    "\n",
    "\n",
    "    embedding1 = semantic_model.encode(text1, convert_to_tensor=True)\n",
    "    embedding2 = semantic_model.encode(text2, convert_to_tensor=True)\n",
    "    \n",
    "    cosine_similarity = util.pytorch_cos_sim(embedding1, embedding2)\n",
    "    return cosine_similarity.item()\n",
    "\n",
    "\n",
    "ckpt_path=\"./LTW/ckpt/tmp/selective_network_epoch0_step2000.pth\"\n",
    "wm = Watermark(checkpoint_path=ckpt_path,device=device,k=6,model=model,tokenizer=tokenizer, max_new_tokens= 225,min_new_tokens=175,embed_unigram_wm=True)\n",
    "wm_ablation=Watermark_ablation(checkpoint_path=ckpt_path,device=device,k=6,model=model,tokenizer=tokenizer, max_new_tokens= 225,min_new_tokens=175,embed_unigram_wm=True)\n",
    "\n",
    "gamma=0.25\n",
    "\n",
    "detector = Detector(vocab=list(tokenizer.get_vocab().values()),\n",
    "                                        gamma=gamma,\n",
    "                                        tokenizer=tokenizer,\n",
    "                                        z_threshold=4,\n",
    "                                        model=model,\n",
    "                                        k=6,\n",
    "                                        checkpoint_path=\"./LTW/ckpt/tmp/selective_network_epoch0_step2000.pth\",\n",
    "                                        embed_unigram_wm=True,   \n",
    "                                        )\n",
    "\n",
    "detector_ablation = Detector_ablation(vocab=list(tokenizer.get_vocab().values()),\n",
    "                                        gamma=gamma,\n",
    "                                        tokenizer=tokenizer,\n",
    "                                        z_threshold=4,\n",
    "                                        model=model,\n",
    "                                        k=6,\n",
    "                                        checkpoint_path=\"./LTW/ckpt/tmp/selective_network_epoch0_step2000.pth\",\n",
    "                                        embed_unigram_wm=True,   \n",
    "                                        )\n"
   ]
  },
  {
   "cell_type": "code",
   "execution_count": null,
   "metadata": {},
   "outputs": [
    {
     "name": "stderr",
     "output_type": "stream",
     "text": [
      "Asking to truncate to max_length but no maximum length is provided and the model has no predefined maximum length. Default to no truncation.\n"
     ]
    }
   ],
   "source": [
    "for delta in wm_strength:\n",
    "    for data in dataset:\n",
    "        text=data['text'] \n",
    "        input_text=text[:300]\n",
    "        human_ans=get_first_n_words(text[300:],200)\n",
    "\n",
    "        output=wm.generate_watermark(input_text,gamma,delta)\n",
    "        output=output[0]\n",
    "        ppl=calculate_perplexity(output)\n",
    "        sim=calculate_sim(human_ans,output)\n",
    "        perplexity[\"with\"][delta].append(ppl)\n",
    "        cossim[\"with\"][delta].append(sim)\n",
    "\n",
    "        output=input_text+output\n",
    "        tokenized_input=tokenizer.encode(input_text,  return_tensors='pt',add_special_tokens=False).to(device)\n",
    "        tokenized_output=tokenizer.encode(output, return_tensors='pt').to(device)\n",
    "        tokenized_output=tokenized_output[0]\n",
    "        tokenized_input=tokenized_input[0]\n",
    "        detection_result=detector.detect(tokenized_output,tokenized_input)\n",
    "        z_value[\"with\"][delta].append(detection_result['z_score'])\n",
    "\n",
    "        \n",
    "\n",
    "        output_ablation=wm_ablation.generate_watermark(input_text,gamma,delta)\n",
    "        output_ablation=output_ablation[0]\n",
    "        ppl_ablation=calculate_perplexity(output_ablation)\n",
    "        sim_ablation=calculate_sim(human_ans,output_ablation)\n",
    "        perplexity[\"without\"][delta].append(ppl_ablation)\n",
    "        cossim[\"without\"][delta].append(sim_ablation)\n",
    "\n",
    "        output_ablation=input_text+output_ablation\n",
    "        tokenized_input=tokenizer.encode(input_text,  return_tensors='pt',add_special_tokens=False).to(device)\n",
    "        tokenized_output=tokenizer.encode(output_ablation, return_tensors='pt').to(device)\n",
    "        tokenized_output=tokenized_output[0]\n",
    "        tokenized_input=tokenized_input[0]\n",
    "        detection_result=detector.detect(tokenized_output,tokenized_input)\n",
    "        z_value[\"without\"][delta].append(detection_result['z_score'])\n",
    "\n",
    "\n",
    "eval_records={\n",
    "    \"perplexity\":perplexity,\n",
    "    \"similarity\":cossim,\n",
    "    \"z_value\":z_value\n",
    "}\n",
    "import json\n",
    "with open('./LTW/eval_records/ablation.json', 'w') as f:\n",
    "    json.dump(eval_records, f)\n",
    "        \n",
    "\n",
    "        \n",
    "    \n"
   ]
  },
  {
   "cell_type": "code",
   "execution_count": null,
   "metadata": {},
   "outputs": [],
   "source": []
  },
  {
   "cell_type": "code",
   "execution_count": null,
   "metadata": {},
   "outputs": [],
   "source": [
    "import json\n",
    "with open('./LTW/eval_records/ablation.json', 'r') as f:\n",
    "    eval_records=json.load(f)"
   ]
  },
  {
   "cell_type": "code",
   "execution_count": null,
   "metadata": {},
   "outputs": [
    {
     "name": "stdout",
     "output_type": "stream",
     "text": [
      "{'perplexity': {'with': {'1.5': 11.685854241847991,\n",
      "                         '2': 12.35365509414673,\n",
      "                         '2.5': 13.003083664178849,\n",
      "                         '3': 13.409905518531799,\n",
      "                         '3.5': 13.980577872276307,\n",
      "                         '4': 14.029300050258637},\n",
      "                'without': {'1.5': 11.800519680976867,\n",
      "                            '2': 12.524202003240585,\n",
      "                            '2.5': 13.216772216796874,\n",
      "                            '3': 13.402639038085937,\n",
      "                            '3.5': 13.921514095783234,\n",
      "                            '4': 14.307615527153015}},\n",
      " 'z_value': {'with': {'1.5': 6.84429695346313,\n",
      "                      '2': 9.292729847120354,\n",
      "                      '2.5': 11.242841852467619,\n",
      "                      '3': 12.670466243233228,\n",
      "                      '3.5': 13.775517287574695,\n",
      "                      '4': 14.497399286758627},\n",
      "             'without': {'1.5': 6.831124683859327,\n",
      "                         '2': 9.030546223115305,\n",
      "                         '2.5': 11.120120836515573,\n",
      "                         '3': 12.442677115434467,\n",
      "                         '3.5': 13.569884508995509,\n",
      "                         '4': 14.369388990279418}}}\n"
     ]
    }
   ],
   "source": [
    "wm_strength_list = [\"1.5\", \"2\", \"2.5\", \"3\", \"3.5\", \"4\"]\n",
    "avg_records = {\n",
    "    \"perplexity\": {\"with\": {}, \"without\": {}},\n",
    "    \"z_value\": {\"with\": {}, \"without\": {}}\n",
    "}\n",
    "\n",
    "for metric in [\"perplexity\", \"z_value\"]:\n",
    "\n",
    "    for mode in [\"with\", \"without\"]:\n",
    "        for wm_strength in wm_strength_list:\n",
    "\n",
    "            value_list = eval_records[metric][mode][wm_strength]\n",
    "\n",
    "            if value_list:  \n",
    "                avg_value = sum(value_list) / len(value_list)\n",
    "            else:\n",
    "                avg_value = None  \n",
    "\n",
    "            avg_records[metric][mode][wm_strength] = avg_value\n",
    "\n",
    "\n",
    "import pprint\n",
    "pprint.pprint(avg_records)"
   ]
  },
  {
   "cell_type": "code",
   "execution_count": null,
   "metadata": {},
   "outputs": [
    {
     "name": "stdout",
     "output_type": "stream",
     "text": [
      "\\begin{table}\n",
      "\\centering\n",
      "\\caption{Ablation Study Results}\n",
      "\\label{ablation_results}\n",
      "\\begin{tabular}{lcccccccc}\n",
      "\\hline\n",
      "Setting & Metrics & $\\delta = 1.5$ & $\\delta = 2$ & $\\delta = 2.5$ & $\\delta = 3$ & $\\delta = 3.5$ & $\\delta = 4$ \\\\\n",
      "\\hline\n",
      "With & Perplexity & 11.686 & 12.354 & 13.003 & 13.410 & 13.981 & 14.029 \\\\\n",
      " & Z-Value & 6.844 & 9.293 & 11.243 & 12.670 & 13.776 & 14.497 \\\\\n",
      "\\hline\n",
      "Without & Perplexity & 11.801 & 12.524 & 13.217 & 13.403 & 13.922 & 14.308 \\\\\n",
      " & Z-Value & 6.831 & 9.031 & 11.120 & 12.443 & 13.570 & 14.369 \\\\\n",
      "\\hline\n",
      "\\end{tabular}\n",
      "\\end{table}\n"
     ]
    }
   ],
   "source": [
    "\n",
    "latex_table = \"\\\\begin{table}\\n\"\n",
    "latex_table += \"\\\\centering\\n\"\n",
    "latex_table += \"\\\\caption{Ablation Study Results}\\n\"\n",
    "latex_table += \"\\\\label{ablation_results}\\n\"\n",
    "latex_table += \"\\\\begin{tabular}{lcc\" + \"c\" * len(wm_strength_list) + \"}\\n\"\n",
    "latex_table += \"\\\\hline\\n\"\n",
    "\n",
    "\n",
    "header = \"Settings & Metrics\"\n",
    "for strength in wm_strength_list:\n",
    "    header += f\" & $\\\\delta = {strength}$\"\n",
    "latex_table += header + \" \\\\\\\\\\n\"\n",
    "latex_table += \"\\\\hline\\n\"\n",
    "\n",
    "\n",
    "methods = {\"with\": \"With\", \"without\": \"Without\"}\n",
    "metrics_map = {\n",
    "    \"perplexity\": \"Perplexity\",\n",
    "    \"z_value\": \"Z-Value\"\n",
    "}\n",
    "\n",
    "\n",
    "for method, method_name in methods.items():\n",
    "\n",
    "    first_metric = True\n",
    "    \n",
    "\n",
    "    for metric in avg_records.keys():\n",
    "        if first_metric:\n",
    "            latex_table += f\"{method_name} & {metrics_map.get(metric, metric)}\"\n",
    "            first_metric = False\n",
    "        else:\n",
    "            latex_table += f\" & {metrics_map.get(metric, metric)}\"\n",
    "        \n",
    "\n",
    "        for strength in wm_strength_list:\n",
    "            value = avg_records[metric][method].get(strength)\n",
    "\n",
    "            formatted_value = f\"{value:.3f}\" if value is not None else \"N/A\"\n",
    "            latex_table += f\" & {formatted_value}\"\n",
    "        \n",
    "        latex_table += \" \\\\\\\\\\n\"\n",
    "    \n",
    "\n",
    "    if method == \"with\":\n",
    "        latex_table += \"\\\\hline\\n\"\n",
    "\n",
    "latex_table += \"\\\\hline\\n\"\n",
    "latex_table += \"\\\\end{tabular}\\n\"\n",
    "latex_table += \"\\\\end{table}\"\n",
    "\n",
    "print(latex_table)"
   ]
  }
 ],
 "metadata": {
  "kernelspec": {
   "display_name": "markllm_env",
   "language": "python",
   "name": "python3"
  },
  "language_info": {
   "codemirror_mode": {
    "name": "ipython",
    "version": 3
   },
   "file_extension": ".py",
   "mimetype": "text/x-python",
   "name": "python",
   "nbconvert_exporter": "python",
   "pygments_lexer": "ipython3",
   "version": "3.9.20"
  }
 },
 "nbformat": 4,
 "nbformat_minor": 2
}
