TTMark introduces a pairwise watermarking framework that extends distortion‑free watermarking from single tokens to adjacent token pairs, enlarging the watermarking alphabet from V to V². By watermarking the joint distribution of consecutive tokens, the detector can exploit both token entropy and conditional entropy while maintaining distortion‑freeness. Experiments on multiple language models and datasets show that TTMARK improves detectability, robustness to edits, and localized watermark detection without degrading generation quality.
By Ruibo Chen, Zhengmian Hu, Donghang Lu, Xuehao Cui, Georgios Milis, Yihan Wu, Jian Du, Heng Huang
arXiv:2609.37218v1 Announce Type: cross
Abstract: Semantic watermarking improves robustness against watermark removal attacks by embedding detectable signals into sentence-level representations. Howe...
By Zewen Sun, Tongyang Zhao, Liyao Xiang, Mingxuan Ma, Lingzhe Wang, Zhiyuan Li
arXiv:2609.38722v1 Announce Type: cross
Abstract: LLM watermarking has become an effective approach to distinguishing AI-generated text from human-written text by embedding detectable patterns during...
By Zewei Deng, Muhammad Siddeek, Liyan Xie, Mohamed Seif, Mengdi Wang, H. Vincent Poor, Andrea Goldsmith
CORE-BREW is a new multi‑bit watermarking method for large language models that uses log‑likelihood ratios for soft‑decision decoding, targeting a fixed hit rate to calibrate the watermark channel. It introduces entropy‑aware erasures to reduce perturbations in low‑entropy contexts and combines likelihood‑based scoring with soft‑decision list decoding to better exploit token‑level reliability. Experiments on open‑source LLMs show that CORE‑BREW improves detection robustness and payload recovery compared to the BREW baseline while keeping false‑positive rates low and maintaining translation quality metrics close to unwatermarked text.
By Joeun Kim, HoEun Kim, Young-Sik Kim
The paper introduces a dataset watermarking technique that embeds a watermark by increasing the co‑occurrence of randomly selected word pairs through meaning‑preserving local edits. The watermark can be detected solely from generated text with provable false‑positive control, and experiments on four base models and three datasets show reliable detection (p < 0.01) even when the watermarked data constitutes less than 5% of fine‑tuning tokens. Compared to existing methods, the approach better preserves benchmark utility and semantic integrity.
By Pengrun Huang, Kamalika Chaudhuri, Yu-Xiang Wang
The paper introduces the first watermark designed specifically for diffusion language models (DLMs), which generate tokens in arbitrary order unlike traditional autoregressive models. It overcomes the challenge of missing prior tokens by applying the watermark in expectation over the context and promoting tokens that strengthen the watermark when used as context. Experiments show a >99% true positive rate with minimal quality loss and comparable robustness to existing autoregressive watermarks.
By Thibaud Gloaguen, Robin Staab, Nikola Jovanovi\'c, Martin Vechev