Pith. sign in

REVIEW 4 cited by

A Resilient and Accessible Distribution-Preserving Watermark for Large Language Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2310.07710 v2 pith:QCPHQUMP submitted 2023-10-11 cs.CR cs.CLcs.LG

classification cs.CRcs.CLcs.LG
keywords watermarkingdistribution-preservinglanguagedistributionmodelstokensaccessiblecontent
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Watermarking techniques offer a promising way to identify machine-generated content via embedding covert information into the contents generated from language models. A challenge in the domain lies in preserving the distribution of original generated content after watermarking. Our research extends and improves upon existing watermarking framework, placing emphasis on the importance of a \textbf{Di}stribution-\textbf{P}reserving (DiP) watermark. Contrary to the current strategies, our proposed DiPmark simultaneously preserves the original token distribution during watermarking (distribution-preserving), is detectable without access to the language model API and prompts (accessible), and is provably robust to moderate changes of tokens (resilient). DiPmark operates by selecting a random set of tokens prior to the generation of a word, then modifying the token distribution through a distribution-preserving reweight function to enhance the probability of these selected tokens during the sampling process. Extensive empirical evaluation on various language models and tasks demonstrates our approach's distribution-preserving property, accessibility, and resilience, making it a effective solution for watermarking tasks that demand impeccable quality preservation.

Discussion (0). Sign in to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Optimal Estimation of Watermark Proportions in Hybrid AI-Human Texts

    stat.ML 2025-06 conditional novelty 7.0 of 10

    For continuous-score text watermarks, the proportion of watermarked tokens in mixed AI-human text is identifiable and can be estimated at the minimax-optimal rate.

  2. LLM Watermark Evasion via Bias Inversion

    cs.CR 2025-09 conditional novelty 6.0 of 10

    Applying a negative logit bias to high-surprisal tokens during LLM paraphrasing drops the green-token rate below the detector threshold, driving watermark detection probability down exponentially and yielding over 99%...

  3. A Watermark for Auto-Regressive Image Generation Models

    cs.CV 2025-06 conditional novelty 6.0 of 10

    Clustering visual tokens into equivalence classes lets a distortion-free reweight watermark survive the retokenization step in auto-regressive image generation.

  4. Invisible Entropy: Towards Safe and Efficient Low-Entropy LLM Watermarking

    cs.CL 2025-05 conditional novelty 5.0 of 10

    A lightweight entropy classifier plus an adaptive threshold method can watermark and detect low-entropy LLM code outputs without querying the original model, matching much larger detectors at 99% fewer detection-phase...

Pith tools