REVIEW 21 cited by
A Watermark for Large Language Models
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Potential harms of large language models can be mitigated by watermarking model output, i.e., embedding signals into generated text that are invisible to humans but algorithmically detectable from a short span of tokens. We propose a watermarking framework for proprietary language models. The watermark can be embedded with negligible impact on text quality, and can be detected using an efficient open-source algorithm without access to the language model API or parameters. The watermark works by selecting a randomized set of "green" tokens before a word is generated, and then softly promoting use of green tokens during sampling. We propose a statistical test for detecting the watermark with interpretable p-values, and derive an information-theoretic framework for analyzing the sensitivity of the watermark. We test the watermark using a multi-billion parameter model from the Open Pretrained Transformer (OPT) family, and discuss robustness and security.
Forward citations
Cited by 21 Pith papers
-
Beyond Heuristic Tuning: Power-Calibrated LLM Watermarking
A power-calibrated statistical framework gives closed-form links from KGW watermark parameters (γ, δ) to detection power and KL distortion, enabling principled Pareto-optimal selection.
-
Attacks on Machine-Text Detectors Retain Stylistic Fingerprints
A style-aware paraphrasing attack evades all nine tested AI-text detectors at the single-document level, but multi-document analysis makes the attack detectable again.
-
UTS at ELOQUENT 2026 Voight-Kampff: structural shifts in AI writing bypass state-of-the-art detectors
Structural register and narrative-form shifts make AI-written text evade adversarially retrained detectors, winning the ELOQUENT 2026 Voight-Kampff competition.
-
WorldMark: A Plug-and-Play World Knowledge Interface for Cross-Host Language Model Watermarking
WorldMark modulates watermark strength per token using knowledge-graph saliency, improving robust detection and perplexity for MorphMark watermark variants on C4.
-
FPEdit: Robust LLM Fingerprinting through Localized Parameter Editing
FPEdit uses knowledge editing with a promote-suppress objective to embed robust, stealthy natural-language fingerprints into LLMs, achieving 94 to 100 percent retention after fine-tuning while preserving benchmark per...
-
A Watermark for Auto-Regressive Image Generation Models
Clustering visual tokens into equivalence classes lets a distortion-free reweight watermark survive the retokenization step in auto-regressive image generation.
-
Expert Survey: AI Reliability & Security Research Priorities
Expert ratings place capability forecasting and dangerous-capability evaluations at the top of a 105-area AI reliability and security research priority list.
-
AGENT-X: Adaptive Guideline-based Expert Network for Threshold-free AI-generated teXt detection
AGENT-X is a zero-shot multi-LLM framework for AI-generated text detection that routes texts to guideline-specific agents and aggregates their calibrated confidences without threshold tuning.
-
Fast In-Spectrum Graph Watermarks
F&F watermarks unweighted graphs by inserting a Gaussian key into Fourier coefficients of the adjacency matrix and binarizing the result, achieving O(N^2 log N) embedding and extraction with robustness to random edge flips.
-
Training AI to be Loyal
The paper outlines OML 1.0, an optimistic fingerprint-based protocol intended to give open-source models community ownership, alignment, and control.
-
DAMAGE: Detecting Adversarially Modified AI Generated Text
Adding humanizer-processed text to training data yields a detector that catches 98.26% of humanized AI essays at a 5% false-positive rate and stays robust to a detector-targeted attack.
-
Task-Agnostic Language Model Watermarking via High Entropy Passthrough Layers
A backdoor watermark for LLMs using passthrough layers trained to output high-entropy text on a private key, with near-perfect extraction in benign settings but with layer-removal robustness contradicted by the paper'...
-
Recourse, Repair, Reparation, & Prevention: A Stakeholder Analysis of AI Supply Chains
The redress available after an AI supply chain harm is determined by whether stakeholders can agree on a remedy and whether that remedy is technically, legally, and financially achievable.
-
Navigating Shortcuts, Spurious Correlations, and Confounders: From Origins via Detection to Mitigation
A unifying taxonomy and formal definition that connects shortcut learning, spurious correlations, Clever Hans behavior, and confounders across detection, mitigation, and datasets.
-
SEFD: Semantic-Enhanced Framework for Detecting LLM-Generated Text
SEFD combines retrieval-based semantic similarity with existing detectors and an adaptive pool to improve detection of paraphrased LLM-generated text in sequential streams.
-
Temperature Matters: Enhancing Watermark Robustness Against Paraphrasing Attacks
A watermark that seeds each token's sampling temperature from a hash of the previous h tokens is claimed to beat the Aaronson watermark under a 30% BERT paraphrase attack, based on a single ROC curve without error bars.
-
Glimpse: Enabling White-Box Methods to Use Proprietary Models for Zero-Shot LLM-Generated Text Detection
Glimpse estimates full token distributions from top-K API probabilities, enabling white-box detectors like Fast-DetectGPT to reach about 0.95 AUROC on GPT-4, Claude-3, and Gemini-1.5 text.
-
Multi-Stage Prompt Inference Attacks on Enterprise LLM Systems
Multi-stage prompt inference attacks against enterprise LLMs are formalized and defenses are proposed, but the preprint gives no reproducible evidence for its central claims.
-
CoTGuard: Using Chain-of-Thought Triggering for Copyright Protection in Multi-Agent LLM Systems
A trigger-based watermark for multi-agent reasoning traces detects only the injected phrase, not the reproduction of copyrighted content.
-
AI-Generated Content in Cross-Domain Applications: Research Trends, Challenges and Propositions
A cross-domain vision paper that surveys AI-generated content and proposes research directions, without introducing new empirical results.
-
Code LLMs: A Taxonomy-based Survey
This paper presents a taxonomy-based review of code-focused large language models, grouping tasks, corpora, models, benchmarks, and challenges, and compiles code-generation benchmark scores.
Discussion (0). Continue with ORCID to comment.