Pith. sign in

REVIEW 21 cited by

A Watermark for Large Language Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2301.10226 v4 pith:QKTYHJ66 submitted 2023-01-24 cs.LG cs.CLcs.CR

classification cs.LGcs.CLcs.CR
keywords watermarklanguagemodelmodelstokensframeworkgeneratedgreen
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Potential harms of large language models can be mitigated by watermarking model output, i.e., embedding signals into generated text that are invisible to humans but algorithmically detectable from a short span of tokens. We propose a watermarking framework for proprietary language models. The watermark can be embedded with negligible impact on text quality, and can be detected using an efficient open-source algorithm without access to the language model API or parameters. The watermark works by selecting a randomized set of "green" tokens before a word is generated, and then softly promoting use of green tokens during sampling. We propose a statistical test for detecting the watermark with interpretable p-values, and derive an information-theoretic framework for analyzing the sensitivity of the watermark. We test the watermark using a multi-billion parameter model from the Open Pretrained Transformer (OPT) family, and discuss robustness and security.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 21 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Beyond Heuristic Tuning: Power-Calibrated LLM Watermarking

    stat.ML 2026-07 accept novelty 7.0 of 10

    A power-calibrated statistical framework gives closed-form links from KGW watermark parameters (γ, δ) to detection power and KL distortion, enabling principled Pareto-optimal selection.

  2. Attacks on Machine-Text Detectors Retain Stylistic Fingerprints

    cs.CL 2025-05 conditional novelty 7.0 of 10

    A style-aware paraphrasing attack evades all nine tested AI-text detectors at the single-document level, but multi-document analysis makes the attack detectable again.

  3. UTS at ELOQUENT 2026 Voight-Kampff: structural shifts in AI writing bypass state-of-the-art detectors

    cs.CR 2026-07 conditional novelty 6.5 of 10

    Structural register and narrative-form shifts make AI-written text evade adversarially retrained detectors, winning the ELOQUENT 2026 Voight-Kampff competition.

  4. WorldMark: A Plug-and-Play World Knowledge Interface for Cross-Host Language Model Watermarking

    cs.CR 2026-08 conditional novelty 6.0 of 10

    WorldMark modulates watermark strength per token using knowledge-graph saliency, improving robust detection and perplexity for MorphMark watermark variants on C4.

  5. FPEdit: Robust LLM Fingerprinting through Localized Parameter Editing

    cs.CR 2025-08 conditional novelty 6.0 of 10

    FPEdit uses knowledge editing with a promote-suppress objective to embed robust, stealthy natural-language fingerprints into LLMs, achieving 94 to 100 percent retention after fine-tuning while preserving benchmark per...

  6. A Watermark for Auto-Regressive Image Generation Models

    cs.CV 2025-06 conditional novelty 6.0 of 10

    Clustering visual tokens into equivalence classes lets a distortion-free reweight watermark survive the retokenization step in auto-regressive image generation.

  7. Expert Survey: AI Reliability & Security Research Priorities

    cs.CY 2025-05 conditional novelty 6.0 of 10

    Expert ratings place capability forecasting and dangerous-capability evaluations at the top of a 105-area AI reliability and security research priority list.

  8. AGENT-X: Adaptive Guideline-based Expert Network for Threshold-free AI-generated teXt detection

    cs.CL 2025-05 reject novelty 6.0 of 10

    AGENT-X is a zero-shot multi-LLM framework for AI-generated text detection that routes texts to guideline-specific agents and aggregates their calibrated confidences without threshold tuning.

  9. Fast In-Spectrum Graph Watermarks

    cs.DS 2025-02 conditional novelty 6.0 of 10

    F&F watermarks unweighted graphs by inserting a Gaussian key into Fourier coefficients of the adjacency matrix and binarizing the result, achieving O(N^2 log N) embedding and extraction with robustness to random edge flips.

  10. Training AI to be Loyal

    cs.CY 2025-01 reject novelty 6.0 of 10

    The paper outlines OML 1.0, an optimistic fingerprint-based protocol intended to give open-source models community ownership, alignment, and control.

  11. DAMAGE: Detecting Adversarially Modified AI Generated Text

    cs.CL 2025-01 conditional novelty 6.0 of 10

    Adding humanizer-processed text to training data yields a detector that catches 98.26% of humanized AI essays at a 5% false-positive rate and stays robust to a detector-targeted attack.

  12. Task-Agnostic Language Model Watermarking via High Entropy Passthrough Layers

    cs.CL 2024-12 reject novelty 6.0 of 10

    A backdoor watermark for LLMs using passthrough layers trained to output high-entropy text on a private key, with near-perfect extraction in benign settings but with layer-removal robustness contradicted by the paper'...

  13. Recourse, Repair, Reparation, & Prevention: A Stakeholder Analysis of AI Supply Chains

    cs.CY 2025-07 conditional novelty 5.0 of 10

    The redress available after an AI supply chain harm is determined by whether stakeholders can agree on a remedy and whether that remedy is technically, legally, and financially achievable.

  14. Navigating Shortcuts, Spurious Correlations, and Confounders: From Origins via Detection to Mitigation

    cs.LG 2024-12 accept novelty 5.0 of 10

    A unifying taxonomy and formal definition that connects shortcut learning, spurious correlations, Clever Hans behavior, and confounders across detection, mitigation, and datasets.

  15. SEFD: Semantic-Enhanced Framework for Detecting LLM-Generated Text

    cs.CL 2024-11 conditional novelty 5.0 of 10

    SEFD combines retrieval-based semantic similarity with existing detectors and an adaptive pool to improve detection of paraphrased LLM-generated text in sequential streams.

  16. Temperature Matters: Enhancing Watermark Robustness Against Paraphrasing Attacks

    cs.CL 2025-06 reject novelty 4.0 of 10

    A watermark that seeds each token's sampling temperature from a hash of the previous h tokens is claimed to beat the Aaronson watermark under a 30% BERT paraphrase attack, based on a single ROC curve without error bars.

  17. Glimpse: Enabling White-Box Methods to Use Proprietary Models for Zero-Shot LLM-Generated Text Detection

    cs.CL 2024-12 conditional novelty 4.0 of 10

    Glimpse estimates full token distributions from top-K API probabilities, enabling white-box detectors like Fast-DetectGPT to reach about 0.95 AUROC on GPT-4, Claude-3, and Gemini-1.5 text.

  18. Multi-Stage Prompt Inference Attacks on Enterprise LLM Systems

    cs.CR 2025-07 reject novelty 3.0 of 10

    Multi-stage prompt inference attacks against enterprise LLMs are formalized and defenses are proposed, but the preprint gives no reproducible evidence for its central claims.

  19. CoTGuard: Using Chain-of-Thought Triggering for Copyright Protection in Multi-Agent LLM Systems

    cs.CL 2025-05 reject novelty 3.0 of 10

    A trigger-based watermark for multi-agent reasoning traces detects only the injected phrase, not the reproduction of copyrighted content.

  20. AI-Generated Content in Cross-Domain Applications: Research Trends, Challenges and Propositions

    cs.AI 2025-09 conditional novelty 2.0 of 10

    A cross-domain vision paper that surveys AI-generated content and proposes research directions, without introducing new empirical results.

  21. Code LLMs: A Taxonomy-based Survey

    cs.CL 2024-12 reject novelty 2.0 of 10

    This paper presents a taxonomy-based review of code-focused large language models, grouping tasks, corpora, models, benchmarks, and challenges, and compiles code-generation benchmark scores.

Pith tools