{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:VR764D76JT4XM3ZHW5MAE4N2B3","short_pith_number":"pith:VR764D76","schema_version":"1.0","canonical_sha256":"ac7fee0ffe4cf9766f27b7580271ba0ed9bc3fd5b738f9237a59f9c19874d01b","source":{"kind":"arxiv","id":"2505.05190","version":2},"attestation_state":"computed","paper":{"title":"Revealing Weaknesses in Text Watermarking Through Self-Information Rewrite Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Hongcheng Guo, Leonid Sigal, Yangming Li, Yixin Cheng","submitted_at":"2025-05-08T12:39:00Z","abstract_excerpt":"Text watermarking aims to subtly embed statistical signals into text by controlling the Large Language Model (LLM)'s sampling process, enabling watermark detectors to verify that the output was generated by the specified model. The robustness of these watermarking algorithms has become a key factor in evaluating their effectiveness. Current text watermarking algorithms embed watermarks in high-entropy tokens to ensure text quality. In this paper, we reveal that this seemingly benign design can be exploited by attackers, posing a significant risk to the robustness of the watermark. We introduce"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2505.05190","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-05-08T12:39:00Z","cross_cats_sorted":["cs.AI","cs.CL","cs.CR"],"title_canon_sha256":"6a4162e2b89a9cbb00eb28482b8f96b8281fb7d78d81d329627ad8019c79c6fe","abstract_canon_sha256":"868720e126ca70504d3dfa74f5026460e60a4fa4cc0ac7a05018f4a79feb1834"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:01:36.826548Z","signature_b64":"xHXu4qNnkt+QZtBdPX4LWlODv1O5cNxpMaS5BZgXR/wAHzEg63R+nMnSppfr6eE5oYgZkpl/yJoqTRdVjV6uBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ac7fee0ffe4cf9766f27b7580271ba0ed9bc3fd5b738f9237a59f9c19874d01b","last_reissued_at":"2026-07-05T11:01:36.826063Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:01:36.826063Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Revealing Weaknesses in Text Watermarking Through Self-Information Rewrite Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Hongcheng Guo, Leonid Sigal, Yangming Li, Yixin Cheng","submitted_at":"2025-05-08T12:39:00Z","abstract_excerpt":"Text watermarking aims to subtly embed statistical signals into text by controlling the Large Language Model (LLM)'s sampling process, enabling watermark detectors to verify that the output was generated by the specified model. The robustness of these watermarking algorithms has become a key factor in evaluating their effectiveness. Current text watermarking algorithms embed watermarks in high-entropy tokens to ensure text quality. In this paper, we reveal that this seemingly benign design can be exploited by attackers, posing a significant risk to the robustness of the watermark. We introduce"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.05190","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.05190/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2505.05190","created_at":"2026-07-05T11:01:36.826120+00:00"},{"alias_kind":"arxiv_version","alias_value":"2505.05190v2","created_at":"2026-07-05T11:01:36.826120+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.05190","created_at":"2026-07-05T11:01:36.826120+00:00"},{"alias_kind":"pith_short_12","alias_value":"VR764D76JT4X","created_at":"2026-07-05T11:01:36.826120+00:00"},{"alias_kind":"pith_short_16","alias_value":"VR764D76JT4XM3ZH","created_at":"2026-07-05T11:01:36.826120+00:00"},{"alias_kind":"pith_short_8","alias_value":"VR764D76","created_at":"2026-07-05T11:01:36.826120+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.16471","citing_title":"From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI","ref_index":27,"is_internal_anchor":false},{"citing_arxiv_id":"2509.20924","citing_title":"RLCracker: Evaluating the Worst-Case Vulnerability of LLM Watermarks with Adaptive RL Attacks","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2604.11546","citing_title":"RLSpoofer: A Lightweight Evaluator for LLM Watermark Spoofing Resilience","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2604.26965","citing_title":"The Impact of AI-Generated Text on the Internet","ref_index":6,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/VR764D76JT4XM3ZHW5MAE4N2B3","json":"https://pith.science/pith/VR764D76JT4XM3ZHW5MAE4N2B3.json","graph_json":"https://pith.science/api/pith-number/VR764D76JT4XM3ZHW5MAE4N2B3/graph.json","events_json":"https://pith.science/api/pith-number/VR764D76JT4XM3ZHW5MAE4N2B3/events.json","paper":"https://pith.science/paper/VR764D76"},"agent_actions":{"view_html":"https://pith.science/pith/VR764D76JT4XM3ZHW5MAE4N2B3","download_json":"https://pith.science/pith/VR764D76JT4XM3ZHW5MAE4N2B3.json","view_paper":"https://pith.science/paper/VR764D76","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2505.05190&json=true","fetch_graph":"https://pith.science/api/pith-number/VR764D76JT4XM3ZHW5MAE4N2B3/graph.json","fetch_events":"https://pith.science/api/pith-number/VR764D76JT4XM3ZHW5MAE4N2B3/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/VR764D76JT4XM3ZHW5MAE4N2B3/action/timestamp_anchor","attest_storage":"https://pith.science/pith/VR764D76JT4XM3ZHW5MAE4N2B3/action/storage_attestation","attest_author":"https://pith.science/pith/VR764D76JT4XM3ZHW5MAE4N2B3/action/author_attestation","sign_citation":"https://pith.science/pith/VR764D76JT4XM3ZHW5MAE4N2B3/action/citation_signature","submit_replication":"https://pith.science/pith/VR764D76JT4XM3ZHW5MAE4N2B3/action/replication_record"}},"created_at":"2026-07-05T11:01:36.826120+00:00","updated_at":"2026-07-05T11:01:36.826120+00:00"}