{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:06:52Z","timestamp":1784300812687,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,7,5]],"date-time":"2026-07-05T00:00:00Z","timestamp":1783209600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,7,5]]},"DOI":"10.1145\/3803437.3805553","type":"proceedings-article","created":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:27:39Z","timestamp":1784298459000},"page":"1187-1191","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["The Watermark Paradox: How Provenance Verification Paves the Road to Camouflaged Backdoors"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-3693-786X","authenticated-orcid":false,"given":"Haoyi","family":"Zhang","sequence":"first","affiliation":[{"name":"Xi\u2019an Jiaotong-Liverpool University, SuZhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-2482-2344","authenticated-orcid":false,"given":"Huaijin","family":"Ran","sequence":"additional","affiliation":[{"name":"Xi'an Jiaotong-Liverpool University, SuZhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4462-6916","authenticated-orcid":false,"given":"Kisub","family":"Kim","sequence":"additional","affiliation":[{"name":"Daegu Gyeongbuk Institute of Science and Technology, Daegu, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6377-0884","authenticated-orcid":false,"given":"Xunzhu","family":"Tang","sequence":"additional","affiliation":[{"name":"University of Luxembourg, Luxembourg, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,17]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00140"},{"key":"e_1_3_2_1_2_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Azizi Ahmadreza","year":"2021","unstructured":"Ahmadreza Azizi, Ibrahim Asadullah Tahmid, Asim Waheed, Neal Mangaokar, Jiameng Pu, Mobin Javed, Chandan K Reddy, and Bimal Viswanath. 2021. {T-Miner}: A generative approach to defend against trojan attacks on {DNN-based} text classification. In 30th USENIX Security Symposium (USENIX Security 21). 2255\u20132272."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3586030"},{"key":"e_1_3_2_1_4_1","volume-title":"The Thirty Seventh Annual Conference on Learning Theory. PMLR, 1125\u20131139","author":"Christ Miranda","year":"2024","unstructured":"Miranda Christ, Sam Gunn, and Or Zamir. 2024. Undetectable watermarks for language models. In The Thirty Seventh Annual Conference on Learning Theory. PMLR, 1125\u20131139."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-024-08025-4"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616243"},{"key":"e_1_3_2_1_7_1","volume-title":"12th USENIX Symposium on Operating Systems Design and Implementation (OSDI 16)","author":"Gu Ronghui","year":"2016","unstructured":"Ronghui Gu, Zhong Shao, Hao Chen, Xiongnan Newman Wu, Jieung Kim, Vilhelm Sj\u00f6berg, and David Costanzo. 2016. {CertiKOS}: An extensible architecture for building certified concurrent {OS} kernels. In 12th USENIX Symposium on Operating Systems Design and Implementation (OSDI 16). 653\u2013669."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0608"},{"key":"e_1_3_2_1_9_1","volume-title":"International Conference on Machine Learning. PMLR, 17061\u201317084","author":"Kirchenbauer John","year":"2023","unstructured":"John Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz, Ian Miers, and Tom Goldstein. 2023. A watermark for large language models. In International Conference on Machine Learning. PMLR, 17061\u201317084."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1629575.1629596"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1195"},{"key":"e_1_3_2_1_12_1","volume-title":"Robust distortion-free watermarks for language models. arXiv preprint arXiv:2307.15593","author":"Kuditipudi Rohith","year":"2023","unstructured":"Rohith Kuditipudi, John Thickstun, Tatsunori Hashimoto, and Percy Liang. 2023. Robust distortion-free watermarks for language models. arXiv preprint arXiv:2307.15593 (2023)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.268"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1538788.1538814"},{"key":"e_1_3_2_1_15_1","volume-title":"Back-doorllm: A comprehensive benchmark for backdoor attacks on large language models. arXiv e-prints","author":"Li Yige","year":"2024","unstructured":"Yige Li, Hanxun Huang, Yunhan Zhao, Xingjun Ma, and Jun Sun. 2024. Back-doorllm: A comprehensive benchmark for backdoor attacks on large language models. arXiv e-prints (2024), arXiv-2408."},{"key":"e_1_3_2_1_16_1","volume-title":"A semantic invariant robust watermark for large language models. arXiv preprint arXiv:2310.06356","author":"Liu Aiwei","year":"2023","unstructured":"Aiwei Liu, Leyi Pan, Xuming Hu, Shiao Meng, and Lijie Wen. 2023. A semantic invariant robust watermark for large language models. arXiv preprint arXiv:2310.06356 (2023)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833579"},{"key":"e_1_3_2_1_18_1","volume-title":"Markllm: An open-source toolkit for llm watermarking. arXiv preprint arXiv:2405.10051","author":"Pan Leyi","year":"2024","unstructured":"Leyi Pan, Aiwei Liu, Zhiwei He, Zitian Gao, Xuandong Zhao, Yijian Lu, Binglin Zhou, Shuliang Liu, Xuming Hu, Lijie Wen, et al. 2024. Markllm: An open-source toolkit for llm watermarking. arXiv preprint arXiv:2405.10051 (2024)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2021.3051235"},{"key":"e_1_3_2_1_20_1","volume-title":"The impact of ai on developer productivity: Evidence from github copilot. arXiv preprint arXiv:2302.06590","author":"Peng Sida","year":"2023","unstructured":"Sida Peng, Eirini Kalliamvakou, Peter Cihon, and Mert Demirer. 2023. The impact of ai on developer productivity: Evidence from github copilot. arXiv preprint arXiv:2302.06590 (2023)."},{"key":"e_1_3_2_1_21_1","volume-title":"Kunhao Zheng, Mantas Baksys, Igor Babuschkin, and Ilya Sutskever.","author":"Polu Stanislas","year":"2022","unstructured":"Stanislas Polu, Jesse Michael Han, Kunhao Zheng, Mantas Baksys, Igor Babuschkin, and Ilya Sutskever. 2022. Formal mathematics statement curriculum learning. arXiv preprint arXiv:2202.01344 (2022)."},{"key":"e_1_3_2_1_22_1","volume-title":"Hidden killer: Invisible textual backdoor attacks with syntactic trigger. arXiv preprint arXiv:2105.12400","author":"Qi Fanchao","year":"2021","unstructured":"Fanchao Qi, Mukai Li, Yangyi Chen, Zhengyan Zhang, Zhiyuan Liu, Yasheng Wang, and Maosong Sun. 2021. Hidden killer: Invisible textual backdoor attacks with syntactic trigger. arXiv preprint arXiv:2105.12400 (2021)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1561\/2500000045"},{"key":"e_1_3_2_1_24_1","volume-title":"Can AI-generated text be reliably detected? arXiv preprint arXiv:2303.11156","author":"Sadasivan Vinu Sankar","year":"2023","unstructured":"Vinu Sankar Sadasivan, Aounon Kumar, Sriram Balasubramanian, Wenxiao Wang, and Soheil Feizi. 2023. Can AI-generated text be reliably detected? arXiv preprint arXiv:2303.11156 (2023)."},{"key":"e_1_3_2_1_25_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Schuster Roei","year":"2021","unstructured":"Roei Schuster, Congzheng Song, Eran Tromer, and Vitaly Shmatikov. 2021. You autocomplete me: Poisoning vulnerabilities in neural code completion. In 30th USENIX Security Symposium (USENIX Security 21). 1559\u20131575."},{"key":"e_1_3_2_1_26_1","volume-title":"Backdooring neural code search. arXiv preprint arXiv:2305.17506","author":"Sun Weisong","year":"2023","unstructured":"Weisong Sun, Yuchen Chen, Guanhong Tao, Chunrong Fang, Xiangyu Zhang, Quanjun Zhang, and Bin Luo. 2023. Backdooring neural code search. arXiv preprint arXiv:2305.17506 (2023)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3617555.3617874"},{"key":"e_1_3_2_1_28_1","volume-title":"Solving olympiad geometry without human demonstrations. Nature 625, 7995","author":"Trinh Trieu H","year":"2024","unstructured":"Trieu H Trinh, Yuhuai Wu, Quoc V Le, He He, and Thang Luong. 2024. Solving olympiad geometry without human demonstrations. Nature 625, 7995 (2024), 476\u2013482."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3491101.3519665"},{"key":"e_1_3_2_1_30_1","volume-title":"Can large language models write good property-based tests? arXiv preprint arXiv:2307.04346","author":"Vikram Vasudev","year":"2023","unstructured":"Vasudev Vikram, Caroline Lemieux, Joshua Sunshine, and Rohan Padhye. 2023. Can large language models write good property-based tests? arXiv preprint arXiv:2307.04346 (2023)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_1_32_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Yan Shenao","year":"2024","unstructured":"Shenao Yan, Shen Wang, Yue Duan, Hanbin Hong, Kiho Lee, Doowon Kim, and Yuan Hong. 2024. An {LLM-Assisted} {Easy-to-Trigger} backdoor attack on code completion models: Injecting disguised vulnerabilities against strong detection. In 33rd USENIX Security Symposium (USENIX Security 24). 1795\u20131812."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00097"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.52202\/075280-0944"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00022"},{"key":"e_1_3_2_1_36_1","volume-title":"Provable robust watermarking for ai-generated text. arXiv preprint arXiv:2306.17439","author":"Zhao Xuandong","year":"2023","unstructured":"Xuandong Zhao, Prabhanjan Ananth, Lei Li, and Yu-Xiang Wang. 2023. Provable robust watermarking for ai-generated text. arXiv preprint arXiv:2306.17439 (2023)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3520312.3534864"}],"event":{"name":"FSE Companion '26: 34th ACM International Conference on the Foundations of Software Engineering","location":"Concordia University Montreal QC Canada","acronym":"FSE Companion '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3803437.3805553","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:34:08Z","timestamp":1784298848000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3803437.3805553"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,5]]},"references-count":37,"alternative-id":["10.1145\/3803437.3805553","10.1145\/3803437"],"URL":"https:\/\/doi.org\/10.1145\/3803437.3805553","relation":{},"subject":[],"published":{"date-parts":[[2026,7,5]]},"assertion":[{"value":"2026-07-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}