{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T07:44:54Z","timestamp":1781077494511,"version":"3.54.1"},"reference-count":47,"publisher":"International Association for Cryptologic Research","issue":"4","license":[{"start":{"date-parts":[[2024,10,9]],"date-time":"2024-10-09T00:00:00Z","timestamp":1728432000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IACR CiC"],"accepted":{"date-parts":[[2024,12,3]]},"abstract":"<jats:p>  We present a publicly-detectable watermarking scheme for LMs: the detection algorithm contains no secret information, and it is executable by anyone.   We embed a publicly-verifiable cryptographic signature into LM output using rejection sampling and prove that this produces unforgeable and distortion-free (i.e., undetectable without access to the public key) text output.   We make use of error-correction to overcome periods of low entropy, a barrier for all prior watermarking schemes.   We implement our scheme and find that our formal claims are met in practice. <\/jats:p>","DOI":"10.62056\/ahmpdkp10","type":"journal-article","created":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T17:00:52Z","timestamp":1736787652000},"update-policy":"https:\/\/doi.org\/10.62056\/adfjwm02dj","source":"Crossref","is-referenced-by-count":11,"title":["Publicly-Detectable Watermarking for Language Models"],"prefix":"10.62056","volume":"1","author":[{"given":"Jaiden","family":"Fairoze","sequence":"first","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01an7q238","id-type":"ROR","asserted-by":"publisher"}],"name":"University of California, Berkeley","place":["USA"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1330-0419","authenticated-orcid":false,"given":"Sanjam","family":"Garg","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01an7q238","id-type":"ROR","asserted-by":"publisher"}],"name":"University of California, Berkeley","place":["USA"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Somesh","family":"Jha","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01y2jtd41","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Wisconsin\u2013Madison","place":["USA"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6586-8378","authenticated-orcid":false,"given":"Saeed","family":"Mahloujifar","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/01zbnvs85","id-type":"ROR","asserted-by":"publisher"}],"name":"Fundamental Artificial Intelligence Research at Meta","place":["USA"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6839-4697","authenticated-orcid":false,"given":"Mohammad","family":"Mahmoody","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/0153tk833","id-type":"ROR","asserted-by":"publisher"}],"name":"University of Virginia","place":["USA"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-9057-1007","authenticated-orcid":false,"given":"Mingyuan","family":"Wang","sequence":"additional","affiliation":[{"id":[{"id":"https:\/\/ror.org\/02vpsdb40","id-type":"ROR","asserted-by":"publisher"}],"name":"New York University Shanghai","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"48349","published-online":{"date-parts":[[2025,1,13]]},"reference":[{"key":"ref1:guo2022don","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2022.i3.223-263","article-title":"Don\u2019t reject this: Key-recovery timing attacks due to\n  rejection-sampling in HQC and BIKE","author":"Qian Guo","year":"2022","journal-title":"IACR Transactions on Cryptographic Hardware and Embedded\n  Systems"},{"key":"ref2:paszke2019pytorch","article-title":"PyTorch: An imperative style, high-performance deep\n  learning library","author":"Adam Paszke","year":"2019","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref3:piet2023mark","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2312.00273","article-title":"Mark my words: Analyzing and evaluating language model\n  watermarks","author":"Julien Piet","year":"2023","journal-title":"arXiv preprint arXiv:2312.00273"},{"key":"ref4:sadasivan2023can","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2303.11156","article-title":"Can AI-generated text be reliably detected?","author":"Vinu Sankar Sadasivan","year":"2023","journal-title":"arXiv preprint arXiv:2303.11156"},{"key":"ref5:yoo2023robust","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2305.01904","article-title":"Robust natural language watermarking through invariant\n  features","author":"KiYoon Yoo","year":"2023","journal-title":"arXiv preprint arXiv:2305.01904"},{"key":"ref6:jiang2023mistral","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2310.06825","article-title":"Mistral 7B","author":"Albert Q Jiang","year":"2023","journal-title":"arXiv preprint arXiv:2310.06825"},{"key":"ref7:hopper2002provably","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45708-9_6","article-title":"Provably secure steganography","author":"Nicholas J Hopper","year":"2002"},{"key":"ref8:gehrmann2019gltr","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1906.04043","article-title":"GLTR: Statistical detection and visualization of generated\n  text","author":"Sebastian Gehrmann","year":"2019","journal-title":"arXiv preprint arXiv:1906.04043"},{"key":"ref9:raffel2020exploring","article-title":"Exploring the limits of transfer learning with a unified\n  text-to-text transformer","author":"Colin Raffel","year":"2020","journal-title":"The Journal of Machine Learning Research"},{"key":"ref10:touvron2023llama","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2307.09288","article-title":"Llama 2: Open foundation and fine-tuned chat models","author":"Hugo Touvron","year":"2023","journal-title":"arXiv preprint arXiv:2307.09288"},{"key":"ref11:liu2023private","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2307.16230","article-title":"A private watermark for large language models","author":"Aiwei Liu","year":"2023","journal-title":"arXiv preprint arXiv:2307.16230"},{"key":"ref12:gemini","volume-title":"Our next-generation model: Gemini 1.5","author":"Google DeepMind","year":"2024"},{"key":"ref13:gptzero","volume-title":"GPTZero | The Trusted AI Detector for ChatGPT, GPT-4, &\n  More","author":"GPTZero","year":"2023"},{"key":"ref14:guruswami2017deletion","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2017.2659765","article-title":"Deletion codes in the high-noise and high-rate regimes","author":"Venkatesan Guruswami","year":"2017","journal-title":"IEEE Transactions on Information Theory"},{"key":"ref15:abdelnabi2021adversarial","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00083","article-title":"Adversarial watermarking transformer: Towards tracing text\n  provenance with data hiding","author":"Sahar Abdelnabi","year":"2021"},{"key":"ref16:openaidetector","volume-title":"New AI classifier for indicating AI-written text","author":"Jan Hendrik Kirchner","year":"2023"},{"key":"ref17:kaptchuk2021meteor","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484550","article-title":"Meteor: Cryptographically secure steganography for\n  realistic distributions","author":"Gabriel Kaptchuk","year":"2021"},{"key":"ref18:holtzman2019curious","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1904.09751","article-title":"The curious case of neural text degeneration","author":"Ari Holtzman","year":"2019","journal-title":"arXiv preprint arXiv:1904.09751"},{"key":"ref19:qiang2023natural","doi-asserted-by":"publisher","DOI":"10.1016\/j.artint.2023.103859","article-title":"Natural language watermarking via paraphraser-based lexical\n  substitution","author":"Jipeng Qiang","year":"2023","journal-title":"Artificial Intelligence"},{"key":"ref20:cachin1998information","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-49380-8_21","article-title":"An information-theoretic model for steganography","author":"Christian Cachin","year":"1998"},{"key":"ref21:mitchell2023detectgpt","article-title":"DetectGPT: zero-shot machine-generated text detection using\n  probability curvature","author":"Eric Mitchell","year":"2023","journal-title":"Proceedings of the 40th International Conference on Machine\n  Learning"},{"key":"ref22:munyer2023deeptextmark","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3376693","article-title":"DeepTextMark: A Deep learning-driven text watermarking\n  approach for identifying large language model generated text","author":"Travis Munyer","year":"2024","journal-title":"IEEE Access"},{"key":"ref23:kirchenbauer2023watermark","article-title":"A watermark for large language models","author":"John Kirchenbauer","year":"2023"},{"key":"ref24:welleck2019neural","article-title":"Neural text generation with unlikelihood training","author":"Sean Welleck","year":"2019"},{"key":"ref25:chen2023exploring","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2304.00723","article-title":"Exploring the use of large language models for\n  reference-free text quality evaluation: A preliminary empirical study","author":"Yi Chen","year":"2023","journal-title":"arXiv preprint arXiv:2304.00723"},{"key":"ref26:christ2024undetectable","article-title":"Undetectable Watermarks for Language Models","author":"Miranda Christ","year":"2024"},{"key":"ref27:rombach2022high","article-title":"High-resolution image synthesis with latent diffusion\n  models","author":"Robin Rombach","year":"2022"},{"key":"ref28:zhang2022opt","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2205.01068","article-title":"Opt: Open pre-trained transformer language models","author":"Susan Zhang","year":"2022","journal-title":"arXiv preprint arXiv:2205.01068"},{"key":"ref29:zhang2024watermarks","article-title":"Watermarks in the sand: Impossibility of strong\n  watermarking for language models","author":"Hanlin Zhang","year":"2024"},{"key":"ref30:neurocryptography","volume-title":"Neurocryptography","author":"Scott Aaronson","year":"2023"},{"key":"ref31:kuditipudi2024robust","article-title":"Robust distortion-free watermarks for language models","author":"Rohith Kuditipudi","year":"2024","journal-title":"Transactions on Machine Learning Research"},{"key":"ref32:openai2023gpt4","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2303.08774","article-title":"GPT-4 technical report","author":"OpenAI","year":"2023","journal-title":"arXiv preprint arXiv:2303.08774"},{"key":"ref33:boneh2001short","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45682-1_30","article-title":"Short signatures from the Weil pairing","author":"Dan Boneh","year":"2001"},{"key":"ref34:wong2001secret","doi-asserted-by":"publisher","DOI":"10.1109\/83.951543","article-title":"Secret and public key image watermarking schemes for image\n  authentication and ownership verification","author":"Ping Wah Wong","year":"2001","journal-title":"IEEE transactions on image processing"},{"key":"ref35:qu2024provably","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2401.16820","article-title":"Provably robust multi-bit watermarking for AI-generated\n  text via error correction code","author":"Wenjie Qu","year":"2024","journal-title":"arXiv preprint arXiv:2401.16820"},{"key":"ref36:lavergne2008detecting","article-title":"Detecting fake content with relative entropy scoring","author":"Thomas Lavergne","year":"2008","journal-title":"Proceedings of the 2008 International Conference on\n  Uncovering Plagiarism, Authorship and Social Software Misuse"},{"key":"ref37:hft","volume-title":"Hugging Face Transformers","author":"Hugging Face","year":"2023"},{"key":"ref38:sun2005secure","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2005.846776","article-title":"A secure and robust digital signature scheme for JPEG2000\n  image authentication","author":"Qibin Sun","year":"2005","journal-title":"IEEE Transactions on Multimedia"},{"key":"ref39:chakraborty2023possibilities","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2304.04736","article-title":"On the possibilities of AI-generated text detection","author":"Souradip Chakraborty","year":"2023","journal-title":"arXiv preprint arXiv:2304.04736"},{"key":"ref40:krishna2023paraphrasing","article-title":"Paraphrasing evades detectors of AI-generated text, but\n  retrieval is an effective defense","volume":"36","author":"Kalpesh Krishna","year":"2023","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref41:hoeffding","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4612-0865-5_26","article-title":"Probability inequalities for sums of bounded random\n  variables","author":"Wassily Hoeffding","year":"1994","journal-title":"The Collected Works of Wassily Hoeffding"},{"key":"ref42:beresneva2016computer","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-41754-7_43","article-title":"Computer-generated text detection using machine learning: A\n  systematic review","author":"Daria Beresneva","year":"2016"},{"key":"ref43:zellers2019defending","article-title":"Defending against neural fake news","author":"Rowan Zellers","year":"2019","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref44:zheng2021rejection","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/9948618","article-title":"Rejection sampling revisit: how to choose parameters in\n  lattice-based signature","author":"Zhongxiang Zheng","year":"2021","journal-title":"Mathematical Problems in Engineering"},{"key":"ref45:bellare1993random","doi-asserted-by":"publisher","DOI":"10.1145\/168588.168596","article-title":"Random oracles are practical: A paradigm for designing\n  efficient protocols","author":"Mihir Bellare","year":"1993"},{"key":"ref46:golowich2024edit","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2406.02633","article-title":"Edit distance robust watermarks for language models","author":"Noah Golowich","year":"2024","journal-title":"arXiv preprint arXiv:2406.02633"},{"key":"ref47:jawahar2020automatic","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2011.01314","article-title":"Automatic detection of machine generated text: A critical\n  survey","author":"Ganesh Jawahar","year":"2020","journal-title":"arXiv preprint arXiv:2011.01314"}],"container-title":["IACR Communications in Cryptology"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T17:12:23Z","timestamp":1736788343000},"score":1,"resource":{"primary":{"URL":"https:\/\/cic.iacr.org\/p\/1\/4\/31"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,13]]},"references-count":47,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,1,13]]}},"URL":"https:\/\/doi.org\/10.62056\/ahmpdkp10","archive":["Internet Archive","Internet Archive"],"relation":{},"ISSN":["3006-5496"],"issn-type":[{"value":"3006-5496","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,13]]},"assertion":[{"value":"2024-10-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-03","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"cc1-4-65"}}