defense arXiv Dec 22, 2025 · Dec 2025
Zhiqing Hu, Chenxu Zhao, Jiazhong Lu et al. · China Academy of Engineering Physics · National Interdisciplinary Research Center of Engineering Physics +1 more
Triple-set vocabulary watermark for LLM text achieves higher detection accuracy than binary KGW while preserving readability
Output Integrity Attack nlp
Misuse of LLM-generated text can be curbed by watermarking techniques that embed implicit signals into the output. We propose a watermark that partitions the vocabulary at each decoding step into three sets (Green/Yellow/Red) with fixed ratios and restricts sampling to the Green and Yellow sets. At detection time, we replay the same partitions, compute Green-enrichment and Red-depletion statistics, convert them to one-sided z-scores, and aggregate their p-values via Fisher's method to decide whether a passage is watermarked. We implement generation, detection, and testing on Llama 2 7B, and evaluate true-positive rate, false-positive rate, and text quality. Results show that the triple-partition scheme achieves high detection accuracy at fixed FPR while preserving readability.
llm transformer China Academy of Engineering Physics · National Interdisciplinary Research Center of Engineering Physics · Chengdu University of Information Technology