PMark: Towards Robust and Distortion-free Semantic-level Watermarking with Channel Constraints

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Huo, Jiahao, Liu, Shuliang, Wang, Bin, Zhang, Junyan, Yan, Yibo, Liu, Aiwei, Hu, Xuming, Zhou, Mingxun
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914362737819648
author Huo, Jiahao
Liu, Shuliang
Wang, Bin
Zhang, Junyan
Yan, Yibo
Liu, Aiwei
Hu, Xuming
Zhou, Mingxun
author_facet Huo, Jiahao
Liu, Shuliang
Wang, Bin
Zhang, Junyan
Yan, Yibo
Liu, Aiwei
Hu, Xuming
Zhou, Mingxun
contents Semantic-level watermarking (SWM) for large language models (LLMs) enhances watermarking robustness against text modifications and paraphrasing attacks by treating the sentence as the fundamental unit. However, existing methods still lack strong theoretical guarantees of robustness, and reject-sampling-based generation often introduces significant distribution distortions compared with unwatermarked outputs. In this work, we introduce a new theoretical framework on SWM through the concept of proxy functions (PFs) $\unicode{x2013}$ functions that map sentences to scalar values. Building on this framework, we propose PMark, a simple yet powerful SWM method that estimates the PF median for the next sentence dynamically through sampling while enforcing multiple PF constraints (which we call channels) to strengthen watermark evidence. Equipped with solid theoretical guarantees, PMark achieves the desired distortion-free property and improves the robustness against paraphrasing-style attacks. We also provide an empirically optimized version that further removes the requirement for dynamical median estimation for better sampling efficiency. Experimental results show that PMark consistently outperforms existing SWM baselines in both text quality and robustness, offering a more effective paradigm for detecting machine-generated text. Our code will be released at [this URL](https://github.com/PMark-repo/PMark).
format Preprint
id arxiv_https___arxiv_org_abs_2509_21057
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle PMark: Towards Robust and Distortion-free Semantic-level Watermarking with Channel Constraints
Huo, Jiahao
Liu, Shuliang
Wang, Bin
Zhang, Junyan
Yan, Yibo
Liu, Aiwei
Hu, Xuming
Zhou, Mingxun
Cryptography and Security
Computation and Language
Semantic-level watermarking (SWM) for large language models (LLMs) enhances watermarking robustness against text modifications and paraphrasing attacks by treating the sentence as the fundamental unit. However, existing methods still lack strong theoretical guarantees of robustness, and reject-sampling-based generation often introduces significant distribution distortions compared with unwatermarked outputs. In this work, we introduce a new theoretical framework on SWM through the concept of proxy functions (PFs) $\unicode{x2013}$ functions that map sentences to scalar values. Building on this framework, we propose PMark, a simple yet powerful SWM method that estimates the PF median for the next sentence dynamically through sampling while enforcing multiple PF constraints (which we call channels) to strengthen watermark evidence. Equipped with solid theoretical guarantees, PMark achieves the desired distortion-free property and improves the robustness against paraphrasing-style attacks. We also provide an empirically optimized version that further removes the requirement for dynamical median estimation for better sampling efficiency. Experimental results show that PMark consistently outperforms existing SWM baselines in both text quality and robustness, offering a more effective paradigm for detecting machine-generated text. Our code will be released at [this URL](https://github.com/PMark-repo/PMark).
title PMark: Towards Robust and Distortion-free Semantic-level Watermarking with Channel Constraints
topic Cryptography and Security
Computation and Language
url https://arxiv.org/abs/2509.21057