TextSeal: A Localized LLM Watermark for Provenance & Distillation Protection

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Sander, Tom, Chang, Hongyan, Souček, Tomáš, Tran, Tuan, Lacatusu, Valeriu, Rebuffi, Sylvestre-Alvise, Mourachko, Alexandre, Parimi, Surya, Ropers, Christophe, Moritz, Rashel, Stark, Vanessa, Elsahar, Hady, Fernandez, Pierre
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917518837284864
author Sander, Tom
Chang, Hongyan
Souček, Tomáš
Tran, Tuan
Lacatusu, Valeriu
Rebuffi, Sylvestre-Alvise
Mourachko, Alexandre
Parimi, Surya
Ropers, Christophe
Moritz, Rashel
Stark, Vanessa
Elsahar, Hady
Fernandez, Pierre
author_facet Sander, Tom
Chang, Hongyan
Souček, Tomáš
Tran, Tuan
Lacatusu, Valeriu
Rebuffi, Sylvestre-Alvise
Mourachko, Alexandre
Parimi, Surya
Ropers, Christophe
Moritz, Rashel
Stark, Vanessa
Elsahar, Hady
Fernandez, Pierre
contents We introduce TextSeal, a state-of-the-art watermark for large language models. Building on Gumbel-max sampling, TextSeal introduces dual-key generation to restore output diversity, along with entropy-weighted scoring and multi-region localization for improved detection. It supports serving optimizations such as speculative decoding and multi-token prediction, and does not add any inference overhead. TextSeal strictly dominates baselines like SynthID-text in detection strength and is robust to dilution, maintaining confident localized detection even in heavily mixed human/AI documents. The scheme is theoretically distortion-free, and evaluation across reasoning benchmarks confirms that it preserves downstream performance; while a multilingual human evaluation (6000 A/B comparisons, 5 languages) shows no perceptible quality difference. Beyond its use for provenance detection, TextSeal is also ``radioactive'': its watermark signal transfers through model distillation, enabling detection of unauthorized use.
format Preprint
id arxiv_https___arxiv_org_abs_2605_12456
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle TextSeal: A Localized LLM Watermark for Provenance & Distillation Protection
Sander, Tom
Chang, Hongyan
Souček, Tomáš
Tran, Tuan
Lacatusu, Valeriu
Rebuffi, Sylvestre-Alvise
Mourachko, Alexandre
Parimi, Surya
Ropers, Christophe
Moritz, Rashel
Stark, Vanessa
Elsahar, Hady
Fernandez, Pierre
Cryptography and Security
Computation and Language
Machine Learning
We introduce TextSeal, a state-of-the-art watermark for large language models. Building on Gumbel-max sampling, TextSeal introduces dual-key generation to restore output diversity, along with entropy-weighted scoring and multi-region localization for improved detection. It supports serving optimizations such as speculative decoding and multi-token prediction, and does not add any inference overhead. TextSeal strictly dominates baselines like SynthID-text in detection strength and is robust to dilution, maintaining confident localized detection even in heavily mixed human/AI documents. The scheme is theoretically distortion-free, and evaluation across reasoning benchmarks confirms that it preserves downstream performance; while a multilingual human evaluation (6000 A/B comparisons, 5 languages) shows no perceptible quality difference. Beyond its use for provenance detection, TextSeal is also ``radioactive'': its watermark signal transfers through model distillation, enabling detection of unauthorized use.
title TextSeal: A Localized LLM Watermark for Provenance & Distillation Protection
topic Cryptography and Security
Computation and Language
Machine Learning
url https://arxiv.org/abs/2605.12456