Pith. sign in

REVIEW 4 cited by

Waterfall: Framework for Robust and Scalable Text Watermarking and Provenance for LLMs

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.04411 v2 pith:ZWHWPRAP submitted 2024-07-05 cs.CR cs.AIcs.CL

classification cs.CRcs.AIcs.CL
keywords watermarkingtextwaterfallllmsrobustcodedataprovenance
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Protecting intellectual property (IP) of text such as articles and code is increasingly important, especially as sophisticated attacks become possible, such as paraphrasing by large language models (LLMs) or even unauthorized training of LLMs on copyrighted text to infringe such IP. However, existing text watermarking methods are not robust enough against such attacks nor scalable to millions of users for practical implementation. In this paper, we propose Waterfall, the first training-free framework for robust and scalable text watermarking applicable across multiple text types (e.g., articles, code) and languages supportable by LLMs, for general text and LLM data provenance. Waterfall comprises several key innovations, such as being the first to use LLM as paraphrasers for watermarking along with a novel combination of techniques that are surprisingly effective in achieving robust verifiability and scalability. We empirically demonstrate that Waterfall achieves significantly better scalability, robust verifiability, and computational efficiency compared to SOTA article-text watermarking methods, and showed how it could be directly applied to the watermarking of code. We also demonstrated that Waterfall can be used for LLM data provenance, where the watermarks of LLM training data can be detected in LLM output, allowing for detection of unauthorized use of data for LLM training and potentially enabling model-centric watermarking of open-sourced LLMs which has been a limitation of existing LLM watermarking works. Our code is available at https://github.com/aoi3142/Waterfall.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Paladin: Defending LLM-enabled Phishing Emails with a New Trigger-Tag Paradigm

    cs.CR 2025-09 conditional novelty 7.0 of 10

    A trigger-tag watermark embedded by fine-tuning lets modified LLMs mark their own phishing outputs for cheap detection.

  2. Can Watermarking Techniques Help Prevent LLM Model Stealing?

    cs.CR 2026-07 conditional novelty 6.5 of 10

    Softplus-then-perturb with embedding-seeded Gaussian noise defeats PCA/averaging/RPCA dimension-extraction attacks on Mistral-7B and GPT-2 with only modest quality loss.

  3. Robust Multi-bit Text Watermark with LLM-based Paraphrasers

    cs.AI 2024-12 conditional novelty 6.0 of 10

    A multi-bit text watermark is encoded by alternating two LLM paraphrasers per sentence, decoded by a trained classifier, and shown robust to word substitution and paraphrasing attacks.

  4. When Only the Final Text Survives: Implicit Execution Tracing for Multi-Agent Auditing

    cs.AI 2026-03 conditional novelty 5.0 of 10

    Per-agent watermark-style signals embedded during generation allow segment-level attribution and transition recovery from final text alone.

Pith tools