{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:DFFDPXFGOASEVTJZSJHGVGAQGL","short_pith_number":"pith:DFFDPXFG","canonical_record":{"source":{"id":"2605.10977","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-09T01:09:01Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"ccdbdffbb36eadba48815173fbbdbefd11570f03737c0682011893e1b174a67c","abstract_canon_sha256":"8cc47a1f256314c7b70fb1acd61c517e15e81c26ddae61860ad20dd18e808e3a"},"schema_version":"1.0"},"canonical_sha256":"194a37dca670244acd39924e6a981032d378674f0d504e758d033e93b8e4b648","source":{"kind":"arxiv","id":"2605.10977","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.10977","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"arxiv_version","alias_value":"2605.10977v2","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.10977","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"pith_short_12","alias_value":"DFFDPXFGOASE","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"pith_short_16","alias_value":"DFFDPXFGOASEVTJZ","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"pith_short_8","alias_value":"DFFDPXFG","created_at":"2026-05-26T01:02:35Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:DFFDPXFGOASEVTJZSJHGVGAQGL","target":"record","payload":{"canonical_record":{"source":{"id":"2605.10977","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-09T01:09:01Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"ccdbdffbb36eadba48815173fbbdbefd11570f03737c0682011893e1b174a67c","abstract_canon_sha256":"8cc47a1f256314c7b70fb1acd61c517e15e81c26ddae61860ad20dd18e808e3a"},"schema_version":"1.0"},"canonical_sha256":"194a37dca670244acd39924e6a981032d378674f0d504e758d033e93b8e4b648","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T01:02:35.567255Z","signature_b64":"lkBvESZ7wRXLRExKy+p1defGHtsmRk3sai4hlWp/VpxU5pccDAfDW+2qsWz0bKP2PWsg7qjEI3sOR5b//t6XDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"194a37dca670244acd39924e6a981032d378674f0d504e758d033e93b8e4b648","last_reissued_at":"2026-05-26T01:02:35.566440Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T01:02:35.566440Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.10977","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T01:02:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Alk6p6mS5Eryz5JxuyxicLk9DsSPqdsVpc/sBeQvZ6Sxm/cWnuODROqCtmHoltINv+ZJlnJhxs8L35PNR0tKCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T05:59:57.095589Z"},"content_sha256":"f85a42261309d6e5e475d73aadd3158a0c33526373f91770f29967a16c2f08ea","schema_version":"1.0","event_id":"sha256:f85a42261309d6e5e475d73aadd3158a0c33526373f91770f29967a16c2f08ea"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:DFFDPXFGOASEVTJZSJHGVGAQGL","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"PASA: A Principled Embedding-Space Watermarking Approach for LLM-Generated Text under Semantic-Invariant Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"PASA embeds watermarks in LLM semantic embedding space to detect generated text after paraphrasing without distorting output.","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Haiyun He, Zhenxin Ai","submitted_at":"2026-05-09T01:09:01Z","abstract_excerpt":"Watermarking for large language models (LLMs) is a promising approach for detecting LLM-generated text and enabling responsible deployment. However, existing watermarking methods are often vulnerable to semantic-invariant attacks, such as paraphrasing. We propose PASA, a principled, robust, and distortion-free watermarking algorithm that embeds and detects a watermark at the semantic level. PASA operates on semantic clusters in a latent embedding space and constructs a distributional dependency between token and auxiliary sequences via shared randomness synchronized by a secret key and semanti"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"PASA remains robust even under strong paraphrasing attacks while preserving high text quality, outperforming standard vocabulary-space baselines.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The assumption that semantic clusters in the latent embedding space can be constructed reliably and that the distributional dependency created by shared randomness synchronized via secret key and semantic history yields the claimed joint optimality and robustness without hidden vulnerabilities or detectable artifacts.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"PASA is a semantic-level watermarking method for LLM text that uses embedding-space clusters and synchronized randomness to remain detectable after paraphrasing while preserving text quality.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"PASA embeds watermarks in LLM semantic embedding space to detect generated text after paraphrasing without distorting output.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"52ddba5365c15ef1021df3a37fcebd8bc0cb93bb7f29ecb373200827f4bf258f"},"source":{"id":"2605.10977","kind":"arxiv","version":2},"verdict":{"id":"4b46ebf2-42a0-47a7-8891-637658859697","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-13T01:09:25.478980Z","strongest_claim":"PASA remains robust even under strong paraphrasing attacks while preserving high text quality, outperforming standard vocabulary-space baselines.","one_line_summary":"PASA is a semantic-level watermarking method for LLM text that uses embedding-space clusters and synchronized randomness to remain detectable after paraphrasing while preserving text quality.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The assumption that semantic clusters in the latent embedding space can be constructed reliably and that the distributional dependency created by shared randomness synchronized via secret key and semantic history yields the claimed joint optimality and robustness without hidden vulnerabilities or detectable artifacts.","pith_extraction_headline":"PASA embeds watermarks in LLM semantic embedding space to detect generated text after paraphrasing without distorting output."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.10977/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"claim_evidence","ran_at":"2026-05-20T09:22:01.956584Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"ai_meta_artifact","ran_at":"2026-05-19T22:38:15.074045Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_title_agreement","ran_at":"2026-05-19T14:31:18.255902Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_compliance","ran_at":"2026-05-19T10:59:30.061381Z","status":"completed","version":"1.0.0","findings_count":0}],"snapshot_sha256":"d87a0299ea6b9e19b7bead0d94c8b71d8271b2b0d798836fac42f7d53a44d777"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"4b46ebf2-42a0-47a7-8891-637658859697"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T01:02:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8DVb3o/JHgcm6AmMWUe5m4MiToeddRO2luIpZmv4LVOhjv/KWQWKNyfxWt5bOj8O5fV5YgcgcU5BQZR8v6+9Dw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T05:59:57.096187Z"},"content_sha256":"82bd35e74a51d8d1721d72bec63b34ab1bc90a2fc184f22bae55fed1466728be","schema_version":"1.0","event_id":"sha256:82bd35e74a51d8d1721d72bec63b34ab1bc90a2fc184f22bae55fed1466728be"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/DFFDPXFGOASEVTJZSJHGVGAQGL/bundle.json","state_url":"https://pith.science/pith/DFFDPXFGOASEVTJZSJHGVGAQGL/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/DFFDPXFGOASEVTJZSJHGVGAQGL/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-06T05:59:57Z","links":{"resolver":"https://pith.science/pith/DFFDPXFGOASEVTJZSJHGVGAQGL","bundle":"https://pith.science/pith/DFFDPXFGOASEVTJZSJHGVGAQGL/bundle.json","state":"https://pith.science/pith/DFFDPXFGOASEVTJZSJHGVGAQGL/state.json","well_known_bundle":"https://pith.science/.well-known/pith/DFFDPXFGOASEVTJZSJHGVGAQGL/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:DFFDPXFGOASEVTJZSJHGVGAQGL","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8cc47a1f256314c7b70fb1acd61c517e15e81c26ddae61860ad20dd18e808e3a","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-09T01:09:01Z","title_canon_sha256":"ccdbdffbb36eadba48815173fbbdbefd11570f03737c0682011893e1b174a67c"},"schema_version":"1.0","source":{"id":"2605.10977","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.10977","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"arxiv_version","alias_value":"2605.10977v2","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.10977","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"pith_short_12","alias_value":"DFFDPXFGOASE","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"pith_short_16","alias_value":"DFFDPXFGOASEVTJZ","created_at":"2026-05-26T01:02:35Z"},{"alias_kind":"pith_short_8","alias_value":"DFFDPXFG","created_at":"2026-05-26T01:02:35Z"}],"graph_snapshots":[{"event_id":"sha256:82bd35e74a51d8d1721d72bec63b34ab1bc90a2fc184f22bae55fed1466728be","target":"graph","created_at":"2026-05-26T01:02:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"PASA remains robust even under strong paraphrasing attacks while preserving high text quality, outperforming standard vocabulary-space baselines."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The assumption that semantic clusters in the latent embedding space can be constructed reliably and that the distributional dependency created by shared randomness synchronized via secret key and semantic history yields the claimed joint optimality and robustness without hidden vulnerabilities or detectable artifacts."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"PASA is a semantic-level watermarking method for LLM text that uses embedding-space clusters and synchronized randomness to remain detectable after paraphrasing while preserving text quality."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"PASA embeds watermarks in LLM semantic embedding space to detect generated text after paraphrasing without distorting output."}],"snapshot_sha256":"52ddba5365c15ef1021df3a37fcebd8bc0cb93bb7f29ecb373200827f4bf258f"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-20T09:22:01.956584Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-19T22:38:15.074045Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_title_agreement","ran_at":"2026-05-19T14:31:18.255902Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_compliance","ran_at":"2026-05-19T10:59:30.061381Z","status":"completed","version":"1.0.0"}],"endpoint":"/pith/2605.10977/integrity.json","findings":[],"snapshot_sha256":"d87a0299ea6b9e19b7bead0d94c8b71d8271b2b0d798836fac42f7d53a44d777","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Watermarking for large language models (LLMs) is a promising approach for detecting LLM-generated text and enabling responsible deployment. However, existing watermarking methods are often vulnerable to semantic-invariant attacks, such as paraphrasing. We propose PASA, a principled, robust, and distortion-free watermarking algorithm that embeds and detects a watermark at the semantic level. PASA operates on semantic clusters in a latent embedding space and constructs a distributional dependency between token and auxiliary sequences via shared randomness synchronized by a secret key and semanti","authors_text":"Haiyun He, Zhenxin Ai","cross_cats":["cs.AI"],"headline":"PASA embeds watermarks in LLM semantic embedding space to detect generated text after paraphrasing without distorting output.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-09T01:09:01Z","title":"PASA: A Principled Embedding-Space Watermarking Approach for LLM-Generated Text under Semantic-Invariant Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.10977","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-13T01:09:25.478980Z","id":"4b46ebf2-42a0-47a7-8891-637658859697","model_set":{"reader":"grok-4.3"},"one_line_summary":"PASA is a semantic-level watermarking method for LLM text that uses embedding-space clusters and synchronized randomness to remain detectable after paraphrasing while preserving text quality.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"PASA embeds watermarks in LLM semantic embedding space to detect generated text after paraphrasing without distorting output.","strongest_claim":"PASA remains robust even under strong paraphrasing attacks while preserving high text quality, outperforming standard vocabulary-space baselines.","weakest_assumption":"The assumption that semantic clusters in the latent embedding space can be constructed reliably and that the distributional dependency created by shared randomness synchronized via secret key and semantic history yields the claimed joint optimality and robustness without hidden vulnerabilities or detectable artifacts."}},"verdict_id":"4b46ebf2-42a0-47a7-8891-637658859697"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f85a42261309d6e5e475d73aadd3158a0c33526373f91770f29967a16c2f08ea","target":"record","created_at":"2026-05-26T01:02:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8cc47a1f256314c7b70fb1acd61c517e15e81c26ddae61860ad20dd18e808e3a","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-09T01:09:01Z","title_canon_sha256":"ccdbdffbb36eadba48815173fbbdbefd11570f03737c0682011893e1b174a67c"},"schema_version":"1.0","source":{"id":"2605.10977","kind":"arxiv","version":2}},"canonical_sha256":"194a37dca670244acd39924e6a981032d378674f0d504e758d033e93b8e4b648","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"194a37dca670244acd39924e6a981032d378674f0d504e758d033e93b8e4b648","first_computed_at":"2026-05-26T01:02:35.566440Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T01:02:35.566440Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"lkBvESZ7wRXLRExKy+p1defGHtsmRk3sai4hlWp/VpxU5pccDAfDW+2qsWz0bKP2PWsg7qjEI3sOR5b//t6XDw==","signature_status":"signed_v1","signed_at":"2026-05-26T01:02:35.567255Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.10977","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f85a42261309d6e5e475d73aadd3158a0c33526373f91770f29967a16c2f08ea","sha256:82bd35e74a51d8d1721d72bec63b34ab1bc90a2fc184f22bae55fed1466728be"],"state_sha256":"0d63db4b63d631d6f0c03b67970581192d24cc3892f9ed66e534da43c674d9df"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"zJqPKj6EP9axrEn9rsmy/YxzcRsT89SxBGyYNdHYdxyKZA2xWwNABcf+GqRoxdedgwq5MWksyRP6c35UQoVQBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-06T05:59:57.099707Z","bundle_sha256":"bef2e1e8df4e6721fcfe04b2f3b91258427a7a8f56a60a75d2d8b830b9a92342"}}