Addressing Tokenization Inconsistency in Steganography and Watermarking Based on Large Language Models
Ruiyi Yan, Yugo Murawaki
Abstract
Large language models have significantly enhanced the capacities and efficiency of text generation. On the one hand, they have improved the quality of text-based steganography. On the other hand, they have also underscored the importance of watermarking as a safeguard against malicious misuse. In this study, we focus on tokenization inconsistency (TI) between the sender and the receiver in steganography and watermarking, where TI can undermine robustness. Our investigation reveals that the problematic tokens responsible for TI exhibit two key characteristics: infrequency and temporariness. Based on these findings, we propose two tailored solutions for TI elimination: a stepwise verification method for steganography and a post-hoc rollback method for watermarking. Experiments show that (1) compared to traditional disambiguation methods in steganography, directly addressing TI leads to improvements in fluency, imperceptibility, and antisteganalysis capacity; (2) for watermarking, addressing TI enhances detectability and robustness against attacks. The code is available at https://github.com/ryehr/Consistency .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Hide and Seek in Embedding Space: Geometry-based Steganography and Detection in Large Language ModelsCharles Westphal, Keivan Navaie, Fernando RosasICML 2026 · 1 citation
- Efficient Provably Secure Linguistic Steganography via Range CodingRuiyi Yan, Yugo MurawakiACL 2026
- Anchored Sliding Window: Toward Robust and Imperceptible Linguistic SteganographyRuiyi Yan, Shiao Meng, Yugo MurawakiACL 2026
Builds on9
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz et al.ICML 2023 · 854 citations
- On the Reliability of Watermarks for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Manli Shu et al.ICLR 2024 · 202 citations
- Near-imperceptible Neural Linguistic Steganography via Self-Adjusting Arithmetic CodingJiaming Shen, Heng Ji, Jiawei HanEMNLP 2020 · 39 citations
- An Entropy-based Text Watermarking Detection MethodYijian Lu, Aiwei Liu, Dianzhi Yu, Jingjing Li et al.ACL 2024 · 14 citations
- Glitch Tokens in Large Language Models: Categorization Taxonomy and Effective DetectionYuxi Li, Yi Liu, Gelei Deng, Ying Zhang et al.FSE 2024 · 12 citations
Related papers
- Watermarking Large Language Models: An Unbiased and Low-risk MethodMinjia Mao, Dongjun Wei, Zeyu Chen, Xiao Fang et al.ACL 2025 · 6 citations
- A Linguistics-Aware LLM Watermarking via Syntactic PredictabilityShinwoo Park, Hyejin Park, Hyeseon An, Yo-Sub HanACL 2026 · 2 citations
- Can Watermarks Survive Translation? On the Cross-lingual Consistency of Text Watermark for Large Language ModelsZhiwei He, Binglin Zhou, Hongkun Hao, Aiwei Liu et al.ACL 2024 · 17 citations
- Provable Robust Watermarking for AI-Generated TextXuandong Zhao, Prabhanjan Vijendra Ananth, Lei Li, Yu-Xiang WangICLR 2024 · 312 citations
- Catch-22: On the Fundamental Tradeoff Between Detectability and Robustness in LLM WatermarkingKuheli Pratihar, Debdeep MukhopadhyayICML 2026
