Edit Distance Robust Watermarks via Indexing Pseudorandom Codes
Noah Golowich, Ankur Moitra
Abstract
Motivated by the problem of detecting AI-generated text, we consider the problem of watermarking the output of language models with provable guarantees. We aim for watermarks which satisfy: (a) undetectability, a cryptographic notion introduced by Christ, Gunn&Zamir (2024) which stipulates that it is computationally hard to distinguish watermarked language model outputs from the model's actual output distribution; and (b) robustness to channels which introduce a constant fraction of adversarial insertions, substitutions, and deletions to the watermarked text. Earlier schemes could only handle stochastic substitutions and deletions, and thus we are aiming for a more natural and appealing robustness guarantee that holds with respect to edit distance. Our main result is a watermarking scheme which achieves both undetectability and robustness to edits when the alphabet size for the language model is allowed to grow as a polynomial in the security parameter. To derive such a scheme, we follow an approach introduced by Christ&Gunn (2024), which proceeds via first constructing pseudorandom codes satisfying undetectability and robustness properties analogous to those above; our key idea is to handle adversarial insertions and deletions by interpreting the symbols as indices into the codeword, which we call indexing pseudorandom codes. Additionally, our codes rely on weaker computational assumptions than used in previous work. Then we show that there is a generic transformation from such codes over large alphabets to watermarking schemes for arbitrary language models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- AdaDetectGPT: Adaptive Detection of LLM-Generated Text with Statistical GuaranteesHongyi Zhou, Jin Zhu, Pingfan Su, Kai Ye et al.NeurIPS 2025 · 23 citations
- On the Impossibility of Separating Intelligence from Judgment: The Computational Intractability of Filtering for AI AlignmentSarah Ball, Greg Gluch, Shafi Goldwasser, Frauke Kreuter et al.ICLR 2026 · 16 citations
- Learn-to-Distance: Distance Learning for Detecting LLM-Generated TextHongyi Zhou, Jin Zhu, Kai Ye, Ying Yang et al.ICLR 2026 · 10 citations
- Improved Pseudorandom Codes from Permuted PuzzlesMiranda Christ, Noah Golowich, Sam Gunn, Ankur Moitra et al.STOC 2026 · 5 citations
- SoK: Watermarking for AI-Generated ContentXuandong Zhao, Sam Gunn, Miranda Christ, Jaiden Fairoze et al.S&P 2025
Builds on12
- Visual Autoregressive Modeling: Scalable Image Generation via Next-Scale PredictionKeyu Tian, Yi Jiang, Zehuan Yuan, Bingyue Peng et al.NeurIPS 2024 · 1,199 citations
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz et al.ICML 2023 · 854 citations
- Vector-quantized Image Modeling with Improved VQGANJiahui Yu, Xin Li, Jing Yu Koh, Han Zhang et al.ICLR 2022 · 753 citations
- Provable Robust Watermarking for AI-Generated TextXuandong Zhao, Prabhanjan Vijendra Ananth, Lei Li, Yu-Xiang WangICLR 2024 · 312 citations
- On the Reliability of Watermarks for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Manli Shu et al.ICLR 2024 · 202 citations
Related papers
- Pseudorandom Error-Correcting CodesMiranda Christ, Sam GunnCRYPTO 2024 · 17 citations
- An Undetectable Watermark for Generative Image ModelsSam Gunn, Xuandong Zhao, Dawn SongICLR 2025
- Unforgeable Watermarks for Language Models via Robust SignaturesHuijia Lin, Kameron Shahabi, Min Jae SongCRYPTO 2026
- Watermarking Language Models for Many Adaptive UsersAloni Cohen, Alexander Hoover, Gabe SchoenbachS&P 2025
- Ideal Pseudorandom CodesOmar Alrabiah, Prabhanjan Ananth, Miranda Christ, Yevgeniy Dodis et al.STOC 2025 · 2 citations
