USENIX Security2026Top-tier venue
PVMark: Enabling Public Verifiability for LLM Watermarking Schemes
Haohua Duan, Liyao Xiang, Xin Zhang, Baochun Li, Bo Li
Abstract
Watermarking schemes for large language models (LLMs) have been proposed to identify the source of the generated text. However, current watermarking solutions hardly resolve the trust issue: the watermark detection often relies on the secret key and thus remains opaque to the public; otherwise any adversary may launch removal attacks if the secret key is exposed. To resolve the dilemma, we propose PVMark, a plugin based on zero-knowledge proof (ZKP), enabling the watermark detection process to be publicly verifiable by third parties without disclosing any secret key. PVMark novelly hinges upon the proof of `correct execution' of watermark detection on which a set of constraints are built, and is optimized according to the structural nature of the detection process. Developed for three representative watermarking schemes, we implement multiple variants of PVMark in Python, Rust and Circom, covering combinations of three hash functions and four ZKP protocols, showing our approach effectively works under a variety of circumstances. By experimental results, PVMark efficiently enables public verifiability on the state-of-the-art LLM watermarking schemes yet without compromising the watermarking performance, and hence is promising for practical deployment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ade93d30-8d72-4a89-9b4e-1d0fd5a8a763Builds on17
- DetectGPT: Zero-Shot Machine-Generated Text Detection using Probability CurvatureEric Mitchell, Yoonho Lee, Alexander Khazatsky, Christopher D. Manning et al.ICML 2023 · 988 citations
- A Watermark for Large Language ModelsJohn Kirchenbauer, Jonas Geiping, Yuxin Wen, Jonathan Katz et al.ICML 2023 · 854 citations
- Paraphrasing evades detectors of AI-generated text, but retrieval is an effective defenseKalpesh Krishna, Yixiao Song, Marzena Karpinska, John Wieting et al.NeurIPS 2023 · 657 citations
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy et al.USENIX Security 2021 · 410 citations
- Provable Robust Watermarking for AI-Generated TextXuandong Zhao, Prabhanjan Vijendra Ananth, Lei Li, Yu-Xiang WangICLR 2024 · 312 citations
Related papers
- An Unforgeable Publicly Verifiable Watermark for Large Language ModelsAiwei Liu, Leyi Pan, Xuming Hu, Shuang Li et al.ICLR 2024 · 63 citations
- WaterMax: breaking the LLM watermark detectability-robustness-quality trade-offEva Giboulot, Teddy FuronNeurIPS 2024 · 76 citations
- De-mark: Watermark Removal in Large Language ModelsRuibo Chen, Yihan Wu, Junfeng Guo, Heng HuangICML 2025
- IPMark: A Sentence-Level Watermark for LLMs with Hierarchical Personalization and Efficient DetectionWenbo An, Lianwei Wu, Zehao WangICML 2026
- Black-Box Detection of Language Model WatermarksThibaud Gloaguen, Nikola Jovanovic, Robin Staab, Martin T. VechevICLR 2025
