arXiv:2605.29434cs.CRcs.AI2026-05中稿 · ICML

让文本水印抵抗改写时的句子拆分合并,提升鲁棒性。

AliMark: Enhancing Robustness of Sentence-Level Watermarking Against Text Paraphrasing

论文配图:AliMark: Enhancing Robustness of Sentence-Level Watermarking Against Text Paraphrasing
图 1 · 摘自论文原文
  • 将水印编码为比特序列,通过多变体对齐检测
  • 在DIPPER和GPT-3.5攻击下,水印提取率显著更高
  • 适合需要强鲁棒性的内容防伪场景

现有句级水印方法通过语义锚定增强对改写的鲁棒性,但其前缀设计仍易受句子拆分与合并等结构扰动影响,尤其在强改写器如DIPPER和GPT-3.5下表现不佳。为此,我们提出AliMark,将句级水印重构为比特序列编码与对齐问题:生成多个重排文本变体,自适应对齐其提取的比特序列与秘密比特序列,以最小化对齐代价。该多候选对齐设计天然提升了对句子拆分与合并的鲁棒性。大量实验表明,AliMark在多种改写攻击下显著优于当前最优基线。

原文摘要 · Abstract (English)

Existing sentence-level watermarking methods enhance robustness to paraphrasing by anchoring watermarks in sentence semantics. However, their prefix-based designs remain vulnerable to structural perturbations, such as sentence splitting and merging, which commonly arise under strong paraphrasers like DIPPER and GPT-3.5. To mitigate this issue, we propose AliMark, a framework that reformulates sentence-level watermarking as a bit sequence encoding and alignment problem between a potentially watermarked text and a secret bit sequence. Notably, our approach adopts a two-stage detection strategy: we generate multiple restructured text variants and adaptively align their extracted bit sequences with the secret bit sequence to minimize alignment cost. This multi-candidate alignment design naturally improves robustness to sentence merges and splits. Extensive experiments demonstrate that AliMark substantially outperforms state-of-the-art baselines under diverse paraphrasing attacks.

文本水印对抗攻击自然语言处理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。