arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

迈向更强的代码水印:一种语法驱动的方法来优化质量与可检测性之间的权衡

Toward Stronger Code Watermarking: A Grammar-Driven Approach to Optimizing the Trade-off Between Quality and Detectability

Licheng Yu, Aiwei Liu, Songze Li

arXiv 2607.10210首次发表:更新:

发表机构

Southeast University; Tsinghua University(东南大学; 清华大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对大语言模型代码生成中质量与可检测性权衡难题,提出语法驱动水印方法(GDW),通过语法引导机制和角色感知调制注入水印,设计加权检测统计量,实验表明其在多方面优于现有方法且具鲁棒性。

AI 中文摘要

随着大语言模型(LLMs)的快速发展,文本水印已成为识别机器生成内容的关键技术。然而,直接将现有的基于对数几率的水印方法应用于代码生成仍具有挑战性,因为代码的低熵性质加剧了代码质量和水印可检测性之间的权衡。本文提出了一种名为语法驱动水印(GDW)的新颖代码水印方法。GDW通过语法引导的三级掩码机制保持句法有效性,并通过结构角色感知调制注入水印信号,对承载内容的令牌赋予更强的偏差,对句法关键令牌应用更保守的偏差。我们进一步设计角色感知加权检测统计量以提高可检测性。跨多种编程语言、模型和解码策略的实验表明,GDW比现有方法建立了更强的质量-可检测性权衡边界,同时保持对变量重命名攻击的鲁棒性。

英文摘要

With the rapid development of Large Language Models (LLMs), text watermarking has emerged as a crucial technique for identifying machine-generated content. However, directly applying existing logits-based watermarking methods to code generation remains challenging, since the low-entropy nature of code exacerbates the trade-off between code quality and watermark detectability. In this paper, we propose a novel code watermarking approach called Grammar-Driven Watermark (GDW) for LLMs. GDW preserves syntactic validity through a grammar-guided three-level masking mechanism and injects watermark signals via structural role-aware modulation, assigning a stronger bias to content-bearing tokens while applying a more conservative bias to syntax-critical tokens. Aligning with the generation process, we further design a role-aware weighted detection statistic to improve detectability. Experiments across multiple programming languages, models, and decoding strategies show that GDW establishes a stronger quality-detectability trade-off frontier than existing methods, while maintaining robustness against variable-renaming attacks.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑