arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

PURA:可证明无偏且鲁棒的多比特文本归属

PURA: Provably Unbiased and Robust Multi-Bit Watermarking for AI-Generated Text Attribution

Yaofei Wang, Jinyang Guo, Shuchao Du, Chao Wang, Qiyi Yao, Donghui Hu, Weiming Zhang, Nenghai Yu, Kejiang Chen

arXiv 2608.22218首次发表:更新:

AI 中文总结

PURA是一种可证明无偏的多比特文本归属水印方法,通过在潜在采样空间嵌入载荷,在高载荷下性能远超基线,兼具鲁棒性与高效性。

AI 中文摘要

AI生成文本的细粒度归属对于问责制和审计而言日益重要,但现有的多比特水印方法仍难以同时满足三个核心需求:保留基础生成分布、支持高容量载荷、在文本编辑后仍可恢复。本文提出PURA,一种可证明无偏且鲁棒的多比特文本归属水印方法。PURA不直接扰动词元概率,而是通过带密钥的逆变换采样在潜在采样空间中嵌入载荷,并将观测到的词元视为软区间证据、跨序列聚合这些证据来恢复载荷。该设计可精确保留基础生成分布,同时大幅提升文本后编辑和信道扰动下的恢复稳定性。基于此恢复范式,本文进一步开展统一鲁棒性分析,证明在有界攻击强度下,每比特错误概率随序列长度呈指数衰减。大量实验表明,在高载荷场景下,PURA的性能显著优于现有无偏基线。例如,在200个词元中嵌入36比特时,PURA的消息匹配率达91.7%,是性能最强的无偏基线的三倍以上,同时保留文本质量、与未加水印文本统计上接近,且仅产生毫秒级的验证开销。

英文摘要

Fine-grained attribution of AI-generated text is becoming increasingly important for accountability and auditing, yet existing multi-bit watermarking methods still struggle to simultaneously preserve the base generation distribution, support high-capacity payloads, and remain recoverable after editing. We present PURA, a provably unbiased and robust multi-bit watermarking method for text attribution. Instead of perturbing token probabilities directly, PURA embeds payloads in the latent sampling space via keyed inverse transform sampling, and recovers them by treating observed tokens as soft interval evidence and aggregating such evidence across the sequence. This design preserves the base generation distribution exactly while substantially improving recovery stability under post-editing and channel perturbations. Building on this recovery paradigm, we further develop a unified robustness analysis and show that, under bounded attack strength, the per-bit error probability decays exponentially with sequence length. Extensive experiments show that PURA substantially outperforms existing unbiased baselines in the high-payload regime. For example, when embedding 36 bits in 200 tokens, PURA achieves a 91.7\% message match rate, more than three times that of the strongest unbiased baseline, while preserving text quality and remaining statistically close to unwatermarked text, and incurring only millisecond-level verification overhead. Our code is available at

CommentsAccepted to ACM CCS 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑