acceptodds
Under review as a conference paper at ICLR 2027

SEAL: Statistical Embedding Alignment for Code Watermarking

Abstract

Large language models can now generate high-quality code at scale, making reliable source tracing increasingly important. Code watermarking, however, is more restrictive than text watermarking: generated code must remain executable, functionally correct, and robust to common edits. In contrast to the existing code watermarking methods that rely on embedding the signal in token choices, syntax-aware rules, or decoding-time biases, tying the watermark to surface form, we propose SEAL, a semantic-space watermarking method for code generation that embeds the signal through candidate selection in code embedding space. Rather than retraining model parameters, decoding logits, or alternating the final program, SEAL selects among model-generated candidates whose semantic projection signs align with a secret key. We further establish two theoretical results proving that SEAL produces a statistically detectable signal that strengthens under aggregation across generated functions, while remaining robust to code transformations that preserve most semantic watermark signs. Experiments on HumanEval and MBPP with CodeLlama-7B and StarCoder2-7B show that SEAL is competitive with SWEET and STONE. Aggregation improves low-FPR detection, and SEAL remains detectable under formatting changes, variable renaming, and code rewrites. Our results show that semantic embedding-space selection offers a practical path toward robust code watermarking, where each generated function serves as the watermark-carrying unit and the signal is encoded in the semantic representation.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.