acceptodds
Under review as a conference paper at ICLR 2027

What Survives a Rewrite? Information Budgets for Inherited Watermarks

Abstract

Watermarked text often reaches a verifier after another model has rewritten it. That model may add a new watermark, but the upstream key reaches it only through the inherited document. We ask what survives such a rewrite. The coupling of old and new text has three information budgets: erased, transmitted, and fresh. A key enters the new text only through the fresh budget and leaves only through the erased one; the inherited key, which cannot enter, is capped by the transmitted budget. A task bounds the fresh budget through the outputs it allows and the erased budget through the inputs each output tolerates, and what every admissible output reveals fixes a retention floor. When fidelity means preserving a statistic , the floor is exactly , attained by conditional resampling that preserves the text distribution. For binary symmetric rewriting, we derive the exact injection optimum for uniform keys of every bit length. Failures cost at most the key alphabet, and a sharp loss bound for nearly exact copying is independent of document length. Finite-alphabet experiments exhibit the optimal operations and strict gaps below the budgets. Controlled experiments on two language models separate task execution from detector survival: Qwen3-4B rewrites all four target facts correctly in reports, while inherited-key detection falls from upstream to in each sampling arm. Paired -document comparisons isolate re-watermarking, and complete three-hop trajectories show that early stopping leaves hop-3 detection counts unchanged.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.