PhaseLock: Phase-Structured Tokenization for Watermarking Periodic Time Series
Abstract
Generation-time watermarks for time series bias a discrete token sequence toward a secret set of codes and detect the watermark by re-encoding the observed signal. Existing methods tokenize windows starting at arbitrary positions and treat the codebook as an unstructured set, so patches at different phases of the period are represented and marked in the same way. The bias can then favor codes used at other phases, and the detector does not know the phase of the observed window. We take the phase of a periodic series as the organizing principle for the codebook, the watermark, and the detector. PhaseLock partitions the codebook into phase groups and quantizes each patch using the group corresponding to its phase. The tokenizer and generator are trained only on windows aligned to the patch grid of the period. PhaseLock outputs each generated window with a random temporal shift, allowing samples to start at arbitrary times as in real data, and it injects the watermark with a phase-gated bias, so that each phase is marked with its own codes. At detection, a single re-encoding network recovers the grid alignment, phase, and codes directly from the observed signal. On ten periodic benchmarks, PhaseLock remains detectable under post-editing attacks at a lower Context-FID than the same generator with an unstructured codebook of equal size. It also yields fewer false positives under wrong keys and preserves the periodicity of the data more closely than existing watermarks.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.