acceptodds
Under review as a conference paper at ICLR 2027

PACER: Provably Secure Steganography under Asymmetric Receiver Access with Certified Recovery

Abstract

Many high-capacity provably secure steganography (PSS) schemes for large language models require the receiver to reproduce the sender's token distribution using the same model and prompt. In practice, privacy or resource constraints may prevent the receiver from accessing the sender's prompt or model, creating asymmetric receiver access. Existing asymmetric baselines use token-only recovery to avoid this dependence, but often have low embedding rates or limited recovery reliability and do not benefit from receiver-side resources that may remain available. We present PACER, a provably secure linguistic steganography framework for asymmetric receiver access with certified recovery. PACER separates the sender's token distribution used during generation from the receiver-side information used for recovery. When a receiver-side distribution is available, PACER combines maximal coupling with token-class coupling to extract recovery evidence while preserving the sender's token distribution. Otherwise, token-class coupling alone enables token-only recovery. An e-process accumulates this evidence and certifies payload blocks under a prescribed error bound. We prove PACER's computational security and show that the probability of incorrect recovery in any certification process is at most this bound. Experiments show that PACER achieves reliable recovery across different receiver access modes and that receiver-side distributions increase the embedding rate over token-only recovery. With receiver-side information, PACER achieves more than 42 times the embedding rate of the reliable asymmetric baseline. In token-only mode, PACER achieves more than 16 times that rate, with faster encoding and decoding.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.