CodeKAST: Keyed AST-Safe Structural Watermarking for LLM-Generated Code
Abstract
Watermarking code generated by large language models poses the challenge of embedding detectable evidence without compromising functional correctness. Existing methods rely on the assumption that biasing token distributions at generation time is sufficient to leave a persistent watermark signal in code. Our analysis reveals a fundamental limitation of this assumption: program semantics are carried by structure rather than surface tokens, and token-level biases can perturb syntax-critical elements, thereby compromising functional correctness. To address this problem, we propose CodeKAST, a unified framework that embeds key-controlled structural evidence in the abstract syntax tree space rather than the raw token space and uses constrained syntax transformations to generate functional watermarked programs. Specifically, an HMAC-controlled encoding scheme derives a structural state for each supported AST site from a secret key and pre-declared verification information; a candidate program is released only after passing syntax checking, round-trip reconstruction, and execution-based screening. During verification, CodeKAST compares the structural states observed in the released code with those expected under a nominated key. The resulting evidence supports both watermark-presence detection and candidate-key attribution, while the verifier abstains when the available sites are insufficient to distinguish candidate keys.On HumanEval+ and MBPP+, CodeKAST achieves the best detection performance among the evaluated methods under a unified model and evaluation protocol, while preserving the functional correctness of the original code, without an extra generative model training process.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.