CohortMark: Watermarking Text Cohorts While Preserving Every Proper Subset
Abstract
Text watermarks seek detectable signals with limited distributional change. Pre-serving individual distributions need not preserve subgroup laws; preserving thecomplete group's clean law conditional on key and metadata leaves no evidence.Our insight is to separate observation scopes: preserve every proper subset whileplacing evidence in the original group's higher-order relation. Token discretiza-tion can erase this dependence. CohortMark uses an analysis of this loss to designa finite-harmonic coupling whose shape controls evidence without altering sub-set laws. Source-model replay with required metadata gives the original group'sexact token-interval likelihood ratio. With ideal exact sampling, token probabili-ties based only on each member's own prompt and history, and fresh joint drawsper step, all predesignated nonempty proper subsets follow independent clean se-quence laws at each fixed key and nonce. Across two model families and twotasks, the three-member instance achieves 94.8-99.0% recall at separately cal-ibrated nominal 1% false-positive rates. All four settings meet predeclared re-call noninferiority and false-positive criteria against SynthID; both Llama settingssupport higher recall. Exchanging one member at the same three-text, 768-tokenbudget reduces positive rates to 1.0–1.2%, linking evidence to original joint gen-eration. In automatic ELI5 evaluation, intervals for changes from clean in thefraction of groups with at least one usable answer lie within ±3 percentage points.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.