acceptodds
Under review as a conference paper at ICLR 2027

WordMark: A Tokenizer-agnostic Word-level Watermark for Large Language Models

Abstract

Large language models are increasingly used by writing services to generate professional documents whose provenance and integrity may later need to be verified. Although multi-bit watermarking is able to embed a signed provenance record directly in the text, existing generation-time methods typically define bits over model-specific token sequences. Thus, verification requires the originating tokenizer, making these methods poorly suited to services that route requests among heterogeneous or evolving backend models. We present WordMark, a tokenizer-agnostic, word-level multi-bit watermark. During generation, a lightweight generator-specific token encoder predicts the word-level bit that each candidate token is likely to produce, enabling bit-guided autoregressive sampling. A shared word decoder then uses representations from an auxiliary language model to recover context-dependent bits directly from the resulting words. WordMark embeds each ECC codeword bit as a parity constraint over a small group of carrier words, reducing forced low-probability choices. For watermark detection, the payload is represented by repeated index-dependent ECC codewords and verified through designated-codeword matching, reducing false positives on non-watermarked text. Experiments across multiple auxiliary language models, generators, payload lengths, and text domains demonstrate reliable payload recovery and watermark detection while preserving generation quality without requiring the detector to know the generator tokenizer.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.