WordMark: A Tokenizer-agnostic Word-level Watermark for Large Language Models
Abstract
Large language models are increasingly used by writing services to generate professional documents whose provenance and integrity may later need to be verified. Although multi-bit watermarking is able to embed a signed provenance record directly in the text, existing generation-time methods typically define bits over model-specific token sequences. Thus, verification requires the originating tokenizer, making these methods poorly suited to services that route requests among heterogeneous or evolving backend models. We present WordMark, a tokenizer-agnostic, word-level multi-bit watermark. During generation, a lightweight generator-specific token encoder predicts the word-level bit that each candidate token is likely to produce, enabling bit-guided autoregressive sampling. A shared word decoder then uses representations from an auxiliary language model to recover context-dependent bits directly from the resulting words. WordMark embeds each ECC codeword bit as a parity constraint over a small group of carrier words, reducing forced low-probability choices. For watermark detection, the payload is represented by repeated index-dependent ECC codewords and verified through designated-codeword matching, reducing false positives on non-watermarked text. Experiments across multiple auxiliary language models, generators, payload lengths, and text domains demonstrate reliable payload recovery and watermark detection while preserving generation quality without requiring the detector to know the generator tokenizer.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.