Skip to content
Search
paperMay 2026Unreviewed

PASA: A Principled Embedding-Space Watermarking Approach for LLM-Generated Text under Semantic-Invariant Attacks

Zhenxin Ai, Haiyun He

Abstract

Watermarking for large language models (LLMs) is a promising approach for detecting LLM-generated text and enabling responsible deployment. However, existing watermarking methods are often vulnerable to semantic-invariant attacks, such as paraphrasing. We propose PASA, a principled, robust, and distortion-free watermarking algorithm that embeds and detects a watermark at the semantic level. PASA operates on semantic clusters in a latent embedding space and constructs a distributional dependency

Categories

Cite

@misc{zhenxin2026pasa,
  title = {{PASA: A Principled Embedding-Space Watermarking Approach for LLM-Generated Text under Semantic-Invariant Attacks}},
  author = {{Zhenxin Ai} and Haiyun He},
  year = {2026},
  month = may,
  eprint = {2605.10977},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.10977}
}