May 2026Unreviewed
PASA: A Principled Embedding-Space Watermarking Approach for LLM-Generated Text under Semantic-Invariant Attacks
Zhenxin Ai, Haiyun He
Abstract
Watermarking for large language models (LLMs) is a promising approach for detecting LLM-generated text and enabling responsible deployment. However, existing watermarking methods are often vulnerable to semantic-invariant attacks, such as paraphrasing. We propose PASA, a principled, robust, and distortion-free watermarking algorithm that embeds and detects a watermark at the semantic level. PASA operates on semantic clusters in a latent embedding space and constructs a distributional dependency
Categories
Cite
@misc{zhenxin2026pasa,
title = {{PASA: A Principled Embedding-Space Watermarking Approach for LLM-Generated Text under Semantic-Invariant Attacks}},
author = {{Zhenxin Ai} and Haiyun He},
year = {2026},
month = may,
eprint = {2605.10977},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.10977}
}