Skip to content
Search
paperMay 2026Unreviewed

Blind PRNG Hijacking: An Undetectable Integrity-Preserving Attack Against LLM Watermarking

Ziyang You, Huilong He, Xiaoke Yang, Xuxing Lu

Abstract

Cryptographic watermarking is a leading defense for attributing text generated by large language models (LLMs). Existing schemes, including KGW, Unigram, and DipMark, derive their security guarantees from the assumption that the underlying pseudo-random number generator (PRNG) is trustworthy. This work introduces SeedHijack, the first supply-chain attack on LLM watermarking that is simultaneously (i) blind -- requiring no knowledge of the watermark key, detector, or model logits, (ii) integrity-

Categories

Cite

@misc{you2026blind,
  title = {{Blind PRNG Hijacking: An Undetectable Integrity-Preserving Attack Against LLM Watermarking}},
  author = {Ziyang You and Huilong He and Xiaoke Yang and Xuxing Lu},
  year = {2026},
  month = may,
  eprint = {2605.28632},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.28632}
}