May 2026Unreviewed
Blind PRNG Hijacking: An Undetectable Integrity-Preserving Attack Against LLM Watermarking
Ziyang You, Huilong He, Xiaoke Yang, Xuxing Lu
Abstract
Cryptographic watermarking is a leading defense for attributing text generated by large language models (LLMs). Existing schemes, including KGW, Unigram, and DipMark, derive their security guarantees from the assumption that the underlying pseudo-random number generator (PRNG) is trustworthy. This work introduces SeedHijack, the first supply-chain attack on LLM watermarking that is simultaneously (i) blind -- requiring no knowledge of the watermark key, detector, or model logits, (ii) integrity-
Categories
Cite
@misc{you2026blind,
title = {{Blind PRNG Hijacking: An Undetectable Integrity-Preserving Attack Against LLM Watermarking}},
author = {Ziyang You and Huilong He and Xiaoke Yang and Xuxing Lu},
year = {2026},
month = may,
eprint = {2605.28632},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.28632}
}