Linguistic Holonomy and Statistical Watermarks: Inner Geometry of Meaning-Preserving Transformations

arXiv cs.CL Papers

Summary

The paper analyzes statistical watermarks in language models by formalizing meaning-preserving transformations using linguistic holonomy, proving that watermark detection depends on the survival of seeding windows and establishing a decay law for the watermark signal.

arXiv:2608.19369v1 Announce Type: new Abstract: Statistical watermarks for language models live in the freedom of the signifier: they choose among tokens that are nearly equivalent in meaning, and they are therefore eroded by exactly those transformations which move the form of a text while leaving its content in place. The literature measures such transformations by their endpoint, through the semantic similarity between the original and the rewritten text. We show that the endpoint is the wrong statistic. Adapting the formalism of linguistic loops, we prove that the invariant of a chain of meaning-preserving transformations factorises canonically into an endpoint part and a holonomy in the stabiliser of the initial state, the second of which the semantic deficit cannot see; the loop rotation is parallel transport on the unit sphere of the embedding space, so that the analogy with the Wilson loop becomes a theorem rather than a figure of speech. On the side of the detector we prove an exact identity: the residual statistic is proportional to the number of positions whose seeding window survived intact, from which the decay law $\rho^{h+1}$ follows as the independent-edit corollary. The identity has a disconcerting consequence, which we confirm to three decimal places: at one and the same retention rate the surviving signal may be one half of the original, one quarter of it, or exactly nothing, according only to where the edits fall.
Original Article
View Cached Full Text

Cached at: 08/21/26, 10:02 AM

# Linguistic Holonomy and Statistical Watermarks:Inner Geometry of Meaning-Preserving Transformations
Source: [https://arxiv.org/html/2608.19369](https://arxiv.org/html/2608.19369)
Daniele CorradettiAffiliation:Grupo de Física Matemática, Instituto Superior TécnicoAffiliation:Av\. Rovisco Pais, 1049\-001 Lisboa, PortugalAffiliation:Departamento de Matemática, Universidade do AlgarveAffiliation:Campus de Gambelas, 8005\-139 Faro, PortugalEmail:[danielecorradetti@tecnico\.ulisboa\.pt](mailto:)

###### Abstract

Statistical watermarks for language models live in the freedom of the signifier: they choose among tokens that are nearly equivalent in meaning, and they are therefore eroded by exactly those transformations which move the form of a text while leaving its content in place\. The literature measures such transformations by their endpoint, through the semantic similarity between the original and the rewritten text\. We show that the endpoint is the wrong statistic\. Adapting the formalism of linguistic loops, we prove that the invariant of a chain of meaning\-preserving transformations factorises canonically into an endpoint part and a holonomy in the stabiliser of the initial state, the second of which the semantic deficit cannot see; the loop rotation is parallel transport on the unit sphere of the embedding space, so that the analogy with the Wilson loop becomes a theorem rather than a figure of speech\. On the side of the detector we prove an exact identity: the residual statistic is proportional to the number of positions whose seeding window survived intact, from which the decay lawρh\+1\\rho^\{h\+1\}follows as the independent\-edit corollary\. The identity has a disconcerting consequence, which we confirm to three decimal places: at one and the same retention rate the surviving signal may be one half of the original, one quarter of it, or exactly nothing, according only to where the edits fall\.

## 1Introduction and Motivation

When Raymond Queneau published his*Exercices de style*in 1947, inspired by Bach’s*Art of Fugue*, he wrote the same trivial anecdote ninety\-nine times\. A man is jostled on a bus; two hours later a friend advises him to move a button on his overcoat\. Nothing else happens\. What varies is everything else: the register, the tense, the person, the alphabet, the sonnet form, the language of a mathematician\. The content is held fixed by fiat, and the form is allowed to move as far as it can\. Queneau took himself to be doing something intrinsically geometric, and named an early version of the work*Dodécaèdre*; the intuition, as was argued in\[[4](https://arxiv.org/html/2608.19369#bib.bib4)\], is not casual at all\.

Eighty years later the same operation has acquired an adversarial use\. Since 2 August 2026 the outputs of at least one major language model carry a machine\-readable mark, in response to the transparency obligations of Article 50 of the European AI Act\[[1](https://arxiv.org/html/2608.19369#bib.bib1)\]\. The published description of such marks is careful: the mark does not change meaning, quality or readability, it survives copying and light editing, and it is stated to be lost under paraphrase, heavy editing, translation and mixing with other text\. Whoever wishes to remove the mark, then, is being invited to perform an*Exercice de style*\. The question of how much of the mark survives such an exercise is the subject of this article\.

### The landscape

The dominant construction is the*green\-list*watermark of Kirchenbauer*et al\.*\[[7](https://arxiv.org/html/2608.19369#bib.bib7)\]: at each step a pseudo\-random subset of the vocabulary, of relative sizeγ\\gamma, is declared green on the basis of a secret key and of thehhpreceding tokens, and the logits of green tokens are raised by a biasδb\\delta\_\{b\}\. Detection counts green tokens and reads off azz\-score\. Settingh=0h=0gives the Unigram scheme of Zhao*et al\.*\[[15](https://arxiv.org/html/2608.19369#bib.bib15)\], whose robustness is provable\. A different family, initiated by Aaronson and developed by Kuditipudi*et al\.*\[[10](https://arxiv.org/html/2608.19369#bib.bib10)\]and by Christ, Gunn and Zamir\[[2](https://arxiv.org/html/2608.19369#bib.bib2)\], leaves the output distribution mathematically untouched and replaces instead the source of randomness in the sampler; these are the*distortion\-free*schemes\. A production deployment at scale, using tournament sampling, is described in\[[5](https://arxiv.org/html/2608.19369#bib.bib5)\]\. A synoptic view is given in Table[1](https://arxiv.org/html/2608.19369#S1.T1)\.

Table 1:*Synoptic table of the families of text watermarks\. The last column is the one that matters for this article: in every family except the Unigram scheme, an edit damages not only the position it touches but every position that used it as seeding context\. It is this asymmetry which the geometry of Section[4](https://arxiv.org/html/2608.19369#S4)and the identity of Section[5](https://arxiv.org/html/2608.19369#S5)make precise\.*Against these constructions stands a literature of attacks\. Krishna*et al\.*\[[9](https://arxiv.org/html/2608.19369#bib.bib9)\]introduced a dedicated paraphraser; Sadasivan*et al\.*\[[13](https://arxiv.org/html/2608.19369#bib.bib13)\]iterated it; a recent large\-scale study\[[3](https://arxiv.org/html/2608.19369#bib.bib3)\]chains rewritings up to five deep and reports detection falling from87\.9%87\.9\\%on the original outputs to4\.86%4\.86\\%after five hops\. Kirchenbauer*et al\.*\[[8](https://arxiv.org/html/2608.19369#bib.bib8)\]had already observed, on empirical grounds, that a longer seeding context makes a watermark less robust to editing\.

All of these studies share a habit of measurement\. An attack is scored by its*endpoint*: by the semantic similarity between the original and the final text, and by a count of how many tokens or hops separate them\. The intermediate states are treated as scaffolding\.

### The gap

This habit is not innocent\. Consider two chains of rewritings that begin at the same text and end at texts of identical meaning\. One proceeds directly; the other wanders through three languages and returns\. By any endpoint measure they are the same attack\. Are they?

To ask the question one needs a formalism in which the intermediate states are part of the object rather than part of the apparatus\. Such a formalism exists\. In\[[4](https://arxiv.org/html/2608.19369#bib.bib4)\]a*linguistic loop*was defined as a chain of transformations that move the signifier while preserving the semantic core, its*semantic deficit*was defined as the cosine distance between the first and last embedded states, and a rotationR𝒰∈SO⁡\(n\)\\mathrm\{R\}\_\{\\mathcal\{U\}\}\\in\\mathrm\{SO\}\(n\)was associated with the entire chain by composing the minimal rotations between consecutive states\. The signature of a quadratic form built fromR𝒰\\mathrm\{R\}\_\{\\mathcal\{U\}\}was proposed as the invariant of the loop, and the construction was compared, in the introduction of that paper, with the Wilson loop of lattice gauge theory\.

We take up that formalism, and we find three things\.

The first is that the proposed invariant collapses\. The representing matrixIn−R𝒰∗I\_\{n\}\-\\mathrm\{R\}^\{\*\}\_\{\\mathcal\{U\}\}is always positive semidefinite, so its Sylvester signature is\(2​p,0,n−2​p\)\(2p,0,n\-2p\)and carries no more information than its rank\. The negative index, which is where a signature normally keeps its content, is identically zero\.

The second is that the analogy with the Wilson loop is not an analogy\. The minimal rotation of\[[4](https://arxiv.org/html/2608.19369#bib.bib4)\]*is*parallel transport along the minimising geodesic of the unit sphere;R𝒰\\mathrm\{R\}\_\{\\mathcal\{U\}\}is parallel transport along the geodesic polygon of the chain; and the quantity that the semantic deficit discards is precisely a holonomy, an element ofSO⁡\(n−1\)\\mathrm\{SO\}\(n\-1\)fixing the initial state\. Endpoint and path separate canonically, and they are independent: neither constrains the other\.

The third is that on the side of the detector there is an exact law, and it is not the law the field has been assuming\. The residual statistic after an attack is proportional to the number of scored positions whose entire seeding window survived\. When the edits are independent this givesρh\+1\\rho^\{h\+1\}, which explains in closed form the trend reported in\[[8](https://arxiv.org/html/2608.19369#bib.bib8)\]\. When they are not — and real edits never are — the retention rateρ\\rhodoes not determine the residual at all\.

### Contribution

In this work we prove that the invariant of a linguistic loop factorises canonically asR𝒰=Rdir​H\\mathrm\{R\}\_\{\\mathcal\{U\}\}=\\mathrm\{R\}\_\{\\mathrm\{dir\}\}HwithHHin the stabiliser of the base point, that the semantic deficit depends only on the first factor, and that the two factors are functionally independent; we identifyHHas the Riemannian holonomy of the geodesic polygon of the chain, which on the two\-sphere is the area of the enclosed triangle; we show that the signature invariant of\[[4](https://arxiv.org/html/2608.19369#bib.bib4)\]degenerates to a rank and is superseded by the angle spectrum; and we prove the intact\-window identity for green\-list and exponential detectors, with its corollary that an adversary who knows the context widthhhcan annihilate the signal while retaining a fraction1−1/\(h\+1\)1\-1/\(h\+1\)of the tokens\. Every statement is verified numerically against exact detectors whose keys we hold, and the geometric machinery is applied to real chains of round\-trip machine translation\.

In Section[2](https://arxiv.org/html/2608.19369#S2)we recall, in a self\-contained form, the apparatus of linguistic loops\. In Section[3](https://arxiv.org/html/2608.19369#S3)we prove the degeneracy of the signature\. Section[4](https://arxiv.org/html/2608.19369#S4)contains the factorisation, the identification with parallel transport and the Gauss–Bonnet corollary\. Section[5](https://arxiv.org/html/2608.19369#S5)turns to the detector and proves the intact\-window law\. Section[6](https://arxiv.org/html/2608.19369#S6)reports the experiments, including a preregistered test whose outcome we report whichever way it fell\. Section[7](https://arxiv.org/html/2608.19369#S7)discusses what the results do and do not license\.

## 2Linguistic loops and their invariants

We recall the apparatus of\[[4](https://arxiv.org/html/2608.19369#bib.bib4)\], in the form in which we shall use it\. The reader who knows that paper may skip to Section[3](https://arxiv.org/html/2608.19369#S3); the reader who does not should find here everything the sequel requires\.

Language is not a metric space, but its images under an embedding map are\. A*metrizable linguistic space*is a triple\(𝒜,ψ,d\)\(\\mathscr\{A\},\\psi,d\)where𝒜\\mathscr\{A\}is a set of linguistic elements — words, phrases, whole propositions — in a context of interest, and

ψ:𝒜⟶ℝn,λ⟼ψ⁡\(λ\),\\psi:\\mathscr\{A\}\\longrightarrow\\mathbb\{R\}^\{n\},\\qquad\\lambda\\longmapsto\\psi\(\\lambda\),\(2\.1\)is an embedding map, generally neither injective nor surjective\. A distanced∗d\_\{\*\}onℝn\\mathbb\{R\}^\{n\}induces a*semantic distance*on𝒜\\mathscr\{A\}by composition,

d⁡\(λ,ν\):=d∗​\(ψ⁡\(λ\),ψ⁡\(ν\)\),d\(\\lambda,\\nu\):=d\_\{\*\}\\bigl\(\\psi\(\\lambda\),\\psi\(\\nu\)\\bigr\),\(2\.2\)and throughout this articled∗d\_\{\*\}is the cosine distance

d∗,cos​\(x,y\)=1−x⋅y‖x‖​‖y‖\.d\_\{\*,\\cos\}\(x,y\)=1\-\\frac\{x\\cdot y\}\{\\\|x\\\|\\,\\\|y\\\|\}\.\(2\.3\)The choice is not innocuous and we shall return to it in Remark[3\.2](https://arxiv.org/html/2608.19369#S3.Thmtheorem2): it is what makes the whole construction orthogonally natural rather than linearly natural\.

A*linguistic transformation*UUis a map of𝒜\\mathscr\{A\}into itself which acts on the signifier while preserving, in a controlled way, the semantic core\. In\[[4](https://arxiv.org/html/2608.19369#bib.bib4)\]three requirements are imposed: closure,U⁡\(λ\)∈𝒜U\(\\lambda\)\\in\\mathscr\{A\}; reversibility, the existence of an approximate inverseU−1U^\{\-1\}withd⁡\(U−1​\(U⁡\(λ\)\),λ\)<εd\(U^\{\-1\}\(U\(\\lambda\)\),\\lambda\)<\\varepsilonfor a fixed thresholdε\\varepsilon; and coherence, the requirement that similar elements have similar images\. Translation between languages, conversion to the negative or interrogative form, dialectal or stylistic adaptation, expansion and synthesis, and paraphrase are all linguistic transformations; inventing a story is not, because its generative content is too large for the original to be reconstructible\.

Given a sequence𝒰=\{𝟙,U1,…,UL\}\\mathcal\{U\}=\\\{\\mathbb\{1\},U\_\{1\},\\dots,U\_\{L\}\\\}of such transformations and an initial elementλ\\lambda, the iterated composition produces a chain in𝒜\\mathscr\{A\}, whose image underψ\\psiis a chain of vectors

ψ\(𝒰\(λ\)\)=\{v0,v1,…,vL\},v0=ψ\(λ\),vi=ψ\(\(Ui∘⋯∘U1\)\(λ\)\)\.\\psi\(\\mathcal\{U\}\(\\lambda\)\)=\\\{v\_\{0\},v\_\{1\},\\dots,v\_\{L\}\\\},\\qquad v\_\{0\}=\\psi\(\\lambda\),\\quad v\_\{i\}=\\psi\\bigl\(\(U\_\{i\}\\circ\\cdots\\circ U\_\{1\}\)\(\\lambda\)\\bigr\)\.\(2\.4\)The*semantic deficit*of the chain is the distance between its extremes,

δ𝒰​\(λ\):=d∗​\(v0,vL\),\\delta\_\{\\mathcal\{U\}\}\(\\lambda\):=d\_\{\*\}\(v\_\{0\},v\_\{L\}\),\(2\.5\)and whenδ𝒰<ξ\\delta\_\{\\mathcal\{U\}\}<\\xifor a fixed thresholdξ\\xithe sequence is called a*linguistic loop*\. Small deficit means the meaning came back; the form, in the meantime, may have gone anywhere\.

To capture where it went, one rewrites the chain as a sequence of rotations\. Forx,y∈ℝnx,y\\in\\mathbb\{R\}^\{n\}neither zero nor antipodal, writex^=x/‖x‖\\hat\{x\}=x/\\\|x\\\|and let

ℛ~x,y:=In\+\(y^​x^T−x^​y^T\)\+11\+x^T​y^​\(y^​x^T−x^​y^T\)2∈SO⁡\(n\)\\widetilde\{\\mathcal\{R\}\}^\{x,y\}:=I\_\{n\}\+\\bigl\(\\hat\{y\}\\hat\{x\}^\{T\}\-\\hat\{x\}\\hat\{y\}^\{T\}\\bigr\)\+\\frac\{1\}\{1\+\\hat\{x\}^\{T\}\\hat\{y\}\}\\bigl\(\\hat\{y\}\\hat\{x\}^\{T\}\-\\hat\{x\}\\hat\{y\}^\{T\}\\bigr\)^\{2\}\\;\\in\\;\\mathrm\{SO\}\(n\)\(2\.6\)be the*minimal rotation*carryingx^\\hat\{x\}toy^\\hat\{y\}\. Its minimality is the statement that it rotates in the plane spanned byxxandyyonly, acting as the identity on the orthogonal complement\. The whole chain is then summarised by the ordered product

R𝒰:=ℛ~vL−1,vLℛ~vL−2,vL−1⋯ℛ~v0,v1∈SO\(n\),\\mathrm\{R\}\_\{\\mathcal\{U\}\}:=\\widetilde\{\\mathcal\{R\}\}^\{v\_\{L\-1\},v\_\{L\}\}\\widetilde\{\\mathcal\{R\}\}^\{v\_\{L\-2\},v\_\{L\-1\}\}\\cdots\\widetilde\{\\mathcal\{R\}\}^\{v\_\{0\},v\_\{1\}\}\\;\\in\\;\\mathrm\{SO\}\(n\),\(2\.7\)which satisfiesR𝒰​v^0=v^L\\mathrm\{R\}\_\{\\mathcal\{U\}\}\\hat\{v\}\_\{0\}=\\hat\{v\}\_\{L\}and, unlike the deficit, remembers the intermediate states\. WritingR𝒰∗=12​\(R𝒰\+R𝒰T\)\\mathrm\{R\}^\{\*\}\_\{\\mathcal\{U\}\}=\\tfrac\{1\}\{2\}\(\\mathrm\{R\}\_\{\\mathcal\{U\}\}\+\\mathrm\{R\}\_\{\\mathcal\{U\}\}^\{T\}\)for the symmetric part, an elementary computation recovers the deficit as a quadratic form,

δ𝒰​\(λ\)=Q𝒰​\(v^0,v^0\),Q𝒰​\(v^,v^\):=v^T​\(In−R𝒰∗\)​v^,\\delta\_\{\\mathcal\{U\}\}\(\\lambda\)=Q\_\{\\mathcal\{U\}\}\(\\hat\{v\}\_\{0\},\\hat\{v\}\_\{0\}\),\\qquad Q\_\{\\mathcal\{U\}\}\(\\hat\{v\},\\hat\{v\}\):=\\hat\{v\}^\{T\}\\bigl\(I\_\{n\}\-\\mathrm\{R\}^\{\*\}\_\{\\mathcal\{U\}\}\\bigr\)\\hat\{v\},\(2\.8\)whose representing matrix is the real symmetricIn−R𝒰∗I\_\{n\}\-\\mathrm\{R\}^\{\*\}\_\{\\mathcal\{U\}\}\. It was proposed in\[[4](https://arxiv.org/html/2608.19369#bib.bib4)\]that the Sylvester signature of this matrix be taken as the invariant of the loop, on the ground that it probes finer structural properties than the deficit alone\. That it probes finer properties is true\. How much finer is the subject of the next section\.

## 3The signature and its degeneracy

A signature keeps its information in the interplay between its positive and negative indices; Sylvester’s law of inertia is informative because a form can be indefinite\. The forms which arise from linguistic loops, however, cannot\.

###### Proposition 3\.1\(Degeneracy of the signature\)\.

LetR∈SO⁡\(n\)R\\in\\mathrm\{SO\}\(n\)with non\-trivial rotation anglesθ1,…,θp∈\(0,π\]\\theta\_\{1\},\\dots,\\theta\_\{p\}\\in\(0,\\pi\], and setM=In−12​\(R\+RT\)M=I\_\{n\}\-\\tfrac\{1\}\{2\}\(R\+R^\{T\}\)\. ThenMMis positive semidefinite, its spectrum is

\{1−cosθkwith multiplicity2\}k=1p∪\{0with multiplicityn−2p\},\\bigl\\\{\\,1\-\\cos\\theta\_\{k\}\\ \\text\{with multiplicity \}2\\,\\bigr\\\}\_\{k=1\}^\{p\}\\ \\cup\\ \\bigl\\\{\\,0\\ \\text\{with multiplicity \}n\-2p\\,\\bigr\\\},\(3\.1\)and consequently

sign⁡\(M\)=\(2​p,0,n−2​p\)\.\\mathrm\{sign\}\(M\)=\(2p,\\,0,\\,n\-2p\)\.\(3\.2\)The negative index vanishes identically,rank⁡\(M\)=2​p\\mathrm\{rank\}\(M\)=2p, and the signature is a function of the single integerpp\.

###### Proof\.

By the real normal form of a special orthogonal matrix there isQ∈O⁡\(n\)Q\\in\\mathrm\{O\}\(n\)withQT​R​Q=diag⁡\(R⁡\(θ1\),…,R⁡\(θp\),In−2​p\)Q^\{T\}RQ=\\mathrm\{diag\}\(R\(\\theta\_\{1\}\),\\dots,R\(\\theta\_\{p\}\),I\_\{n\-2p\}\), whereR⁡\(θ\)R\(\\theta\)is the planar rotation byθ\\theta\. Angles are taken in\(0,π\]\(0,\\pi\]: the eigenvalue−1\-1of an element ofSO⁡\(n\)\\mathrm\{SO\}\(n\)occurs with even multiplicity, and each pair constitutes a blockR⁡\(π\)R\(\\pi\), whileθ=0\\theta=0contributes a trivial block absorbed intoIn−2​pI\_\{n\-2p\}\. SinceR​\(θ\)T=R⁡\(−θ\)R\(\\theta\)^\{T\}=R\(\-\\theta\), the symmetric part of a block iscos⁡\(θ\)​I2\\cos\(\\theta\)I\_\{2\}, whence

QT​M​Q=diag⁡\(\(1−cos⁡θ1\)​I2,…,\(1−cos⁡θp\)​I2,0\)\.Q^\{T\}MQ=\\mathrm\{diag\}\\bigl\(\(1\-\\cos\\theta\_\{1\}\)I\_\{2\},\\dots,\(1\-\\cos\\theta\_\{p\}\)I\_\{2\},\\,0\\bigr\)\.\(3\.3\)AsQQis orthogonal, \([3\.3](https://arxiv.org/html/2608.19369#S3.E3)\) is at once a congruence and a similarity, so its diagonal entries are the eigenvalues ofMM, which is \([3\.1](https://arxiv.org/html/2608.19369#S3.E1)\); and1−cos⁡θk\>01\-\\cos\\theta\_\{k\}\>0forθk∈\(0,π\]\\theta\_\{k\}\\in\(0,\\pi\], which gives positive semidefiniteness and \([3\.2](https://arxiv.org/html/2608.19369#S3.E2)\)\. ∎

The proof is four lines, and this is itself the point: nothing in the construction could have produced an indefinite form, because a rotation never moves a vector further than antipodally\. It is worth stating what survives\. The integerpp, the number of two\-planes in which the chain has genuinely rotated, is a real invariant of the loop, and it is not visible in the deficit; what does not survive is the expectation that a signature carries more than a rank\.

The natural replacement is not far to seek\. SinceQT​R​QQ^\{T\}RQis determined up to permutation of the blocks by the multiset of angles, the complete invariant ofRRunder conjugation is the*angle spectrum*

Θ⁡\(R\):=\{θ1,…,θp\},\\Theta\(R\):=\\\{\\theta\_\{1\},\\dots,\\theta\_\{p\}\\\},\(3\.4\)equivalently the conjugacy class ofRRinSO⁡\(n\)\\mathrm\{SO\}\(n\), of which \([3\.2](https://arxiv.org/html/2608.19369#S3.E2)\) retains only the cardinality\. That the refinement is strict is immediate: forn≥4n\\geq 4any two rotations with two non\-trivial planes and different angles share the signature\(4,0,n−4\)\(4,0,n\-4\)and differ inΘ\\Theta\. We shall use throughout the scalar reduction

‖Θ⁡\(R\)‖2=\(∑k=1pθk2\)1/2,\\\|\\Theta\(R\)\\\|\_\{2\}=\\Bigl\(\\sum\_\{k=1\}^\{p\}\\theta\_\{k\}^\{2\}\\Bigr\)^\{1/2\},\(3\.5\)which we call the*rotation energy*ofRR, with the warning that it is a lossy summary ofΘ\\Thetaand is used for convenience of regression, not because it is canonical\.

## 4The holonomy of a linguistic loop

The deficit \([2\.5](https://arxiv.org/html/2608.19369#S2.E5)\) is a function of the two extreme states\. The loop matrix \([2\.7](https://arxiv.org/html/2608.19369#S2.E7)\) is a function of all of them\. The difference between the two is an object, and it is a familiar one\.

We begin by observing that the minimal rotation was not an arbitrary choice of interpolant\.

###### Lemma 4\.1\(The minimal rotation is parallel transport\)\.

Letx^,y^\\hat\{x\},\\hat\{y\}be distinct, non\-antipodal unit vectors ofℝn\\mathbb\{R\}^\{n\}andP=span⁡\(x^,y^\)P=\\mathrm\{span\}\(\\hat\{x\},\\hat\{y\}\)\. Thenℛ~x,y\\widetilde\{\\mathcal\{R\}\}^\{x,y\}is the parallel transport of the round metric ofSn−1S^\{n\-1\}along the minimising geodesic fromx^\\hat\{x\}toy^\\hat\{y\}, extended toℝn\\mathbb\{R\}^\{n\}as the ambient rotation fixingP⟂P^\{\\perp\}pointwise\.

###### Proof\.

The minimising geodesic is the arc of the great circleSn−1∩PS^\{n\-1\}\\cap P\. A fieldWWalong a geodesicccof the round sphere is parallel exactly when its ambient derivative is normal to the sphere, that is whenW′=−⟨W,c′⟩​cW^\{\\prime\}=\-\\langle W,c^\{\\prime\}\\rangle c\. DecomposingW=WP\+W⟂W=W\_\{P\}\+W\_\{\\perp\}, the componentW⟂W\_\{\\perp\}is constant, sinceccandc′c^\{\\prime\}lie inPP, whileWPW\_\{P\}rotates insidePPby the arclength travelled\. Transport is therefore the rotation byθ=arccos⁡\(x^⋅y^\)\\theta=\\arccos\(\\hat\{x\}\\cdot\\hat\{y\}\)insidePPtogether with the identity onP⟂P^\{\\perp\}\. WritingA=y^​x^T−x^​y^TA=\\hat\{y\}\\hat\{x\}^\{T\}\-\\hat\{x\}\\hat\{y\}^\{T\}one hasA​P⟂=0AP^\{\\perp\}=0, so \([2\.6](https://arxiv.org/html/2608.19369#S2.E6)\) is the identity onP⟂P^\{\\perp\}; onPPit carriesx^\\hat\{x\}toy^\\hat\{y\}preserving orientation and metric, hence it is the rotation byθ\\theta\. ∎

ThusR𝒰\\mathrm\{R\}\_\{\\mathcal\{U\}\}is parallel transport along the geodesic polygon joiningv^0,v^1,…,v^L\\hat\{v\}\_\{0\},\\hat\{v\}\_\{1\},\\dots,\\hat\{v\}\_\{L\}on the unit sphere of the embedding space, and the chain of reformulations is literally a path on a sphere\. The Wilson loop of\[[4](https://arxiv.org/html/2608.19369#bib.bib4)\]was not a metaphor\.

###### Proposition 4\.2\(Endpoint–path factorisation\)\.

LetV=\(v0,…,vL\)V=\(v\_\{0\},\\dots,v\_\{L\}\)be a chain as in \([2\.4](https://arxiv.org/html/2608.19369#S2.E4)\), withn≥3n\\geq 3and no two consecutive states antipodal\. PutRdir=ℛ~v0,vL\\mathrm\{R\}\_\{\\mathrm\{dir\}\}=\\widetilde\{\\mathcal\{R\}\}^\{v\_\{0\},v\_\{L\}\}and

H:=Rdir−1​R𝒰\.H:=\\mathrm\{R\}\_\{\\mathrm\{dir\}\}^\{\-1\}\\,\\mathrm\{R\}\_\{\\mathcal\{U\}\}\.\(4\.1\)Then

1. \(i\)H​v^0=v^0H\\hat\{v\}\_\{0\}=\\hat\{v\}\_\{0\}, so thatH∈Stab⁡\(v^0\)≅SO⁡\(n−1\)H\\in\\mathrm\{Stab\}\(\\hat\{v\}\_\{0\}\)\\cong\\mathrm\{SO\}\(n\-1\), andR𝒰=Rdir​H\\mathrm\{R\}\_\{\\mathcal\{U\}\}=\\mathrm\{R\}\_\{\\mathrm\{dir\}\}Hcanonically;
2. \(ii\)δ𝒰=1−⟨v^0,Rdir​v^0⟩\\delta\_\{\\mathcal\{U\}\}=1\-\\langle\\hat\{v\}\_\{0\},\\mathrm\{R\}\_\{\\mathrm\{dir\}\}\\hat\{v\}\_\{0\}\\rangledepends only onRdir\\mathrm\{R\}\_\{\\mathrm\{dir\}\}, and is therefore blind toHH;
3. \(iii\)HHis the Riemannian holonomy, based atv^0\\hat\{v\}\_\{0\}, of the closed geodesic polygon obtained by closing the path with the geodesic fromv^L\\hat\{v\}\_\{L\}back tov^0\\hat\{v\}\_\{0\};
4. \(iv\)for everyu∈Sn−1u\\in S^\{n\-1\}and everyH0∈Stab⁡\(v^0\)H\_\{0\}\\in\\mathrm\{Stab\}\(\\hat\{v\}\_\{0\}\)there is a chain with initial statev^0\\hat\{v\}\_\{0\}, final stateuuand holonomy exactlyH0H\_\{0\}\.

###### Proof\.

\(i\) By constructionℛ~vi−1,vi​v^i−1=v^i\\widetilde\{\\mathcal\{R\}\}^\{v\_\{i\-1\},v\_\{i\}\}\\hat\{v\}\_\{i\-1\}=\\hat\{v\}\_\{i\}, so by inductionR𝒰​v^0=v^L\\mathrm\{R\}\_\{\\mathcal\{U\}\}\\hat\{v\}\_\{0\}=\\hat\{v\}\_\{L\}; andRdir​v^0=v^L\\mathrm\{R\}\_\{\\mathrm\{dir\}\}\\hat\{v\}\_\{0\}=\\hat\{v\}\_\{L\}by definition\. SinceRdir\\mathrm\{R\}\_\{\\mathrm\{dir\}\}is orthogonal,H​v^0=RdirT​v^L=v^0H\\hat\{v\}\_\{0\}=\\mathrm\{R\}\_\{\\mathrm\{dir\}\}^\{T\}\\hat\{v\}\_\{L\}=\\hat\{v\}\_\{0\}\. An element ofSO⁡\(n\)\\mathrm\{SO\}\(n\)fixing a unit vector preserves its orthogonal hyperplane and restricts there to an element ofSO⁡\(n−1\)\\mathrm\{SO\}\(n\-1\)\.

\(ii\) Immediate from \([2\.5](https://arxiv.org/html/2608.19369#S2.E5)\), \([2\.3](https://arxiv.org/html/2608.19369#S2.E3)\) andv^L=Rdir​v^0\\hat\{v\}\_\{L\}=\\mathrm\{R\}\_\{\\mathrm\{dir\}\}\\hat\{v\}\_\{0\}\.

\(iii\) By Lemma[4\.1](https://arxiv.org/html/2608.19369#S4.Thmtheorem1),R𝒰\\mathrm\{R\}\_\{\\mathcal\{U\}\}andRdir\\mathrm\{R\}\_\{\\mathrm\{dir\}\}are the transports along the two paths, and \([4\.1](https://arxiv.org/html/2608.19369#S4.E1)\) is the transport around the closed circuit\.

\(iv\) It suffices to realise everyH0H\_\{0\}as the holonomy of a closed geodesic polygon based atv^0\\hat\{v\}\_\{0\}: appending the single geodesic leg fromv^0\\hat\{v\}\_\{0\}touumultiplies the loop matrix on the left byℛ~v^0,u\\widetilde\{\\mathcal\{R\}\}^\{\\hat\{v\}\_\{0\},u\}and leaves the holonomy unchanged\. Fix a two\-planeQ⊂v^0⟂Q\\subset\\hat\{v\}\_\{0\}^\{\\perp\}and an angleα∈\(0,2​π\)\\alpha\\in\(0,2\\pi\), and letΣ=Sn−1∩\(span⁡\(v^0\)⊕Q\)\\Sigma=S^\{n\-1\}\\cap\(\\mathrm\{span\}\(\\hat\{v\}\_\{0\}\)\\oplus Q\), a totally geodesic two\-sphere throughv^0\\hat\{v\}\_\{0\}whose tangent space there isQQ\. A geodesic triangle inΣ\\Sigmawith vertexv^0\\hat\{v\}\_\{0\}and areaα\\alphaexists, since the area of a geodesic triangle on the unit two\-sphere sweeps the whole of\(0,2​π\)\(0,2\\pi\); transport around a loop contained in a totally geodesic submanifold is the transport computed inside it, extended by the identity on the normal directions, so by Corollary[4\.3](https://arxiv.org/html/2608.19369#S4.Thmtheorem3)below the holonomy is the rotation ofQQbyα\\alphaand the identity elsewhere\. By the normal form used in Proposition[3\.1](https://arxiv.org/html/2608.19369#S3.Thmtheorem1), every element ofSO⁡\(n−1\)\\mathrm\{SO\}\(n\-1\)is a product of at most⌊\(n−1\)/2⌋\\lfloor\(n\-1\)/2\\rfloorsuch plane rotations, and the corresponding polygons, each beginning and ending atv^0\\hat\{v\}\_\{0\}, may be concatenated\. ∎

Part \(iv\) deserves a word, because it is what makes the factorisation worth having\. It says that the endpoint datum and the path datum are*free*: prescribing how far the meaning has drifted places no constraint whatever on how far the form has wandered, and conversely\. Incidentally the proof re\-establishes, without appeal to the classification of symmetric spaces, thatHol⁡\(Sn−1,v^0\)=SO⁡\(n−1\)\\mathrm\{Hol\}\(S^\{n\-1\},\\hat\{v\}\_\{0\}\)=\\mathrm\{SO\}\(n\-1\)\.

###### Corollary 4\.3\(Gauss–Bonnet\)\.

Forn=3n=3andL=2L=2the holonomy is the rotation of the tangent plane atv^0\\hat\{v\}\_\{0\}by the spherical excess of the geodesic trianglev^0​v^1​v^2\\hat\{v\}\_\{0\}\\hat\{v\}\_\{1\}\\hat\{v\}\_\{2\}, that is by its area\.

###### Proof\.

Gauss–Bonnet with Gaussian curvature11, the excess of a geodesic triangle beingA\+B\+C−πA\+B\+C\-\\pi\. ∎

This is the statement to keep in mind, and it is worth dwelling on\. On the two\-sphere the invariant that the semantic deficit throws away is the*area swept*by the chain of reformulations\. Two paraphrase chains ending at the same meaning differ by the area they enclose\. One should add, since the numerics will otherwise appear to fail, that the angle of a rotation is recovered from its eigenvalues only as a principal value in\(0,π\]\(0,\\pi\], so the holonomy determines the area outright when the triangle covers at most a hemisphere and modulo2​π2\\piin general\.

We shall use the scalar

η⁡\(𝒰\):=‖Θ⁡\(H\)‖2\\eta\(\\mathcal\{U\}\):=\\\|\\Theta\(H\)\\\|\_\{2\}\(4\.2\)and call it the*holonomy energy*of the chain\. It is, again, a lossy reduction: a null result forη\\etais not a null result forHH\.

## 5Watermarks as functionals on the loop

We now cross from the semantic channel to the channel in which a watermark actually lives\. The two are complementary, and the complementarity is the conceptual heart of this article: what a meaning\-preserving chain*preserves*is the semantic core, and what a watermark*occupies*is precisely the freedom that remains once the meaning is fixed\. The invariant and the carrier are, so to speak, dual coordinates on the same transformation\. A loop with small deficit and large holonomy is, from the point of view of the detector, the worst case\.

### 5\.1The intact\-window law

Fix a green\-list scheme with green fractionγ\\gamma, context widthh≥0h\\geq 0and biasδb\\delta\_\{b\}, detecting a sequencey0,…,yT−1y\_\{0\},\\dots,y\_\{T\-1\}by

z=G−γ​T′T′​γ​\(1−γ\),T′:=T−h,z=\\frac\{G\-\\gamma T^\{\\prime\}\}\{\\sqrt\{T^\{\\prime\}\\gamma\(1\-\\gamma\)\}\},\\qquad T^\{\\prime\}:=T\-h,\(5\.1\)whereGGcounts the scored positionst=h,…,T−1t=h,\\dots,T\-1at whichyty\_\{t\}lies in the green list seeded by\(yt−h,…,yt−1\)\(y\_\{t\-h\},\\dots,y\_\{t\-1\}\)\. Let an attack replace the tokens at a setEEof positions without changing the length, and define the*intact\-window set*

I:=\{t:h≤t<T,\[t−h,t\]∩E=∅\}\.I:=\\bigl\\\{\\,t:h\\leq t<T,\\ \[t\-h,\\,t\]\\cap E=\\emptyset\\,\\bigr\\\}\.\(5\.2\)
We assume, as is standard, that the hash behaves as a random oracle, so that green membership is an independent Bernoulli\(γ\)\(\\gamma\)across distinct pairs of seed and token; and that at each scored position of unattacked watermarked text the green indicator is Bernoulli\(γw\)\(\\gamma\_\{w\}\)withγw\>γ\\gamma\_\{w\}\>\\gamma, independently across positions\. The second is a mean\-field hypothesis and is the weaker of the two; we return to it below\.

###### Theorem 5\.1\(Intact\-window law\)\.

Under the two hypotheses above,

𝔼⁡\[zatt\]=\|I\|T′​𝔼​\[z0\]\.\\mathbb\{E\}\[z\_\{\\mathrm\{att\}\}\]=\\frac\{\|I\|\}\{T^\{\\prime\}\}\\;\\mathbb\{E\}\[z\_\{0\}\]\.\(5\.3\)

###### Proof\.

Fix a scored positiontt\. Ift∈It\\in Ithenyty\_\{t\}and its whole seeding window are those the generator produced, so the pair evaluated by the detector is the pair the generator evaluated, and it is green with probabilityγw\\gamma\_\{w\}\. Ift∉It\\notin Ithen either the window or the token differs, so the pair is one the generator never biased, and by the random\-oracle hypothesis its green indicator is a fresh Bernoulli\(γ\)\(\\gamma\)\. Summing,

𝔼⁡\[Gatt\]=\|I\|γw\+\(T′−\|I\|\)​γ=γ​T′\+\|I\|\(γw−γ\),\\mathbb\{E\}\[G\_\{\\mathrm\{att\}\}\]=\|I\|\\gamma\_\{w\}\+\(T^\{\\prime\}\-\|I\|\)\\gamma=\\gamma T^\{\\prime\}\+\|I\|\(\\gamma\_\{w\}\-\\gamma\),\(5\.4\)and substituting into \([5\.1](https://arxiv.org/html/2608.19369#S5.E1)\) gives𝔼⁡\[zatt\]=\|I\|\(γw−γ\)/T′​γ​\(1−γ\)\\mathbb\{E\}\[z\_\{\\mathrm\{att\}\}\]=\|I\|\(\\gamma\_\{w\}\-\\gamma\)/\\sqrt\{T^\{\\prime\}\\gamma\(1\-\\gamma\)\}\. The same computation with\|I\|=T′\|I\|=T^\{\\prime\}gives𝔼⁡\[z0\]\\mathbb\{E\}\[z\_\{0\}\], and the ratio is \([5\.3](https://arxiv.org/html/2608.19369#S5.E3)\)\. ∎

The identity is deterministic in\|I\|\|I\|; no distribution over the edits has been assumed\. It is only when one wishes to compute\|I\|\|I\|that a model of the attack becomes necessary, and the model the field has implicitly been using is the independent one\.

###### Corollary 5\.2\(Context\-width decay law\)\.

If each position is retained independently with probabilityρ\\rho, then𝔼​\|I\|=ρh\+1​T′\\mathbb\{E\}\|I\|=\\rho^\{h\+1\}T^\{\\prime\}and

𝔼⁡\[zatt\]=ρh\+1​𝔼​\[z0\]\.\\mathbb\{E\}\[z\_\{\\mathrm\{att\}\}\]=\\rho^\{h\+1\}\\,\\mathbb\{E\}\[z\_\{0\}\]\.\(5\.5\)The signal decays exponentially in the context width and only linearly in the retention rate\.

Equation \([5\.5](https://arxiv.org/html/2608.19369#S5.E5)\) is, in closed form, the trend that\[[8](https://arxiv.org/html/2608.19369#bib.bib8)\]reported empirically\. It also explains a phenomenon familiar to anyone who has attacked such a scheme by hand: the signal falls considerably faster than the fraction of altered words, and it falls faster the longer the seeding context\. Since𝔼⁡\[z0\]\\mathbb\{E\}\[z\_\{0\}\]grows asT′\\sqrt\{T^\{\\prime\}\}, one obtains at once the length required for detection at a fixed thresholdz∗z^\{\*\},

T′≥\(z∗\)2​γ​\(1−γ\)\(ρh\+1​\(γw−γ\)\)2,T^\{\\prime\}\\;\\geq\\;\\frac\{\(z^\{\*\}\)^\{2\}\\gamma\(1\-\\gamma\)\}\{\\bigl\(\\rho^\{h\+1\}\(\\gamma\_\{w\}\-\\gamma\)\\bigr\)^\{2\}\},\(5\.6\)which grows likeρ−2​\(h\+1\)\\rho^\{\-2\(h\+1\)\}and quantifies the published warning that short passages carry no reliable signal\.

### 5\.2Why the retention rate is the wrong statistic

Real edits are not independent\. A translator rewrites clauses, not tokens; a human editor works on paragraphs\. The following is therefore not a curiosity but the typical case\.

###### Proposition 5\.3\(Arrangement dominates the rate\)\.

Fix the retention rateρ=1−\|E\|/T\\rho=1\-\|E\|/T\. Then

1. \(i\)ifEEis a single contiguous run,\|I\|≥T′−\|E\|−h\|I\|\\geq T^\{\\prime\}\-\|E\|\-h, so the residual ratio is at leastρ−h/T′\\rho\-h/T^\{\\prime\},*independently ofhh*;
2. \(ii\)ifEEconsists ofbbmaximal contiguous runs,\|I\|≥T′−\|E\|−h​b\|I\|\\geq T^\{\\prime\}\-\|E\|\-hb;
3. \(iii\)ifEEcontains an arithmetic progression of stepk≤h\+1k\\leq h\+1covering\[0,T\)\[0,T\), thenI=∅I=\\emptysetand the expected residual is exactly zero\.

Consequently, whenever1−ρ≥1/\(h\+1\)1\-\\rho\\geq 1/\(h\+1\), the residual ratio ranges over essentially the whole of\[0,ρ\]\[0,\\rho\]as the arrangement varies at fixedρ\\rho\.

###### Proof\.

A scored position leavesIIonly if its window ofh\+1h\+1consecutive positions meetsEE\. For a single run of length\|E\|\|E\|the windows meeting it are those witht∈\[min⁡E,max⁡E\+h\]t\\in\[\\min E,\\max E\+h\], at most\|E\|\+h\|E\|\+hof them, which is \(i\); withbbruns the bound is additive, which is \(ii\)\. IfEEcontains everykk\-th position withk≤h\+1k\\leq h\+1, every window ofh\+1h\+1consecutive positions contains a member ofEE, soI=∅I=\\emptysetand Theorem[5\.1](https://arxiv.org/html/2608.19369#S5.Thmtheorem1)gives zero\. ∎

The consequence is worth stating without euphemism\. An adversary who knowshh— andhhis a published design parameter, not a secret — can reduce the expected detector statistic to zero while retaining a fraction1−1/\(h\+1\)1\-1/\(h\+1\)of the tokens\. For the common choiceh=1h=1this means editing one token in two; forh=3h=3, one in four\. Nothing in the attack requires knowledge of the key\. This is not a new attack so much as an exact accounting of a known design tension\[[8](https://arxiv.org/html/2608.19369#bib.bib8),[11](https://arxiv.org/html/2608.19369#bib.bib11)\], but we have not found it written down in this form, and its corollary — that a robustness table indexed by retention rate or by endpoint similarity is under\-specified — appears not to have been drawn\.

### 5\.3Scope

It is worth being explicit about what has*not*been proved\. Theorem[5\.1](https://arxiv.org/html/2608.19369#S5.Thmtheorem1)concerns substitutions that preserve length\. Insertions and deletions shift the indices, and the correct generalisation replacesIIby the set of positions whose window survives as a contiguous block of the attacked text; the identity then holds only approximately\. The mean\-field hypothesis onγw\\gamma\_\{w\}is false in real text, where entropy varies strongly with content, so that \([5\.3](https://arxiv.org/html/2608.19369#S5.E3)\) is an*upper*bound on what survives in the wild\. And nothing here concerns any undisclosed production scheme: the deployment recalled in the introduction motivates the question and is not an object of measurement\.

## 6Experiments

Three experiments are reported\. The first verifies numerically that the propositions describe the objects the pipeline computes\. The second tests Theorem[5\.1](https://arxiv.org/html/2608.19369#S5.Thmtheorem1)and Proposition[5\.3](https://arxiv.org/html/2608.19369#S5.Thmtheorem3)against exact detectors\. The third applies the geometry to real chains of round\-trip machine translation, and executes a test whose criterion was fixed in writing before any measurement was taken\. All code, run directories and manifests are described in Section[6\.4](https://arxiv.org/html/2608.19369#S6.SS4)\.

### 6\.1The geometry

Over300300pseudo\-random chains in each of the dimensionsn∈\{8,16,64,384\}n\\in\\\{8,16,64,384\\\}, with chain lengths in\{2,3,4,6,8\}\\\{2,3,4,6,8\\\}, the worst deviations observed were: minimum eigenvalue ofIn−R𝒰∗I\_\{n\}\-\\mathrm\{R\}^\{\*\}\_\{\\mathcal\{U\}\}equal to−6\.1×10−15\-6\.1\\times 10^\{\-15\}; negative indexn−=0n\_\{\-\}=0in every case;\|n\+−2​p\|=0\|n\_\{\+\}\-2p\|=0in every case;‖H​v^0−v^0‖=3\.3×10−12\\\|H\\hat\{v\}\_\{0\}\-\\hat\{v\}\_\{0\}\\\|=3\.3\\times 10^\{\-12\}; and‖Rdir​H−R𝒰‖=5\.9×10−12\\\|\\mathrm\{R\}\_\{\\mathrm\{dir\}\}H\-\\mathrm\{R\}\_\{\\mathcal\{U\}\}\\\|=5\.9\\times 10^\{\-12\}\. This is Propositions[3\.1](https://arxiv.org/html/2608.19369#S3.Thmtheorem1)and[4\.2](https://arxiv.org/html/2608.19369#S4.Thmtheorem2)at machine precision\.

Independence, part \(iv\) of Proposition[4\.2](https://arxiv.org/html/2608.19369#S4.Thmtheorem2), is exhibited directly\. A family of chains with a prescribed common endpoint, wandering through an increasing number of extra dimensions, gives a semantic deficit constant at0\.122417440\.12241744with spread exactly zero, while the holonomy energy runs from00to1\.04651\.0465\(Table[2](https://arxiv.org/html/2608.19369#S6.T2)\)\.

Table 2:*This table summarizes the independence of the endpoint and path data, in dimensionn=64n=64\. All seven chains share the same first and last state, so the semantic deficit is constant to the last recorded digit; the holonomy energy is not\. Note also that the signature, in the last column, moves in steps and is constant on pairs of rows, exactly as Proposition[3\.1](https://arxiv.org/html/2608.19369#S3.Thmtheorem1)predicts it must\.*Corollary[4\.3](https://arxiv.org/html/2608.19369#S4.Thmtheorem3)is verified on random geodesic triangles of the two\-sphere: for the159159of200200triangles of area at mostπ\\pi, the holonomy angle and the spherical excess agree to better than1\.8×10−91\.8\\times 10^\{\-9\}; the remainder agree after reduction to the principal branch, as the corollary says they must\. Finally, the blindness of the signature is visible in the data: among random chains sharing the signature\(8,0,56\)\(8,0,56\), the rotation energy ranges over\[0\.937,1\.464\]\[0\.937,1\.464\]and the holonomy energy over\[0\.365,0\.791\]\[0\.365,0\.791\]\.

### 6\.2The intact\-window law against exact detectors

To test Theorem[5\.1](https://arxiv.org/html/2608.19369#S5.Thmtheorem1)one needs a detector whose key one holds and a generator whose entropy one controls\. We therefore emit from a Zipf distribution over a vocabulary of40004000with a freshly permuted support at each step, which fixes the entropy by construction, and watermark it with our own implementations of the green\-list scheme ath∈\{0,1,2,3\}h\\in\\\{0,1,2,3\\\}and of the context\-seeded exponential scheme, usingγ=0\.25\\gamma=0\.25andδb=2\.0\\delta\_\{b\}=2\.0\. Sequences are400400tokens long and each condition is averaged over120120of them\.

Under independent edits, the mean absolute deviation between the observed ratio andρh\+1\\rho^\{h\+1\}, over the seven values ofρ\\rhofrom11down to0\.50\.5, is0\.00230\.0023,0\.00230\.0023,0\.00220\.0022and0\.00210\.0021forh=0,1,2,3h=0,1,2,3, and0\.00110\.0011for the exponential scheme\. Atρ=0\.5\\rho=0\.5the observed ratios are0\.4990\.499,0\.2470\.247,0\.1250\.125and0\.0650\.065against the predicted0\.5000\.500,0\.2500\.250,0\.1250\.125and0\.0630\.063\. Corollary[5\.2](https://arxiv.org/html/2608.19369#S5.Thmtheorem2)is confirmed across two decades of the ratio and across both families\.

The consequence of Proposition[5\.3](https://arxiv.org/html/2608.19369#S5.Thmtheorem3)is more striking, and is collected in Table[3](https://arxiv.org/html/2608.19369#S6.T3)\. At one and the same retention rate, the residual signal depends only on where the edits fall\. Atρ=0\.5\\rho=0\.5withh=1h=1, the same half of the tokens survives in all three columns and the residual statistic is one half of the original, one quarter of it, or nothing at all\.

Table 3:*Residual detector statistic, as a fraction of the original, for the green\-list scheme withh=1h=1under three edit patterns of identical retention rate\. Counting the intact\-window set directly from each edit pattern, Theorem[5\.1](https://arxiv.org/html/2608.19369#S5.Thmtheorem1)predicts0\.947,0\.897,0\.797,0\.697,0\.597,0\.4960\.947,0\.897,0\.797,0\.697,0\.597,0\.496for the middle column and0\.902,0\.802,0\.602,0\.401,0\.201,0\.0000\.902,0\.802,0\.602,0\.401,0\.201,0\.000for the right\-hand one\. The largest discrepancy is0\.0080\.008and the typical one0\.0030\.003, over120120sequences per cell; and the periodic pattern atρ=0\.5\\rho=0\.5is predicted to give exactly zero, and does\.*
### 6\.3Real transformation chains

The two experiments reported so far measure objects that we ourselves built\. The third measures text\.

From thirty open\-ended prompts spread over five domains we generate, with a0\.50\.5B instruction\-tuned model at temperature one, one hundred and eighty new tokens under each of the three schemes: the green\-list scheme ath=1h=1, the unigram scheme ath=0h=0, and the context\-seeded exponential scheme\. The keys are ours, so every detector statistic below is exact and not an estimate\. The ninety passages so obtained have medianz0z\_\{0\}equal to9\.629\.62,9\.309\.30and19\.0519\.05respectively, and every single one of them is detected abovez=4z=4: they are the population on which an attack can be said to do anything at all\.

Each passage then travels six chains of round\-trip machine translation, sentence by sentence, through the Opus\-MT models: three single round trips, through German, French and Spanish; two chains of two pivots, one through German and then French and one through German twice; and a three\-pivot detour through French, German and Spanish\. Every return to English is a waypoint at which the exact detector is run, and every waypoint — the German, French and Spanish ones included — is embedded by a multilingual encoder of dimension384384, so that the invariants of Sections[3](https://arxiv.org/html/2608.19369#S3)and[4](https://arxiv.org/html/2608.19369#S4)are computed along the chain as it is actually traversed and not along its English shadow\. The retention rateρ\\rhoand the intact\-window fraction\|I\|/T′\|I\|/T^\{\\prime\}are not modelled but measured, by longest\-common\-subsequence alignment on the tokenizer’s own token ids, which are the objects the detector sees\. Consecutive waypoints never come near to being antipodal — over all540540chains the smallest cosine similarity between neighbours is0\.1480\.148— so the minimal rotation of Section[2](https://arxiv.org/html/2608.19369#S2)is everywhere well defined\.

Table 4:*The six chains; medians over the ninety passages of the three schemes, except the last column, which counts the chains still detected abovez=4z=4\. Ordered by semantic deficit, every column moves monotonically: the meaning drifts, the path lengthens, the surface is retained less and the mark fades, all together\. That is precisely why the endpoint alone cannot be read as a measure of attack strength, and why the test below holds it fixed\.*Table[4](https://arxiv.org/html/2608.19369#S6.T4)collects what the chains do\. Of the540540attacked passages,464464are still detected abovez=4z=4—173173of the180180unigram chains,165165of the exponential ones and126126of the green\-list ones — so round\-trip translation at this depth is an erosion and not an erasure\. It is worth seeing where it does erase\. The green\-list scheme carried through French, German and Spanish has a median residualzzof3\.983\.98, which is below the threshold, while the same three pivots leave the unigram scheme at5\.885\.88and the exponential one at8\.908\.90; but the exponential scheme starts from a much higherz0z\_\{0\}, so the honest comparison is between fractions, and there the context\-free scheme retains0\.6850\.685of its statistic against0\.5090\.509and0\.6010\.601for the two schemes that seed on a context\. That is the ordering Corollary[5\.2](https://arxiv.org/html/2608.19369#S5.Thmtheorem2)demands: what cannot be broken is a window of one\.

*The intact\-window law on real text\.*Theorem[5\.1](https://arxiv.org/html/2608.19369#S5.Thmtheorem1)was proved for substitutions that preserve length, and translation preserves nothing of the kind\. The correction is not a new hypothesis but the same theorem with the normalisation of the statistic carried through: all three detectors divide by the square root of the number of scored positions, so if the attacked text offersTatt′T^\{\\prime\}\_\{\\mathrm\{att\}\}of them against the original’sT0′T^\{\\prime\}\_\{0\}, then

𝔼⁡\[zatt\]𝔼⁡\[z0\]=\|I\|T0′​Tatt′=\|I\|T0′​T0′Tatt′,\\frac\{\\mathbb\{E\}\[z\_\{\\mathrm\{att\}\}\]\}\{\\mathbb\{E\}\[z\_\{0\}\]\}=\\frac\{\|I\|\}\{\\sqrt\{T^\{\\prime\}\_\{0\}\\,T^\{\\prime\}\_\{\\mathrm\{att\}\}\}\}=\\frac\{\|I\|\}\{T^\{\\prime\}\_\{0\}\}\\,\\sqrt\{\\frac\{T^\{\\prime\}\_\{0\}\}\{T^\{\\prime\}\_\{\\mathrm\{att\}\}\}\},\(6\.1\)the intact\-window fraction times a factor which is one when the length is preserved\. Table[5](https://arxiv.org/html/2608.19369#S6.T5)compares both forms with what the detectors actually returned\.

Table 5:*Theorem[5\.1](https://arxiv.org/html/2608.19369#S5.Thmtheorem1)against the538538chains whose statistic is finite; medians\. The measured intact\-window fraction predicts the median residual to within one hundredth for the context\-free scheme, three for the green\-list scheme and seven for the exponential one\. The independent\-edit corollaryρh\+1\\rho^\{h\+1\}, which needs no measurement of the attacked text at all, happens to fall closer for the green\-list scheme and much further for the exponential one, where it is off by twelve hundredths; and chain by chain it is the measured fraction that follows the residual, correlating\+0\.67\+0\.67with it against\+0\.54\+0\.54for the retention rate\. The median absolute error per chain is0\.0830\.083,0\.0540\.054and0\.0880\.088, which the length correction of \([6\.1](https://arxiv.org/html/2608.19369#S6.E1)\) moves to0\.0860\.086,0\.0670\.067and0\.0810\.081: at this depth of translation the length is preserved in the median, and the correction has little to do\.*The medians agree; the scatter chain by chain does not vanish, and it should not, since the mean\-field hypothesis of Section[5](https://arxiv.org/html/2608.19369#S5)is false in real text, where entropy varies from one sentence to the next\. One caution about the instrument is due here: the intact\-window count is read off the longest common subsequence of the two token strings and does not verify that a surviving window is still contiguous in the attacked text, so\|I\|/T′\|I\|/T^\{\\prime\}is an upper bound on the number of intact windows the detector really meets\. Both green\-list schemes do come out just below it\. The exponential scheme comes out above, which we record without explaining: its statistic is a sum of continuous scores and not a count of successes, and the mean\-field hypothesis bites differently there\. What is more interesting is a sign\. Pooled over all chains, the correlation between the intact\-window fraction and the residual is\+0\.51\+0\.51for the green\-list scheme and\+0\.67\+0\.67for the exponential one, but−0\.21\-0\.21for the unigram scheme — as though, for the one scheme where the law is simplest, retaining more of the text destroyed more of the mark\. It does not\. A pooled correlation compares passages with one another, and passages differ in entropy, in length, and in how much watermark was ever in them; the law speaks about one passage carried along attacks of differing severity\. Computed within each passage, across the six chains that passage travels, the correlation is\+0\.73\+0\.73for the green\-list scheme and\+0\.68\+0\.68for each of the other two, and it is positive in2828,2828and2929of the thirty passages\. The anomaly is an instance of Simpson’s paradox, and we report it because the pooled number, taken by itself, would have been read as evidence against a theorem which the same data in fact support\.

One family of chains deserves to be named rather than averaged away\. In nine chains the residualzzfalls below−3\-3, and in two more the exponentialpp\-value underflows to one, which sends its normal\-equivalent statistic to−∞\-\\inftyand removes those two from the regressions below\. All but one of the eleven show the text expanding, in the extreme case from180180tokens to881881, and they come from only five of the ninety passages: the translator has fallen into repetition\. Repetition is exactly the circumstance in which the random\-oracle hypothesis fails outright, since one repeated pair of context and token is scored again and again and the effective number of independent positions collapses\. Such chains are reported and not trimmed\.

*The preregistered test\.*The criterion was fixed in writing before any measurement was taken\. In a regression of the residual ratio on the retention rate, the semantic deficit and the holonomy energy, the partial coefficient onη\\etawas required to be negative and significant atα=0\.01\\alpha=0\.01, Bonferroni corrected for the three schemes, in at least two of them; failing that, the path\-dependence claim was to be recorded as refuted and reported as a negative result\. Table[6](https://arxiv.org/html/2608.19369#S6.T6)gives the outcome\. The criterion is met\. The coefficient onη\\etais negative in all three schemes and clears the corrected threshold of3\.3×10−33\.3\\times 10^\{\-3\}in two of them, the unigram scheme by five orders of magnitude and the green\-list scheme by a factor of two\.

Table 6:*The preregistered regression\. The predictors are standardised, so that the coefficients may be compared; the corrected threshold is3\.3×10−33\.3\\times 10^\{\-3\}\. The last column is a robustness check which the clause did not ask for: the same coefficient with a standard error clustered on the base passages, of which there are only thirty, so that the check is a severe one\. Under it the unigram scheme still clears the threshold and the green\-list scheme no longer does\.*We would rather state the result at its strongest defensible level than at its most flattering one\. The six chains of a scheme are applied to the same thirty passages, so the observations are clustered and the classical standard error is optimistic\. Clustered on the passage, the unigram coefficient stands atp=8\.2×10−4p=8\.2\\times 10^\{\-4\}and the green\-list one moves top=3\.5×10−2p=3\.5\\times 10^\{\-2\}, which is significant at five per cent and not at the corrected one\. Absorbing the passage altogether — so that each chain is compared only with the other five chains of the same text, which is the comparison this whole article is about — the coefficient onη\\etabecomes−0\.11\-0\.11for the green\-list scheme,−0\.14\-0\.14for the unigram one and−0\.13\-0\.13for the exponential one: all negative, and now of one size, withppequal to2\.5×10−22\.5\\times 10^\{\-2\},2\.1×10−42\.1\\times 10^\{\-4\}and0\.130\.13respectively\. The honest summary is this\. With the passage held fixed, a chain that wanders further destroys more of the mark at equal retention and equal endpoint, by an amount which is stable across all three schemes; the evidence that this is not chance is decisive for the context\-free scheme, good for the green\-list scheme and inconclusive for the exponential one; and thirty clusters are few\.

One further number belongs in the reader’s hands before the result is weighed\. In this corpus the two geometric quantities are far from independent: the correlation betweenδ𝒰\\delta\_\{\\mathcal\{U\}\}andη⁡\(𝒰\)\\eta\(\\mathcal\{U\}\)is\+0\.85\+0\.85for the green\-list scheme,\+0\.91\+0\.91for the unigram one and\+0\.90\+0\.90for the exponential one, and within a passage it is scarcely lower, at\+0\.86\+0\.86,\+0\.89\+0\.89and\+0\.80\+0\.80\. Round\-trip translation lengthens the path and moves the endpoint together; Proposition[4\.2](https://arxiv.org/html/2608.19369#S4.Thmtheorem2)\(iv\) says that the two data are free, but this corpus does not exercise that freedom, and a family of chains engineered to hold the one while varying the other — a larger experiment than this one — would be the natural next step\. Two consequences follow\. The separate coefficients of Table[6](https://arxiv.org/html/2608.19369#S6.T6)are not separate effects: two nearly collinear predictors entering with opposite signs are a suppression pair, and that is what produces the positive coefficient on the semantic deficit in the unigram row — a coefficient which survives absorbing the passage, and which we can describe but not explain\. And the preregistered test is a demanding one, since onceδ\\deltais held only a fifth to a quarter of the variation ofη\\etais left to carry any effect at all; that it is significant nonetheless, in two schemes of three, is the fact worth taking away\.

The matched\-delta strata, which are the design the criterion was written for, tell the same story from the other side\. Within the four bands of semantic deficit the rank correlation between the holonomy energy and the residual is negative in all four for the green\-list scheme, at−0\.46\-0\.46,−0\.46\-0\.46,−0\.23\-0\.23and−0\.53\-0\.53\. And among the ninety\-five chains whose semantic deficit lies between0\.050\.05and0\.070\.07— as matched an endpoint as this instrument can deliver — the holonomy energy ranges over a factor of nearly three, from0\.0530\.053to0\.1460\.146, while the residual runs from0\.2850\.285to0\.9980\.998\. Two chains may bring a text to the same meaning and leave, the one of them, essentially the whole mark, and the other, less than a third of it\.

*What the encoder can and cannot see\.*One caveat is ours to raise before a referee raises it\. The encoder is multilingual, and a multilingual encoder is by design nearly invariant under translation: it places a German waypoint almost on top of its English source\. That is the property which makes it the right instrument for the semantic deficit and a poor one for the path, since it flattens the very excursion the holonomy is meant to record\. The effect is measurable: over the268268chains with more than one pivot the median holonomy energy is0\.1170\.117along the full chain and0\.0560\.056when only the English waypoints are kept\. The remaining270270chains are single round trips, whose two English waypoints determine no holonomy whatever — a loop through two points is its own direct rotation andHHis the identity exactly\. Repeating the regression on the English waypoints alone, which is exploratory and was not preregistered, the coefficient on the holonomy energy is−0\.128\-0\.128for the unigram scheme \(p=5\.4×10−6p=5\.4\\times 10^\{\-6\}\),−0\.081\-0\.081for the exponential one \(p=0\.065p=0\.065\) and−0\.029\-0\.029for the green\-list one \(p=0\.41p=0\.41\)\. It does not change the verdict, and it was not permitted to\.

Three things this experiment does not establish\. It does not establish thatη\\etais causal: a chain that wanders further is also a chain that has been rewritten more, and nothing reported here separates the two\. It does not transfer to learned paraphrasers, which choose their path adversarially where round\-trip translation chooses it only incidentally\. And it rests on a single embedder, so thatδ\\deltaandη\\etaare both defined by one encoder’s idea of meaning; replication across encoders is the first thing we should do with more compute than this article had\.

### 6\.4Reproducibility

The watermark keys are ours, so every detection statistic reported here is ground truth and not an estimate\. A detector whose key one holds is nevertheless still an implementation, and an implementation deserves to be audited before it is believed; since the three schemes are re\-implemented here rather than imported, there are no published numbers to reproduce, and what remains available is self\-calibration\. On400400token streams of length400400not produced with the key, the realised green fraction isγ\\gammato within sampling error \(0\.24750\.2475,0\.25080\.2508and0\.24980\.2498forh=1,2,3h=1,2,3againstγ=0\.25\\gamma=0\.25\); the nullzz\-statistic has mean and standard deviation\(−0\.11,0\.99\)\(\-0\.11,0\.99\),\(0\.04,0\.97\)\(0\.04,0\.97\)and\(−0\.01,1\.03\)\(\-0\.01,1\.03\)in the same three conditions, at Kolmogorov–Smirnov distance0\.0700\.070,0\.0640\.064and0\.0560\.056from the standard normal; and no stream in any condition reachedz=4z=4\. Watermarked text scored with a key other than the one that produced it gives a meanzzof−0\.03\-0\.03,\+0\.03\+0\.03and−0\.29\-0\.29for the green\-list, the unigram and the exponential scheme, with unit standard deviation and no false alarm, while the same text scored with the correct key is detected in every single case, at meanzzof20\.820\.8,20\.920\.9and37\.037\.0\. Thepp\-values of the exponential scheme are uniform under the null \(Kolmogorov–Smirnov0\.0440\.044,p=0\.40p=0\.40\)\.

One asymmetry is worth recording, because it belongs to the scheme and not to our implementation of it\. Forh=0h=0the green list is fixed for the whole text, so the null is key\-dependent by construction: the statistic is centred not onγ\\gammabut on the green fraction of the particular key, and that displacement has standard deviationT/\|V\|\\sqrt\{T/\|V\|\}across keys\. Over2424keys we measure0\.3280\.328against the predicted0\.3160\.316\. At the synthetic vocabulary of40004000used for the calibration the effect is plainly visible; at the vocabulary of a real tokenizer it is0\.030\.03and negligible\. The context\-free scheme is thus marginally the harder of the two to calibrate, which is the reverse of the robustness ordering established in Section[5](https://arxiv.org/html/2608.19369#S5), and a small irony of the design space\.

Table 7:*Every numerical claim of Section[6](https://arxiv.org/html/2608.19369#S6)and the run that produced it\. Directory names are the script name prefixed byrun\_and suffixed by the stamp of the third column, under7\. Results/Article\_LLW/\. The corpus was built in three successive invocations, each carrying forward the chains of the one before, so that an interruption on a machine of this size would cost at most one of them; the stamp given is that of the last, whose manifest records the provenance of the other two\. The final row is the targeted re\-audit of the records which had failed to regenerate, discussed below\.*The models are open\-weights and named in the manifests: a0\.50\.5B instruction\-tuned generator, the Opus\-MT sentence translators for the three pivot languages, and a multilingual sentence encoder of dimension384384for the embeddingψ\\psi\. Generation is deterministic given the model revision, the seed and the key — very nearly, and the exception is worth a paragraph, since it is the sort of thing a reproducibility section usually asserts without looking\. We looked\. Regenerating all ninety stored completions from scratch and comparing them token by token, eighty\-seven came back identical and three diverged, each after a long common prefix:8282,153153and173173tokens of180180\. Regenerating the divergent ones again is instructive\. Two of them diverge every single time, four attempts of four, and always at exactly the same token; the third reproduces itself four times of four, as does a fourth record which had diverged in an earlier sweep\. Regeneration is therefore deterministic within a process and not across processes: the order in which a CPU kernel accumulates a sum depends on the state of the process it runs in, and a difference in the last bits of a logit is enough to move a multinomial sampling boundary, after which the continuation goes its own way\. Two passages of the ninety sit close enough to such a boundary that the process which produced them cannot now be reproduced on this machine at all\. Every number in this article is computed from the stored corpus, whose hash is in the manifest, and the audit says how faithfully that corpus regenerates — a weaker claim than bit\-exact reproducibility, and the true one\.

This is deliberately the small, CPU\-sized version of the testbed: the scale\-up to a larger generator and to learned paraphrasers is stated in Section[7](https://arxiv.org/html/2608.19369#S7)as work to be done, and is not claimed here\. The scripts, the generated corpora, the run directories with their logs and manifests, and the derived measurements from which every number of this section is computed are all in the repository named at the head of this section; the manifests carry the hashes, so that a regeneration may be checked against what was actually run\.

## 7Conclusions and Future Developments

In this work we have taken up the formalism of linguistic loops and carried it to a place where it can be tested\. We proved that the Sylvester signature proposed as the invariant of a loop is always positive semidefinite and therefore degenerates to a rank, the complete invariant being the angle spectrum; that the loop rotation is parallel transport on the unit sphere of the embedding space, so that the chain of reformulations is a path and its residue a holonomy; that this holonomy lies in the stabiliser of the initial state and is exactly what the semantic deficit discards, the two data being functionally independent; and, on the side of the detector, that the residual statistic of a context\-seeded watermark is proportional to the number of positions whose seeding window survived intact\.

It is mesmerizing, and we cannot help but observe it, how neatly the two halves of the picture fit\. What a meaning\-preserving chain preserves is an invariant; what a watermark occupies is the complement of that invariant; and the geometric object which measures the complement — a holonomy inSO⁡\(n−1\)\\mathrm\{SO\}\(n\-1\)— turns out on the two\-sphere to be nothing more exotic than the area swept by the path\. That the same construction which was proposed as a way toward pre\-verbal thought should also measure the erosion of a provenance mark is, in our humble opinion, a point in favour of the construction\.

Three limitations are ours to state\. The intact\-window identity assumes substitutions that preserve length and a mean\-field hypothesis on the strength of the mark; in real text, where entropy varies with content, it is an upper bound\. The holonomy energyη\\etais a lossy scalar reduction ofHH, and a null result for the former is not a null result for the latter\. And the empirical layer of this article is bounded by the compute available to it: a small generator, one attack family, one embedder\.

It would be then definitely interesting to analyse whether a*holonomy\-aware*watermark can be constructed — one whose seeding depends on a quantity invariant under the transport, rather than on the raw token window, and which would therefore be insensitive to the arrangement of the edits in the way that Proposition[5\.3](https://arxiv.org/html/2608.19369#S5.Thmtheorem3)shows the present schemes are not\. The semantic schemes of\[[6](https://arxiv.org/html/2608.19369#bib.bib6)\]are a first step in that direction, and it would be natural to evaluate them with the instrument developed here rather than with an endpoint similarity\. In a forthcoming work we intend to study the holonomy of chains produced by learned paraphrasers rather than by translation, where the path is chosen adversarially and the geometry should be correspondingly richer\. All in all, we have presented evidence that the robustness of a watermark is a functional of the path and not of its endpoint, and that the natural language in which to say so is that of parallel transport\.

## Use of Generative AI

The implementation of the reproducibility certificates listed in Section[6\.4](https://arxiv.org/html/2608.19369#S6.SS4)was supported by AI\-assisted code generation \(Claude Opus, Anthropic\) under the author’s direction; all certificates were independently inspected, run, and validated by the author\. AI tools were also used for language editing during manuscript preparation\. The author conceived the mathematical content, designed and verified the proofs, and takes full responsibility for the content of this article\.

## Acknowledgments

## References

- \[1\]Anthropic,*How Claude marks AI\-generated content*, Help Center article 16266773, August 2026\.
- \[2\]M\. Christ, S\. Gunn, O\. Zamir,*Undetectable Watermarks for Language Models*, COLT 2024\.
- \[3\]*Chainwash: Multi\-Step Rewriting Attacks on Diffusion Language Model Watermarks*, arXiv:2605\.05503, 2026\.
- \[4\]D\. Corradetti, A\. Marrani,*Linguistic Loops and Geometric Invariants as a Way to Pre\-Verbal Thought?*, arXiv:2503\.23311, 2025\.
- \[5\]S\. Dathathri*et al\.*,*Scalable watermarking for identifying large language model outputs*, Nature, 2024\.
- \[6\]A\. Hou*et al\.*,*SemStamp: A Semantic Watermark with Paraphrastic Robustness for Text Generation*, NAACL 2024\.
- \[7\]J\. Kirchenbauer, J\. Geiping, Y\. Wen, J\. Katz, I\. Miers, T\. Goldstein,*A Watermark for Large Language Models*, ICML 2023\.
- \[8\]J\. Kirchenbauer*et al\.*,*On the Reliability of Watermarks for Large Language Models*, ICLR 2024\.
- \[9\]K\. Krishna, Y\. Song, M\. Karpinska, J\. Wieting, M\. Iyyer,*Paraphrasing evades detectors of AI\-generated text, but retrieval is an effective defense*, NeurIPS 2023\.
- \[10\]R\. Kuditipudi, J\. Thickstun, T\. Hashimoto, P\. Liang,*Robust Distortion\-free Watermarks for Language Models*, TMLR 2024\.
- \[11\]*No Free Lunch in LLM Watermarking: Trade\-offs in Watermarking Design Choices*, arXiv:2402\.16187, 2024\.
- \[12\]J\. Piet, C\. Sitawarin*et al\.*,*Mark My Words: Analyzing and Evaluating Language Model Watermarks*, arXiv:2312\.00273\.
- \[13\]V\. Sadasivan, A\. Kumar, S\. Balasubramanian, W\. Wang, S\. Feizi,*Can AI\-Generated Text be Reliably Detected?*
- \[14\]H\. Zhang*et al\.*,*Watermarks in the Sand: Impossibility of Strong Watermarking for Language Models*, ICML 2024\.
- \[15\]X\. Zhao, P\. Ananth, L\. Li, Y\.\-X\. Wang,*Provable Robust Watermarking for AI\-Generated Text*, ICLR 2024\.

Similar Articles

A Linguistics-Aware LLM Watermarking via Syntactic Predictability

arXiv cs.CL

This paper introduces STELA, a linguistics-aware watermarking framework for LLMs that leverages syntactic predictability via POS n-grams to balance text quality and detection robustness. The method enables publicly verifiable watermark detection without requiring access to model logits, demonstrating superior performance across typologically diverse languages (English, Chinese, Korean).

Linguistics-Aware Non-Distortionary LLM Watermarking

arXiv cs.CL

Introduces LUNA, a linguistics-aware LLM watermarking method that achieves non-distortionary embedding and model-free detection across multiple languages, significantly improving AUROC and perplexity preservation.

Robust Text Watermarking for Large Language Models via Dual Semantic Embeddings

arXiv cs.CL

This paper presents Dual-Embedding Watermarking (DEW), a semantic watermarking scheme for LLMs that improves robustness against paraphrasing and translation by leveraging contextual and token-level embeddings. Experimental results show improved detection after paraphrasing and translation compared to prior methods.