{"id":"https://openalex.org/W7123952065","doi":"https://doi.org/10.1109/access.2026.3653833","title":"Adaptive Robust Watermarking for Large Language Models via Dynamic Token Embedding Perturbation","display_name":"Adaptive Robust Watermarking for Large Language Models via Dynamic Token Embedding Perturbation","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7123952065","doi":"https://doi.org/10.1109/access.2026.3653833"},"language":null,"primary_location":{"id":"doi:10.1109/access.2026.3653833","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2026.3653833","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1109/access.2026.3653833","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5121592635","display_name":"Ziyang Zeng","orcid":null},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Ziyang Zeng","raw_affiliation_strings":["New York University, New York, NY, USA"],"affiliations":[{"raw_affiliation_string":"New York University, New York, NY, USA","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070980467","display_name":"Lin Han","orcid":"https://orcid.org/0000-0003-0617-2367"},"institutions":[{"id":"https://openalex.org/I135310074","display_name":"University of Wisconsin\u2013Madison","ror":"https://ror.org/01y2jtd41","country_code":"US","type":"education","lineage":["https://openalex.org/I135310074"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Han Lin","raw_affiliation_strings":["University of Wisconsin&#x2013;Madison, Madison, WI, USA"],"affiliations":[{"raw_affiliation_string":"University of Wisconsin&#x2013;Madison, Madison, WI, USA","institution_ids":["https://openalex.org/I135310074"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047934496","display_name":"S Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Shuxin Zhang","raw_affiliation_strings":["University of California, Berkeley, Berkeley, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5009846438","display_name":"B. Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I1174212","display_name":"University of Southern California","ror":"https://ror.org/03taz7m60","country_code":"US","type":"education","lineage":["https://openalex.org/I1174212"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Boyuan Wang","raw_affiliation_strings":["University of Southern California, Los Angeles, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of Southern California, Los Angeles, CA, USA","institution_ids":["https://openalex.org/I1174212"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5121592635"],"corresponding_institution_ids":["https://openalex.org/I57206974"],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.19618827,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"14","issue":null,"first_page":"9319","last_page":"9339"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.607699990272522,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.607699990272522,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.08169999718666077,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.05389999970793724,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.8662999868392944},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.8034999966621399},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.632099986076355},{"id":"https://openalex.org/keywords/security-token","display_name":"Security token","score":0.6273000240325928},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.5389000177383423},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.4909999966621399},{"id":"https://openalex.org/keywords/scrambling","display_name":"Scrambling","score":0.4092999994754791},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.35569998621940613}],"concepts":[{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.8662999868392944},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8367000222206116},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.8034999966621399},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.632099986076355},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.6273000240325928},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.5389000177383423},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.4909999966621399},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4327999949455261},{"id":"https://openalex.org/C182548165","wikidata":"https://www.wikidata.org/wiki/Q2261483","display_name":"Scrambling","level":2,"score":0.4092999994754791},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.38609999418258667},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3799000084400177},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.35569998621940613},{"id":"https://openalex.org/C28490314","wikidata":"https://www.wikidata.org/wiki/Q189436","display_name":"Speech recognition","level":1,"score":0.3467999994754791},{"id":"https://openalex.org/C38935604","wikidata":"https://www.wikidata.org/wiki/Q4330363","display_name":"Stylized fact","level":2,"score":0.3343000113964081},{"id":"https://openalex.org/C3073032","wikidata":"https://www.wikidata.org/wiki/Q15912075","display_name":"Information hiding","level":3,"score":0.3271999955177307},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.32580000162124634},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.3246999979019165},{"id":"https://openalex.org/C157524613","wikidata":"https://www.wikidata.org/wiki/Q2828883","display_name":"Fine-tuning","level":2,"score":0.3221000134944916},{"id":"https://openalex.org/C175291020","wikidata":"https://www.wikidata.org/wiki/Q1156822","display_name":"Offset (computer science)","level":2,"score":0.31610000133514404},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.3125999867916107},{"id":"https://openalex.org/C6295992","wikidata":"https://www.wikidata.org/wiki/Q976521","display_name":"Cryptosystem","level":3,"score":0.31200000643730164},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.30820000171661377},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.3041999936103821},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.27970001101493835},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.27649998664855957},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.27149999141693115},{"id":"https://openalex.org/C205711294","wikidata":"https://www.wikidata.org/wiki/Q176953","display_name":"Rendering (computer graphics)","level":2,"score":0.2583000063896179},{"id":"https://openalex.org/C204806902","wikidata":"https://www.wikidata.org/wiki/Q2333581","display_name":"Semantic security","level":5,"score":0.2535000145435333}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/access.2026.3653833","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2026.3653833","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1109/access.2026.3653833","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2026.3653833","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":23,"referenced_works":["https://openalex.org/W2951080837","https://openalex.org/W3114326827","https://openalex.org/W3133702157","https://openalex.org/W4385572007","https://openalex.org/W4390489178","https://openalex.org/W4401042646","https://openalex.org/W4401042803","https://openalex.org/W4402169037","https://openalex.org/W4402670359","https://openalex.org/W4402671579","https://openalex.org/W4402671946","https://openalex.org/W4402672097","https://openalex.org/W4402683725","https://openalex.org/W4403680773","https://openalex.org/W4404782556","https://openalex.org/W4404783813","https://openalex.org/W4409513158","https://openalex.org/W4410492021","https://openalex.org/W4412694115","https://openalex.org/W4412735004","https://openalex.org/W4413130824","https://openalex.org/W4413277247","https://openalex.org/W4415378952"],"related_works":[],"abstract_inverted_index":{"Large":[0],"Language":[1],"Models":[2],"(LLMs)":[3],"have":[4],"demonstrated":[5],"remarkable":[6],"capabilities":[7],"in":[8,56,103,109,232],"generating":[9],"high-quality":[10],"text,":[11],"raising":[12],"significant":[13],"concerns":[14],"regarding":[15],"copyright":[16],"protection":[17],"and":[18,47,119,174,189,228],"content":[19,48,190],"provenance":[20],"verification.":[21],"However,":[22],"most":[23],"existing":[24,209],"watermarking":[25,73,231],"techniques":[26],"rely":[27],"on":[28,138,150],"uniform":[29],"perturbation":[30],"or":[31],"rule-based":[32],"token":[33],"biasing":[34],"schemes,":[35],"which":[36,132],"exhibit":[37],"critical":[38],"vulnerabilities":[39],"under":[40,171,177],"adversarial":[41],"attacks":[42,182,186],"such":[43],"as":[44],"paraphrasing,":[45],"translation,":[46],"truncation,":[49],"often":[50],"failing":[51],"to":[52,82],"maintain":[53],"detection":[54,135,162],"reliability":[55],"real-world":[57,233],"deployment":[58,235],"scenarios.":[59,236],"To":[60],"address":[61],"these":[62],"challenges,":[63],"this":[64],"paper":[65],"introduces":[66],"a":[67,93,165,223],"novel":[68],"<italic":[69],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[70],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">context-aware":[71],"robust":[72],"framework</i>":[74],"that":[75,98],"dynamically":[76],"adjusts":[77],"watermark":[78,101,130],"embedding":[79],"strength":[80],"according":[81],"contextual":[83],"semantic":[84,95],"characteristics":[85],"during":[86],"text":[87,213],"generation.":[88],"The":[89],"proposed":[90,199],"approach":[91],"incorporates":[92],"token-level":[94],"modulation":[96],"mechanism":[97],"strategically":[99],"intensifies":[100],"signals":[102],"copyright-sensitive":[104,234],"segments":[105],"while":[106,211],"minimizing":[107],"perturbations":[108],"semantically":[110],"neutral":[111],"regions,":[112],"achieving":[113],"an":[114,122],"improved":[115],"balance":[116],"between":[117],"imperceptibility":[118],"robustness.":[120],"Furthermore,":[121],"adaptive":[123],"threshold":[124],"estimation":[125],"algorithm":[126],"is":[127],"developed":[128],"for":[129,226],"detection,":[131],"automatically":[133],"calibrates":[134],"boundaries":[136],"based":[137],"noise":[139],"statistics,":[140],"significantly":[141],"enhancing":[142],"resilience":[143],"against":[144],"diverse":[145],"attack":[146],"vectors.":[147],"Extensive":[148],"experiments":[149],"the":[151,198],"WaterBench":[152],"benchmark":[153],"demonstrate":[154],"superior":[155],"performance":[156],"over":[157],"state-of-the-art":[158],"baselines,":[159],"maintaining":[160],"high":[161],"accuracy":[163],"with":[164,208,215],"95.3%":[166],"true":[167],"positive":[168,203],"rate":[169],"(TPR)":[170],"clean":[172],"conditions":[173],"strong":[175],"robustness":[176],"severe":[178],"perturbations,":[179],"including":[180],"paraphrasing":[181],"(82.7%":[183],"TPR),":[184,188],"translation":[185],"(78.4%":[187],"truncation":[191],"(88.9%":[192],"TPR":[193],"at":[194],"50%":[195],"retention).":[196],"Meanwhile,":[197],"method":[200],"reduces":[201],"false":[202],"rates":[204],"by":[205],"43.2%":[206],"compared":[207],"approaches":[210],"preserving":[212],"quality":[214],"negligible":[216],"perplexity":[217],"increase":[218],"(1.8%).":[219],"These":[220],"results":[221],"establish":[222],"new":[224],"paradigm":[225],"practical":[227],"scalable":[229],"LLM":[230]},"counts_by_year":[],"updated_date":"2026-01-24T23:23:39.755997","created_date":"2026-01-14T00:00:00"}
