{"id":"https://openalex.org/W7162812661","doi":"https://doi.org/10.48550/arxiv.2605.28890","title":"Echoes within the Reasoning: Stealthy and Effective Watermarking via Chain of Thought","display_name":"Echoes within the Reasoning: Stealthy and Effective Watermarking via Chain of Thought","publication_year":2026,"publication_date":"2026-05-27","ids":{"openalex":"https://openalex.org/W7162812661","doi":"https://doi.org/10.48550/arxiv.2605.28890"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.28890","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.28890","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.28890","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5015582604","display_name":"Jiacheng Lu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lu, Jiacheng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5137313566","display_name":"Yiming Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Yiming","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5137319261","display_name":"Tao Song","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Song, Tao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101993649","display_name":"Weijian Wang","orcid":"https://orcid.org/0000-0003-2478-5175"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Weijian","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5137337190","display_name":"Wenjie Qu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Qu, Wenjie","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5137319839","display_name":"Haibing Guan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Guan, Haibing","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5137382355","display_name":"Jiaheng Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Jiaheng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8981000185012817,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8981000185012817,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.0203000009059906,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.017400000244379044,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.8496999740600586},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6578999757766724},{"id":"https://openalex.org/keywords/fidelity","display_name":"Fidelity","score":0.5992000102996826},{"id":"https://openalex.org/keywords/subspace-topology","display_name":"Subspace topology","score":0.5922999978065491},{"id":"https://openalex.org/keywords/representation","display_name":"Representation (politics)","score":0.4577000141143799},{"id":"https://openalex.org/keywords/signature","display_name":"Signature (topology)","score":0.3849000036716461},{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.3594000041484833},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.33309999108314514}],"concepts":[{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.8496999740600586},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6578999757766724},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6517999768257141},{"id":"https://openalex.org/C2776459999","wikidata":"https://www.wikidata.org/wiki/Q2119376","display_name":"Fidelity","level":2,"score":0.5992000102996826},{"id":"https://openalex.org/C32834561","wikidata":"https://www.wikidata.org/wiki/Q660730","display_name":"Subspace topology","level":2,"score":0.5922999978065491},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.49470001459121704},{"id":"https://openalex.org/C2776359362","wikidata":"https://www.wikidata.org/wiki/Q2145286","display_name":"Representation (politics)","level":3,"score":0.4577000141143799},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.4138000011444092},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.3849000036716461},{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.3594000041484833},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.33309999108314514},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.31310001015663147},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.3122999966144562},{"id":"https://openalex.org/C113364801","wikidata":"https://www.wikidata.org/wiki/Q26674","display_name":"High fidelity","level":2,"score":0.3057999908924103},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.2985999882221222},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.2939999997615814},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.28200000524520874},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.2703999876976013},{"id":"https://openalex.org/C2780704645","wikidata":"https://www.wikidata.org/wiki/Q9251458","display_name":"Observer (physics)","level":2,"score":0.2648000121116638},{"id":"https://openalex.org/C195344581","wikidata":"https://www.wikidata.org/wiki/Q2555318","display_name":"Automated reasoning","level":2,"score":0.2599000036716461},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.258899986743927},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.2565000057220459},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.2563999891281128},{"id":"https://openalex.org/C118930307","wikidata":"https://www.wikidata.org/wiki/Q600590","display_name":"Tuple","level":2,"score":0.25}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.28890","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.28890","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"Preprint"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.28890","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.28890","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"sustainable_development_goals":[{"score":0.7463127970695496,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Large":[0],"Language":[1],"Models":[2],"with":[3,54,73],"Chain-of-Thought":[4],"reasoning":[5,20,47,124,129],"capabilities":[6],"represent":[7],"valuable":[8],"intellectual":[9],"property,":[10],"yet":[11],"existing":[12],"black-box":[13,105],"watermarking":[14,36],"methods":[15],"often":[16],"trade":[17],"robustness":[18],"for":[19],"fidelity":[21,125],"by":[22,49],"perturbing":[23],"final":[24],"answers":[25],"or":[26],"relying":[27],"on":[28],"fragile":[29],"trigger":[30],"patterns.":[31],"We":[32],"propose":[33],"BiCoT,":[34],"a":[35,55,102],"framework":[37],"that":[38,83,107,121],"embeds":[39],"ownership":[40],"signals":[41],"into":[42],"the":[43,71,81,116],"internal":[44],"geometry":[45],"of":[46],"traces":[48],"aligning":[50],"high-saliency":[51],"structural":[52],"anchors":[53],"private":[56],"signature":[57],"subspace":[58],"while":[59,131],"regularizing":[60],"ordinary":[61],"control":[62],"tokens":[63,110],"to":[64,111],"preserve":[65],"semantic":[66],"capacity.":[67],"This":[68],"design":[69],"couples":[70],"watermark":[72],"reasoning-relevant":[74],"representations,":[75],"making":[76],"removal":[77],"difficult":[78],"without":[79],"disrupting":[80],"features":[82],"support":[84],"coherent":[85],"reasoning.":[86],"To":[87],"enable":[88],"verification":[89],"under":[90,135],"model":[91],"theft":[92],"and":[93,140,146],"representation":[94],"drift,":[95],"we":[96],"introduce":[97],"Robust":[98],"Subspace":[99],"Registration":[100],"(RSR),":[101],"Top-":[103],"logprob-based":[104],"verifier":[106],"uses":[108],"sentinel":[109],"calibrate":[112],"systematic":[113],"shifts":[114],"in":[115],"output":[117],"distribution.":[118],"Experiments":[119],"show":[120],"BiCoT":[122],"preserves":[123],"across":[126,144],"diverse":[127],"complex":[128],"tasks":[130],"achieving":[132],"robust":[133],"detection":[134],"fine-tuning,":[136],"quantization,":[137],"model-level":[138],"perturbations,":[139],"adaptive":[141],"output-level":[142],"attacks":[143],"in-domain":[145],"out-of-distribution":[147],"settings.":[148]},"counts_by_year":[],"updated_date":"2026-07-01T06:00:48.157686","created_date":"2026-05-30T00:00:00"}
