[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-llm-watermark-flags-tampering-not-just-origin":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},4991,"new-llm-watermark-flags-tampering-not-just-origin","New LLM Watermark Flags Tampering, Not Just Origin","A new dual-signal watermarking method lets AI text carry both an edit-resistant origin marker and a fragile tamper detector at the same time.","Researchers have built an LLM watermark that does two jobs at once: prove where text came from and flag if someone altered it after the fact.\n\nMost watermarking schemes optimize for one property - robustness. They embed a signal that survives paraphrasing and light editing, so a platform can still trace a passage back to the model that generated it. The problem, as this paper points out, is that the same durability lets an attacker rewrite the substantive content of a passage while the watermark quietly survives, preserving attribution on text that's since been changed. The researchers call this piggyback spoofing. Their fix embeds two watermark signals into each token using the same underlying mechanism but separate keys and seeding windows - one tuned to survive edits, the other tuned to break under them. A tournament-style reweighting process keeps the output distribution unbiased, and detection reads both signals together to sort text into three buckets: intact, tampered, or unwatermarked.\n\nThis matters because provenance and integrity have been treated as the same problem when they're not. A watermark that only proves \"this came from an LLM\" says nothing about whether the specific claims in front of you are what the model actually produced - which is precisely the gap bad actors exploit when they want the credibility of an AI byline without the content it originally generated. Splitting the two functions gives platforms a more honest signal: not just who wrote it, but whether what you're reading is still what they wrote.\n\nIt's a narrow academic result - two models, two prompt datasets, no production deployment - but it's a useful reminder that watermarking is not a solved problem so much as a moving set of trade-offs between resilience and evidentiary value.","[\"watermarking\",\"llm\",\"ai-safety\",\"content-provenance\"]","2026-08-14T04:00:00.000Z","2026-08-15T04:00:20.745Z","2026-08-15T04:00:32.651Z","published",null,[],"ai",[26,27,28,29],"watermarking","llm","ai-safety","content-provenance",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2608.12713",0,{"sections":36},[37,41,45,50,55,60,65,70,75,80,85,90,95,100],{"name":38,"slug":24,"count":39,"latest_published_at":40},"AI",3293,"2026-08-20T04:00:00.000Z",{"name":42,"slug":43,"count":44,"latest_published_at":40},"Security","security",435,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",140,"2026-08-19T18:25:42.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]