---
格式版本: 2
标题: "Flip, Don't Shuffle: Watermarking LLMs at the Speed of Inference"
原文链接: "https://arxiv.org/abs/2609.03844"
发布日期: "2026-09-03"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Thu, 3 Sep 2026 13:38:49 UTC (110 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-09-06T21:23:54+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-09-06T21:21:19+08:00"
入库时间: "2026-09-06T13:23:54.810Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=GPU&searchtype=all"
匹配关键词:
  - "GPU"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 15
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为LLM水印算法，与超节点/AI Rack/机柜级AI基础设施、供电散热互连或量产落地完全无关，仅提及GPU hash，属明显无关内容。"
AI质检模型: "zj-deepseek-v4-flash"
AI质检时间: "2026-09-06T21:24:00+08:00"
AI主题相关性: 0
AI来源权威性: 8
AI新颖性: 3
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 4
AI摘要: "提出Stateless Bernoulli Watermarking（SBW），一种用于大语言模型的统计水印方法，通过独立伯努利试验确定绿名单，成员判定复杂度降至O(1)，无需中间分配，端到端生成开销小于1%。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-06T23:44:24.567Z"
采集批次: "2026年9月6日19点27分09秒"
采集批次ID: "20260906-192709-237"
去重键: "https://arxiv.org/abs/2609.03844"
---

## Computer Science > Cryptography and Security

## Title:Flip, Don't Shuffle: Watermarking LLMs at the Speed of Inference

Authors:[Simone Ceppi](https://arxiv.org/search/cs?searchtype=author&query=Ceppi,+S), [Ignacio Sanchez](https://arxiv.org/search/cs?searchtype=author&query=Sanchez,+I)

[View PDF](https://arxiv.org/pdf/2609.03844) [HTML (experimental)](https://arxiv.org/html/2609.03844v1)

> Abstract:We introduce Stateless Bernoulli Watermarking (SBW), a new statistical watermark for Large Language Models that determines green list membership through independent per-token Bernoulli trials. Unlike KGW's vocabulary permutation or SynthID's multi-layer tournament, SBW requires only a single comparison per token against a counter-based random number generator, reducing membership complexity to $O(1)$ and enabling single-kernel execution with zero intermediate allocations. We prove that this formulation preserves the same detection guarantees as fixed-size green lists: the z-score test remains $\mathcal{N}(0,1)$ under the null. The stateless architecture enables capabilities unavailable to existing methods: full-vocabulary self-salt watermarking (over 6000 $\times$ faster than KGW's self-salt and 2 $\times$ faster than SynthID despite biasing the entire vocabulary with candidate-dependent seeding) and architectural compatibility with distributed inference. In end-to-end generation benchmarks, SBW adds less than 1\\% overhead at all batch sizes. We additionally identify hash function design as a previously unexplored axis for watermark quality, showing that a GPU-native Jenkins hash improves null calibration by 1.8 $\times$ while producing more diverse text. Experiments across two seeding schemes and eight $(\gamma, \delta)$ configurations confirm statistical equivalence with ROC-AUC differences below 0.01.

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR); Computation and Language (cs.CL); Machine Learning (cs.LG) |
| Cite as: | [arXiv:2609.03844](https://arxiv.org/abs/2609.03844) \[cs.CR\] |
|  | (or [arXiv:2609.03844v1](https://arxiv.org/abs/2609.03844v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2609.03844](https://doi.org/10.48550/arXiv.2609.03844) |

## Submission history

From: Simone Ceppi \[[view email](https://arxiv.org/show-email/86e7b83e/2609.03844)\]  
**\[v1\]** Thu, 3 Sep 2026 13:38:49 UTC (110 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2609.03844) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
