collaborators

8 papers

cs.CR2026

TrajMark: Ownership Attribution and Segment-Level Tamper Localization for Coding-Agent Trajectories

Bokang Zeng, Zheng Gao, Xiaoyu Li +2

Watermarking the final patch produced by a coding agent provides provenance evidence for the submitted artifact, but does not authenticate the visible process that produced it. Beh…

cs.CR2026

DRIFT: Removing Diffusion Watermarks by Deflecting the Generative Trajectory

Rui Bao, Zheng Gao, Xiaoyu Li +3

Diffusion watermarking embeds verifiable signals into the generative process and commonly verifies them by recovering trajectory-dependent evidence, making the marks robust to conv…

cs.CV2026

IRIS: Visual-Semantic Binding for Forgery-Resistant Watermarking of Diffusion Images

Xiaoyan Feng, Zheng Gao, Tong Guan +4

Most in-generation diffusion watermarks embed patterns independent of the image that carries them, and attackers transplant the marks onto images the generator did not produce, res…

cs.CR2026

Tracing Provenance and Detecting Tampering with Complementary LLM Watermarks

Xiaoyan Feng, Yanjun Zhang, He Zhang +2

Watermarking LLM-generated text is an important task for tracing its provenance. Existing LLM watermarks preserve provenance under editing, but this same robustness allows an adver…

cs.CR2026

Watermark Forensics for Generative Models: An Information-Theoretic Perspective

Xiaoyu Li, Zheng Gao, Xiaoyan Feng +3

A watermark in a generative model's output is usually asked only whether a text is machine-made. The same mark can do more: attribute it to the user who produced it, extract a hidd…

cs.CR2026

TRACE: A Two-Channel Robust Attribution Watermark via Complementary Embeddings for LLM-Agent Trajectories

Zheng Gao, Xiaoyu Li, Xiaoyan Feng +5

LLM agents reach users through resellers, who may rebrand a developer's agent or substitute a cheaper model. When provenance is disputed, attribution rests on the trajectory log (t…