Paper 2026/2291

Evidence on Demand: Selectively Disclosable Watermarks for Generative AI

Yuuki Fujita, Kyoto University, National Institute of Advanced Industrial Science and Technology
Keisuke Hara, The University of Osaka, National Institute of Advanced Industrial Science and Technology
Abstract

Cryptographic watermarking for generative AI equips a generative model with a hidden mark that identifies its outputs as machine-generated, without affecting output quality. This study proposes a new cryptographic watermarking method with selective disclosability. Under this scheme, detection is restricted by default to the model owner, who can selectively issue a short token for any single output. This token enables any third party to verify that the specific output is watermarked, while guaranteeing that all other outputs remain undetectable, even to the token holder. This scheme is particularly useful in scenarios where a provider must certify a single controversial output without compromising the privacy of other outputs. In addition to two existing security properties, namely robustness and unforgeability, we formalize two security properties, undetectability of undisclosed data and disclosure soundness, to achieve our goal. We then propose our construction based on prior work (Lin, Shahabi, and Song, CRYPTO 2026) and prove it satisfies the four security notions. Our construction is broadly applicable to autoregressive generative AI models, including LLMs.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
CryptographyWatermarkDigital SignatureSteganographyAI Security
Contact author(s)
fujita yuki 67f @ st kyoto-u ac jp
hara-keisuke @ ist osaka-u ac jp
History
2026-10-04: approved
2026-10-01: received
See all versions
Short URL
https://ia.cr/2026/2291
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2291,
      author = {Yuuki Fujita and Keisuke Hara},
      title = {Evidence on Demand: Selectively Disclosable Watermarks for Generative {AI}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2291},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2291}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.