[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85852-en":3,"doc-seo-85852-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},85852,8796095461610,"Oliver","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Toward Stronger Code Watermarking: A Grammar-Driven Approach to Optimizing the Trade-off Between Quality and Detectability","Large Language Models (LLMs) enable widespread machine-generated code, making text watermarking essential for provenance verification and potential copyright concerns. Existing logits-based watermarking is difficult to transfer to code because low-entropy, rigid syntax intensifies the conflict between generation quality and detectability. This paper introduces Grammar-Driven Watermark (GDW), which uses a grammar-guided three-level masking mechanism to preserve syntactic validity and applies structural role-aware modulation for better trade-offs. Experiments across languages and decoding strategies show improved quality–detectability and robustness to variable-renaming attacks.","Toward Stronger Code Watermarking: A Grammar-Driven Approach to Optimizing the Trade-off Between Quality and Detectability  \nLicheng Yu1 , Aiwei Liu2 , Songze Li1 *  \n1 Southeast University 2Tsinghua University  \n{lichengyu, [songzeli}@seu.edu.cn](songzeli}@seu.edu.cn) , [liuaiwei20@gmail.com](liuaiwei20@gmail.com)  \narXiv :2607 . 102 10v 1 [ cs .CR] 11 Jul 2026  \nAbstract  \nWith the rapid development of Large Language Models (LLMs), text watermarking has emerged as a crucial technique for identifying machine-generated content. However, directly applying existing logits-based watermarking methods to code generation remains challenging, since the low-entropy nature of code exacerbates the trade-off between code quality and watermark detectability. In this paper, we propose a novel code watermarking approach called Grammar-Driven Watermark (GDW) for LLMs. GDW preserves syntactic validity through a grammar-guided threelevel masking mechanism and injects watermark signals via structural role-aware modulation, assigning a stronger bias to contentbearing tokens while applying a more conservative bias to syntax-critical tokens. Aligning with the generation process, we further design a role-aware weighted detection statistic to improve detectability. Experiments across multiple programming languages, models, and decoding strategies show that GDW establishes a stronger quality-detectability trade-off frontier than existing methods, while maintaining robustness against variable-renaming attacks.  \n1 Introduction  \nIn recent years, large language models (LLMs) have become indispensable tools for code generation and programming assistance, powering widely used AI coding assistants such as GitHub Copilot (Microsoft and OpenAI, 2021), Cursor (Anysphere, 2023) and Claude Code (Anthropic, 2025) . However, as LLM-generated code becomes increasingly integrated into open-source projects and industrial software, concerns about code provenance and potential copyright infringement have increased substantially (Dey et al., 2019) . Therefore, algorithms that can effectively identify machine-generated code have become crucial.  \n* Corresponding author.  \nFigure 1: Comparison among existing logits-based watermark, entropy-based watermark, and our GrammarDriven Watermark in terms of the trade-off between watermark detectability and code quality. Our proposed method GDW achieves a better trade-off frontier.  \nWatermarking has emerged as a promising solution for identifying machine-generated content by embedding imperceptible but statistically detectable signals into model outputs. One dominant paradigm for LLM text watermarking is the logitsbased watermark, which injects signals by modifying the model’s output logits (Kirchenbauer et al., 2023a) . Specifically, the vocabulary is pseudorandomly partitioned into a ‘green list’ and a ‘red list’ at each decoding step. By adding a constant bias to the logits of green-list tokens, the model is encouraged to select tokens within the green list, which can later be identified via a statistical z-test.  \nHowever, while logits-based watermarking methods have shown effectiveness in natural language generation tasks, their application to code is hindered by the low-entropy nature of programming languages. Code is low-entropy text, where the model’s output logits are highly concentrated due to the rigid syntax. In such settings, naively injecting watermark bias into low-entropy tokens can significantly distort the generation process. A watermark bias that is too strong may degrade the code’s functionality or readability, while a weaker watermark bias might be difficult to detect.  \nFigure 2: Mean token entropy of syntax-critical tokensand content-bearing tokens measured with Qwen2.5-Coder-3B across Python, Java, and Go. This observation motivates our structural role-aware modulation strategy.  \nTo address this, researchers propose entropybased watermarking methods (Lee et al., 2024 ; Lu et al., 2024), applying waterma","cbCaidyF0WODBOMi","https://ap.wps.com/l/cbCaidyF0WODBOMi","pdf",1323251,3,1,12,"English","en",105,"# Abstract\n# Introduction\n## Motivation and problem setting\n## Limitations of existing watermarking for code\n## Entropy observations for syntax vs content tokens\n## Proposed Grammar-Driven Watermark (GDW)","[{\"question\":\"Why are logits-based watermarking methods challenging for code generation?\",\"answer\":\"Code tokens have low entropy due to rigid syntax, so adding watermark bias can significantly distort generation. A strong bias harms functionality or readability, while a weak bias reduces detectability.\"},{\"question\":\"How does Grammar-Driven Watermark (GDW) preserve syntactic validity?\",\"answer\":\"GDW integrates a context-free grammar into decoding and uses a grammar-guided three-level masking mechanism. This enforces syntactic constraints while watermark signals are injected.\"},{\"question\":\"What strategy does GDW use to balance quality and detectability?\",\"answer\":\"GDW applies role-aware modulation: stronger watermark bias to content-bearing tokens and more conservative bias to syntax-critical tokens. It also uses a role-aware weighted detection statistic aligned with the generation process.\"}]",1784206706,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"toward-stronger-code-watermarking-a-grammar-driven-approach-to-optimizing-the-trade-off-between-quality-and-detectability","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/toward-stronger-code-watermarking-a-grammar-driven-approach-to-optimizing-the-trade-off-between-quality-and-detectability/85852/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why are logits-based watermarking methods challenging for code generation?","Question",{"text":75,"@type":76},"Code tokens have low entropy due to rigid syntax, so adding watermark bias can significantly distort generation. A strong bias harms functionality or readability, while a weak bias reduces detectability.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does Grammar-Driven Watermark (GDW) preserve syntactic validity?",{"text":80,"@type":76},"GDW integrates a context-free grammar into decoding and uses a grammar-guided three-level masking mechanism. This enforces syntactic constraints while watermark signals are injected.",{"name":82,"@type":73,"acceptedAnswer":83},"What strategy does GDW use to balance quality and detectability?",{"text":84,"@type":76},"GDW applies role-aware modulation: stronger watermark bias to content-bearing tokens and more conservative bias to syntax-critical tokens. It also uses a role-aware weighted detection statistic aligned with the generation process.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]