WMTrace

Forensic detection and benchmarking of LLM text watermarks

View the Project on GitHub gtesei/llm-watermark

Likelihood/rank detector (D3)

See Installing local models for pinned downloads, storage, and license-audit steps.

likelihood-rank is WMTrace’s generic causal-language-model baseline. It reports mean token NLL, perplexity, mean rank, mean log-rank, mean entropy, GLTR rank buckets, and bounded token-level contributions. It is registered by default but returns E0 until a complete offline bundle is configured.

It is not a universal AI detector. Scores depend on the scoring model, language, domain, length, release date, and formatting. A calibrated E3 result is generic evidence under one declared configuration; it is not watermark or provider evidence.

Offline bundle

A bundle directory contains a complete local Hugging Face causal LM and fast tokenizer, plus WMTrace metadata:

artifacts/causal-lm-v1/
|-- manifest.json
|-- calibration.json
|-- config.json
|-- tokenizer.json              # or tokenizer.model
|-- tokenizer_config.json
`-- model.safetensors           # sharded safetensors are supported

manifest.json records immutable revisions, licenses, context length, precision, device requirements, validity date, and the SHA-256 of every declared file. WMTrace verifies every declared checksum and requires local model weights, model configuration, a fast-tokenizer artifact, and a checksummed calibration file before loading the runtime.

Scanning uses local_files_only=True; it never downloads a tokenizer or model. Stage artifacts explicitly under their licenses before configuring WMTrace.

Calibration artifact

calibration.json contains:

WMTrace checks that each threshold is resolvable by, and consistent with, the stored empirical null. P-values use an add-one empirical tail estimate. A missing, expired, mismatched, or statistically inconsistent calibration cannot produce E3.

Example local configuration:

{
  "schema_version": 1,
  "detectors": {
    "likelihood-rank": {
      "bundle": "causal-lm-v1",
      "device": "cpu",
      "target_fpr": 0.01,
      "min_tokens": 32
    }
  },
  "bundles": {
    "causal-lm-v1": {
      "manifest": "artifacts/causal-lm-v1/manifest.json",
      "calibration": "calibration.json"
    }
  }
}

Use wmtrace scan --language en document.txt or the language field in the LLM Detect tab. A language or length mismatch returns E2 diagnostics rather than a calibrated authorship claim.

Current validation status

The implementation has deterministic arithmetic, window-ownership, artifact, abstention, calibration, negative-control, namespace, and import-isolation tests. No production model bundle or external benchmark is distributed with WMTrace. A release claim for a particular model remains blocked until its pinned bundle, licenses, matched human controls, and frozen external benchmark report are published.