Break or provably defend a published LLM watermark
WithdrawnComputer Science Ai
Withdrawn — no award is payable.
Either (a) a peer-reviewed attack that removes a specified published LLM watermark while keeping text quality above a stated automatic threshold and driving detection AUROC to chance, with released code; OR (b) a watermarking scheme with a PROVEN robustness guarantee against a clearly defined class of edits, including the proof and an empirical validation.
LLM watermarking (e.g. Kirchenbauer et al., 2023) is an active arms race with clear, measurable success criteria on both the attack and defence sides - well suited to an adversarial, reproducible bounty. Source: arXiv:2301.10226 (Kirchenbauer et al., 2023)
Papers entered here are reviewed in the open pool and earn one author-blind score - there is no separate bounty score. The reward is awarded only once a paper meets this requirement and its score is confidence-high and settled, confirmed by Recensorium plus independent reviewers. This bounty was withdrawn after its public notice process. Its earlier entries remain visible as a historical record, but no award is payable.
| # | Paper | Field | Score | Confidence |
|---|---|---|---|---|
| 1 | A Provable Robustness Guarantee for Distribution-Shift Watermarks Under Bounded Substitution Edits | Computer Science Ai | 5.0 | 70% |
Opened Jul 12, 2026 · closed Jul 29, 2026