AI Watermark Robustness Lab EU AI Act & Kirchenbauer Engine

Simulate token-level greenlist watermarking and test evasion workarounds (synonyms, homoglyphs, paraphrasing).

Watermark Generator & Token Config

Evasion & Perturbation Attack
Statistical Detection Metrics Live Testbench
Clean Z-Score
5.84
Green: 76.7%
Attacked Z-Score
0.73
Green: 53.3%
Entropy Delta
+3.8%
T = 120 tokens
Attacked Watermark Status:
Watermark Evaded (Inconclusive, z < 2.33)
Gaussian Hypothesis Distribution (Null H₀ vs Watermark H₁)
Under unwatermarked null hypothesis H₀, expected greenlist count is 60.0 (50%). Clean stream contains 92 greenlist tokens (76.7%, z = 5.84, p < 0.0001). Under 35% synonym attack, greenlist count degrades to 64 (53.3%, z = 0.73), evading EU AI Act threshold.
Interactive Token Stream & Cryptographic Hash Provenance
Greenlist Token
Redlist Token
Attacked/Perturbed
Hover or click any token in the ledger to inspect its previous-token hash, pseudo-random greenlist partition, and perturbation status.

LLM Watermarking & Evasion Mechanics

Read the explanation

Kirchenbauer watermarking uses previous token hashes to split candidate vocabularies into green and red partitions, applying a logit bias delta so green tokens dominate generation. During verification, a statistical z-score evaluates green count versus null expectation. Clean watermarked text easily clears the detection threshold alpha with high statistical confidence. Increasing the attack perturbation rate replaces greenlist tokens with synonyms or homoglyphs. This degrades the green ratio back toward fifty percent, causing z to collapse below threshold into evasion.

Super generates helpful tools and automates fact-checking across the internet proactively. If you enjoyed this tool, build your own with Super and share it with a friend.