AIwatermark.studio

Statistical watermarks: how AI text betrays itself through word choice

Updated 2026-06-06

A statistical watermark does not hide between characters: it lives in word choice. While generating, the model slightly favours one half of its vocabulary, drawn by a secret key. Over a long text that imbalance becomes measurable. It is the hardest mark to remove cleanly, and the one that attracts the most unfounded promises.

01

The green-list mechanism

At every generated token, the model splits its vocabulary in two using a pseudo-random function of the preceding tokens and a key. It adds a small bonus to candidates in the "green" half. The text stays fluent and the meaning intact, but the proportion of green tokens drifts away from chance.

The detector, which knows the key, redoes the computation and counts. Over thirty words noise dominates and nothing is conclusive. Over a thousand, the gap becomes statistically massive. That is why these detectors are far more confident about a long article than about a paragraph.

02

Why the usual tricks fail

  • Swapping spaces for invisible characters: no carrier token changes, so the score is identical.
  • Translating out and back: translation reshuffles tokens and genuinely weakens the signal, but degrades style and introduces mistranslations.
  • Asking the model to "rewrite its own text": if it applies the same watermark, you get a new marked text.
  • Inserting deliberate typos: this damages the text without removing the imbalance in the remaining words.
03

What targeted rewriting can do

The only coherent approach is to change word choices where meaning allows: logical connectors, degree adverbs, light verbs, surface phrasing, punctuation, list structure. Each substitution takes a favoured token out of the count. A useful metric is favoured-token density per thousand words, before and after.

Two requirements make this usable. Rewriting must be scoped by language: the favoured tokens of a French text are not those of an English one, and a mixed dictionary produces gibberish. And a replacement word must never itself be a favoured token, otherwise you just move the problem.

The limits should be stated plainly: the higher the intensity, the flatter the style; agreement and phrasing need a reread; and a density drop, however large, does not prove a proprietary detector will fail. Use it as a starting point you then rework, not as a magic button.

04

The detectors that read no watermark at all

Most tools sold as "AI detectors" use no watermark key. They score perplexity and regularity — how suspiciously smooth the text is. They get it wrong regularly, including on entirely human writing, and especially for non-native authors.

Practical consequence: against that kind of tool what works is writing work — varying sentence length, committing to personal choices, keeping concrete examples. No automatic substitution replaces that.

Frequently asked questions

Can a statistical text watermark be removed?

Favoured-token density can be reduced substantially by rewriting surface words, which weakens the measured signal. Removal cannot be guaranteed: the watermark key is private and the detector remains the only judge.

Does the text need to be long for the watermark to be detectable?

Yes. The test is statistical: below roughly a hundred words it is usually inconclusive, and confidence grows with length.

Does rewriting change the meaning of my text?

It targets surface words rather than meaning-bearing terms, but at high intensity the style flattens and awkward phrasing appears. A reread before publishing is essential.

Clean your file or your text

Detection and cleaning inside your browser: no upload, no account, no quota. Your files never leave your device.

Open the studio