Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/suhanmen/sew
Static AnalysisCode AnalysisCryptographyPapers & ResearchAI Security
GitHubsuhanmen/sew

SEW

Embeds and detects keyed, style-based watermarks in LLM-generated Python, Java, and C++ code via CST rewriting, preserving functional correctness and resisting code-editing attacks.

View Repository
1113h 1m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SEW: Style-Encoded Watermarking of LLM-Generated Code

GitHub Repo stars GitHub last commit GitHub contributors

Paper Link📖

📰 News

  • 📢 NEW! The SEW paper is available on arXiv: arXiv:2609.39414. (Sep 30, 2026)
  • 📢 The official SEW code has been released on GitHub. (Sep 30, 2026)

🔍 Motivation

FeatureToken-level watermarks (KGW, SWEET, Unigram, STONE, STA-1)Post-hoc watermarks (ACW, SrcMarker, RoSeMary)✨ SEW
AccessDecoding-time (biases token selection)Post-hoc (rewrites finished code)Post-hoc (rewrites finished code, model-agnostic)
Functional correctnessChanges the program (detectability–correctness trade-off)Can break programs (Java/C++ pass@1 ≈ 12% for neural rewriting)Preserved (pass@1 equal to unwatermarked code)
Predictability—Recurring patterns (recovered from 10 watermarked programs)Key- and context-dependent (choices vary with each program's structure)
Detection (TPR@FPR5%)14–60%31–98%⚡ 98.7–99.5%

Watermarking LLM-generated code supports provenance tracking. Watermarks that modify token selection during generation trade detectability against functional correctness, and they require control over the generating model. Post-hoc methods instead watermark completed code with predefined transformations or trained neural models, but their recurring patterns make the watermark predictable across programs, and patterns that are already common in unwatermarked code are counted as watermark evidence, which causes false detections. SEW asks: can the code style of an already generated program carry a watermark that is correct by construction, hard to predict, and calibrated against human-written code?

✨ About SEW

SEW overview

SEW (Style-Encoded Watermarking) embeds and detects watermarks in already generated code through three components:

  1. Code style rules with keyed, context-dependent choices. Semantically equivalent style choices collected from style guides and transformation rules (29 for Python, 22 for Java, 19 for C++; e.g., x += 1 / x = x + 1, range(n) / range(0, n), if (c) s; / if (c) { s; }) are matched on the concrete syntax tree (CST). Which variant a site takes is decided by a secret key and the site's structural context.
  2. Style-preference calibration. Watermark evidence is evaluated against the probability of each style variant in human-written code, so styles that people already prefer count for less.
  3. Context-aware style aggregation. Sites at structurally matching locations that are assigned the same style choice are combined into one vote, so that repeated applications of one choice do not inflate the evidence.

Detection needs only the suspect code and the key — not the generating model, the original code, or any record of the embedding.

🚀 What makes SEW valuable?

✅ Model-agnostic and correct by construction — SEW only rewrites style sites where both variants have the same semantics, so it works on the output of any model and keeps pass@1 equal to that of the unwatermarked code.

✅ Calibrated evidence — A Poisson-binomial test with style probabilities estimated from human-written code (LeetCode solutions, disjoint from the evaluation data) keeps false detections on human code low.

✅ Robust and hard to infer — SEW keeps its detection under formatting, linting, comment removal and variable renaming, and an adversary who observes watermarked programs cannot recover its style choices the way it recovers those of the post-hoc baselines.

📈 Results

Main result — detection on CodeContests (TPR@FPR5% / AUROC, %), averaged over three LLMs (Qwen3.5-9B, gemma-4-12B-it, gpt-oss-20b).

TypeMethodPythonJavaC++
Token-levelKGW48.33 / 80.5643.30 / 72.3159.31 / 84.54
SWEET59.92 / 85.1841.19 / 76.5660.01 / 87.24
Unigram57.45 / 88.9736.54 / 71.3747.05 / 71.13
STONE28.09 / 62.3314.38 / 62.9523.65 / 64.79
STA-135.26 / 66.2620.93 / 61.4844.71 / 73.72
Post-hocACW90.10 / 95.05––
SrcMarker90.21 / 97.8671.52 / 93.5869.88 / 81.55
RoSeMary97.86 / 97.3231.00 / 95.4681.26 / 89.44
SEW99.49 / 99.6498.70 / 98.9999.22 / 99.38

Functional correctness (pass@1 of the watermarked code, %; unwatermarked code: 57.63 / 52.05 / 53.74).

MethodPythonJavaC++
ACW56.00––
SrcMarker56.7811.8711.82
RoSeMary56.3911.7111.52
SEW57.6352.0553.74

Robustness to code-editing attacks (TPR@FPR5%, %, averaged over three LLMs and three languages; ACW: Python only).

MethodNo attackFormattingLintingComment removalRenaming
KGW50.3143.3149.9924.4843.26
SWEET53.7149.7953.0019.3448.83
ACW90.100.5193.5689.353.17
SrcMarker77.2077.2376.4277.2026.43
RoSeMary70.0467.0069.4270.0422.26
SEW99.1495.5798.9999.1499.14

Our experiments on CodeContests with three LLMs and three programming languages show:

Download Tool