Skip to main navigation Skip to search Skip to main content

SARW: A Secure Semantic Watermarking Framework for Data Ownership and Attribution in RAG Knowledge Bases

  • Beijing Institute of Technology
  • Shandong Provincial Key Laboratory of Energy Industry Internet Big Data Technology
  • Amazon.com, Inc.

Research output: Contribution to journalArticlepeer-review

Abstract

Retrieval-Augmented Generation (RAG) enhances the factual accuracy and temporal relevance of large language model (LLM) outputs by integrating external knowledge sources, driving its widespread adoption in real-world applications. However, this explicit dependence on retrievable knowledge repositories introduces significant risks of intellectual property (IP) leakage and unauthorized reuse, elevating IP protection in RAG systems to a critical concern. While text watermarking techniques have advanced considerably, they often fail in RAG contexts. LLMs frequently rephrase, summarize, or semantically reorganize retrieved content during generation, severely degrading the persistence and detectability of conventional watermarks embedded directly in source documents or outputs. To overcome this limitation, we propose Semantic Atom-based RAG Watermarking (SARW), a distributed watermarking framework purpose-built for RAG ecosystems. SARW decomposes copyright statements into structured semantic graphs and extracts verifiable semantic atoms. These atoms are covertly embedded into knowledge base documents using natural language steganography, with topic-aware matching and retrieval-ranking optimization ensuring alignment with semantically relevant host documents. Extensive experiments demonstrate SARW's efficacy: it achieves most configurations exceed 90% detection accuracy across general and domain-specific question-answering benchmarks while exhibiting resilience against knowledge-base tampering, paraphrasing, and partial retrieval attacks, validating its practicality for secure attribution in RAG knowledge bases through retrieved-context-level verification.

Original languageEnglish
JournalIEEE Transactions on Dependable and Secure Computing
DOIs
Publication statusAccepted/In press - 2026
Externally publishedYes

Keywords

  • Intellectual property protection
  • large language models
  • retrieval-augmented generation
  • semantic steganography
  • text watermarking

Fingerprint

Dive into the research topics of 'SARW: A Secure Semantic Watermarking Framework for Data Ownership and Attribution in RAG Knowledge Bases'. Together they form a unique fingerprint.

Cite this