such as editing, paraphrasing, and token replacement. However, watermark stealing attacks pose
a serious threat to these schemes, which use a fixed-width token context to seed pseudorandom
generator functions. We propose a variable-width context mechanism to increase robustness against
stealing attacks while maintaining quality and detectability of watermarked text. We implement our
mechanism on the KGW-SelfHash variant of the watermark proposed by Kirchenbauer et al.
and evaluate it against the watermark stealing attack developed by Jovanovic et al.. We find that
our mitigation successfully degrades the attack’s effectiveness while maintaining high quality and
detectability of watermarked text.