SrcMarker: Dual-Channel Source Code Watermarking via Scalable Code Transformations

Borui Yang, Wei Li, Liyao Xiang, Bo Li

IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 4

Overview

In an era defined by the explosive growth of the developer community and the pervasive influence of large language models (LLMs) in code generation, the protection of intellectual property and the verification of code authorship have become paramount concerns. Borui Yang, along with his colleagues Wei Li, Liyao Xiang, and Bo Li, presented SrcMarker at IEEE S&P, a novel dual-channel source code watermarking system designed to address these pressing challenges. This talk introduces a sophisticated method for embedding invisible bit strings into source code snippets, serving as an undeniable indicator of ownership or as a means to differentiate between human-written and machine-generated code.

Watch on YouTube

Visual summary for SrcMarker: Dual-Channel Source Code Watermarking via Scalable Code Transformations by Borui Yang, Wei Li, Liyao Xiang, Bo Li
Visual summary for SrcMarker: Dual-Channel Source Code Watermarking via Scalable Code Transformations by Borui Yang, Wei Li, Liyao Xiang, Bo Li

Key moments

  1. 0:00 Introduction and problem: protecting code ownership
  2. 1:15 Introducing Source marker: a code watermarking system
  3. 2:20 Unique challenges of watermarking source code
  4. 4:00 Four key designs of Source marker system
  5. 5:00 Source marker architecture: embedding, extraction, approximation
  6. 6:40 How feature approximation enables end-to-end training
  7. 8:30 Beginning of experimental evaluation

SrcMarker: Dual-Channel Source Code Watermarking via Scalable Code Transformations

Speakers: Borui Yang; Wei Li; Liyao Xiang; Bo Li

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=WMJzS0RvQBQ

Overview

In an era defined by the explosive growth of the developer community and the pervasive influence of large language models (LLMs) in code generation, the protection of intellectual property and the verification of code authorship have become paramount concerns. Borui Yang, along with his colleagues Wei Li, Liyao Xiang, and Bo Li, presented SrcMarker at IEEE S&P, a novel dual-channel source code watermarking system designed to address these pressing challenges. This talk introduces a sophisticated method for embedding invisible bit strings into source code snippets, serving as an undeniable indicator of ownership or as a means to differentiate between human-written and machine-generated code.

SrcMarker stands out by proactively safeguarding code ownership, allowing developers to embed a unique watermark into their code before public release. Should an adversary attempt to claim false ownership or misuse the code, the embedded watermark provides irrefutable proof. The system achieves this by performing semantic-preserving code transformations on the abstract syntax tree (AST) of the input code, ensuring that the watermarked code remains functionally identical and readable. Its innovative approach combines rule-based transformations with neural networks and a unique feature approximation module, enabling end-to-end training despite the discrete nature of source code.

The significance of SrcMarker extends beyond traditional copyright protection. With LLMs like ChatGPT increasingly generating plausible yet potentially problematic code, there's an urgent need to distinguish AI-generated content. SrcMarker offers a promising solution to this, providing a mechanism to tag human-authored code, thereby maintaining the integrity and trustworthiness of platforms like Stack Overflow that have banned AI-generated responses. By tackling the inherent complexities of source code – its dual nature for human understanding and machine processing, and its discrete string format – SrcMarker represents a significant advancement in the field of software intellectual property protection and code provenance.

Background

▶ Watch: Introduction and problem: protecting code ownership (0:00)

The concept of digital watermarking is well-established in various media, yet its application to source code has remained largely unexplored and fraught with unique difficulties. Existing watermarking techniques, such as software watermarking for executables or text watermarking for natural languages, cannot be directly adapted to source code due to fundamental differences in assumptions and constraints. Software watermarking, for instance, typically targets compiled binaries, injecting hidden control flows or secret runtime behaviors without concern for readability. Source code, however, demands readability for human developers. Conversely, text watermarking, which relies on word substitutions or sentence structure modifications, often ignores the strict syntax rules of programming languages, risking the creation of broken or non-compilable code.

The inherent nature of source code presents a complex set of challenges for any watermarking system. Source code exists within two distinct channels: the natural channel, which caters to human developers for understanding and maintenance, and the formal channel, which is processed by automated tools like compilers. A robust source code watermarking system must preserve the semantics of both channels. This means the code's functionality must remain unchanged (formal semantics), and its readability and maintainability for humans must not be significantly degraded (natural semantics).

Furthermore, a delicate balance must be struck across multiple, often conflicting, requirements for the watermark itself: accuracy (correct extraction), efficiency (embedding/extraction speed), transparency (minimal perceptual impact on the code), robustness (resistance to attacks), and capacity (amount of information embedded). Perhaps the most significant technical hurdle arises from the discrete nature of source code. Unlike images or audio, which exist in continuous spaces amenable to gradient-based optimization, source code is a sequence of discrete strings. This discreteness makes it challenging to apply modern learning-based methods that typically rely on continuous gradients for training neural networks, necessitating innovative approaches to bridge this gap. Addressing these multifaceted challenges is precisely where SrcMarker introduces its novel contributions.

Key Findings

▶ Watch: Unique challenges of watermarking source code (2:20)

SrcMarker's core innovation lies in its comprehensive approach to overcoming the inherent difficulties of source code watermarking, incorporating four specific design principles:

  1. Rule-Based Semantic-Preserving Code Transformations: The system employs transformations guided by the Abstract Syntax Tree (AST) of the input code. By operating on this structural representation, SrcMarker theoretically guarantees the semantic equivalence of the watermarked code to its original version, ensuring no functional changes.
  2. Dual-Channel Watermark Embedding: Acknowledging the natural and formal channels of source code, SrcMarker embeds watermarks into both. It performs variable renaming in the natural channel, subtly altering identifiers without changing functionality, and executes code structure transformations (e.g., converting a for loop to a while loop) in the formal channel. This dual-channel strategy significantly increases watermark capacity and enhances robustness by providing mutual backups.
  3. Integration of Neural Networks: To minimize the extensive manual effort typically required for designing purely rule-based systems, SrcMarker integrates neural networks into both the embedding and extraction processes. These networks learn to identify optimal transformation points and extract watermarks efficiently.
  4. Feature Approximation for Discrete Operations: To enable end-to-end training of the entire system, SrcMarker introduces an approximation method that bridges the non-differentiable gap caused by discrete code transformations. This module simulates the effects of discrete operations within the continuous feature space of neural networks, allowing gradient-based optimization to be applied.

The experimental evaluation of SrcMarker, conducted on three datasets covering four programming languages, demonstrated its superior performance compared to adapted text watermarking baselines (AWT from S&P 2021 and CS from AAAI 2022). SrcMarker showed comparable accuracy and efficiency in function-level watermarking (embedding a 4-bit watermark). Crucially, it significantly outperformed baselines in transparency, preserving both operational semantics (verified via AST-based syntax checks on CodeSearchNet (CSN) and execution tests on MBXP) and natural semantics (measured by CodeBLUE and MR scores, ensuring consistency with natural language descriptions).

Regarding robustness, SrcMarker proved resilient to single-channel attacks, a direct benefit of its dual-channel design. While dual-channel attacks (e.g., randomly renaming 50% of variables and performing two random code transformations) were more potent, they came at a greater cost in terms of natural semantics degradation. The system also demonstrated resilience against adaptive de-watermarking and re-watermarking attempts by sophisticated adversaries. Finally, while capacity naturally decreased with more embedded bits, SrcMarker maintained comparable performance, highlighting its practical utility for embedding meaningful information. The work also introduced Mutable AST, a language-agnostic code transformation pipeline, which is a valuable contribution for future research in this domain.

Technical Deep Dive

▶ Watch: Four key designs of Source marker system (4:00)

SrcMarker's architecture is meticulously designed to handle the unique constraints of source code, comprising three primary components: the Watermark Embedding Module, the Watermark Extraction Module, and the crucial Feature Approximation Module.

The Watermark Embedding Module initiates the process by using a set of neural networks to extract continuous feature vectors from the input source code and the watermark bit string. These networks then select a specific set of semantic-preserving transformations to be applied. The actual execution of these transformations is handled by a rule-based transformation pipeline. For this pipeline, the researchers developed Mutable AST, a novel, unified AST representation that abstracts away language-specific details. This design allows transformations to be performed consistently across multiple programming languages (e.g., Python, Java, C++), improving efficiency and correctness compared to existing language-specific tools. For instance, a transformation might involve converting a for loop into an equivalent while loop in the formal channel, or renaming a local variable i to idx in the natural channel. These transformations are guided by the AST, ensuring that the code's syntax and formal semantics remain intact.

The Watermark Extraction Module mirrors the embedding process by employing a similar learning-based design. Neural networks are trained to analyze the potentially watermarked code's feature vectors and deduce the embedded bit string. The challenge here, however, is the non-differentiable nature of the discrete transformations applied during embedding. Traditional neural network training relies on backpropagating gradients through a continuous computational graph.

This is where the Feature Approximation Module plays its pivotal role. Source code, while discrete in its input form, is internally represented by continuous feature vectors within the neural network. Any transformation applied to the code will inevitably manifest as a corresponding change in this feature vector. The approximation module leverages this insight: it takes the original code's continuous feature vector and the selected discrete transformations as input. It then produces an approximated version of the transformed code's feature vector. This approximation process occurs entirely within the continuous and differentiable feature space of the neural networks. This means the module can simulate the effect of discrete code transformations in a differentiable manner. By introducing this approximated feature, the module effectively "bridges the non-differentiable gap" between the discrete embedding operations and the continuous extraction process. This allows gradients to flow back from the extraction module through the approximation module, enabling the entire SrcMarker system to be trained end-to-end using standard gradient-based optimization techniques. This clever design is fundamental to SrcMarker's ability to learn complex embedding and extraction strategies without being hampered by the discrete nature of its input.

The dual-channel embedding strategy is a cornerstone of SrcMarker's robustness and capacity. In the natural channel, watermarks are embedded via variable renaming. For example, a variable named temp might be renamed to _tmp_ or val based on a learned pattern associated with the watermark bits. While these changes are visible to humans, they do not alter the code's functionality and are generally considered minor modifications in terms of natural semantics, as long as they adhere to coding conventions. In the formal channel, watermarks are embedded through code structure transformations. This involves altering control flow or data structures in ways that are semantically equivalent but syntactically different. Examples include converting a for loop into a while loop, changing the order of independent statements, or modifying conditional expressions. These transformations are more profound syntactically but are carefully selected to preserve the operational behavior of the code, as verified by the AST. This combination ensures that even if one channel is compromised by an adversary, the other can still potentially carry enough information to verify the watermark, significantly enhancing the system's resilience.

Demo / Proof of Concept

▶ Watch: How feature approximation enables end-to-end training (6:40)

While the presentation did not feature a live, interactive demonstration, Borui Yang provided a clear illustration of SrcMarker's impact on code. At approximately [14:00] in the talk, an example was shown where specific regions of source code were highlighted to indicate changes made by SrcMarker during the watermark embedding process. The key takeaway from this visual proof of concept was that "despite these changes, the code still remains valid and its functionality remains unchanged." This effectively demonstrated SrcMarker's core promise of semantic preservation and transparency, showcasing that the embedded watermark does not introduce bugs or break the code's operational integrity.

Beyond function-level watermarking, the talk introduced a practical project-level watermarking scheme, which serves as an extended proof of concept for real-world application. This scheme addresses the need to protect an entire source code repository, not just individual functions. The approach involves decomposing a long, unique project-level watermark into shorter segments. Each segment is then embedded into a distinct function within the repository using the function-level watermarking techniques.

The verification of this project-level watermark is achieved through a statistical null hypothesis test. By extracting the segments from multiple functions across the repository, a statistical analysis can be performed to determine if the collective segments correspond to the original long watermark. This setup offers several advantages:

  1. Longer, Unique Identifiers: A project-level watermark can be significantly longer than a function-level one, providing a unique identifier robust enough for comprehensive copyright protection.
  2. Increased Robustness: The distributed nature of the watermark across many functions inherently increases its robustness. Even if several watermarked functions are removed or corrupted by an adversary, a sufficient number of remaining functions can still allow for successful verification through statistical aggregation.
  3. Practicality: This scheme demonstrates a more practical and scalable use of SrcMarker for enterprise-level intellectual property protection, allowing developers to verify ownership of entire codebases rather than just isolated snippets.

This project-level approach effectively extends the proof of concept from individual function transformations to a robust, scalable system capable of addressing real-world software ownership verification challenges.

Defensive Implications

▶ Watch: Beginning of experimental evaluation (8:30)

SrcMarker offers significant defensive implications for developers, organizations, and the broader software ecosystem, particularly in the face of rampant code reuse, intellectual property theft, and the rise of AI-generated code.

The primary defensive application is copyright protection and ownership verification. Developers can proactively embed a unique watermark into their proprietary or open-source code before making it public. If this code is subsequently stolen, used without authorization, or falsely claimed by an adversary, the original developer can extract the watermark to unequivocally prove their ownership. This provides a crucial mechanism for legal recourse and reinforces intellectual property rights in a digital landscape where code can be easily copied and redistributed. For example, if a company suspects a competitor has illicitly used their patented algorithm, SrcMarker could provide forensic evidence.

Secondly, SrcMarker presents a potential solution to the growing challenge of distinguishing human-written code from machine-generated code, especially from large language models (LLMs). As platforms like Stack Overflow have recognized, AI-generated content can be plausible but also incorrect or harmful. By embedding a "human-authored" watermark, developers could provide a verifiable signal of provenance, helping to maintain the integrity and trust of collaborative coding environments and ensuring the quality of code contributions. While not explicitly detailed as a defense against LLMs, it's a defense for human authorship.

The dual-channel embedding design itself acts as a defensive measure against adversarial attacks. By distributing watermark information across both natural (variable renaming) and formal (code structure transformations) channels, SrcMarker gains inherent robustness. An adversary attempting to remove or corrupt the watermark without breaking the code's functionality or readability would need to target both channels simultaneously, which is significantly more difficult and costly. Single-channel attacks are often insufficient to remove the watermark entirely.

Furthermore, SrcMarker's resilience against adaptive de-watermarking and re-watermarking attacks is a critical defensive attribute. The research showed that even an adversary with full knowledge of SrcMarker's design, attempting to train their own de-watermarking model, struggled to remove the original watermark without producing "barely usable" or "broken code" due to a lack of understanding of syntax constraints. Similarly, re-watermarking attempts by adversaries did not result in SrcMarker responding to the adversary's new watermark, as the extraction module is specifically trained for the original watermark. This highlights the advantage of the end-to-end training and distinct model architectures, making it difficult for an attacker to subtly alter the code and inject their own verifiable mark.

In essence, SrcMarker empowers defenders with a proactive, resilient, and verifiable mechanism to assert code ownership and provenance. While it doesn't prevent theft outright, it significantly raises the bar for adversaries by providing a strong evidentiary tool and making it challenging to tamper with ownership information without noticeable degradation to the code itself.

Key Takeaways

  • Novel Dual-Channel System: SrcMarker is a pioneering dual-channel source code watermarking system that addresses the unique challenges of embedding ownership information into programming code while preserving both its operational functionality (formal semantics) and human readability (natural semantics).
  • Hybrid Design for Complexity: It cleverly combines rule-based semantic-preserving code transformations, guided by the Abstract Syntax Tree (AST), with neural networks for efficient embedding and extraction. This hybrid approach reduces manual effort and enhances learning capabilities.
  • Bridging Discrete and Continuous: A critical innovation is the Feature Approximation Module, which enables end-to-end training of the entire system. It simulates the effects of discrete code transformations within a continuous feature space, allowing gradient-based optimization despite the non-differentiable nature of source code.
  • Robustness Through Dual-Channel Embedding: Watermarks are embedded in both natural (variable renaming) and formal (code structure transformations like for-to-while loop conversion) channels. This dual-channel strategy significantly boosts watermark capacity and provides enhanced robustness against various adversarial attacks.
  • Practical Applicability and Performance: SrcMarker demonstrates strong performance in effectiveness, transparency, robustness (including against adaptive attacks), and capacity. It offers a practical project-level watermarking scheme for entire code repositories, allowing for verifiable ownership of large codebases.
  • Language-Agnostic Transformations: The introduction of Mutable AST provides a unified, language-agnostic code transformation pipeline, making SrcMarker adaptable to different programming languages and a valuable contribution for future research in code analysis and manipulation.

About the Speaker(s)

The primary presenter for this work was Borui Yang. While specific titles and affiliations were not detailed in the transcript, the context of an IEEE S&P conference presentation indicates that Borui Yang is a researcher, likely a Ph.D. student or post-doctoral researcher, contributing to the field of cybersecurity and software engineering. He was joined by co-authors Wei Li, Liyao Xiang, and Bo Li, who collaborated on the research and development of SrcMarker. Their collective work, presented at a prestigious security conference, underscores their expertise in advanced topics related to program analysis, machine learning applications in security, and intellectual property protection for software.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

SrcMarker is a groundbreaking dual-channel source code watermarking system that tackles the critical problem of IP protection and code provenance in the age of LLMs. Its innovative 'Feature Approximation Module' cleverly bridges the discrete-continuous gap for neural network training, allowing for robust, end-to-end learning of semantic-preserving transformations. This is a significant technical leap with immediate, actionable impact.

Heather Calloway (CISO) — STRONG ACCEPT

SrcMarker offers a robust technical solution for critical code ownership and provenance challenges, especially with AI-generated content. This provides security leaders a powerful tool for intellectual property protection and accountability, fundamentally altering how we verify code authorship in enterprise environments.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024