MCGMark: An Encodable and Robust Online Watermark for Tracing LLM-Generated Malicious Code
With the advent of large language models (LLMs), numerous software service providers are developing LLMs tailored for code generation, such as CodeLlama. However, these models can be exploited by malicious developers to generate malicious code, posing severe threats to the software ecosystem. To address this issue, we first conducted an empirical study and built MCGTest , a dataset of \(406\) prompts designed to elicit malicious code from LLMs. Leveraging this dataset, we propose MCGMark , a watermarking method to trace and attribute LLM-generated malicious code. MCGMark subtly embeds user-specific information into generated code by controlling the token selection process, ensuring the watermark is imperceptible. Additionally, MCGMark dynamically adjusts the token selection range to induce the LLM to favor high-probability tokens, thus ensuring code quality. Furthermore, by leveraging code structure, MCGMark avoids embedding watermarks into regions easily modified by attackers, such as comments and variable names, enhancing robustness against tampering. Experiments on several advanced LLMs show that MCGMark successfully embeds watermarks in approximately \(85\%\) of cases, under the constraint of a \(400\) -token limit. Moreover, it maintains code quality and demonstrates strong resilience against common code modification. This approach offers a practical solution for tracing malicious code and mitigating the misuse of LLMs.
Authors
- Kaiwen Ning (ORCID: https://orcid.org/0009-0009-6009-8285)
- Jiachi Chen (ORCID: https://orcid.org/0000-0002-0192-9992)
- Wei Li (ORCID: https://orcid.org/0000-0002-3135-0447)
- Yanlin Wang (ORCID: https://orcid.org/0000-0001-7761-7269)
- Yu Zhang (ORCID: https://orcid.org/0000-0002-2052-2231)
- Tao Zhang (ORCID: https://orcid.org/0009-0006-7058-9131)
- Qingyuan Zhong (ORCID: https://orcid.org/0009-0002-6825-7518)
Institutions
- Macau University of Science and Technology (MO)
- Sun Yat-sen University (CN)
- Harbin Institute of Technology (CN)
- Peng Cheng Laboratory (CN)
Publication Details
- Journal
- ACM Transactions on Software Engineering and Methodology
- Published
- 2026-10-06
- DOI
- https://doi.org/10.1145/3846177
- Citations
- 1
- Primary Topic
- Advanced Steganography and Watermarking Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00