AuxMark defends against unauthorized copying of AI agent behaviors

AuxMark: Defending Against Unauthorized Agent Distillation via Auxiliary Behavioral Watermarking

Cryptography and Security

Summary

Large AI agents that perform tasks by interacting with environments can have their behavior copied without permission, creating unauthorized versions called student agents. The authors introduce AuxMark, a method that hides harmless extra actions in the original agent’s behavior as a secret watermark. Later, they can test if a suspicious agent copied this watermark by checking its responses to specific checks called evidence cards. Their tests show AuxMark reliably detects copied agents without affecting how well agents perform tasks, even when attackers try to remove or modify the watermark.

What this means in practice

  • For ai product security teams: Detect unauthorized copies of proprietary AI agents to protect intellectual property in deployed systems.$Commercial implications: Provides a method for companies to prove and detect illegal cloning of their AI assistants, enabling legal protection and enforcement.
  • For software platform operators: Audit AI agents submitted to platforms for signs of unauthorized distillation to prevent abuse of shared models.

Authors

Yiqing Feng, Haozhe Feng, Shunan Shang, Xiaoyu Zhang, Jian Lou, Haodong Zhao, Mingxun Zhou

Abstract

Large language model agents can acquire complex capabilities through multi-step interaction and tool use, but their trajectories can also be illegally collected to dis- till student agents. However, existing watermarking methods either do not fit the structured and interactive nature of agent environments or lack reliable effective- ness across tasks and model architectures. We introduce AuxMark, a behavioral watermarking framework for tracing unauthorized agent distillation. AuxMark dynamically inserts safe, non-essential auxiliary action into teacher trajectories, and stores the associated contexts as private evidence cards. To audit a suspicious student model, AuxMark constructs paired real and fake probes from these cards and applies a card-level sign test. This black-box protocol supports both model- level detection and trace-level attribution. Across three agent benchmarks, two teacher agents, and four student architectures, AuxMark detects all 24 distilled models with zero false positives on 48 clean models. It also preserves task utility and remains effective against data flooding, paraphrasing, truncation, and adaptive cleaning attacks. Our code will be released at this URL.