CARTS preserves per‑position rank information of an autoregressive language model to transform a payload into a stegotext of identical token length. Under deterministic model assumptions we prove exact correctness and introduce a rank‑coordinate representation where keys act as bijections on the rank‑vector space. From this we define four security notions: context search, key collisions, message equivocation, and non‑commutativity of the encoding maps. We then relate these notions theoretically, showing that message equivocation reduces to context search and discussing the tension between key collisions and equivocation. An empirical evaluation on Llama 3 8B recovered the original payload in every trial, observed no key collisions with random keys, found that a handcrafted collision is only local, and detected no commuting key pairs, indicating resistance to the studied attacks. This work establishes a formal foundation for using language models in cryptography and privacy‑preserving communication.
Review