I'm not sure the watermark has been demonstrated to have that kind of property. Even if you use a CSRNG as the 'key' once you're feeding it through the token selection process it's going to risk re-introducing certain correlations.

How would you re-introduce correlations on top of a CSPRNG without a cryptographic break?