MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language Models
Shojiro Yamabe, Futa Kai Waseda, Tsubasa Takahashi, Koki Wataoka
Abstract
Protecting the intellectual property of Large Language Models (LLMs) has become increasingly critical due to the high cost of training. Model merging, which integrates multiple expert models into a single multi-task model, introduces a novel risk of unauthorized use of LLMs due to its efficient merging process. While fingerprinting techniques have been proposed for verifying model ownership, their resistance to model merging remains unexplored. To address this gap, we propose a novel fingerprinting method, MERGEPRINT, which embeds robust fingerprints capable of surviving model merging. MERGEPRINT enables blackbox ownership verification, where owners only need to check if a model produces target outputs for specific fingerprint inputs, without accessing model weights or intermediate outputs. By optimizing against a pseudo-merged model that simulates merged behavior, MERGEPRINT ensures fingerprints that remain detectable after merging. Additionally, to minimize performance degradation, we pre-optimize the fingerprint inputs. MERGEPRINT pioneers a practical solution for black-box ownership verification, protecting LLMs from misappropriation via merging, while also excelling in resistance to broader model theft threats. * indicates equal contribution.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1c7442ff-8ecb-4802-a735-f6760bc1301bCited by top-tier papers4
- Model Provenance Testing for Large Language ModelsIvica Nikolic, Teodora Baluta, Prateek SaxenaNeurIPS 2025 · 20 citations
- ErrorTrace: A Black-Box Traceability Mechanism Based on Model Family Error SpaceChuanchao Zang, Xiangtao Meng, Wenyu Chen, Tianshuo Cong et al.NeurIPS 2025 · 4 citations
- Defending Unauthorized Model Merging via Dual-Stage Weight ProtectionWei-Jia Chen, Min-Yan Tsai, Cheng-Yi Lee, Chia-Mu YuCVPR 2026 · 2 citations
- UMMF: Protecting Copyright of Large Vision-Language Models through Unlearning-based Multimodal Memorization FingerprintXiaofan Zheng, Xinghao Wang, Xiaojun WanACL 2026
Builds on13
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- WinoGrande: An Adversarial Winograd Schema Challenge at ScaleKeisuke Sakaguchi, Ronan Le Bras, Chandra Bhagavatula, Yejin ChoiAAAI 2020 · 3,037 citations
- PIQA: Reasoning about Physical Commonsense in Natural LanguageYonatan Bisk, Rowan Zellers, Ronan Le Bras, Jianfeng Gao et al.AAAI 2020 · 2,916 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- Language Models are Super Mario: Absorbing Abilities from Homologous Models as a Free LunchLe Yu, Bowen Yu, Haiyang Yu, Fei Huang et al.ICML 2024 · 605 citations
Related papers
- ImF: Embedding an Implicit Fingerprint in Your Large Language ModelsJiaxuan Wu, Wanli Peng, Hang Fu, Yiming Xue et al.ACL 2026
- iSeal: Encrypted Fingerprinting for Reliable LLM Ownership VerificationZixun Xiong, Gaoyi Wu, Qingyang Yu, Mingyu Derek Ma et al.AAAI 2026
- SIF: Semantically In-Distribution Fingerprints for Large Vision-Language ModelsYifei Zhao, Qian Lou, Mengxin ZhengCVPR 2026 · 2 citations
- Hey, That's My Model! Introducing Chain & Hash, An LLM Fingerprinting TechniqueMark Russinovich, Yanan Cai, Ahmed SalemICLR 2026 · 51 citations
- CircuitPrint: Mechanistic Circuit Fingerprints for Large Language ModelsZhenxiong Yan, Suhang Yao, Yu Liu, Wenqiang JinICML 2026
