ImF: Embedding an Implicit Fingerprint in Your Large Language Models
Jiaxuan Wu, Wanli Peng, Hang Fu, Yiming Xue, Juan Wen
Abstract
Training and serving large language models (LLMs) is resource-intensive, making reliable intellectual property (IP) protection and blackbox ownership verification increasingly important. Model fingerprinting enables such verification by injecting a small set of secret query-response behaviors, but many existing fingerprints rely on explicit markers or predetermined outputs that are weakly grounded in prompt semantics. This semantic mismatch yields atypical fingerprint responses, reduces stealthiness, and exposes fingerprints to removal by response normalization. We formalize this vulnerability via a new removal attack, Generation Revision Intervention (GRI), which applies system-prompt-level revision and response standardization to steer models toward typical answers, substantially compromising representative injected baselines. To close this semantic gap, we propose the Implicit Fingerprints (ImF): we encode ownership information into a natural-looking target response y via linguistic steganography, then derive a CoTaugmented query x that embeds semantic cues from y to guide the model toward an output sufficiently close to y for decoding-based verification. Experiments on 15 LLMs show that ImF improves stealthiness and remains verifiable under model updates and deploymenttime prompt interventions; additional analyses further show stability under common decoding variation and realistic related-model partial merging.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 374a7c40-4fa4-4560-b3ed-0f023dd3326fBuilds on13
- Measuring Massive Multitask Language UnderstandingDan Hendrycks, Collin Burns, Steven Basart, Andy Zou et al.ICLR 2021 · 7,905 citations
- Hey, That's My Model! Introducing Chain & Hash, An LLM Fingerprinting TechniqueMark Russinovich, Yanan Cai, Ahmed SalemICLR 2026 · 51 citations
- HuRef: HUman-REadable Fingerprint for Large Language ModelsBoyi Zeng, Lizheng Wang, Yuncong Hu, Yi Xu et al.NeurIPS 2024 · 48 citations
- SSLGuard: A Watermarking Scheme for Self-supervised Learning Pre-trained EncodersTianshuo Cong, Xinlei He, Yang ZhangCCS 2022 · 28 citations
- False Claims against Model Ownership ResolutionJian Liu, Rui Zhang, Sebastian Szyller, Kui Ren et al.USENIX Security 2024 · 22 citations
Related papers
- CTCC: A Robust and Stealthy Fingerprinting Framework for Large Language Models via Cross-Turn Contextual Correlation BackdoorZhenhua Xu, Xixiang Zhao, Xubin Yue, Shengwei Tian et al.EMNLP 2025
- SIF: Semantically In-Distribution Fingerprints for Large Vision-Language ModelsYifei Zhao, Qian Lou, Mengxin ZhengCVPR 2026 · 2 citations
- MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language ModelsShojiro Yamabe, Futa Kai Waseda, Tsubasa Takahashi, Koki WataokaACL 2025 · 4 citations
- iSeal: Encrypted Fingerprinting for Reliable LLM Ownership VerificationZixun Xiong, Gaoyi Wu, Qingyang Yu, Mingyu Derek Ma et al.AAAI 2026
- EverTracer: Hunting Stolen Large Language Models via Stealthy and Robust Probabilistic FingerprintZhenhua Xu, Meng Han, Wenpeng XingEMNLP 2025 · 2 citations
