Hey, That's My Model! Introducing Chain & Hash, An LLM Fingerprinting Technique
Mark Russinovich, Yanan Cai, Ahmed Salem
Abstract
Growing concerns over the theft and misuse of Large Language Models (LLMs) have heightened the need for effective fingerprinting, which links a model to its original version to detect misuse. In this paper, we define five key properties for a successful fingerprint: Transparency, Efficiency, Persistence, Robustness, and Unforgeability. We introduce a novel fingerprinting framework that provides verifiable proof of ownership while maintaining fingerprint integrity. Our approach makes two main contributions. First, we propose a "chain and hash" technique that cryptographically binds fingerprint prompts with their responses, ensuring no adversary can generate colliding fingerprints and allowing model owners to irrefutably demonstrate their creation. Second, we address a realistic threat model in which instruction-tuned models' output distribution can be significantly altered through meta-prompts. By integrating random padding and varied meta-prompt configurations during training, our method preserves fingerprint robustness even when the model's output style is significantly modified. Experimental results demonstrate that our framework offers strong security for proving ownership and remains resilient against benign transformations like fine-tuning, as well as adversarial attempts to erase fingerprints. Finally, we also demonstrate its applicability to fingerprinting LoRA adapters.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d8541bfe-ef07-4a0b-a6ca-49178f4cc017Cited by top-tier papers13
- Scalable Fingerprinting of Large Language ModelsAnshul Nasery, Jonathan Hayase, Creston Brooks, Peiyao Sheng et al.NeurIPS 2025 · 17 citations
- MEraser: An Effective Fingerprint Erasure Approach for Large Language ModelsJingxuan Zhang, Zhenhua Xu, Rui Hu, Wenpeng Xing et al.ACL 2025 · 16 citations
- DiffIP: Representation Fingerprints for Robust IP Protection of Diffusion ModelsZhuoling Li, Haoxuan Qu, Jason Kuen, Jiuxiang Gu et al.ICCV 2025 · 4 citations
- ErrorTrace: A Black-Box Traceability Mechanism Based on Model Family Error SpaceChuanchao Zang, Xiangtao Meng, Wenyu Chen, Tianshuo Cong et al.NeurIPS 2025 · 4 citations
- AWM: Accurate Weight-Matrix Fingerprint for Large Language ModelsBoyi Zeng, Lin Chen, Ziwei He, Xinbing Wang et al.ICLR 2026 · 3 citations
Builds on6
- Measuring Massive Multitask Language UnderstandingDan Hendrycks, Collin Burns, Steven Basart, Andy Zou et al.ICLR 2021 · 7,905 citations
- TruthfulQA: Measuring How Models Mimic Human FalsehoodsStephanie Lin, Jacob Hilton, Owain EvansACL 2022 · 3,228 citations
- WinoGrande: An Adversarial Winograd Schema Challenge at ScaleKeisuke Sakaguchi, Ronan Le Bras, Chandra Bhagavatula, Yejin ChoiAAAI 2020 · 3,037 citations
- Aligning AI With Shared Human ValuesDan Hendrycks, Collin Burns, Steven Basart, Andrew Critch et al.ICLR 2021 · 878 citations
- BadPre: Task-agnostic Backdoor Attacks to Pre-trained NLP Foundation ModelsKangjie Chen, Yuxian Meng, Xiaofei Sun, Shangwei Guo et al.ICLR 2022 · 133 citations
Related papers
- CTCC: A Robust and Stealthy Fingerprinting Framework for Large Language Models via Cross-Turn Contextual Correlation BackdoorZhenhua Xu, Xixiang Zhao, Xubin Yue, Shengwei Tian et al.EMNLP 2025
- MergePrint: Merge-Resistant Fingerprints for Robust Black-box Ownership Verification of Large Language ModelsShojiro Yamabe, Futa Kai Waseda, Tsubasa Takahashi, Koki WataokaACL 2025 · 4 citations
- EverTracer: Hunting Stolen Large Language Models via Stealthy and Robust Probabilistic FingerprintZhenhua Xu, Meng Han, Wenpeng XingEMNLP 2025 · 2 citations
- ImF: Embedding an Implicit Fingerprint in Your Large Language ModelsJiaxuan Wu, Wanli Peng, Hang Fu, Yiming Xue et al.ACL 2026
- PROMPRINT: Prompt Fingerprinting via First-Token Response for LLM App Cloning DetectionJungmin Lee, Peizhuo Lv, Yeonjoon LeeACL 2026
