Paper list of LLM fingerprinting, based on our paper titled "SoK: Large Language Model Copyright Auditing via Fingerprinting".
33
8 commits
updated Aug 28, 2025
This repository provides a collection of papers about LLM fingerprinting and is based on the paper entitled "SoK: Large Language Model Copyright Auditing via Fingerprinting".
LLM fingerprinting is a passive approach that does not require modifying the model. Instead, it non-intrusively extracts a set of inherent yet distinctive characteristics that collectively serve as the model's "fingerprint". The core idea is that any model derived from the source model $M_o$ will preserve a statistically significant portion of this fingerprint.
In this paper and repository, we follow a classic narrow definition of LLM watermarking and fingerprinting. The primary difference between watermarking and fingerprinting is whether the method requires modifying the model's parameters and LLM fingerprinting is a non-intrusive method. Some existing papers embed "fingerprints" into LLMs by modifying their parameters. In this paper and repository, we classify these methods as LLM watermarking.
The primary advantage of LLM fingerprinting lies in its non-intrusive nature. Since it does not alter the model, it introduces no performance degradation. The computational overhead is typically confined, which is often less intensive than the fine-tuning required for watermarking. Consequently, fingerprinting offers a more flexible and widely applicable paradigm for copyright auditing, especially for models that are already in the public domain.
In this SoK, we also provide a comprehensive benchmark named LeaFBench for evaluating LLM fingerprinting methods.
If you find this repository useful, please cite our paper:
@article{shao2025sok,
title={SoK: Large Language Model Copyright Auditing via Fingerprinting},
author={Shao, Shuo and Li, Yiming and He, Yu and Yao, Hongwei and Yang, Wenyuan and Tao, Dacheng and Qin, Zhan},
journal={arXiv preprint arXiv:2508.19843},
year={2025}
}
| Title | Conference/Journal | Year | Type | Subtype | Query Data | Relied Features | Fingerprint Comparison | Code |
|---|---|---|---|---|---|---|---|---|
| A DNN Fingerprint for Non-Repudiable Model Ownership Identification and Piracy Detection | TIFS | 2022 | White-box | Static | NA | Lower Layer Weights | Adjusted Cosine Similarity | / |
| HuRef: HUman-REadable Fingerprint for Large Language Models | NeurIPS | 2024 | White-box | Static | NA | Parameters' Direction | Cosine Similarity | Link |
| EasyDetector: Using Linear Probe to Detect the Provenance of Large Language Models | TrustCom | 2024 | White-box | Forward-pass | Existing Dataset | Intermediate Features | Linear Probe | / |
| Intrinsic Fingerprint of LLMs: Continue Training is NOT All You Need to Steal A Model! | arXiv | 2025 | White-box | Static | NA | Parameters' Statistics | Correlation Coefficient | / |
| Matrix-driven instant review: Confident detection and reconstruction of LLM plagiarism on PC | arXiv | 2025 | White-box | Static | NA | Model Weight Matrices | Matrix Transformations based on Large Deviation Theory | / |
| REEF: Representation Encoding Fingerprints for Large Language Models | ICLR | 2025 | White-box | Forward-pass | Existing Dataset | Intermediate Features | Centered Kernel Alignment | Link |
| Gradient-Based Model Fingerprinting for LLM Similarity Detection and Family Classification | arXiv | 2025 | White-box | Backward-pass | Unknown | Gradient | Euclidean Distance | / |
| A Fingerprint for Large Language Models | arXiv | 2024 | Black-box | Untargeted | Random Queries | Output Logits | Euclidean Distance & Dimension Difference | Link |
| Hide and Seek: Fingerprinting Large Language Models with Evolutionary Learning | arXiv | 2024 | Black-box | Untargeted | LLM-generated Prompts | Output Content | Detective LLM | Link |
| TRAP: Targeted Random Adversarial Prompt Honeypot for Black-Box Identification | ACL Findings | 2024 | Black-box | Targeted | A Base Prompt Combined with an Optimized Suffix | Output Content | Exact Match | Link |
| ProFLingo: A Fingerprinting-based Intellectual Property Protection Scheme for Large Language Models | IEEE CNS | 2024 | Black-box | Targeted | A Prompt with an Optimized Prefix | Output Content | Target Response Rate | Link |
| LLMmap: Fingerprinting For Large Language Models | USENIX Security | 2025 | Black-box | Untargeted | Manually-crafted Prompts | Output Content | Cosine Similarity | Link |
| Model Equality Testing: Which Model is this API Serving? | ICLR | 2025 | Black-box | Untargeted | Manually-crafted Prompts | Hamming Distance Kernel | Maximum Mean Discrepancy | Link |
| Your Large Language Models are Leaving Fingerprints | COLING Workshop | 2025 | Black-box | Untargeted | Existing Dataset | N-gram | ML Classifier | / |
| Invisible Traces: Using Hybrid Fingerprinting to identify underlying LLMs in GenAI Apps | arXiv | 2025 | Black-box | Untargeted | Crafted Strategic Prompts & Generic Prompts | Output Content | Transformer-based Classifier & LLM | / |
| CoTSRF: Utilize Chain of Thought as Stealthy and Robust Fingerprint of Large Language Models | arXiv | 2025 | Black-box | Untargeted | Reasoning Questions with CoT Prompts | Output Content | KL Divergence | / |
| DuFFin: A Dual-Level Fingerprinting Framework for LLMs IP Protection | arXiv | 2025 | Black-box | Untargeted | A Combination of Trigger Prompts | Output Content | Cosine Similarity & Hamming Distance | Link |
| Auditing Black-Box LLM APIs with a Rank-Based Uniformity Test | arXiv | 2025 | Black-box | Untargeted | Natural Prompts | The Log-rank of Response Tokens | Cramér-von Mises Statistical Test | / |
| Attacks and defenses against LLM fingerprinting | arXiv | 2025 | Black-box | Untargeted | An RL-optimized Set of Queries | Output Content | Transformer-based Classifier | / |
| RAP-SM: Robust Adversarial Prompt via Shadow Models for Copyright Verification of Large Language Models | arXiv | 2025 | Black-box | Targeted | A Prompt Combined with an Optimized Suffix | Output Content | Exact Match | / |
| RoFL: Robust Fingerprinting of Language Models | arXiv | 2025 | Black-box | Targeted | Optimized Unlikely Token Sequences | Output Content | Exact Match | Link |
| LLM-FIN: Large Language Models Fingerprinting Attack on Edge Devices | ISQED | 2024 | Side-channel | / | / | Memory Usage Pattern | ML-based | / |
| LLMs Have Rhythm: Fingerprinting Large Language Models Using Inter-Token Times and Network Traffic Analysis | OJCOMS | 2025 | Side-channel | / | / | Inter-token Times | DL-based | / |
Paper list of LLM fingerprinting, based on our paper titled "SoK: Large Language Model Copyright Auditing via Fingerprinting".
33
8 commits
updated Aug 28, 2025
This repository provides a collection of papers about LLM fingerprinting and is based on the paper entitled "SoK: Large Language Model Copyright Auditing via Fingerprinting".
LLM fingerprinting is a passive approach that does not require modifying the model. Instead, it non-intrusively extracts a set of inherent yet distinctive characteristics that collectively serve as the model's "fingerprint". The core idea is that any model derived from the source model $M_o$ will preserve a statistically significant portion of this fingerprint.
In this paper and repository, we follow a classic narrow definition of LLM watermarking and fingerprinting. The primary difference between watermarking and fingerprinting is whether the method requires modifying the model's parameters and LLM fingerprinting is a non-intrusive method. Some existing papers embed "fingerprints" into LLMs by modifying their parameters. In this paper and repository, we classify these methods as LLM watermarking.
The primary advantage of LLM fingerprinting lies in its non-intrusive nature. Since it does not alter the model, it introduces no performance degradation. The computational overhead is typically confined, which is often less intensive than the fine-tuning required for watermarking. Consequently, fingerprinting offers a more flexible and widely applicable paradigm for copyright auditing, especially for models that are already in the public domain.
In this SoK, we also provide a comprehensive benchmark named LeaFBench for evaluating LLM fingerprinting methods.
If you find this repository useful, please cite our paper:
@article{shao2025sok,
title={SoK: Large Language Model Copyright Auditing via Fingerprinting},
author={Shao, Shuo and Li, Yiming and He, Yu and Yao, Hongwei and Yang, Wenyuan and Tao, Dacheng and Qin, Zhan},
journal={arXiv preprint arXiv:2508.19843},
year={2025}
}
| Title | Conference/Journal | Year | Type | Subtype | Query Data | Relied Features | Fingerprint Comparison | Code |
|---|---|---|---|---|---|---|---|---|
| A DNN Fingerprint for Non-Repudiable Model Ownership Identification and Piracy Detection | TIFS | 2022 | White-box | Static | NA | Lower Layer Weights | Adjusted Cosine Similarity | / |
| HuRef: HUman-REadable Fingerprint for Large Language Models | NeurIPS | 2024 | White-box | Static | NA | Parameters' Direction | Cosine Similarity | Link |
| EasyDetector: Using Linear Probe to Detect the Provenance of Large Language Models | TrustCom | 2024 | White-box | Forward-pass | Existing Dataset | Intermediate Features | Linear Probe | / |
| Intrinsic Fingerprint of LLMs: Continue Training is NOT All You Need to Steal A Model! | arXiv | 2025 | White-box | Static | NA | Parameters' Statistics | Correlation Coefficient | / |
| Matrix-driven instant review: Confident detection and reconstruction of LLM plagiarism on PC | arXiv | 2025 | White-box | Static | NA | Model Weight Matrices | Matrix Transformations based on Large Deviation Theory | / |
| REEF: Representation Encoding Fingerprints for Large Language Models | ICLR | 2025 | White-box | Forward-pass | Existing Dataset | Intermediate Features | Centered Kernel Alignment | Link |
| Gradient-Based Model Fingerprinting for LLM Similarity Detection and Family Classification | arXiv | 2025 | White-box | Backward-pass | Unknown | Gradient | Euclidean Distance | / |
| A Fingerprint for Large Language Models | arXiv | 2024 | Black-box | Untargeted | Random Queries | Output Logits | Euclidean Distance & Dimension Difference | Link |
| Hide and Seek: Fingerprinting Large Language Models with Evolutionary Learning | arXiv | 2024 | Black-box | Untargeted | LLM-generated Prompts | Output Content | Detective LLM | Link |
| TRAP: Targeted Random Adversarial Prompt Honeypot for Black-Box Identification | ACL Findings | 2024 | Black-box | Targeted | A Base Prompt Combined with an Optimized Suffix | Output Content | Exact Match | Link |
| ProFLingo: A Fingerprinting-based Intellectual Property Protection Scheme for Large Language Models | IEEE CNS | 2024 | Black-box | Targeted | A Prompt with an Optimized Prefix | Output Content | Target Response Rate | Link |
| LLMmap: Fingerprinting For Large Language Models | USENIX Security | 2025 | Black-box | Untargeted | Manually-crafted Prompts | Output Content | Cosine Similarity | Link |
| Model Equality Testing: Which Model is this API Serving? | ICLR | 2025 | Black-box | Untargeted | Manually-crafted Prompts | Hamming Distance Kernel | Maximum Mean Discrepancy | Link |
| Your Large Language Models are Leaving Fingerprints | COLING Workshop | 2025 | Black-box | Untargeted | Existing Dataset | N-gram | ML Classifier | / |
| Invisible Traces: Using Hybrid Fingerprinting to identify underlying LLMs in GenAI Apps | arXiv | 2025 | Black-box | Untargeted | Crafted Strategic Prompts & Generic Prompts | Output Content | Transformer-based Classifier & LLM | / |
| CoTSRF: Utilize Chain of Thought as Stealthy and Robust Fingerprint of Large Language Models | arXiv | 2025 | Black-box | Untargeted | Reasoning Questions with CoT Prompts | Output Content | KL Divergence | / |
| DuFFin: A Dual-Level Fingerprinting Framework for LLMs IP Protection | arXiv | 2025 | Black-box | Untargeted | A Combination of Trigger Prompts | Output Content | Cosine Similarity & Hamming Distance | Link |
| Auditing Black-Box LLM APIs with a Rank-Based Uniformity Test | arXiv | 2025 | Black-box | Untargeted | Natural Prompts | The Log-rank of Response Tokens | Cramér-von Mises Statistical Test | / |
| Attacks and defenses against LLM fingerprinting | arXiv | 2025 | Black-box | Untargeted | An RL-optimized Set of Queries | Output Content | Transformer-based Classifier | / |
| RAP-SM: Robust Adversarial Prompt via Shadow Models for Copyright Verification of Large Language Models | arXiv | 2025 | Black-box | Targeted | A Prompt Combined with an Optimized Suffix | Output Content | Exact Match | / |
| RoFL: Robust Fingerprinting of Language Models | arXiv | 2025 | Black-box | Targeted | Optimized Unlikely Token Sequences | Output Content | Exact Match | Link |
| LLM-FIN: Large Language Models Fingerprinting Attack on Edge Devices | ISQED | 2024 | Side-channel | / | / | Memory Usage Pattern | ML-based | / |
| LLMs Have Rhythm: Fingerprinting Large Language Models Using Inter-Token Times and Network Traffic Analysis | OJCOMS | 2025 | Side-channel | / | / | Inter-token Times | DL-based | / |