Token Counts Are Not Model Lineage: A Frozen-Threshold Holdout Study of Black-Box LLM API Fingerprinting
cs.CL
Submitted: 2026-08-30
Updated: 2026-08-30
Comments: 10 pages, 2 figures
Code: https://github.com/ictchenbo/which-llm
License: http://creativecommons.org/licenses/by/4.0/
The gist: Black-box model attribution is increasingly relevant when large language models (LLMs) are served through relay and reseller APIs.
Terminology
Abstract
Black-box model attribution is increasingly relevant when large language models (LLMs) are served through relay and reseller APIs. A tempting low-cost signal is the prompt-token count returned by an OpenAI-compatible endpoint: two models that share a tokenizer and chat template may produce the same count sequence up to a fixed offset. Yet the validity of this signal for broader model-family attribution has received little direct holdout testing. We conduct a frozen-threshold study over 24 labeled endpoint pairs, split evenly into a development set and an untouched holdout set, with three temporal repeats and 30 controlled texts per pair. We introduce a validity-gated result contract that distinguishes an observed dissimilarity from an uninformative measurement caused by missing usage data, rate limits, or endpoint policy. The resulting shift-invariant exact-match score perfectly separates the 12 development pairs, yielding a frozen threshold of 0.725. On holdout, however, only 6 of 12 pairs are eligible under the pre-specified three-repeat rule. Among eligible pairs, balanced accuracy is 0.75, sensitivity is 0.50 (95% Wilson interval 0.15--0.85), and specificity is 1.00 (0.342--1.00). Two same-family pairs---Qwen 3.8 and DeepSeek V4 variants---fall below the frozen threshold. Across 4,320 formal API calls, every log is replayable, while holdout contains 189 non-200 responses and 157 successful responses without prompt-token usage. The study therefore validates token-count consistency as a fingerprint of a shared tokenization stack, but rejects its use as a standalone necessary test for model-family lineage.
Sources
- ProFLingo: A Fingerprinting-based Intellectual Property Protection Scheme for Large Language Models
- A Fingerprint for Large Language Models
- Hide and Seek: Fingerprinting Large Language Models with Evolutionary Learning
- The Challenge of Identifying the Origin of Black-Box Large Language Models
- KBF: Knowledge Boundary as Fingerprint for Language Model and Black-Box API Auditing
- Black-Box Forensics for Conversational LLM Agents
Related papers
- Exploring Solution Divergence and Its Effect on Large Language Model Problem Solving
- Ishigaki-IDS-Bench: A Benchmark for Generating Information Delivery Specification from BIM Information Requirements
- Subliminal Steering: Stronger Encoding of Hidden Signals
- MedStruct-S: A Benchmark for Key Discovery, Key-Conditioned QA and Semi-Structured Extraction from OCR Clinical Reports
- The End of Transformers? On Challenging Attention and the Rise of Sub-Quadratic Architectures
- Untangling the Mechanisms of Misleading Context in Medical Question Answering