Pith. sign in

REVIEW 2 cited by

LLMmap: Fingerprinting For Large Language Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.15847 v4 pith:PSIISXYP submitted 2024-07-22 cs.CR cs.AI

classification cs.CRcs.AI
keywords llmmapfingerprintingidentifyapplicationdifferentevenpromptsresponses
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We introduce LLMmap, a first-generation fingerprinting technique targeted at LLM-integrated applications. LLMmap employs an active fingerprinting approach, sending carefully crafted queries to the application and analyzing the responses to identify the specific LLM version in use. Our query selection is informed by domain expertise on how LLMs generate uniquely identifiable responses to thematically varied prompts. With as few as 8 interactions, LLMmap can accurately identify 42 different LLM versions with over 95% accuracy. More importantly, LLMmap is designed to be robust across different application layers, allowing it to identify LLM versions--whether open-source or proprietary--from various vendors, operating under various unknown system prompts, stochastic sampling hyperparameters, and even complex generation frameworks such as RAG or Chain-of-Thought. We discuss potential mitigations and demonstrate that, against resourceful adversaries, effective countermeasures may be challenging or even unrealizable.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. A Whole New World: Creating a Parallel-Poisoned Web Only AI-Agents Can See

    cs.CR 2025-08 conditional novelty 4.0 of 10

    A website can identify AI agents by their digital fingerprints and serve them a poisoned hidden version of the page, hijacking their actions via indirect prompt injection.

  2. Invisible Traces: Using Hybrid Fingerprinting to identify underlying LLMs in GenAI Apps

    cs.LG 2025-01 conditional novelty 4.0 of 10

    A hybrid of active and passive fingerprinting identifies the underlying LLM in simulated GenAI apps, reaching about 86.5% accuracy with ten observed responses.

Pith tools