about
Chain and Hash, an LLM Fingerprinting Technique (arxiv.org)
2 points by wslh on Aug 29, 2024 | hide | past | pdf | discuss on HN

In plain words: A fingerprint ties secret test prompts to their answers with a tamper-proof chain of codes, making ownership provable and copies impossible to fake. Training with random padding and varied instructions keeps it working after fine-tuning, style changes, or removal attacks, even on add-on modules.

Abstract · Hey, That's My Model! Introducing Chain & Hash, An LLM Fingerprinting Technique

Growing concerns over the theft and misuse of Large Language Models (LLMs) underscore the need for effective fingerprinting to link a model to its original version and detect misuse. We define five essential properties for a successful fingerprint: Transparency, Efficiency, Persistence, Robustness, and Unforgeability. We present a novel fingerprinting framework that provides verifiable proof of ownership while preserving fingerprint integrity. Our approach makes two main contributions. First, a chain and hash technique that cryptographically binds fingerprint prompts to their responses, preventing collisions and enabling irrefutable ownership claims. Second, we address a realistic threat model in which instruction-tuned models' output distribution can be significantly altered through meta-prompts. By incorporating random padding and varied meta-prompt configurations during training, our method maintains robustness even under significant output style changes. Experiments show that our framework securely proves ownership, resists both benign transformations (e.g., fine-tuning) and adversarial fingerprint removal, and extends to fingerprinting LoRA adapters\footnote{We release our code at: https://github.com/microsoft/Chain-Hash.

Mark Russinovich, Yanan Cai, Ahmed Salem
arXiv:2407.10887 · cs.CR, cs.AI · submitted Jul 15, 2024 · updated Jul 1, 2026
abstract · pdf · html · Published at ICLR 2026

add comment on HN