{"id":"https://openalex.org/W7162807340","doi":"https://doi.org/10.48550/arxiv.2605.29979","title":"Fingerprinting Inference Systems of Large Language Models","display_name":"Fingerprinting Inference Systems of Large Language Models","publication_year":2026,"publication_date":"2026-05-28","ids":{"openalex":"https://openalex.org/W7162807340","doi":"https://doi.org/10.48550/arxiv.2605.29979"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.29979","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.29979","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.29979","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5137352450","display_name":"Anna Wimbauer","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wimbauer, Anna","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103070652","display_name":"Jonas M\u00f6ller","orcid":"https://orcid.org/0009-0007-7799-0566"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"M\u00f6ller, Jonas","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5092446289","display_name":"Erik Imgrund","orcid":"https://orcid.org/0009-0003-2854-6419"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Imgrund, Erik","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5066077721","display_name":"Konrad Rieck","orcid":"https://orcid.org/0000-0002-5054-8758"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Rieck, Konrad","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.36340001225471497,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.36340001225471497,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.10599999874830246,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.08969999849796295,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.868399977684021},{"id":"https://openalex.org/keywords/implementation","display_name":"Implementation","score":0.4781999886035919},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.4212000072002411},{"id":"https://openalex.org/keywords/work","display_name":"Work (physics)","score":0.4059999883174896},{"id":"https://openalex.org/keywords/software-implementation","display_name":"Software implementation","score":0.38179999589920044},{"id":"https://openalex.org/keywords/causal-inference","display_name":"Causal inference","score":0.3603000044822693},{"id":"https://openalex.org/keywords/observable","display_name":"Observable","score":0.3077999949455261}],"concepts":[{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.868399977684021},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7232999801635742},{"id":"https://openalex.org/C26713055","wikidata":"https://www.wikidata.org/wiki/Q245962","display_name":"Implementation","level":2,"score":0.4781999886035919},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.42590001225471497},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.4212000072002411},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.4059999883174896},{"id":"https://openalex.org/C2983609787","wikidata":"https://www.wikidata.org/wiki/Q10534782","display_name":"Software implementation","level":3,"score":0.38179999589920044},{"id":"https://openalex.org/C158600405","wikidata":"https://www.wikidata.org/wiki/Q5054566","display_name":"Causal inference","level":2,"score":0.3603000044822693},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.35280001163482666},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3467999994754791},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.31290000677108765},{"id":"https://openalex.org/C32848918","wikidata":"https://www.wikidata.org/wiki/Q845789","display_name":"Observable","level":2,"score":0.3077999949455261},{"id":"https://openalex.org/C2778334786","wikidata":"https://www.wikidata.org/wiki/Q1586270","display_name":"Variation (astronomy)","level":2,"score":0.30630001425743103},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.30239999294281006},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3021000027656555},{"id":"https://openalex.org/C46743427","wikidata":"https://www.wikidata.org/wiki/Q1341685","display_name":"Inference engine","level":3,"score":0.2858000099658966},{"id":"https://openalex.org/C149091818","wikidata":"https://www.wikidata.org/wiki/Q2429814","display_name":"Software system","level":3,"score":0.2800999879837036},{"id":"https://openalex.org/C166052673","wikidata":"https://www.wikidata.org/wiki/Q83021","display_name":"Empirical evidence","level":2,"score":0.27559998631477356},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.27079999446868896},{"id":"https://openalex.org/C168167062","wikidata":"https://www.wikidata.org/wiki/Q1117970","display_name":"Component (thermodynamics)","level":2,"score":0.2662999927997589},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.2619999945163727},{"id":"https://openalex.org/C90559484","wikidata":"https://www.wikidata.org/wiki/Q778379","display_name":"Expression (computer science)","level":2,"score":0.2581999897956848}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.29979","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.29979","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.29979","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.29979","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.6126763820648193}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"behavior":[1,113],"of":[2,13,60,79,114,119],"LLMs":[3,115],"does":[4],"not":[5],"depend":[6],"solely":[7],"on":[8,101],"the":[9,14,19,49,57,89,98,111,120,128,143],"model":[10],"itself.":[11],"Components":[12],"inference":[15,20,90,121,129],"system,":[16],"such":[17,61],"as":[18,158],"engine,":[21,130],"attention":[22,131],"backend,":[23,132],"and":[24,39,82,133,167,175],"hardware":[25,135,166],"platform,":[26],"subtly":[27],"influence":[28],"how":[29],"inputs":[30],"are":[31,77],"processed.":[32],"These":[33],"components":[34,81,118],"differ":[35],"in":[36],"their":[37,63,177],"implementations":[38],"thereby":[40],"induce":[41],"small":[42],"numerical":[43,163],"deviations":[44,76],"across":[45],"systems":[46],"when":[47,142],"running":[48],"same":[50],"model.":[51,99],"While":[52],"prior":[53],"work":[54],"has":[55],"established":[56],"theoretical":[58],"existence":[59],"deviations,":[62],"security":[64],"implications":[65],"have":[66],"remained":[67],"unexplored.":[68],"In":[69],"this":[70,102],"paper,":[71],"we":[72,104],"show":[73,151],"that":[74,95,109,127,152],"these":[75],"characteristic":[78],"specific":[80],"propagate":[83],"to":[84,92,116],"observable":[85],"textual":[86],"outputs,":[87],"exposing":[88],"system":[91],"any":[93],"party":[94],"can":[96,137],"query":[97],"Building":[100],"observation,":[103],"introduce":[105],"a":[106],"fingerprinting":[107,154],"method":[108],"analyzes":[110],"prompt-response":[112],"identify":[117],"system.":[122],"Our":[123],"empirical":[124],"evaluation":[125],"demonstrates":[126],"underlying":[134],"platform":[136],"be":[138],"identified":[139],"reliably,":[140],"even":[141],"LLM":[144],"is":[145,155],"operated":[146],"at":[147],"non-zero":[148],"temperature.":[149],"We":[150,170],"preventing":[153],"fundamentally":[156],"hard,":[157],"it":[159],"would":[160],"require":[161],"eliminating":[162],"differences":[164],"between":[165],"software":[168],"stacks.":[169],"therefore":[171],"propose":[172],"partial":[173],"mitigations":[174],"discuss":[176],"impact.":[178]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-30T00:00:00"}
