{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:7FSUTUEKZ5IPSLTBUCCIRDUWIA","short_pith_number":"pith:7FSUTUEK","schema_version":"1.0","canonical_sha256":"f96549d08acf50f92e61a084888e96401b80849d995400ee8f7573822f571aed","source":{"kind":"arxiv","id":"2402.12991","version":2},"attestation_state":"computed","paper":{"title":"TRAP: Targeted Random Adversarial Prompt Honeypot for Black-Box Identification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Dennis Ulmer, Hwaran Lee, Martin Gubri, Sangdoo Yun, Seong Joon Oh","submitted_at":"2024-02-20T13:20:39Z","abstract_excerpt":"Large Language Model (LLM) services and models often come with legal rules on who can use them and how they must use them. Assessing the compliance of the released LLMs is crucial, as these rules protect the interests of the LLM contributor and prevent misuse. In this context, we describe the novel fingerprinting problem of Black-box Identity Verification (BBIV). The goal is to determine whether a third-party application uses a certain LLM through its chat function. We propose a method called Targeted Random Adversarial Prompt (TRAP) that identifies the specific LLM in use. We repurpose advers"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.12991","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2024-02-20T13:20:39Z","cross_cats_sorted":["cs.AI","cs.CL","cs.CR"],"title_canon_sha256":"a5f44c4a967b3ee05b91a15719f083b43492e37fcc38c391354f10b5b9fc088a","abstract_canon_sha256":"843ec51e62c7d1e7444695018d864ac2dcc601aa6105e7986e3e90c67a61be3b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:28:27.131331Z","signature_b64":"kFjY1Yo2Qkop6jpseC3uHczp93Ao/kiYt8GGan6f+pfSvT3vk/kmCY3Ku/Jdnzqmu+dQ6UzbO6ILZJp8ypuXCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f96549d08acf50f92e61a084888e96401b80849d995400ee8f7573822f571aed","last_reissued_at":"2026-07-05T08:28:27.130855Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:28:27.130855Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"TRAP: Targeted Random Adversarial Prompt Honeypot for Black-Box Identification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Dennis Ulmer, Hwaran Lee, Martin Gubri, Sangdoo Yun, Seong Joon Oh","submitted_at":"2024-02-20T13:20:39Z","abstract_excerpt":"Large Language Model (LLM) services and models often come with legal rules on who can use them and how they must use them. Assessing the compliance of the released LLMs is crucial, as these rules protect the interests of the LLM contributor and prevent misuse. In this context, we describe the novel fingerprinting problem of Black-box Identity Verification (BBIV). The goal is to determine whether a third-party application uses a certain LLM through its chat function. We propose a method called Targeted Random Adversarial Prompt (TRAP) that identifies the specific LLM in use. We repurpose advers"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.12991","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.12991/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.12991","created_at":"2026-07-05T08:28:27.130917+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.12991v2","created_at":"2026-07-05T08:28:27.130917+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.12991","created_at":"2026-07-05T08:28:27.130917+00:00"},{"alias_kind":"pith_short_12","alias_value":"7FSUTUEKZ5IP","created_at":"2026-07-05T08:28:27.130917+00:00"},{"alias_kind":"pith_short_16","alias_value":"7FSUTUEKZ5IPSLTB","created_at":"2026-07-05T08:28:27.130917+00:00"},{"alias_kind":"pith_short_8","alias_value":"7FSUTUEK","created_at":"2026-07-05T08:28:27.130917+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.03330","citing_title":"FLIPS: Instance-Fingerprinting for LLMs via Pseudo-random Sequences","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2509.25448","citing_title":"Fingerprinting LLMs via Prompt Injection","ref_index":4,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/7FSUTUEKZ5IPSLTBUCCIRDUWIA","json":"https://pith.science/pith/7FSUTUEKZ5IPSLTBUCCIRDUWIA.json","graph_json":"https://pith.science/api/pith-number/7FSUTUEKZ5IPSLTBUCCIRDUWIA/graph.json","events_json":"https://pith.science/api/pith-number/7FSUTUEKZ5IPSLTBUCCIRDUWIA/events.json","paper":"https://pith.science/paper/7FSUTUEK"},"agent_actions":{"view_html":"https://pith.science/pith/7FSUTUEKZ5IPSLTBUCCIRDUWIA","download_json":"https://pith.science/pith/7FSUTUEKZ5IPSLTBUCCIRDUWIA.json","view_paper":"https://pith.science/paper/7FSUTUEK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.12991&json=true","fetch_graph":"https://pith.science/api/pith-number/7FSUTUEKZ5IPSLTBUCCIRDUWIA/graph.json","fetch_events":"https://pith.science/api/pith-number/7FSUTUEKZ5IPSLTBUCCIRDUWIA/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/7FSUTUEKZ5IPSLTBUCCIRDUWIA/action/timestamp_anchor","attest_storage":"https://pith.science/pith/7FSUTUEKZ5IPSLTBUCCIRDUWIA/action/storage_attestation","attest_author":"https://pith.science/pith/7FSUTUEKZ5IPSLTBUCCIRDUWIA/action/author_attestation","sign_citation":"https://pith.science/pith/7FSUTUEKZ5IPSLTBUCCIRDUWIA/action/citation_signature","submit_replication":"https://pith.science/pith/7FSUTUEKZ5IPSLTBUCCIRDUWIA/action/replication_record"}},"created_at":"2026-07-05T08:28:27.130917+00:00","updated_at":"2026-07-05T08:28:27.130917+00:00"}