{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:C6VJOE3SXQELHFFSAJNTZD7MRS","short_pith_number":"pith:C6VJOE3S","schema_version":"1.0","canonical_sha256":"17aa971372bc08b394b2025b3c8fec8c8904c739f8f909341cc619a802538921","source":{"kind":"arxiv","id":"2606.04459","version":1},"attestation_state":"computed","paper":{"title":"Token Rankings are Unforgeable Language Model Signatures","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CC","cs.CL"],"primary_cat":"cs.CR","authors_text":"Andreas Grivas, Matthew Finlayson, Swabha Swayamdipta, Xiang Ren","submitted_at":"2026-06-03T05:06:35Z","abstract_excerpt":"Language model parameters are known to impose unique (to each model) geometric constraints on their logit outputs, which serves as a signature that identifies the model, but also leaks the model's final layer parameters when an API distributes logits. We investigate more restrictive APIs that expose token rankings (i.e., their ordering by probability, but not the probability values) and find that rankings also constitute a signature: every model has a unique set of feasible top-$k$ rankings for sufficiently large $k$. Furthermore, the ranking signature is the first known (polynomially) unforge"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.04459","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-03T05:06:35Z","cross_cats_sorted":["cs.AI","cs.CC","cs.CL"],"title_canon_sha256":"45bf80a0b5b8bc6af12c007e584717592db03b5b94c798fd46ffde975522222f","abstract_canon_sha256":"615661f0b3e2e90e64cf512f63ef0d9edfbb371a43a1e6a44ef57aa7391bc2e7"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-04T01:09:08.946344Z","signature_b64":"y6akrZ/QVySAmzxA95DA+pC+w7z0HBO4yJ9aOh+nQSlfhup7ds1ORBqm3uhtUvOZqNSQn5OvUASQOa6h7ksYCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"17aa971372bc08b394b2025b3c8fec8c8904c739f8f909341cc619a802538921","last_reissued_at":"2026-06-04T01:09:08.945818Z","signature_status":"signed_v1","first_computed_at":"2026-06-04T01:09:08.945818Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Token Rankings are Unforgeable Language Model Signatures","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CC","cs.CL"],"primary_cat":"cs.CR","authors_text":"Andreas Grivas, Matthew Finlayson, Swabha Swayamdipta, Xiang Ren","submitted_at":"2026-06-03T05:06:35Z","abstract_excerpt":"Language model parameters are known to impose unique (to each model) geometric constraints on their logit outputs, which serves as a signature that identifies the model, but also leaks the model's final layer parameters when an API distributes logits. We investigate more restrictive APIs that expose token rankings (i.e., their ordering by probability, but not the probability values) and find that rankings also constitute a signature: every model has a unique set of feasible top-$k$ rankings for sufficiently large $k$. Furthermore, the ranking signature is the first known (polynomially) unforge"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.04459","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.04459/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.04459","created_at":"2026-06-04T01:09:08.945896+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.04459v1","created_at":"2026-06-04T01:09:08.945896+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.04459","created_at":"2026-06-04T01:09:08.945896+00:00"},{"alias_kind":"pith_short_12","alias_value":"C6VJOE3SXQEL","created_at":"2026-06-04T01:09:08.945896+00:00"},{"alias_kind":"pith_short_16","alias_value":"C6VJOE3SXQELHFFS","created_at":"2026-06-04T01:09:08.945896+00:00"},{"alias_kind":"pith_short_8","alias_value":"C6VJOE3S","created_at":"2026-06-04T01:09:08.945896+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/C6VJOE3SXQELHFFSAJNTZD7MRS","json":"https://pith.science/pith/C6VJOE3SXQELHFFSAJNTZD7MRS.json","graph_json":"https://pith.science/api/pith-number/C6VJOE3SXQELHFFSAJNTZD7MRS/graph.json","events_json":"https://pith.science/api/pith-number/C6VJOE3SXQELHFFSAJNTZD7MRS/events.json","paper":"https://pith.science/paper/C6VJOE3S"},"agent_actions":{"view_html":"https://pith.science/pith/C6VJOE3SXQELHFFSAJNTZD7MRS","download_json":"https://pith.science/pith/C6VJOE3SXQELHFFSAJNTZD7MRS.json","view_paper":"https://pith.science/paper/C6VJOE3S","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.04459&json=true","fetch_graph":"https://pith.science/api/pith-number/C6VJOE3SXQELHFFSAJNTZD7MRS/graph.json","fetch_events":"https://pith.science/api/pith-number/C6VJOE3SXQELHFFSAJNTZD7MRS/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/C6VJOE3SXQELHFFSAJNTZD7MRS/action/timestamp_anchor","attest_storage":"https://pith.science/pith/C6VJOE3SXQELHFFSAJNTZD7MRS/action/storage_attestation","attest_author":"https://pith.science/pith/C6VJOE3SXQELHFFSAJNTZD7MRS/action/author_attestation","sign_citation":"https://pith.science/pith/C6VJOE3SXQELHFFSAJNTZD7MRS/action/citation_signature","submit_replication":"https://pith.science/pith/C6VJOE3SXQELHFFSAJNTZD7MRS/action/replication_record"}},"created_at":"2026-06-04T01:09:08.945896+00:00","updated_at":"2026-06-04T01:09:08.945896+00:00"}