{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:PSIISXYP5RJL54VBZMPJL4TK4T","short_pith_number":"pith:PSIISXYP","schema_version":"1.0","canonical_sha256":"7c90895f0fec52bef2a1cb1e95f26ae4f454b004ed371e4cbcda9142eab1bba8","source":{"kind":"arxiv","id":"2407.15847","version":4},"attestation_state":"computed","paper":{"title":"LLMmap: Fingerprinting For Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Dario Pasquini, Evgenios M. Kornaropoulos, Giuseppe Ateniese","submitted_at":"2024-07-22T17:59:45Z","abstract_excerpt":"We introduce LLMmap, a first-generation fingerprinting technique targeted at LLM-integrated applications. LLMmap employs an active fingerprinting approach, sending carefully crafted queries to the application and analyzing the responses to identify the specific LLM version in use. Our query selection is informed by domain expertise on how LLMs generate uniquely identifiable responses to thematically varied prompts. With as few as 8 interactions, LLMmap can accurately identify 42 different LLM versions with over 95% accuracy. More importantly, LLMmap is designed to be robust across different ap"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2407.15847","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-07-22T17:59:45Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"7b00bddd70668e4eaf7272ca7eddb297136c2dd20c3e77ff2748dd3739f28068","abstract_canon_sha256":"0a1f4545f10f94a834869a0855d4a480ea73ff87e7d89234fbeef47d6d9a8961"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:12:18.146430Z","signature_b64":"mhQ6uL1r8oqkwXzTA/aTLy2UbxFgUr2IngG+wT4cnkY35W12uvaZk+61+WSuFZoKc5keTthVI+kXf96kniuUDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7c90895f0fec52bef2a1cb1e95f26ae4f454b004ed371e4cbcda9142eab1bba8","last_reissued_at":"2026-07-05T10:12:18.145931Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:12:18.145931Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"LLMmap: Fingerprinting For Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Dario Pasquini, Evgenios M. Kornaropoulos, Giuseppe Ateniese","submitted_at":"2024-07-22T17:59:45Z","abstract_excerpt":"We introduce LLMmap, a first-generation fingerprinting technique targeted at LLM-integrated applications. LLMmap employs an active fingerprinting approach, sending carefully crafted queries to the application and analyzing the responses to identify the specific LLM version in use. Our query selection is informed by domain expertise on how LLMs generate uniquely identifiable responses to thematically varied prompts. With as few as 8 interactions, LLMmap can accurately identify 42 different LLM versions with over 95% accuracy. More importantly, LLMmap is designed to be robust across different ap"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.15847","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.15847/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2407.15847","created_at":"2026-07-05T10:12:18.145992+00:00"},{"alias_kind":"arxiv_version","alias_value":"2407.15847v4","created_at":"2026-07-05T10:12:18.145992+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.15847","created_at":"2026-07-05T10:12:18.145992+00:00"},{"alias_kind":"pith_short_12","alias_value":"PSIISXYP5RJL","created_at":"2026-07-05T10:12:18.145992+00:00"},{"alias_kind":"pith_short_16","alias_value":"PSIISXYP5RJL54VB","created_at":"2026-07-05T10:12:18.145992+00:00"},{"alias_kind":"pith_short_8","alias_value":"PSIISXYP","created_at":"2026-07-05T10:12:18.145992+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.22560","citing_title":"Evidence-Bound Gateway-Path Provenance for Third-Party LLM Inference","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2607.01276","citing_title":"Embedding Inference Attack","ref_index":31,"is_internal_anchor":false},{"citing_arxiv_id":"2508.11548","citing_title":"Copyright Protection for Large Language Models: A Survey of Methods, Challenges, and Trends","ref_index":115,"is_internal_anchor":false},{"citing_arxiv_id":"2509.26404","citing_title":"SeedPrints: Fingerprints Can Even Tell Which Seed Your Large Language Model Was Trained From","ref_index":5,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PSIISXYP5RJL54VBZMPJL4TK4T","json":"https://pith.science/pith/PSIISXYP5RJL54VBZMPJL4TK4T.json","graph_json":"https://pith.science/api/pith-number/PSIISXYP5RJL54VBZMPJL4TK4T/graph.json","events_json":"https://pith.science/api/pith-number/PSIISXYP5RJL54VBZMPJL4TK4T/events.json","paper":"https://pith.science/paper/PSIISXYP"},"agent_actions":{"view_html":"https://pith.science/pith/PSIISXYP5RJL54VBZMPJL4TK4T","download_json":"https://pith.science/pith/PSIISXYP5RJL54VBZMPJL4TK4T.json","view_paper":"https://pith.science/paper/PSIISXYP","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2407.15847&json=true","fetch_graph":"https://pith.science/api/pith-number/PSIISXYP5RJL54VBZMPJL4TK4T/graph.json","fetch_events":"https://pith.science/api/pith-number/PSIISXYP5RJL54VBZMPJL4TK4T/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PSIISXYP5RJL54VBZMPJL4TK4T/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PSIISXYP5RJL54VBZMPJL4TK4T/action/storage_attestation","attest_author":"https://pith.science/pith/PSIISXYP5RJL54VBZMPJL4TK4T/action/author_attestation","sign_citation":"https://pith.science/pith/PSIISXYP5RJL54VBZMPJL4TK4T/action/citation_signature","submit_replication":"https://pith.science/pith/PSIISXYP5RJL54VBZMPJL4TK4T/action/replication_record"}},"created_at":"2026-07-05T10:12:18.145992+00:00","updated_at":"2026-07-05T10:12:18.145992+00:00"}