Attacks and Defenses Against LLM Fingerprinting

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kurian, Kevin, Holland, Ethan, Oesch, Sean
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912534504669184
author Kurian, Kevin
Holland, Ethan
Oesch, Sean
author_facet Kurian, Kevin
Holland, Ethan
Oesch, Sean
contents As large language models are increasingly deployed in sensitive environments, fingerprinting attacks pose significant privacy and security risks. We present a study of LLM fingerprinting from both offensive and defensive perspectives. Our attack methodology uses reinforcement learning to automatically optimize query selection, achieving better fingerprinting accuracy with only 3 queries compared to randomly selecting 3 queries from the same pool. Our defensive approach employs semantic-preserving output filtering through a secondary LLM to obfuscate model identity while maintaining semantic integrity. The defensive method reduces fingerprinting accuracy across tested models while preserving output quality. These contributions show the potential to improve fingerprinting tools capabilities while providing practical mitigation strategies against fingerprinting attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2508_09021
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Attacks and Defenses Against LLM Fingerprinting
Kurian, Kevin
Holland, Ethan
Oesch, Sean
Cryptography and Security
Artificial Intelligence
Machine Learning
As large language models are increasingly deployed in sensitive environments, fingerprinting attacks pose significant privacy and security risks. We present a study of LLM fingerprinting from both offensive and defensive perspectives. Our attack methodology uses reinforcement learning to automatically optimize query selection, achieving better fingerprinting accuracy with only 3 queries compared to randomly selecting 3 queries from the same pool. Our defensive approach employs semantic-preserving output filtering through a secondary LLM to obfuscate model identity while maintaining semantic integrity. The defensive method reduces fingerprinting accuracy across tested models while preserving output quality. These contributions show the potential to improve fingerprinting tools capabilities while providing practical mitigation strategies against fingerprinting attacks.
title Attacks and Defenses Against LLM Fingerprinting
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2508.09021