acceptodds
Under review as a conference paper at ICLR 2027

Matryoshka Fingerprinting for Lineage Verification in Large Language Models

Abstract

Protecting the intellectual property of open-source large language models (LLMs) is increasingly important, since post-hoc modifications can obscure whether a deployed model derives from a protected one. However, existing fingerprinting methods are tied to a single model instance and deployment configuration, so their effectiveness degrades under model heterogeneity (hidden-size variation), vocabulary heterogeneity (vocabulary variation), and deployment heterogeneity (template/temperature variation). We propose Matryoshka Fingerprinting (MF), a transferable fingerprinting framework that verifies model lineage across these three forms of heterogeneity in a black-box manner. By freezing all model parameters and jointly optimizing a nested Matryoshka fingerprint embedding across multiple protected models and deployment contexts, MF lets a single fingerprint be reused across models with different hidden sizes and vocabularies, as well as across different templates and decoding temperatures. Extensive experiments show that MF outperforms existing fingerprinting methods, i.e., REEF, ZeroPrint, and PlugAE, in effectiveness, robustness, efficiency, stealthiness, and harmlessness, while extending potentially to cross-family lineage verification and content attribution.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.