acceptodds
Under review as a conference paper at ICLR 2027

Efficient Black-Box Fingerprinting For Image Generation Models With Ambiguous Images

Abstract

Black-box attribution of image generation models is difficult because fine-tuning and other modifications can substantially alter their outputs. Text-only fingerprints are fragile because semantic preferences become entangled with unconstrained variation in style, layout, and composition. We present AmbiPrint, a passive framework that probes how models resolve controlled semantic ambiguity. Am- biPrint pairs a neutral text prompt with an ambiguous image that guides genera- tion and constrains visual variation without determining the final class. Across 25 open- and closed-source models, AmbiPrint separates source derivatives from in- dependently trained models under fine-tuning, compression, and substantial style and domain shifts. It succeeds with only 100 generations per model where text- only baselines fail. Adaptive attacks can evade attribution by targeting every eval- uated category, but doing so substantially reduces output diversity. AmbiPrint provides a practical and robust signal for black-box model attribution.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.