acceptodds
Under review as a conference paper at ICLR 2027

Corrupted Blocks Are Worse Than None: AgentTrace, a Measurement Study of Latent-Source Recovery Among Identifier-Leaking Clients

Abstract

Recovering which events in an anonymized stream share a source is a well-posed learning problem that lacks scorable data without privileged identity, simulation or leakage: the predicted quantity is the field removed. AgentTrace takes labels from inside the public stream: structured client identifiers across 182,119,794 order events and 23 asset-day sessions resolve to 153 actors, withheld from every model and corroborated, unevenly across identifier families, by an identifier-blind relation. The capture cannot be redistributed; the reusable object is the protocol. The labels cover 38.99% of events and are not random: a behavior-only classifier reads labellability at 0.8790 mean AUROC over 17 sessions, under a rule fixed in advance, so this study measures recovery among identifier-leaking clients. Inside that population the signal exceeds identifier-family classification: with family held constant, version-1 UUID actors separate at 0.9688 and 0.9981 balanced accuracy. The central measurement is a factorial, none of it preregistered, that fixes featurizer, algorithm, oracle and metric and varies only the imposed boundary source. Over 16 sessions at , oracle boundaries beat random size-matched blocks by mean order-level ARI, positive in all 16, but beat not blocking at all by only , a gain that does not survive asset-level inference and reverses in all four ETH sessions. Random size-matched and contiguous blocks both score below not blocking in all 16, by and mean ARI. The fingerprint survives a change of day and of month, at 7.97 to 31.23 times chance across ordered day pairs, and transfers far more weakly across assets, 2.4 times chance pooled and 4.0 once the one build-keyed family is excluded. A label-free contrastive encoder shows no consistent held-out-day gain at oracle , yet avoids the collapse hand features suffer under density-based clustering. Neither timestamp coarsening nor jitter nor size discretization closes the behavioral channel at any magnitude we could build against a refit hand-feature attacker; jitter of at least 1 ms deletes the timing-metadata side channel and a 1% size grid the size-precision fingerprint at 0.3% distortion.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.