{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T08:17:38Z","timestamp":1783153058496,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":59,"publisher":"ACM","funder":[{"name":"&#x5c;&quot;Pioneer&#x5c;&quot; and &#x5c;&quot;Leading Goose&#x5c;&quot; R&D Program of Zhejiang","award":["2024C01169"],"award-info":[{"award-number":["2024C01169"]}]},{"name":"Kunpeng-Ascend Science and Education Innovation Excellence&#x5c;&#x2f;Incubation Center","award":["NA"],"award-info":[{"award-number":["NA"]}]},{"name":"National Natural Science Foundation of China","award":["62441238, U2441240"],"award-info":[{"award-number":["62441238, U2441240"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3774904.3792196","type":"proceedings-article","created":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T13:28:36Z","timestamp":1777296516000},"page":"2637-2648","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Reading Between the Lines: Towards Reliable Black-box LLM Fingerprinting via Zeroth-order Gradient Estimation"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3482-4975","authenticated-orcid":false,"given":"Shuo","family":"Shao","sequence":"first","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2258-265X","authenticated-orcid":false,"given":"Yiming","family":"Li","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4680-5536","authenticated-orcid":false,"given":"Hongwei","family":"Yao","sequence":"additional","affiliation":[{"name":"City University of Hong Kong, Hong Kong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-4989-3317","authenticated-orcid":false,"given":"Yifei","family":"Chen","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-9229-1021","authenticated-orcid":false,"given":"Yuchen","family":"Yang","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7872-6969","authenticated-orcid":false,"given":"Zhan","family":"Qin","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"International Conference on Machine Learning. 5680-5705","author":"Carlini Nicholas","year":"2024","unstructured":"Nicholas Carlini, Daniel Paleka, Krishnamurthy Dvijotham, Thomas Steinke, Jonathan Hayase, A Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, et al., 2024. Stealing part of a production language model. In International Conference on Machine Learning. 5680-5705."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833747"},{"key":"e_1_3_2_1_3_1","unstructured":"Mark Chen Jerry Tworek Heewoo Jun Qiming Yuan et al. 2021. Evaluating large language models trained on code. arXiv preprint arXiv:2107.03374 (2021)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"e_1_3_2_1_5_1","unstructured":"Gheorghe Comanici Eric Bieber Mike Schaekermann Ice Pasupat Noveen Sachdeva Inderjit Dhillon Marcel Blistein Ori Ram Dan Zhang Evan Rosen et al. 2025. Gemini 2.5: Pushing the frontier with advanced reasoning multimodality long context and next generation agentic capabilities. arXiv preprint arXiv:2507.06261 (2025)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589335.3641240"},{"key":"e_1_3_2_1_7_1","volume-title":"DROP: A Reading Comprehension Benchmark Requiring Discrete Reasoning Over Paragraphs. In Conference of the North American","author":"Dua Dheeru","year":"2019","unstructured":"Dheeru Dua, Yizhong Wang, Pradeep Dasigi, Gabriel Stanovsky, Sameer Singh, and Matt Gardner. 2019. DROP: A Reading Comprehension Benchmark Requiring Discrete Reasoning Over Paragraphs. In Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies."},{"key":"e_1_3_2_1_8_1","unstructured":"Wikimedia Foundation. [n.d.]. Wikimedia Downloads. https:\/\/dumps.wikimedia.org"},{"key":"e_1_3_2_1_9_1","volume-title":"International Conference on Learning Representations.","author":"Gao Irena","year":"2025","unstructured":"Irena Gao, Percy Liang, and Carlos Guestrin. 2025. Model Equality Testing: Which Model Is This API Serving?. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_10_1","unstructured":"Aaron Grattafiori Abhimanyu Dubey Abhinav Jauhri Abhinav Pandey Abhishek Kadian Ahmad Al-Dahle Aiesha Letman Akhil Mathur Alan Schelten Alex Vaughan et al. 2024. The llama 3 herd of models. arXiv preprint arXiv:2407.21783 (2024)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.683"},{"key":"e_1_3_2_1_12_1","unstructured":"Daya Guo Dejian Yang Haowei Zhang Junxiao Song Ruoyu Zhang et al. 2025. Deepseek-r1: Incentivizing reasoning capability in llms via reinforcement learning. Nature (2025) 633\u2013-638."},{"key":"e_1_3_2_1_13_1","volume-title":"On Benchmarking Code LLMs for Android Malware Analysis. In ACM SIGSOFT International Symposium on Software Testing and Analysis Workshop.","author":"He Yiling","year":"2025","unstructured":"Yiling He, Hongyu She, Xingzhi Qian, Xinran Zheng, Zhuo Chen, Zhan Qin, and Lorenzo Cavallaro. 2025. On Benchmarking Code LLMs for Android Malware Analysis. In ACM SIGSOFT International Symposium on Software Testing and Analysis Workshop."},{"key":"e_1_3_2_1_14_1","volume-title":"Aligning AI With Shared Human Values. In International Conference on Learning Representations.","author":"Hendrycks Dan","year":"2021","unstructured":"Dan Hendrycks, Collin Burns, Steven Basart, Andrew Critch, Jerry Li, Dawn Song, and Jacob Steinhardt. 2021. Aligning AI With Shared Human Values. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_15_1","volume-title":"Gaussian error linear units (gelus). arXiv preprint arXiv:1606.08415","author":"Hendrycks Dan","year":"2016","unstructured":"Dan Hendrycks and Kevin Gimpel. 2016. Gaussian error linear units (gelus). arXiv preprint arXiv:1606.08415 (2016)."},{"key":"e_1_3_2_1_16_1","unstructured":"Albert Jiang Alexandre Sablayrolles Arthur Mensch Chris Bamford et al. 2023. Mistral 7B. arXiv preprint arXiv:2310.06825 (2023)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS62487.2024.10735575"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Qiao Jin Bhuwan Dhingra Zhengping Liu William Cohen and Xinghua Lu. 2019. PubMedQA: A Dataset for Biomedical Research Question Answering. In Conference on Empirical Methods in Natural Language Processing and International Joint Conference on Natural Language Processing. 2567-2577.","DOI":"10.18653\/v1\/D19-1259"},{"key":"e_1_3_2_1_19_1","volume-title":"Rethinking Data Protection in the (Generative) Artificial Intelligence Era. arXiv preprint arXiv:2507.03034","author":"Li Yiming","year":"2025","unstructured":"Yiming Li, Shuo Shao, Yu He, Junfeng Guo, Tianwei Zhang, Zhan Qin, Pin-Yu Chen, Michael Backes, Philip Torr, Dacheng Tao, and Kui Ren. 2025. Rethinking Data Protection in the (Generative) Artificial Intelligence Era. arXiv preprint arXiv:2507.03034 (2025)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623120"},{"key":"e_1_3_2_1_21_1","volume-title":"TruthfulQA: Measuring How Models Mimic Human Falsehoods. In Annual Meeting of the Association for Computational Linguistics. 3214-3252","author":"Lin Stephanie","year":"2022","unstructured":"Stephanie Lin, Jacob Hilton, and Owain Evans. 2022. TruthfulQA: Measuring How Models Mimic Human Falsehoods. In Annual Meeting of the Association for Computational Linguistics. 3214-3252."},{"key":"e_1_3_2_1_22_1","volume-title":"Shadow in the Cache: Unveiling and Mitigating Privacy Risks of KV-cache in LLM Inference. In Network and Distributed System Security Symposium.","author":"Luo Zhifan","year":"2026","unstructured":"Zhifan Luo, Shuo Shao, Su Zhang, Lijing Zhou, Yuke Hu, Zhihao Liu, and Zhan Qin. 2026. Shadow in the Cache: Unveiling and Mitigating Privacy Risks of KV-cache in LLM Inference. In Network and Distributed System Security Symposium."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jmp.2017.05.006"},{"key":"e_1_3_2_1_24_1","volume-title":"International Conference on Computational Linguistics Workshop. 85-95","author":"McGovern Hope Elizabeth","year":"2025","unstructured":"Hope Elizabeth McGovern, Rickard Stureborg, Yoshi Suhara, and Dimitris Alikaniotis. 2025. Your Large Language Models are Leaving Fingerprints. In International Conference on Computational Linguistics Workshop. 85-95."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639187"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3711896.3736555"},{"key":"e_1_3_2_1_27_1","volume-title":"arXiv preprint arXiv:2501.00656","author":"Furious Team OLMo.","year":"2024","unstructured":"Team OLMo. 2024. 2 OLMo 2 Furious. arXiv preprint arXiv:2501.00656 (2024)."},{"key":"e_1_3_2_1_28_1","unstructured":"OpenAI. 2023. GPT-4 Technical Report. arXiv preprint arXiv:2303.08774 (2023)."},{"key":"e_1_3_2_1_29_1","volume-title":"USENIX Security Symposium.","author":"Pasquini Dario","year":"2025","unstructured":"Dario Pasquini, Evgenios M Kornaropoulos, and Giuseppe Ateniese. 2025. Llmmap: Fingerprinting for large language models. In USENIX Security Symposium."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1162"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D16-1264"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1410"},{"key":"e_1_3_2_1_33_1","volume-title":"SoK: On the Role and Future of AIGC Watermarking in the Era of Gen-AI. arXiv preprint arXiv:2411.11478","author":"Ren Kui","year":"2024","unstructured":"Kui Ren, Ziqi Yang, Li Lu, Jian Liu, Yiming Li, Jie Wan, Xiaodi Zhao, Xianheng Feng, and Shuo Shao. 2024. SoK: On the Role and Future of AIGC Watermarking in the Era of Gen-AI. arXiv preprint arXiv:2411.11478 (2024)."},{"key":"e_1_3_2_1_34_1","volume-title":"CoTSRF: Utilize Chain of Thought as Stealthy and Robust Fingerprint of Large Language Models. arXiv preprint arXiv:2505.16785","author":"Ren Zhenzhen","year":"2025","unstructured":"Zhenzhen Ren, GuoBiao Li, Sheng Li, Zhenxing Qian, and Xinpeng Zhang. 2025. CoTSRF: Utilize Chain of Thought as Stealthy and Robust Fingerprint of Large Language Models. arXiv preprint arXiv:2505.16785 (2025)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589335.3651946"},{"key":"e_1_3_2_1_36_1","unstructured":"Henrique Schechter Vera Sahil Dua Biao Zhang Daniel Salz Ryan Mullins et al. 2025. EmbeddingGemma: Powerful and Lightweight Text Representations. arxiv preprint arxiv:2509.20354 (2025)."},{"key":"e_1_3_2_1_37_1","volume-title":"SoK: Large Language Model Copyright Auditing via Fingerprinting. arXiv preprint arXiv:2508.19843","author":"Shao Shuo","year":"2025","unstructured":"Shuo Shao, Yiming Li, Yu He, Hongwei Yao, Wenyuan Yang, Dacheng Tao, and Zhan Qin. 2025a. SoK: Large Language Model Copyright Auditing via Fingerprinting. arXiv preprint arXiv:2508.19843 (2025)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.230338"},{"key":"e_1_3_2_1_39_1","volume-title":"International Conference on Machine Learning.","author":"Sun Mingjie","year":"2025","unstructured":"Mingjie Sun, Yida Yin, Zhiqiu Xu, J Zico Kolter, and Zhuang Liu. 2025. Idiosyncrasies in large language models. In International Conference on Machine Learning."},{"key":"e_1_3_2_1_40_1","volume-title":"Gemma 2: Improving open language models at a practical size. arXiv preprint arXiv:2408.00118","author":"Team Gemma","year":"2024","unstructured":"Gemma Team. 2024a. Gemma 2: Improving open language models at a practical size. arXiv preprint arXiv:2408.00118 (2024)."},{"key":"e_1_3_2_1_41_1","volume-title":"Qwen2 technical report. arXiv preprint arXiv:2407.10671","author":"Team Qwen","year":"2024","unstructured":"Qwen Team. 2024b. Qwen2 technical report. arXiv preprint arXiv:2407.10671, Vol. 2 (2024)."},{"key":"e_1_3_2_1_42_1","unstructured":"Qwen Team. 2024c. Qwen2.5: A Party of Foundation Models. https:\/\/qwenlm.github.io\/blog\/qwen2.5\/"},{"key":"e_1_3_2_1_43_1","unstructured":"Hugo Touvron Louis Martin Kevin Stone Peter Albert Amjad Almahairi Yasmine Babaei Nikolay Bashlykov Soumya Batra Prajjwal Bhargava Shruti Bhosale et al. 2023. Llama 2: Open foundation and fine-tuned chat models. arXiv preprint arXiv:2307.09288 (2023)."},{"key":"e_1_3_2_1_44_1","unstructured":"Yun-Yun Tsai Chuan Guo Junfeng Yang and Laurens van der Maaten. 2025. RoFL: Robust Fingerprinting of Language Models. arXiv preprint arXiv:2505.12682 (2025)."},{"key":"e_1_3_2_1_45_1","unstructured":"Stephan Tulkens and Thomas van Dongen. 2024. Model2Vec: Fast State-of-the-Art Static Embeddings. https:\/\/github.com\/MinishLab\/model2vec"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450000"},{"key":"e_1_3_2_1_47_1","volume-title":"Gradient-Based Model Fingerprinting for LLM Similarity Detection and Family Classification. arXiv preprint arXiv:2506.01631","author":"Wu Zehao","year":"2025","unstructured":"Zehao Wu, Yanjie Zhao, and Haoyu Wang. 2025. Gradient-Based Model Fingerprinting for LLM Similarity Detection and Family Classification. arXiv preprint arXiv:2506.01631 (2025)."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Haoyi Xiong Jiang Bian Yuchen Li Xuhong Li Mengnan Du Shuaiqiang Wang et al. 2024. When search engine services meet large language models: visions and challenges. IEEE Transactions on Services Computing (2024).","DOI":"10.1109\/TSC.2024.3451185"},{"key":"e_1_3_2_1_49_1","volume-title":"Instructional Fingerprinting of Large Language Models. In Conference of the North American Chapter of the Association for Computational Linguistics.","author":"Xu Jiashu","year":"2024","unstructured":"Jiashu Xu, Fei Wang, Mingyu Ma, Pang Wei Koh, Chaowei Xiao, and Muhao Chen. 2024. Instructional Fingerprinting of Large Language Models. In Conference of the North American Chapter of the Association for Computational Linguistics."},{"key":"e_1_3_2_1_50_1","unstructured":"Zhenhua Xu Xubin Yue Zhebo Wang Qichen Liu Xixiang Zhao Jingxuan Zhang Wenjun Zeng Wengpeng Xing Dezhang Kong Changting Lin et al. 2025. Copyright Protection for Large Language Models: A Survey of Methods Challenges and Trends. arXiv preprint arXiv:2508.11548 (2025)."},{"key":"e_1_3_2_1_51_1","volume-title":"Black-Box Guardrail Reverse-engineering Attack. arXiv preprint arXiv:2511.04215","author":"Yao Hongwei","year":"2025","unstructured":"Hongwei Yao, Yun Xia, Shuo Shao, Haoran Shi, Tong Qiao, and Cong Wang. 2025. Black-Box Guardrail Reverse-engineering Attack. arXiv preprint arXiv:2511.04215 (2025)."},{"key":"e_1_3_2_1_52_1","volume-title":"Annual Conference on Neural Information Processing Systems.","author":"Zeng Boyi","year":"2024","unstructured":"Boyi Zeng, Lizheng Wang, Yuncong Hu, Yi Xu, Chenghu Zhou, Xinbing Wang, Yu Yu, and Zhouhan Lin. 2024. Huref: Human-readable fingerprint for large language models. In Annual Conference on Neural Information Processing Systems."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom63139.2024.00333"},{"key":"e_1_3_2_1_54_1","volume-title":"International Conference on Learning Representations.","author":"Zhang Jie","year":"2025","unstructured":"Jie Zhang, Dongrui Liu, Chen Qian, Linfeng Zhang, Yong Liu, Yu Qiao, and Jing Shao. 2025b. Reef: Representation encoding fingerprints for large language models. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_55_1","volume-title":"Tinyllama: An open-source small language model. arXiv preprint arXiv:2401.02385","author":"Zhang Peiyuan","year":"2024","unstructured":"Peiyuan Zhang, Guangtao Zeng, Tianduo Wang, and Wei Lu. 2024b. Tinyllama: An open-source small language model. arXiv preprint arXiv:2401.02385 (2024)."},{"key":"e_1_3_2_1_56_1","volume-title":"Embedding: Advancing Text Embedding and Reranking Through Foundation Models. arXiv preprint arXiv:2506.05176","author":"Zhang Yanzhao","year":"2025","unstructured":"Yanzhao Zhang, Mingxin Li, Dingkun Long, Xin Zhang, et al., 2025a. Qwen3 Embedding: Advancing Text Embedding and Reranking Through Foundation Models. arXiv preprint arXiv:2506.05176 (2025)."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3198267"},{"key":"e_1_3_2_1_58_1","volume-title":"Collaborative Retrieval for Large Language Model-based Conversational Recommender Systems. In The ACM Web Conference. 3323-3334","author":"Zhu Yaochen","year":"2025","unstructured":"Yaochen Zhu, Chao Wan, Harald Steck, Dawen Liang, Yesu Feng, Nathan Kallus, and Jundong Li. 2025. Collaborative Retrieval for Large Language Model-based Conversational Recommender Systems. In The ACM Web Conference. 3323-3334."},{"key":"e_1_3_2_1_59_1","volume-title":"Universal and transferable adversarial attacks on aligned language models. arXiv preprint arXiv:2307.15043","author":"Zou Andy","year":"2023","unstructured":"Andy Zou, Zifan Wang, Nicholas Carlini, Milad Nasr, J Zico Kolter, and Matt Fredrikson. 2023. Universal and transferable adversarial attacks on aligned language models. arXiv preprint arXiv:2307.15043 (2023)."}],"event":{"name":"WWW '26: The ACM Web Conference 2026","location":"Dubai United Arab Emirates","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2026"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3774904.3792196","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T07:40:31Z","timestamp":1783150831000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3774904.3792196"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":59,"alternative-id":["10.1145\/3774904.3792196","10.1145\/3774904"],"URL":"https:\/\/doi.org\/10.1145\/3774904.3792196","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}