LIDAR fingerprints LLMs through agent behavior
Tsinghua researchers introduce LIDAR, a black-box method that identifies LLMs by analyzing coding-agent trajectories, including tool use, verification, recovery, and conflict resolution. Evaluated across 36 models and two harnesses, it requires no access to weights, logits, or provider internals.
LIDAR shifts model fingerprinting from what agents say to how they work, creating a promising audit layer for opaque AI coding services.
- –Reports 93.52% Top-1 accuracy and 96.31 MRR when combining instance- and distribution-level behavior features
- –Controlled probes expose meaningful differences in verification, transient-failure recovery, and specification-test conflict handling
- –The approach is more resilient than text-based baselines to provider-side identity obfuscation and output-format controls
- –Deployment still requires clean enrollment samples, stable harness behavior, and a closed set of candidate models
- –The security implications are significant: operators could detect silent model substitutions or verify whether a hosted coding agent behaves as advertised
DISCOVERED
1h ago
2026-09-27
PUBLISHED
1h ago
2026-09-27
RELEVANCE
AUTHOR
Discover AI