article open access

Fingerprints That Survive What? Model Lineage Names Three Relations, Robustness Is Indexed by Which Party Is Adversarial, and a Benchmark's Distillation Column Scores the Parent That Was Not Distilled From

Abstract

Language-model fingerprinting is asked to answer questions of the form "is this model derived from that one?", and its methods are routinely reported as robust to fine-tuning, quantization, pruning, merging and distillation. This paper argues that such reports are not comparable, for reasons that a common benchmark does not remove. The word lineage covers three different relations: weight descent, training-signal descent through distillation or imitation, and the identity of the checkpoint behind a served endpoint. A distilled model built on an open base has two parents, one for each of the first two relations, and the first systematic benchmark scores its distillation rows against the weight parent, so a perfect score there says nothing about finding the teacher. Robustness is also indexed by which party is adversarial: an evading host wants a missed match, a substituting provider wants a false match, and a false-claiming accuser wants a match against an independent model. The paper argues, as an inference from published results rather than a measurement, that for similarity-based schemes the tolerance that buys robustness against the host is the opening the accuser uses, and that against the provider it is the weakness itself, since the cheapest substitutes are quantized or fine-tuned copies that a lineage fingerprint is built to accept. The evidence is drawn from roughly seventy published sources, among them a 2025 study in which adaptive attacks defeated eight of ten fingerprint schemes completely, and results showing that models trained independently on the same data, or fine-tuned on the same teacher's outputs, look related to output-level instruments. The paper contributes a partition, a decision procedure and a reporting protocol. It reports no new measurement, and it cannot say how often any of these confusions has decided a real dispute.

The literature search, drafting and citation verification for this paper were carried out with AI assistance under the author's direction. Every arXiv citation was machine-verified against its live arXiv Atom API record, and every other citation against its DOI record, during drafting (title and author list checked against the record returned). Every quantitative claim is taken from the abstract, full text or a table of the source credited with it; full-text numbers were read from the sources' own arXiv HTML renderings rather than from summaries. No experiment was run and no number in this paper was measured by its author. Table 1 re-presents numbers published by the cited papers, each named on its row; Figure 1 re-plots values from three cited tables with no transformation other than multiplying one verification rate by 100. The three-relation partition, the four-role account of robustness, Algorithm 1 and the reporting protocol in Section 11 are original conceptual synthesis by the author, not empirical results, and are presented as such. Two cited sources (Hinton et al. 2015; Tramer et al. 2016) are used only for definitions and were read through their abstracts.

Pranay Mahendrakar, AI specialist

About the author

Pranay Mahendrakar is an ai specialist and large language model engineer based in Bengaluru, India. He builds production artificial intelligence systems and publishes open-access research on how those systems fail. See all 66 papers by Pranay Mahendrakar, or his ORCID record.

Questions about this paper

Who wrote "Fingerprints That Survive What? Model Lineage Names Three Relations, Robustness Is Indexed by Which Party Is Adversarial, and a Benchmark's Distillation Column Scores the Parent That Was Not Distilled From"?

Pranay Mahendrakar wrote "Fingerprints That Survive What? Model Lineage Names Three Relations, Robustness Is Indexed by Which Party Is Adversarial, and a Benchmark's Distillation Column Scores the Parent That Was Not Distilled From", published 30 Sep 2026. Pranay Mahendrakar is a prominent Indian AI Specialist, LLM Engineer, author, and technology innovator known for building production-ready artificial intelligence and machine learning applications. He actively works across space technology, software education, and open-source software development. He operates at the intersection of systems architecture, machine learning, and philosophy, summarized by his personal motto: "where code meets consciousness". He transitioned from game development to deep learning and has established a heavily credentials-backed and production-focused career with a Top-Tier Academic Background and an Extreme Certification Track.

Is "Fingerprints That Survive What? Model Lineage Names Three Relations, Robustness Is Indexed by Which Party Is Adversarial, and a Benchmark's Distillation Column Scores the Parent That Was Not Distilled From" free to read?

Yes. "Fingerprints That Survive What? Model Lineage Names Three Relations, Robustness Is Indexed by Which Party Is Adversarial, and a Benchmark's Distillation Column Scores the Parent That Was Not Distilled From" by Pranay Mahendrakar is open access under a Creative Commons Attribution 4.0 licence, with the full PDF available from Zenodo at https://doi.org/10.5281/zenodo.23064254. There is no paywall and no account required.

How do I cite "Fingerprints That Survive What? Model Lineage Names Three Relations, Robustness Is Indexed by Which Party Is Adversarial, and a Benchmark's Distillation Column Scores the Parent That Was Not Distilled From"?

Cite the DOI: Mahendrakar, P. (2026). Fingerprints That Survive What? Model Lineage Names Three Relations, Robustness Is Indexed by Which Party Is Adversarial, and a Benchmark's Distillation Column Scores the Parent That Was Not Distilled From. Zenodo. https://doi.org/10.5281/zenodo.23064254 A BibTeX entry is provided on this page.

Related research by Pranay Mahendrakar

← All papers by Pranay Mahendrakar