Independent testing will determine whether roughly 200 one-token random-number queries can reliably identify LLMs and expose silent model substitution by third-party API relays.
state: expiredheat: lowuncertainty: highconvergesscott: highmodel-fingerprinting llm-apis api-relays
What is this?
A paper titled “One Token Is Enough” reportedly proposes black-box LLM fingerprinting by measuring output distributions from roughly 200 trivial, one-token prompts, including requests for random numbers. The intended use is to verify that a third-party API relay is serving the advertised model rather than silently substituting another one. The supplied search snippets do not identify the paper’s authors or provide direct experimental results, so the method’s reliability and ability to distinguish closely related or changing model versions remain unestablished here.
Why it matters to Scott
The proposed fingerprint independently operationalizes Scott’s model/artifact-provenance concern and could become a practical compliance test for his active LiteLLM/OpenRouter routing and provider-execution benchmarks. If independent testing validates it, it extends his provenance and observability work with a cheap detector for relay substitution; the existing Basalt case also supplies an immediate application and publishing hook.
ip:framework.agent-provenance-stackip:concept.verification-boundarydev:project.remote-execdev:technology.litellmdev:technology.openrouterradar:basalt-hle-claim-dispute
queries asked of Scott's wikis
- black-box model fingerprinting and identity verification
- silent model substitution in API gateways and relays
- probabilistic testing of nondeterministic LLM APIs
- model provenance and third-party inference trust
- LLM routing observability and compliance harnesses
- behavioral drift versus model identity
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (3) — ⭐ canonical anchor
Interpretation history
2026-07-28T03:21:50Z
The small engagement movement adds no independent replication or relay-substitution test, leaving the proposed fingerprint an unvalidated method with no active momentum. The episode has faded without a substantive testing line to follow.
2026-07-25T20:23:42Z
No independent replication or real relay-substitution test has appeared; the elapsed time adds no validation beyond the paper’s reproducible claim. Keep it as a relevant but dormant method awaiting substantive testing.
2026-07-22T16:26:34Z
The added endpoint-behavior example shows why black-box verification matters, but it neither tests the proposed one-token fingerprint nor independently validates model identification or substitution detection. The case remains a promising, reproducible method awaiting replication.
2026-07-22T16:22:39Z
evidence attached: hn.story.49009050 — The hidden-token and prompt-drift findings materially contextualize how API behavior may fingerprint or expose silent endpoint changes.
2026-07-22T11:23:37Z
The primary-source reconstruction clarifies that the paper reports stable fingerprints and releases reproducibility materials, but no independent replication or relay-substitution test has appeared. The new attachment therefore strengthens testability, not validation.
2026-07-22T07:25:06Z
grounded: converges/high — The proposed fingerprint independently operationalizes Scott’s model/artifact-provenance concern and could become a practical compliance test for his active Lit
2026-07-22T07:22:54Z
origin walked (codex/luna, conf 0.98): anchor reddit.post.1v38j4x -> echo.paper.e75fd47e36 by Tomas Bruckner
2026-07-22T07:21:19Z
case created — The cited paper presents a specific, testable API-verification technique, but the available evidence is a single low-engagement secondary report.
Decision trace
- 07-28 13:21expireThe small engagement movement adds no independent replication or relay-substitution test, leaving the proposed fingerprint an unvalidated method with no active momentum. The episode has faded without
- 07-26 06:23repriceNo independent replication or real relay-substitution test has appeared; the elapsed time adds no validation beyond the paper’s reproducible claim. Keep it as a relevant but dormant method awaiting su
- 07-23 02:26repriceThe added endpoint-behavior example shows why black-box verification matters, but it neither tests the proposed one-token fingerprint nor independently validates model identification or substitution d
- 07-23 02:22attachThe hidden-token and prompt-drift findings materially contextualize how API behavior may fingerprint or expose silent endpoint changes.
- 07-23 02:22propose_attachThe hidden-token and prompt-drift findings materially contextualize how API behavior may fingerprint or expose silent endpoint changes.
- 07-22 21:23repriceThe primary-source reconstruction clarifies that the paper reports stable fingerprints and releases reproducibility materials, but no independent replication or relay-substitution test has appeared. T
- 07-22 21:20mark_dirtyengagement_update
- 07-22 17:25groundThe proposed fingerprint independently operationalizes Scott’s model/artifact-provenance concern and could become a practical compliance test for his active LiteLLM/OpenRouter routing and provider-exe
- 07-22 17:22promote_anchororigin walk conf 0.98
- 07-22 17:21createThe cited paper presents a specific, testable API-verification technique, but the available evidence is a single low-engagement secondary report.