布拉格经济大学研究员托马什·布鲁克纳发现,通过让模型反复输出1到100的随机数,可生成独一无二的"行为指纹"。
对165个模型各问30次后发现,GPT-4o偏爱42和37,Claude Sonnet 5疯狂输出47,Qwen3-Max则30次全部回答42。
该方法仅需约120条请求即可识别模型身份,错误率约10.6%,为验证API是否被偷换模型提供了轻量级方案。
Tomas Bruckner, a researcher at the Prague University of Economics, discovered that by having a model repeatedly output random numbers from 1 to 100, a uni...
Tomas Bruckner, a researcher at the Prague University of Economics, discovered that by having a
model repeatedly output random numbers from 1 to 100, a unique 'behavioral fingerprint' can be generated. After asking 165 models 30 times each, it was found that GPT-4o favors 42 and 37, Claude Sonnet 5 wildly outputs 47, and Qwen3-Max answered 42 all 30 times. This method only requires about 120 requests to identify a model, with an error rate of about 10.6%, providing a lightweight solution for verifying whether an API has had its model swapped.
布拉格经济大学研究员托马什·布鲁克纳发现,通过让模型反复输出1到100的随机数,可生成独一无二的"行为指纹"。
对165个模型各问30次后发现,GPT-4o偏爱42和37,Claude Sonnet 5疯狂输出47,Qwen3-Max则30次全部回答42。
该方法仅需约120条请求即可识别模型身份,错误率约10.6%,为验证API是否被偷换模型提供了轻量级方案。
研究员托马什·布鲁克纳通过让模型反复输出1至100的随机数,提取不同模型的回答偏好,并将其作为识别模型身份的“行为指纹”。
材料称,研究对165个模型各提问30次,观察到GPT-4o偏爱42和37,Claude Sonnet 5常输出47,Qwen3-Max的30次回答均为42。
Aioga判断,这种方法的价值在于用较简单的重复请求辅助核验API背后的模型身份,但约10.6%的错误率意味着结果不能被视为确定性证明。
该方法可能为识别API中转服务是否更换模型提供轻量级线索。值得关注的是,材料仅说明随机数回答偏好,未说明其在更多调用环境中的稳定性。 建议按材料所述约120条请求进行重复测试,并结合错误率审慎解释结果。进一步应用前,值得关注不同模型、不同时间与不同接口条件下的复现情况。
The readable text on this page was extracted from the public source and organized with attribution, publication time and the original link. Copyright remains with the original author and publisher.
Ingestion channel: Summary aggregation · Source domain: mp.weixin.qq.com
Source: 公众号:数字生命卡兹克
Original link: Open original source
Aioga archive: Open intelligence page
Content record: summary-fallback · Updated: 2026-07-21T01:10:49.000Z

统一接入主流 AI 模型 API,为开发、测试与生产环境提供稳定调用入口。
立即访问 api.w173.comAioga aggregates global AI updates and preserves source information for verification and citation.