Open-weight language models are fine-tuned, quantized, pruned, and merged, yet their provenance is often undocumented. We study data-free white-box lineage verification: <strong>can weights alone reveal whether two compatible model checkpoints share ancestry?</strong></p>\n<p>Residual training produces a shared identity aligned component in branch products, so this structure alone cannot establish ancestry. We remove it and compare checkpoint-specific structure across residual blocks, yielding a symmetric lineage score calibrated against independent checkpoints. On residual-MLP and GPT2 benchmarks, the score separates fine-tuned, LoRA-merged, pruned, and quantized descendants from independent and distilled models (AUROC=1.0), distinguishing weight ancestry from behavioral similarity. Under function preserving checkpoint laundering experiments, weight-space baselines lose margin or fail; our score remains unchanged and runs 76× faster than the nearest robust baseline on GPT-2. The projection-pairing signal appears across six language-model families and beyond, and a case study correctly identifies 3 related and 7 unrelated LLaMA-2 public checkpoints. Collectively, these results establish a passive, data-free provenance signal for compatible open-weight language-model checkpoints.</p>\n","updatedAt":"2026-08-20T03:16:03.989Z","author":{"_id":"63b491f3103617b0a5af6b4b","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/63b491f3103617b0a5af6b4b/4RqcGDxdF8Ny9cqyVuwYg.jpeg","fullname":"Aman Singh Thakur","name":"singh96aman","type":"user","isPro":false,"isHf":false,"isHfAdmin":false,"isMod":false,"followerCount":6,"isUserFollowing":false}},"numEdits":0,"identifiedLanguage":{"language":"en","probability":0.8712463974952698},"editors":["singh96aman"],"editorAvatarUrls":["https://cdn-avatars.huggingface.co/v1/production/uploads/63b491f3103617b0a5af6b4b/4RqcGDxdF8Ny9cqyVuwYg.jpeg"],"reactions":[],"isReport":false}}],"primaryEmailConfirmed":false,"paper":{"id":"2608.14929","authors":[{"_id":"6a867042db13816030683ec8","name":"Aman Singh Thakur","hidden":false},{"_id":"6a867042db13816030683ec9","name":"Rayan Khoury","hidden":false}],"mediaUrls":["https://cdn-uploads.huggingface.co/production/uploads/63b491f3103617b0a5af6b4b/J_BAx9y0JAN6SrcOg6D8_.png","https://cdn-uploads.huggingface.co/production/uploads/63b491f3103617b0a5af6b4b/G_Vz7GvwTCnR4wC585_Kf.png","https://cdn-uploads.huggingface.co/production/uploads/63b491f3103617b0a5af6b4b/yzFOGbS53V7-G9k33Nt4_.png"],"publishedAt":"2026-08-14T00:00:00.000Z","submittedOnDailyAt":"2026-08-20T00:00:00.000Z","title":"Training Leaves Traces: Centered Residual Signatures for Language Model Lineage Verification","submittedOnDailyBy":{"_id":"63b491f3103617b0a5af6b4b","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/63b491f3103617b0a5af6b4b/4RqcGDxdF8Ny9cqyVuwYg.jpeg","isPro":false,"fullname":"Aman Singh Thakur","user":"singh96aman","type":"user","name":"singh96aman"},"summary":"Open-weight language models are fine-tuned, quantized, pruned, and merged, yet their provenance is often undocumented. We study data-free white-box lineage verification: can weights alone reveal whether two compatible model checkpoints share ancestry?\n Residual training produces a shared identity-aligned component in branch products, so this structure alone cannot establish ancestry. We remove it and compare checkpoint-specific structure across residual blocks, yielding a symmetric lineage score calibrated against independent checkpoints. On residual-MLP and GPT-2 benchmarks, the score separates fine-tuned, LoRA-merged, pruned, and quantized descendants from independent and distilled models (AUROC=1.0), distinguishing weight ancestry from behavioral similarity. Under function-preserving checkpoint laundering experiments, weight-space baselines lose margin or fail; our score remains unchanged and runs 76x faster than the nearest robust baseline on GPT-2. The projection-pairing signal appears across six language-model families and beyond, and a case study correctly identifies 3 related and 7 unrelated LLaMA-2 public checkpoints. Collectively, these results establish a passive, data-free provenance signal for compatible open-weight language-model checkpoints","upvotes":15,"discussionId":"6a867043db13816030683eca","projectPage":"https://arxiv.org/pdf/2608.14929","ai_summary":"Compatible open-weight language model checkpoints share detectable weight-space ancestry signals that distinguish true lineage from independent or distilled models without requiring data.","ai_keywords":["white-box lineage verification","residual training","identity-aligned component","branch products","residual blocks","lineage score","LoRA-merged","pruned","quantized","checkpoint laundering","projection-pairing signal"],"ai_summary_model":"thinkingmachines/Inkling-Small","organization":{"_id":"5ffdfbadbba2ae614d771970","name":"amazon","fullname":"Amazon","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/66f19ed428ae41c20c470792/8y7msN6A6W82LdQhQd85a.png"}},"canReadDatabase":false,"canManagePapers":false,"canSubmit":false,"hasHfLevelAccess":false,"upvoted":false,"upvoters":[{"_id":"63b491f3103617b0a5af6b4b","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/63b491f3103617b0a5af6b4b/4RqcGDxdF8Ny9cqyVuwYg.jpeg","isPro":false,"fullname":"Aman Singh Thakur","user":"singh96aman","type":"user"},{"_id":"6a86727e1a17a9df25d23955","avatarUrl":"/avatars/cb43fd7ea53937469f104673dce288ee.svg","isPro":false,"fullname":"Aman Thakur","user":"amansinghtha","type":"user"},{"_id":"63ac5701c21e60a3e9b58aa7","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/63ac5701c21e60a3e9b58aa7/g6EX7diOpuA94R2ab-rZC.png","isPro":true,"fullname":"Dipankar Sarkar","user":"dipankarsarkar","type":"user"},{"_id":"691aad397dd80eff9b491bd9","avatarUrl":"/avatars/87b791d072cd80bba46ce5cbf75fa498.svg","isPro":false,"fullname":"Rayan Khoury","user":"rayankhoure","type":"user"},{"_id":"6a6a9a2c719ef934225f3d70","avatarUrl":"/avatars/200d81188918e2e51a6235fac32e52c9.svg","isPro":false,"fullname":"Michael Harris","user":"Velvet-Michael","type":"user"},{"_id":"6a6aa0e36039a754565fcddd","avatarUrl":"/avatars/c7311ecd8157d7f286dfd82f4d33d711.svg","isPro":false,"fullname":"Barbara Taylor","user":"Meridian-Owen","type":"user"},{"_id":"6a6c7b043574d63d5305d6fc","avatarUrl":"/avatars/6e5b4d8ac3a28eee5ad8c18734c2db7b.svg","isPro":false,"fullname":"Patricia Anderson","user":"Rapid-Theo","type":"user"},{"_id":"6a6c840261da43cdbfda1203","avatarUrl":"/avatars/3c6b0a713733718b0ccb485d3e2591fb.svg","isPro":false,"fullname":"Edward Davis","user":"vectorEdward","type":"user"},{"_id":"6a6c8836e34d1f023f2bfc9b","avatarUrl":"/avatars/b100d4c55e4c331a0360b8338388f349.svg","isPro":false,"fullname":"Anthony Gonzalez","user":"Anthony-Gonzalez","type":"user"},{"_id":"6a6aa6be977fbfce4badef39","avatarUrl":"/avatars/c6d41485e9dfb36b632a8715b5650673.svg","isPro":false,"fullname":"Sarah Sanchez","user":"Sarah-Sanchez","type":"user"},{"_id":"6a6de3798dd23bc30b25bf46","avatarUrl":"/avatars/6a699138472a0ca37b44f753d76c9758.svg","isPro":false,"fullname":"George Jackson","user":"meridianVault","type":"user"},{"_id":"6a6de993067f0e2726f81651","avatarUrl":"/avatars/f5162244a4a7aad4706867f5fded818c.svg","isPro":false,"fullname":"Jennifer Taylor","user":"emberField","type":"user"}],"acceptLanguages":["en"],"dailyPaperRank":0,"organization":{"_id":"5ffdfbadbba2ae614d771970","name":"amazon","fullname":"Amazon","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/66f19ed428ae41c20c470792/8y7msN6A6W82LdQhQd85a.png"},"markdownContentUrl":"https://huggingface.co/buckets/huggingchat/papers-content/resolve/2608/2608.14929.md","query":{}}">
Training Leaves Traces: Centered Residual Signatures for Language Model Lineage Verification
Abstract
Compatible open-weight language model checkpoints share detectable weight-space ancestry signals that distinguish true lineage from independent or distilled models without requiring data.
Open-weight language models are fine-tuned, quantized, pruned, and merged, yet their provenance is often undocumented. We study data-free white-box lineage verification: can weights alone reveal whether two compatible model checkpoints share ancestry?
Residual training produces a shared identity-aligned component in branch products, so this structure alone cannot establish ancestry. We remove it and compare checkpoint-specific structure across residual blocks, yielding a symmetric lineage score calibrated against independent checkpoints. On residual-MLP and GPT-2 benchmarks, the score separates fine-tuned, LoRA-merged, pruned, and quantized descendants from independent and distilled models (AUROC=1.0), distinguishing weight ancestry from behavioral similarity. Under function-preserving checkpoint laundering experiments, weight-space baselines lose margin or fail; our score remains unchanged and runs 76x faster than the nearest robust baseline on GPT-2. The projection-pairing signal appears across six language-model families and beyond, and a case study correctly identifies 3 related and 7 unrelated LLaMA-2 public checkpoints. Collectively, these results establish a passive, data-free provenance signal for compatible open-weight language-model checkpoints
Community
Open-weight language models are fine-tuned, quantized, pruned, and merged, yet their provenance is often undocumented. We study data-free white-box lineage verification: can weights alone reveal whether two compatible model checkpoints share ancestry?
Residual training produces a shared identity aligned component in branch products, so this structure alone cannot establish ancestry. We remove it and compare checkpoint-specific structure across residual blocks, yielding a symmetric lineage score calibrated against independent checkpoints. On residual-MLP and GPT2 benchmarks, the score separates fine-tuned, LoRA-merged, pruned, and quantized descendants from independent and distilled models (AUROC=1.0), distinguishing weight ancestry from behavioral similarity. Under function preserving checkpoint laundering experiments, weight-space baselines lose margin or fail; our score remains unchanged and runs 76× faster than the nearest robust baseline on GPT-2. The projection-pairing signal appears across six language-model families and beyond, and a case study correctly identifies 3 related and 7 unrelated LLaMA-2 public checkpoints. Collectively, these results establish a passive, data-free provenance signal for compatible open-weight language-model checkpoints.
Upload images, audio, and videos by dragging in the text input, pasting, or clicking here.
Tap or paste here to upload images
Cite arxiv.org/abs/2608.14929 in a model README.md to link it from this page.
Cite arxiv.org/abs/2608.14929 in a dataset README.md to link it from this page.
Cite arxiv.org/abs/2608.14929 in a Space README.md to link it from this page.
Discussion (0)
Sign in to join the discussion. Free account, 30 seconds — email code or GitHub.
Sign in →No comments yet. Sign in and be the first to say something.