microsoft model fingerprint · v0.3.2

· Public eight-cell reference analysis

microsoft/phi-4 behavioral LLM fingerprint

This page breaks down the exact reference that VerifyLLMAPI uses for microsoft/phi-4: 120 normalized answers across eight low-entropy probes, plus its nearest enrolled models by mean Jensen–Shannon divergence.

Fingerprint summary

Reference answers
120
Samples per cell
15–15
Nearest mean JSD
0.648782

The most concentrated cell was letter-random|ar: g held 46.7% of its answers and entropy measured 1.823 bits. The broadest cell was animal-random|ar at 3.640 bits.

Against the closest enrolled model, letter-random|ar contributed the largest cell distance at JSD 1.000000. This is a descriptive comparison, not proof that either API route serves a named checkpoint.

Completeness: the author dataset allows up to 15 valid answers per selected cell in reference half A. This model contains 120/120 across the eight cells. We show the actual denominator for every share.

The eight test requests

The research pipeline sent each user prompt with a one-answer system constraint, temperature 1, a 16-token output cap, and reasoning disabled. VerifyLLMAPI uses the same prompt text and normalization target.

CellTaskExact request textNormalization and n
animal-random|en Random animal · English Name a random animal.
System constraintAnswer with a single word or a single number only. Output nothing else: no explanation, no punctuation, no quotation marks.
word · 15/15 reference samples
word-random|en Random word · English Name a random word.
System constraintAnswer with a single word or a single number only. Output nothing else: no explanation, no punctuation, no quotation marks.
word · 15/15 reference samples
animal-random|ru Random animal · Russian Назови случайное животное.
System constraintОтвечай только одним словом или одним числом. Не выводи ничего больше: без объяснений, без знаков препинания, без кавычек.
word · 15/15 reference samples
animal-random|ar Random animal · Arabic اذكر حيواناً عشوائياً.
System constraintأجب بكلمة واحدة أو رقم واحد فقط. لا تكتب أي شيء آخر: لا شرح ولا علامات ترقيم ولا علامات اقتباس.
word · 15/15 reference samples
letter-random|zh Random character · Chinese 说出一个随机的汉字。
System constraint只用一个词或一个数字回答。不要输出任何其他内容:不要解释,不要标点符号,不要引号。
grapheme · 15/15 reference samples
animal-random|zh Random animal · Chinese 说出一个随机的动物。
System constraint只用一个词或一个数字回答。不要输出任何其他内容:不要解释,不要标点符号,不要引号。
word · 15/15 reference samples
letter-random|ar Random letter · Arabic اذكر حرفاً عشوائياً من الحروف الأبجدية.
System constraintأجب بكلمة واحدة أو رقم واحد فقط. لا تكتب أي شيء آخر: لا شرح ولا علامات ترقيم ولا علامات اقتباس.
grapheme · 15/15 reference samples
color-random|zh Random color · Chinese 说出一个随机的颜色。
System constraint只用一个词或一个数字回答。不要输出任何其他内容:不要解释,不要标点符号,不要引号。
word · 15/15 reference samples

Response distributions

These are normalized reference-half counts from the published OpenRouter dataset. The tables contain aggregate values, not user data or a live VerifyLLMAPI scan.

1. animal-random|en

Random animal, English. 15 valid reference answers produced 7 normalized values. The mode was elephant at 6/15 (40.0%); entropy was 2.423 bits.

microsoft/phi-4 response distribution for animal-random|en
Normalized responseCountShare
elephant 6 40.0%
kangaroo 3 20.0%
giraffe 2 13.3%
koala 1 6.7%
penguin 1 6.7%
platypus 1 6.7%
zebra 1 6.7%

2. word-random|en

Random word, English. 15 valid reference answers produced 10 normalized values. The mode was elephant at 6/15 (40.0%); entropy was 2.873 bits.

microsoft/phi-4 response distribution for word-random|en
Normalized responseCountShare
elephant 6 40.0%
altruism 1 6.7%
camaraderie 1 6.7%
candle 1 6.7%
daffodil 1 6.7%
dandelion 1 6.7%
innovation 1 6.7%
sunshine 1 6.7%
table 1 6.7%
tableau 1 6.7%

3. animal-random|ru

Random animal, Russian. 15 valid reference answers produced 11 normalized values. The mode was корова at 4/15 (26.7%); entropy was 3.240 bits.

microsoft/phi-4 response distribution for animal-random|ru
Normalized responseCountShare
корова 4 26.7%
лев 2 13.3%
единорог 1 6.7%
зебра 1 6.7%
какаду 1 6.7%
кенгуру 1 6.7%
кит 1 6.7%
коala 1 6.7%
коала 1 6.7%
кот 1 6.7%
панда 1 6.7%

4. animal-random|ar

Random animal, Arabic. 15 valid reference answers produced 13 normalized values. The mode was أسد at 2/15 (13.3%); entropy was 3.640 bits.

microsoft/phi-4 response distribution for animal-random|ar
Normalized responseCountShare
أسد 2 13.3%
قطة 2 13.3%
إنسان 1 6.7%
الفهد 1 6.7%
بطة 1 6.7%
دببة 1 6.7%
علبة 1 6.7%
قط 1 6.7%
قندس 1 6.7%
كأسد 1 6.7%
كلب 1 6.7%
كوكيز 1 6.7%
نسر 1 6.7%

5. letter-random|zh

Random character, Chinese. 15 valid reference answers produced 13 normalized values. The mode was at 2/15 (13.3%); entropy was 3.640 bits.

microsoft/phi-4 response distribution for letter-random|zh
Normalized responseCountShare
2 13.3%
2 13.3%
1 6.7%
1 6.7%
1 6.7%
1 6.7%
1 6.7%
汉字 1 6.7%
1 6.7%
1 6.7%
1 6.7%
1 6.7%
1 6.7%

6. animal-random|zh

Random animal, Chinese. 15 valid reference answers produced 10 normalized values. The mode was 企鹅 at 3/15 (20.0%); entropy was 3.190 bits.

microsoft/phi-4 response distribution for animal-random|zh
Normalized responseCountShare
企鹅 3 20.0%
大象 2 13.3%
熊猫 2 13.3%
狮子 2 13.3%
斑马 1 6.7%
海豚 1 6.7%
珊瑚鱼 1 6.7%
秃鹫 1 6.7%
蝙蝠 1 6.7%
鳄鱼 1 6.7%

7. letter-random|ar

Random letter, Arabic. 15 valid reference answers produced 5 normalized values. The mode was g at 7/15 (46.7%); entropy was 1.823 bits.

microsoft/phi-4 response distribution for letter-random|ar
Normalized responseCountShare
g 7 46.7%
m 5 33.3%
j 1 6.7%
خ 1 6.7%
ز 1 6.7%

8. color-random|zh

Random color, Chinese. 15 valid reference answers produced 9 normalized values. The mode was 紫色 at 4/15 (26.7%); entropy was 2.923 bits.

microsoft/phi-4 response distribution for color-random|zh
Normalized responseCountShare
紫色 4 26.7%
蓝色 3 20.0%
紫罗兰 2 13.3%
布谷鸟绿色 1 6.7%
粉红色 1 6.7%
紫红色 1 6.7%
绛红 1 6.7%
绿色 1 6.7%
青草绿 1 6.7%

Three nearest enrolled references

We compute base-2 JSD for each of the eight categorical distributions, then average the eight distances. A lower value means more similar answer frequencies within this product reference. It does not identify an unknown route by itself.

RankReference modelMean 8-cell JSD
1 anthropic/claude-sonnet-4 0.648782
2 openai/gpt-4o 0.660538
3 qwen/qwen3.6-35b-a3b 0.674784

How many live requests does verification use?

ProfileCells × samplesFresh model requestsSame-data EER
Quick, default complete check4 × 52011.8%
Standard8 × 5408.1%
Paper budget8 × 151206.7%

The current-Agent workflow starts with quick. Each answer comes from a fresh Codex or Claude Code process that reuses host-managed login. These requests can consume host allowance or provider balance.

What this fingerprint can and cannot show

  • The reference records behavior observed through OpenRouter in the author dataset. Provider wrappers, model updates, decoding, and date can move a distribution.
  • The author collection set temperature 1 and disabled reasoning. Current-Agent mode labels sampling as a host default because supported Agent CLIs expose no temperature flag.
  • The eight high-gap cells and product thresholds use the same public cohort. Their EER values are calibration results, not an independent production accuracy claim.
  • A nearest reference is a similarity result. VerifyLLMAPI returns INCONCLUSIVE when the claimed route lacks an enrolled fingerprint.

Primary sources, license, and reproducibility

  1. Tomas Bruckner, One Token Is Enough: Fingerprinting and Verifying Large Language Models from Single-Token Output Distributions, arXiv:2607.10252v1.
  2. Author dataset and derived results, DOI 10.5281/zenodo.21278557, CC BY 4.0.
  3. Author collection and analysis software, DOI 10.5281/zenodo.21278793, MIT.
  4. VerifyLLMAPI atlas JSON, built from reference pamela-openrouter-2026-07-8cell-ref-a, SHA-256 51f3f63cbcfb56b151055d2d10e36a9cc2f0644cc68b580784853d68951fa866.

Page evidence SHA-256: 727d9bc3787815d501bc7cfd6ca43bfb024c126ebe2775f2843dc8cc9dedd20f. This hash covers the model ID, eight cell metrics, nearest references, and strongest cell difference in the generated atlas.

Run a current-Agent model check