qwen model fingerprint · v0.3.2

· Public eight-cell reference analysis

qwen/qwen3.5-9b behavioral LLM fingerprint

This page breaks down the exact reference that VerifyLLMAPI uses for qwen/qwen3.5-9b: 118 normalized answers across eight low-entropy probes, plus its nearest enrolled models by mean Jensen–Shannon divergence.

Fingerprint summary

Reference answers
118
Samples per cell
14–15
Nearest mean JSD
0.489002

The most concentrated cell was color-random|zh: 蓝色 held 73.3% of its answers and entropy measured 1.237 bits. The broadest cell was letter-random|zh at 3.236 bits.

Against the closest enrolled model, word-random|en contributed the largest cell distance at JSD 0.676350. This is a descriptive comparison, not proof that either API route serves a named checkpoint.

Completeness: the author dataset allows up to 15 valid answers per selected cell in reference half A. This model contains 118/120 across the eight cells. We show the actual denominator for every share.

The eight test requests

The research pipeline sent each user prompt with a one-answer system constraint, temperature 1, a 16-token output cap, and reasoning disabled. VerifyLLMAPI uses the same prompt text and normalization target.

CellTaskExact request textNormalization and n
animal-random|en Random animal · English Name a random animal.
System constraintAnswer with a single word or a single number only. Output nothing else: no explanation, no punctuation, no quotation marks.
word · 15/15 reference samples
word-random|en Random word · English Name a random word.
System constraintAnswer with a single word or a single number only. Output nothing else: no explanation, no punctuation, no quotation marks.
word · 15/15 reference samples
animal-random|ru Random animal · Russian Назови случайное животное.
System constraintОтвечай только одним словом или одним числом. Не выводи ничего больше: без объяснений, без знаков препинания, без кавычек.
word · 15/15 reference samples
animal-random|ar Random animal · Arabic اذكر حيواناً عشوائياً.
System constraintأجب بكلمة واحدة أو رقم واحد فقط. لا تكتب أي شيء آخر: لا شرح ولا علامات ترقيم ولا علامات اقتباس.
word · 15/15 reference samples
letter-random|zh Random character · Chinese 说出一个随机的汉字。
System constraint只用一个词或一个数字回答。不要输出任何其他内容:不要解释,不要标点符号,不要引号。
grapheme · 14/15 reference samples
animal-random|zh Random animal · Chinese 说出一个随机的动物。
System constraint只用一个词或一个数字回答。不要输出任何其他内容:不要解释,不要标点符号,不要引号。
word · 15/15 reference samples
letter-random|ar Random letter · Arabic اذكر حرفاً عشوائياً من الحروف الأبجدية.
System constraintأجب بكلمة واحدة أو رقم واحد فقط. لا تكتب أي شيء آخر: لا شرح ولا علامات ترقيم ولا علامات اقتباس.
grapheme · 14/15 reference samples
color-random|zh Random color · Chinese 说出一个随机的颜色。
System constraint只用一个词或一个数字回答。不要输出任何其他内容:不要解释,不要标点符号,不要引号。
word · 15/15 reference samples

Response distributions

These are normalized reference-half counts from the published OpenRouter dataset. The tables contain aggregate values, not user data or a live VerifyLLMAPI scan.

1. animal-random|en

Random animal, English. 15 valid reference answers produced 9 normalized values. The mode was eagle at 4/15 (26.7%); entropy was 2.974 bits.

qwen/qwen3.5-9b response distribution for animal-random|en
Normalized responseCountShare
eagle 4 26.7%
cat 2 13.3%
dog 2 13.3%
penguin 2 13.3%
blue 1 6.7%
dolphin 1 6.7%
elephant 1 6.7%
pangolin 1 6.7%
tiger 1 6.7%

2. word-random|en

Random word, English. 15 valid reference answers produced 9 normalized values. The mode was apple at 6/15 (40.0%); entropy was 2.740 bits.

qwen/qwen3.5-9b response distribution for word-random|en
Normalized responseCountShare
apple 6 40.0%
banana 2 13.3%
balloons 1 6.7%
bloom 1 6.7%
dream 1 6.7%
glimmer 1 6.7%
gumdrop 1 6.7%
sculpt 1 6.7%
star 1 6.7%

3. animal-random|ru

Random animal, Russian. 15 valid reference answers produced 9 normalized values. The mode was лев at 4/15 (26.7%); entropy was 2.840 bits.

qwen/qwen3.5-9b response distribution for animal-random|ru
Normalized responseCountShare
лев 4 26.7%
слон 4 26.7%
енот 1 6.7%
жираф 1 6.7%
змея 1 6.7%
кит 1 6.7%
манка 1 6.7%
медведь 1 6.7%
тигр 1 6.7%

4. animal-random|ar

Random animal, Arabic. 15 valid reference answers produced 8 normalized values. The mode was أسد at 8/15 (53.3%); entropy was 2.307 bits.

qwen/qwen3.5-9b response distribution for animal-random|ar
Normalized responseCountShare
5 1 6.7%
8 1 6.7%
أسد 8 53.3%
أناناس 1 6.7%
سلحفاة 1 6.7%
ضب 1 6.7%
فهد 1 6.7%
نمر 1 6.7%

5. letter-random|zh

Random character, Chinese. 14 valid reference answers produced 10 normalized values. The mode was at 2/14 (14.3%); entropy was 3.236 bits.

qwen/qwen3.5-9b response distribution for letter-random|zh
Normalized responseCountShare
2 14.3%
2 14.3%
2 14.3%
2 14.3%
1 7.1%
1 7.1%
1 7.1%
1 7.1%
1 7.1%
1 7.1%

6. animal-random|zh

Random animal, Chinese. 15 valid reference answers produced 7 normalized values. The mode was 企鹅 at 6/15 (40.0%); entropy was 2.423 bits.

qwen/qwen3.5-9b response distribution for animal-random|zh
Normalized responseCountShare
企鹅 6 40.0%
熊猫 3 20.0%
2 13.3%
大象 1 6.7%
考拉 1 6.7%
1 6.7%
🐶 1 6.7%

7. letter-random|ar

Random letter, Arabic. 14 valid reference answers produced 8 normalized values. The mode was م at 5/14 (35.7%); entropy was 2.638 bits.

qwen/qwen3.5-9b response distribution for letter-random|ar
Normalized responseCountShare
م 5 35.7%
ذ 3 21.4%
ب 1 7.1%
د 1 7.1%
س 1 7.1%
غ 1 7.1%
ق 1 7.1%
ل 1 7.1%

8. color-random|zh

Random color, Chinese. 15 valid reference answers produced 4 normalized values. The mode was 蓝色 at 11/15 (73.3%); entropy was 1.237 bits.

qwen/qwen3.5-9b response distribution for color-random|zh
Normalized responseCountShare
蓝色 11 73.3%
2 13.3%
紫色 1 6.7%
靛蓝 1 6.7%

Three nearest enrolled references

We compute base-2 JSD for each of the eight categorical distributions, then average the eight distances. A lower value means more similar answer frequencies within this product reference. It does not identify an unknown route by itself.

RankReference modelMean 8-cell JSD
1 qwen/qwen3.5-122b-a10b 0.489002
2 qwen/qwen3.6-27b 0.503829
3 openai/gpt-4o-2024-08-06 0.523498

How many live requests does verification use?

ProfileCells × samplesFresh model requestsSame-data EER
Quick, default complete check4 × 52011.8%
Standard8 × 5408.1%
Paper budget8 × 151206.7%

The current-Agent workflow starts with quick. Each answer comes from a fresh Codex or Claude Code process that reuses host-managed login. These requests can consume host allowance or provider balance.

What this fingerprint can and cannot show

  • The reference records behavior observed through OpenRouter in the author dataset. Provider wrappers, model updates, decoding, and date can move a distribution.
  • The author collection set temperature 1 and disabled reasoning. Current-Agent mode labels sampling as a host default because supported Agent CLIs expose no temperature flag.
  • The eight high-gap cells and product thresholds use the same public cohort. Their EER values are calibration results, not an independent production accuracy claim.
  • A nearest reference is a similarity result. VerifyLLMAPI returns INCONCLUSIVE when the claimed route lacks an enrolled fingerprint.

Primary sources, license, and reproducibility

  1. Tomas Bruckner, One Token Is Enough: Fingerprinting and Verifying Large Language Models from Single-Token Output Distributions, arXiv:2607.10252v1.
  2. Author dataset and derived results, DOI 10.5281/zenodo.21278557, CC BY 4.0.
  3. Author collection and analysis software, DOI 10.5281/zenodo.21278793, MIT.
  4. VerifyLLMAPI atlas JSON, built from reference pamela-openrouter-2026-07-8cell-ref-a, SHA-256 51f3f63cbcfb56b151055d2d10e36a9cc2f0644cc68b580784853d68951fa866.

Page evidence SHA-256: 85331e81d0f72a15a237ef98341257fff415e7d8a57f53a9bc39dc6a6485d28e. This hash covers the model ID, eight cell metrics, nearest references, and strongest cell difference in the generated atlas.

Run a current-Agent model check