FINDING · DETECTION

Strong classifiers can be trained from fewer than one third of available traces with gains diminishing rapidly beyond that threshold. At inference time, macro F1 rises sharply within the first 40% of observed actions across all four datasets, meaning model identity can be inferred while the agent is still actively navigating the page.

From 2026-lugoloobi-known-their-actionsKnown By Their Actions: Fingerprinting LLM Browser Agents via UI Traces · §6.2, Figure 6 · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
ml-classifiertraffic-shape

Extracted by claude-sonnet-4-6 — review before relying.