FINDING · DETECTION
Strong classifiers can be trained from fewer than one third of available traces with gains diminishing rapidly beyond that threshold. At inference time, macro F1 rises sharply within the first 40% of observed actions across all four datasets, meaning model identity can be inferred while the agent is still actively navigating the page.
From 2026-lugoloobi-known-their-actions — Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces · §6.2, Figure 6 · 2026 · arXiv preprint
Implications
- Short agent sessions reduce the available fingerprinting signal — circumvention agents should prefer tasks decomposed into many short browsing episodes over single long sessions on potentially adversarial pages.
- Early mid-session identification means a site can condition a targeted prompt injection or content poisoning attack before the agent's task completes, making adversary-controlled pages a real-time threat rather than a post-hoc attribution concern.
Tags
Extracted by claude-sonnet-4-6 — review before relying.