FINDING · DETECTION

Passive JavaScript UI traces are sufficient to fingerprint the underlying LLM of a browser agent with up to 96% macro F1 across 14 frontier models, achieving roughly 10× random-chance accuracy. Even the weakest model pair (Qwen3.5-9B on 2WikiMultiHopQA) reaches 63.7% F1 against a ~7% random baseline for 14 classes.

From 2026-lugoloobi-known-their-actionsKnown By Their Actions: Fingerprinting LLM Browser Agents via UI Traces · §5.1, Figure 2 · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
ml-classifiertraffic-shape

Extracted by claude-sonnet-4-6 — review before relying.