TRACE-LM: Transport-Coded Radioactive Lineage Certificates: Joint Carrier--Code Design, Collusion Tracing, and Anytime-Valid Black-Box Evidence
Andrew Kiruluta
PAPER · v1.0 · 2026-08-21 · human
Abstract
TRACE-LM is a framework for detecting and attributing unauthorized black-box distillation of proprietary foundation models. Rather than treating watermarking, model fingerprints, backdoor tests, and collusion-resistant codes as isolated techniques, TRACE-LM combines them into a statistically rigorous lineage-tracing system. Each customer and service period is assigned a unique code whose signal is jointly designed with its embedding mechanism to remain detectable after uncertain distillation and sanitization processes, while limiting changes to the teacher model’s outputs. This allows the system to identify individual sources, pooled customer data, and approximate harvesting periods instead of making only a binary watermarked-or-not decision. TRACE-LM separates detection from enforcement by combining a passive inherited lineage signal with an independently keyed semantic challenge mechanism. Evidence is accumulated using a statistical process that remains valid under adaptive querying and optional stopping. Successful detection produces a signed, independently verifiable lineage certificate containing calibration records, statistical evidence, source confidence estimates, transfer metadata, and control tests. Any action taken against a suspected model is handled externally rather than through a built-in kill switch. The framework also provides theoretical guarantees for source attribution, robustness to uncertain transfer behavior, coalition recovery, fingerprint removal difficulty, and signal decay.