PROMPRINT: Prompt Fingerprinting via First-Token Response for LLM App Cloning Detection

Jungmin Lee, Peizhuo Lv, Yeonjoon Lee


Abstract
As Large Language Model applications (LLM apps) become widespread, system prompts that determine app behavior are increasingly regarded as intellectual property, raising concerns about leakage. Recent studies show that this threat is no longer theoretical, revealing the prevalence of cloned apps replicating system prompts from others on real-world platforms. These clones pose risks of copyright infringement and malicious misuse, highlighting the need for early and reliable detection. In this paper, we propose PROMPRINT, a novel fingerprinting approach for detecting cloned LLM apps without exposing their system prompts. Motivated by the insight that different system prompts yield distinct responses to the same query, PROMPRINT optimizes queries that induce the LLM to generate a specific first token associated with the given system prompt, resulting in distinctive query–first-token pairs. Experiments on four instruction-tuned LLMs show that generated pairs effectively identify the corresponding system prompts, achieving over 74% probability of generating the target token while remaining below 2.2% on average under other prompts. Furthermore, we demonstrate that our fingerprinting remains robust to partial system prompt modifications and effective under the injection of adversarial instructions.
Anthology ID:
2026.acl-long.1052
Volume:
Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)
Month:
July
Year:
2026
Address:
San Diego, California, United States
Editors:
Maria Liakata, Viviane P. Moreira, Jiajun Zhang, David Jurgens
Venue:
ACL
SIG:
Publisher:
Association for Computational Linguistics
Note:
Pages:
22960–22972
Language:
URL:
https://preview.aclanthology.org/ingest-acl/2026.acl-long.1052/
DOI:
Bibkey:
Cite (ACL):
Jungmin Lee, Peizhuo Lv, and Yeonjoon Lee. 2026. PROMPRINT: Prompt Fingerprinting via First-Token Response for LLM App Cloning Detection. In Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), pages 22960–22972, San Diego, California, United States. Association for Computational Linguistics.
Cite (Informal):
PROMPRINT: Prompt Fingerprinting via First-Token Response for LLM App Cloning Detection (Lee et al., ACL 2026)
Copy Citation:
PDF:
https://preview.aclanthology.org/ingest-acl/2026.acl-long.1052.pdf
Checklist:
 2026.acl-long.1052.checklist.pdf