Known By Their Actions: Fingerprinting LLM Browser Agents via UI Traces

TL;DR AI
2 min readKey summary
Researchers showed that websites can fingerprint LLM browser agents by passively observing UI actions and timing traces.
Across 14 frontier models and four web environments, the method identified the underlying model with up to 96% F1.
The fingerprinting signal generalized across model families and sizes, and still worked after retraining when delays were added.
The finding raises privacy and security concerns because sites could infer which model is driving an agent and tailor attacks accordingly.
