- Sources: arXiv preprint, HN submission
- Summary: The preprint was submitted 2026-09-17 by Sarah Radway, Andrew Cheng, Vijay Janapa Reddi and James Mickens, and is not peer reviewed. It gives fingerprints for five popular engines, names vLLM and SGLang, shows realistic agentic harnesses in which a model identifies the local engine, and describes a proof-of-concept exploit chain from the compromised engine to the bare metal that needs only the model's own output tokens and no maliciously crafted input. The preprint does not specify which engine versions are affected. The authors cite the recent frontier-model sandbox escapes at OpenAI and Anthropic as motivation, and close with engine changes that would make fingerprinting harder.
- Why it matters: The inference engine is the target rather than the components around it, so sandboxing the network proxy and the code-execution environment does not close the path for anyone self-hosting an engine behind an agent harness.
- Follow-up: Track whether vLLM or SGLang adopt the proposed anti-fingerprinting changes.
send feedback on this story