Security1 distinct publisher2 min readPublished
Two fingerprinting methods recovered Qwen ancestry in Nemotron models that had been post-trained and republished under another name, which is why a rule that reads the publisher label cannot see what is in the weights.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Fine-tuning is the mechanism. It is routine practice. A producer starts from an existing checkpoint rather than a blank page, so the inherited dependency never lands in a manifest file; it sits in the learned weights, along with the biases and behavioral patterns that came with them [7]. Cisco frames it this way: models carry supply chains, not passports [16].
The study design deserves as much attention as the result. This was a positive control: the tools were asked to recover a relationship that had already been documented, and what the published account carries is that single confirmation, not a detection rate for models whose base checkpoint nobody declared [21]. Cisco's own framing is narrow, and it should be read as written [8].
The two tools sit on opposite sides of the artifact. Cisco's Model Provenance Kit inspects the model from the inside, while VAIL's Behavioral Fingerprinting works from inference behavior on the outside [4]. For anything consumed as a hosted endpoint, where the weights are not yours to open, the behavioral half is the only one you can run [20]. SecurityWeek's earlier coverage records that Cisco has already released an open source tool for AI model provenance [18].
The proposed manifest lists seven fields, and three of them are themselves models with lineage of their own to declare [19]. That recursion is why the software supply chain analogy [11] hands you the shape of the problem without handing you the tooling. Cisco argues fingerprints can corroborate disclosures or surface relationships worth reviewing, and that the industry does not need to wait for regulation to make the practice routine [13].
The country label still buys something. It identifies the accountable developer, the applicable jurisdiction, and the authorized procurement path [9]. Those are answers to legal questions rather than technical ones. A rule that excludes a publisher because Washington treats Chinese AI as a national security threat [17] therefore polices the paperwork, and the check that would test the model itself is the due diligence Cisco says buyers should already be doing on lineage, training dependencies, behavior, and operational control [14]. Only two vendors can currently perform that check, and procurement cannot.
Ranked by verification strength, evidence, and original report placement.
Cisco published details of research from itself and VAIL in a blog post titled "The 'U.S. vs. China' AI Trap: An Incomplete Proxy for AI Security".
Cisco argues that country labels do not provide a complete picture of an AI model's components, because of a phenomenon it calls provenance entanglement.
Researchers used two AI model fingerprinting methods to analyze model weights and behavioral patterns, and found that these do not accurately or necessarily reflect the model's publisher name and country of origin.
The methods used were Cisco's Model Provenance Kit, which examines the artifact from the inside, and VAIL's Behavioral Fingerprinting, which examines inference behavior from the outside.
Nemotron and Qwen models were chosen for study because it is known that some Nemotron models use Qwen base weights.
Cisco: "Both methods found Nemotron models built from Qwen base weights to be substantially more similar to Qwen models than chance would predict."
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Nvidia's $6bn Poolside licence is the third run of the same play2 distinct publishers
security
AI supply chain incidents are still bad packages and unwatched build pipelines1 distinct publisher
invest
OpenAI's own timeline: twelve days from agent attack to knowing it was them1 distinct publisher
invest
Tiny corp wants Etched's numbers. Jane Street led $700M at $21B without publishing any1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor blog, one outlet, one known pair
Everything technical here traces to Cisco's own post as summarized by SecurityWeek. The headline result is qualitative — "substantially more similar than chance would predict" — with no similarity scores, thresholds or false-positive behavior, and it was measured on the one family pair whose weight reuse was already public. That is a sanity check on the instruments, not yet a demonstration that they find lineage nobody disclosed.
Tooling shipped, nobody yet using it on record
Two artifacts exist — the published research and an open source provenance tool Cisco released earlier — and that is the whole of it. No enterprise has said it screens models this way, no procurement rule has changed, and the model bill of materials remains a proposal with a field list and no first adopter.
Confirmed the known case, headlined the unknown one
"Think you've eliminated Chinese AI? Check the model's lineage" promises a discovery capability the reported experiment did not test: the methods recovered ancestry that was already documented. The underlying claim — that a publisher label cannot see into weights — is sound and modestly stated by Cisco itself; the stretch is between that and the implication that hidden Chinese lineage is now detectable in your stack.
The remedy is a product Cisco already ships
Cisco's recommendation is that lineage verification become routine due diligence; Cisco supplies the Model Provenance Kit and, per SecurityWeek's earlier reporting, an open source provenance tool. The disclosure is present but buried in a related link rather than set against the advice. VAIL's stake in behavioral fingerprinting goes unexamined entirely, and no party whose models were fingerprinted was given room to respond.
Sound argument, thin proof, single channel
We are confident about what Cisco said and why the label-versus-weights argument holds; the mechanism is basic and uncontested. We are much less confident about the strength of the measurement, because one outlet relaying one vendor post gives no way to check the similarity claim, and the recursion problem in the proposed disclosure — teacher, reward and synthetic-data generator models each having lineage of their own — is not addressed anywhere in the coverage.