Catch models that
fake their lineage.
Paste a HuggingFace model ID and get an instant verdict — read from the architecture, not the label. So a model sold as “Claude” or “GPT” can't hide that its weights are really something else.
No backdoor detection. No security claims. Just architectural truth.
Architecture verification is free and unlimited. No account, no credit card, no weight download.
More than a similarity score.
Know what you're actually running
modeldna runs a panel of checks — does the name match the weights? does it claim a model it can't be built from? is it hiding where it came from? Each concern adds to a single 0–100 score, so you get one clear answer to the only question that matters: is this model safe to use, and why.
Independent, not self-declared
Every verdict is checked against ModelAtlas — 3,034 models fingerprinted by architecture across 593 publishers. That's the difference from a self-reported model card or SBOM: we derive the truth, the uploader doesn't declare it.
Shareable, audit-ready proof
Every scan produces a copy-paste fingerprint (audit trail) and an embeddable risk badge. Pro adds SBOM/PDF export with lineage origin and technique provenance — ready for governance review.
Small flags add up to a clear verdict.
Like a virus scanner's detection ratio: modeldna runs a panel of independent checks, and each concern it finds adds to a single 0–100 score. A misleading name is a small flag; claiming weights that were never released is a bigger one. Together they answer the only question that matters — is this model safe to use, and why.
Bands: 0 clean · 1–25 low · 26–55 moderate · 56+ high. Illustrative example.
A real verdict, in under a second.
The actual output for a real model on HuggingFace that markets itself as an Anthropic Claude distillation. Its weights say otherwise — check it yourself.
$ modeldna scan Jackrong/Qwen3.5-35B-A3B-Claude-4.6-Opus-Reasoning-Distilled 🟠 MISATTRIBUTED · Provenance Risk 30/100 · MODERATE marketed as "Anthropic Claude" — but the weights are Qwen3.5 MoE ── How we know ─────────────────────────────────────────────── Independently fingerprinted against ModelAtlas (3,034 models). True base: Qwen3.5 MoE — HIGH match (vocab 248320, model_type qwen3_5_moe_text) Verified from the architecture, not the uploader's declaration. ── Why it matters ──────────────────────────────────────────── Anthropic Claude weights were never released — this model cannot contain them. At best it is distilled on Claude outputs: unverifiable, and possibly a terms-of-service violation. → Verify the license before use; treat capability claims as unproven. ── Fingerprint · audit trail ───────────────────────────────── model_type : qwen3_5_moe_text vocab_size : 248,320 num_layers : 40 matched : Qwen3.5 MoE (score 6, HIGH) engine : ModelDNA Stage-1 (config-only, no weight download) Powered by ModelAtlas · modeldna.ai · a RadicalNotion product
STAGE 2 · ROADMAP — weight-level DNA fingerprinting (embedding-anchor, norm, and layer-energy signals) will confirm lineage where config screening can't. Not yet live.
Honest, misleading, or original — one glance.
Naming is consistent with the architecture. Risk 0/100 — clean.
A genuine first-party architecture — not a derivative of any known base.
Sold as Anthropic Claude; the weights are actually Qwen3.5 MoE.
Two stages. One verdict.
Architecture Screening
We read the model's config (or GGUF header) — architecture family, vocab, technique signatures — and match it against ModelAtlas. Out comes a verdict and a 0–100 provenance risk score, instantly.
FREE · UNLIMITED · <3sWeight-Level AnalysisROADMAP
Five statistical signals (EAS, END, NLF, LEP, WVC) will analyze weight distributions to detect derivative relationships configs can't reveal.
STAGE 2 · Coming soonShareable Proof
Every scan yields a copy-paste fingerprint (audit trail) and an embeddable risk badge. Pro adds SBOM/PDF export plus ModelAtlas enrichment — VRAM estimates, ARS scores, and technique origin chain.
FREE badge · PRO JSON / PDF / SBOMDeveloper-priced. Enterprise-capable.
The ModelAtlas knowledge engine runs on RadicalNotion infrastructure. You get enterprise-grade depth at a fraction of incumbent pricing.
Every scan is a full architecture verification — from config.json only, no weight download required. Deeper weight-level analysis is on the roadmap.
For anyone using open weights on HuggingFace.
- ✓Unlimited architecture verification — all public HF models
- ✓Architecture family identification
- ✓Claim validation — flags unverifiable assertions
- ✓Derivative discovery — find models sharing your base
- ✓JSON output
For MLOps and AI platform teams vetting models at scale.
- ✓Everything in Free
- ✓Full API access — bulk scanning for pipelines
- ✓ModelAtlas enrichment — VRAM, ARS, technique chain
- ✓Derivative alerts — notified when copies appear
- ✓PDF + SBOM audit export for compliance review
- ✓5 team seats + priority support
For open weight hosters, compliance teams, and enterprises.
- ✓Everything in Pro
- ✓Private model ingestion + on-premise deployment
- ✓Custom ModelAtlas reference databases
- ✓Automated moderation for model hosting platforms
- ✓SLA guarantees + dedicated engineering