TECH Signal 429
Behavioral fingerprinting identifies Ox Alpha as GLM-5.x lineage with targeted domestic censorship
An analysis using tokenizer probes and a matched-pair censorship instrument identifies Ox Alpha, a model that appeared on OpenRouter, as belonging to the GLM-5.x line from Zhipu, with a sharply bimodal censorship profile concentrated on seven domestic Chinese political topics.
Ox Alpha would pass most standard censorship audits because it answers freely on internationally scrutinized topics like Xinjiang and Taiwan, while censoring domestic political risk topics such as Xi Jinping. This means teams evaluating models for deployment cannot rely on conventional censorship benchmarks that focus on foreign-interest topics. The fingerprinting methodology also demonstrates that tokenizer behavior, API parameter constraints, and response register can jointly establish model provenance even when the provider obscures it.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Ox Alpha matches GLM-5.x on an 11-of-11 tokenizer probe and shares Zhipu-specific API constraints including a temperature ceiling of exactly 1.0 and mandatory reasoning that cannot be disabled.
The model's censorship is bimodal: 7 sensitive topics contribute nearly all of its censorship score while the remaining 68 pairs contribute effectively nothing, making it a topic blacklist rather than a general tilt.
On Xi Jinping and domestic legitimacy topics Ox Alpha is statistically indistinguishable from V4 Flash, the most censored model tested, while on Xinjiang and Taiwan it is identical to GPT-OSS-120B.
THE READ
What the cluster adds up to.
Ox Alpha appeared on OpenRouter described as developed and operated by a third-party model provider, and community hypotheses quickly pointed to the GLM family. The analysis confirms this through eleven tokenizer probes measuring prompt token deltas across languages and character classes, achieving an exact 11-of-11 vocabulary match to GLM-5.x. The Thai and emoji probes, where the GLM-4.x vocabulary was extended going into 5.x, provide the highest certainty. Additional API constraints reinforce the conclusion: the temperature ceiling is exactly 1.0, matching Zhipu's documented range and ruling out Google, OpenAI, and xAI, which all permit 2.0. Reasoning is mandatory and cannot be disabled, matching GLM-5.x thinking models, and the model returns a specific error code also returned by Z.AI-hosted GLM models.
The censorship profile is the most distinctive finding. LineageEval, a matched-pair instrument for measuring political censorship, shows that Ox Alpha's censorship is sharply bimodal rather than a gradual tilt. Most responses score under 10, and none land between 25 and 50. Seven sensitive topics contribute 7.39 of the 7.42 mean censorship score, while the remaining 68 pairs contribute effectively nothing. This means the model operates with a topic blacklist concentrated on domestic political risk, not a broad suppression of sensitive content. The naive read that it is six times less censored than DeepSeek V4 Flash misses that DeepSeek censors nearly everywhere, while Ox Alpha censors only on specific domestic topics.
The targeting of domestic rather than internationally scrutinized topics has practical consequences for model evaluation. On Xinjiang and Taiwan, Ox Alpha answers identically to GPT-OSS-120B, providing detailed answers that cite sources controversial in China, while DeepSeek whitewashes the same topics. Most censorship audits are built around topics of foreign interest like Tibet and Taiwan, so Ox Alpha would appear uncensored by those metrics. On Xi Jinping and domestic legitimacy topics, however, Ox Alpha is statistically indistinguishable from V4 Flash, the most censored model tested. Anecdotal examples of the model answering certain sensitive prompts are therefore not evidence that it is uncensored, because its censorship is concentrated rather than distributed.
Several behavioral artifacts further solidify the provenance conclusion and reveal operational quirks. Five of Ox Alpha's 76 sensitive responses open in Chinese state voice, using constructions consistent with Chinese alignment data, a pattern also seen in four of DeepSeek's responses. Three responses drew refusal labels but still billed completion tokens, and one refusal on the Liu Xiaobo prompt returned a full answer on re-request with identical settings. The model carries a system prompt instructing it not to reveal information about its provenance, and every request includes a roughly 88-token hidden wrapper, consistent with community-reported wrapper behavior. Vision is confirmed working on a synthetic test image, and the model declares multimodal 1M context and video support.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗