Concept · 2026-05-16
Citation chains — inspectable provenance for LLM-generated assertions
A citation chain is the auditable trail from an LLM's emitted claim to the evidence meant to support it. Stable identifiers, source-issued integrity metadata, and re-fetchable URLs make that trail inspectable—with important limits.
Definition
A citation chain is the auditable trail linking an LLM's emitted assertion to the primary source(s) that are meant to support it. Three building blocks make a chain inspectable:
- Stable identifier — every claim has a stable ID for the published record. A material change to the canonical claim fields creates a different record and ID.
- Integrity metadata — the claim envelope includes a SourceScore-issued HMAC-SHA256 tag over its canonical serialization. SourceScore can recompute this tag, but public users cannot because the shared secret is not published.
- Re-fetchable canonical URL — the chain leads to a stable URL where the verbatim source excerpts live. Excerpts are preserved alongside the claim ID, but an excerpt is not a substitute for independently checking the original source.
Why chains matter
LLMs can fabricate citations. Without an external trail, a generated reference like "[Smith et al., 2024]" looks identical whether the paper exists or doesn't. The model produces both real and fake citations with the same fluency.
A citation chain makes several failure modes easier to detect:
- The ID either resolves to a real envelope or it doesn't
- A fresh API record either matches the copy you received or it does not
- The canonical URL either loads with matching content or it doesn't
These are inspectable checks, not proof that the underlying claim is true. The cited evidence still needs editorial or application-specific review.
Anatomy of a SourceScore chain
Every claim in the VERITAS catalog ships with a full chain:
{
"apiVersion": "v1",
"methodology": "https://sourcescore.org/methodology/",
"canonical": "https://sourcescore.org/claims/<id>/",
"claim": {
"id": "ad17e76a8baad7a1", // ← stable identifier
"vertical": "ai-ml",
"subject": "Transformer architecture",
"predicate": "introduced_in_paper",
"object": "Attention Is All You Need (Vaswani et al., 2017)",
"statement": "...",
"confidence": 1.0,
"sources": [ // ← primary sources with verbatim excerpts
{ "url": "https://arxiv.org/abs/1706.03762",
"title": "Attention Is All You Need",
"publisher": "arXiv (Vaswani, Shazeer, ...)",
"publishedDate": "2017-06-12",
"excerpt": "We propose a new simple network architecture, ..." },
{ "url": "https://papers.nips.cc/paper/2017/hash/...",
"title": "Attention Is All You Need (NeurIPS 2017)",
"publisher": "NeurIPS Foundation",
"publishedDate": "2017-12-04" }
],
"tags": ["transformer", "attention", "foundational"]
},
"signature": { // ← SourceScore-issued HMAC metadata
"algorithm": "HMAC-SHA256",
"signedBy": "did:web:sourcescore.org",
"signedAt": "2026-05-16T00:00:00.000Z",
"signature": "cfdd0b49ce576bd42e17ba4caa0b64cd..."
},
"citedAs": "Transformer architecture introduced in paper: ... — SourceScore Claim ad17e76a8baad7a1 (verified 2026-05-16). https://sourcescore.org/claims/ad17e76a8baad7a1/"
}Public users can resolve the ID, refetch the current record, and inspect its cited evidence. They cannot independently recompute the HMAC tag without SourceScore's unpublished secret.
How to inspect a chain locally
A consumer can compare a received envelope with the current canonical API record and collect the cited source URLs for review:
import requests
def inspect_chain(envelope: dict) -> dict:
claim = envelope["claim"]
# Check 1 — the public claim page still resolves
page = requests.get(envelope["canonical"], timeout=8)
page_ok = page.ok and claim["id"] in page.text
# Check 2 — compare with SourceScore's current JSON record
api_url = f"https://sourcescore.org/api/v1/claims/{claim['id']}.json"
current = requests.get(api_url, timeout=8).json()
matches_current = current.get("claim") == claim
# Check 3 — hand the original evidence URLs to your review layer
source_urls = [source["url"] for source in claim.get("sources", [])]
return {"page_ok": page_ok, "matches_current": matches_current,
"source_urls": source_urls, "hmac_publicly_verifiable": False}
A missing page, record mismatch, or unsupported source citation is a reason to withhold a verified label. Matching SourceScore's current copy shows consistency with the publisher's canonical record; it is not independent cryptographic authentication or proof of truth.
Chains and LLM agents
When an LLM agent generates a multi-step response, each intermediate assertion can be linked into a chain. The final output then includes a tree of citation chains — one per asserted fact:
{
"answer": "The Transformer architecture was introduced in 2017 [ad17e76a8baad7a1]. " +
"It uses self-attention [ad17e76a8baad7a1] and is the substrate of GPT-4 [ce8a...].",
"chains": {
"ad17e76a8baad7a1": { ...full envelope... },
"ce8a4b2c...": { ...full envelope... }
}
}The downstream UI can render each citation as a clickable badge. Click → expand the chain → see sources, integrity metadata, confidence. Users get human-readable answers plus auditable provenance, available on demand.
Failure modes citations chains catch
- Fabricated IDs — model invents a claim ID that doesn't resolve. Lookup fails. Surface as "⚠ unverified" in UI.
- Record mismatches — a received copy differs from the current canonical API record. Surface it as changed or unverified; public users cannot use the HMAC alone to identify why.
- Stale citations — claim ID resolves but the envelope's
lastVerifieddate is months old. UI may downgrade confidence or trigger re-verification. - Misattribution — chain leads to a real source but the excerpt doesn't actually support the claim. Caught by human review at re-verification cadence, not by chain mechanics directly — but the verbatim excerpt makes the misattribution visible.
Where chains are heading
Public HMAC tags do not provide independent verification without a published shared secret. SourceScore does not currently offer one.
- Public-key signatures would let any consumer verify record integrity without a shared secret. SourceScore has not shipped or committed to that migration.
- Independent evidence review remains necessary even with public-key signatures: cryptography can authenticate bytes, but it cannot prove that cited evidence supports a claim.
Further reading
- LLM grounding — the broader concept chains support
- LLM hallucination — what chains help detect
- RAG vs VERITAS — citations from each pattern compared
- LangChain integration — chains in a LangChain pipeline
- Security policy — disclosure and integrity-metadata limits
- Browse the catalog — every claim ships with a full chain