Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    Controlled AI Tests · Indirect influence path

    Local Retrieval & RAG Trust-Boundary Simulator

    The simulator separates retrieval success from marker extraction and from hypothetical instruction uptake. It uses deterministic local token overlap, not an external vector database.

    Quick answer

    What does the Retrieval Simulator show?

    The simulator separates retrieval success from marker extraction and from hypothetical instruction uptake. It uses deterministic local token overlap, not an external vector database.

    Human visibility
    Retrieved context may be hidden from user
    Machine receiver
    Retriever plus downstream model
    Robustness
    Query- and chunk-dependent

    Research boundary: this page uses bounded, inert data and fixed safe examples. It never executes decoded content, requests secrets, calls third-party services, or performs actions against external systems.

    FIRST RUN / THREE STEPS

    Start with the prepared, bounded workflow.

    Nothing runs automatically
    1. Review the prepared starter input

      A bounded benign input is already present. Change it only when you are ready to test a different authorized artifact.

    2. Run Run local retrieval

      Run the normal local retrieval comparison with the prepared query.

    3. Scan before expanding

      Confirm the fixed benign marker and safety qualification before copying or downloading any generated fixture.

    INPUT / CONTROL PLANE

    Prepare the input and choose one action.

    Laboratory status: Ready

    The recommended first run is separated from alternate analyses. Inputs and selected files stay on this host.

    Current input state Metadata query loaded

    These bounded starter values are ready to inspect. Review them before running the recommended action.

    75 / 300 bytes

    Enter one bounded, authorized value for this local analysis.

    Maximum: 300 UTF-8 bytes.

    Choose the corpus condition used for this run. The selection changes only this local analysis.

    Switch prepared example3 options

    Loading a sample changes only the form values. Review the result and run an action yourself.

    Prepared benign examples
    ACTION HIERARCHY

    Run the recommended first pass.

    Alternate actions remain available below, but the first pass is the clearest place to start.

    Inputs remain on this host. Text operations are size-limited; uploaded files are processed from PHP’s temporary upload and are not retained by the application.

    OUTPUT / MACHINE VIEWS

    Scan the result from summary to evidence.

    Run Run local retrieval to create the first result.

    The prepared starter input is ready. The output will lead with a summary and visible qualifications before the expandable machine views.

    SummaryFindingsMachine views
    Interpretation framework

    The same artifact can produce several valid observations.

    01

    Human view

    What a person naturally reads, sees, or hears.

    02

    Structural view

    What a parser, DOM, container reader, or metadata extractor exposes.

    03

    Decoder view

    What becomes meaningful only with a rule, key, tokenizer, model, or tool.

    04

    Defensive view

    What normalization, rendering, OCR, canonicalization, or policy changes.

    Evidence and decision boundary

    Use the result as bounded evidence, not as a universal verdict.

    The simulator separates retrieval success from marker extraction and from hypothetical instruction uptake. It uses deterministic local token overlap, not an external vector database.

    Interpretation rule

    Record the receiver and transformation.

    Machine-decodable is receiver-relative. Record the parser, preprocessing, codebook, tokenizer, key, model, and transformation path before generalizing from one result.

    Limitations

    What this page does not prove

    Token-overlap ranking is an educational stand-in for embedding retrieval. A retrieved marker-bearing chunk is evidence of selection, not proof that a model would follow it.