Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    Linguistic Channels · False-positive and covert-channel evidence

    Defensive Linguistic Steganalysis

    The lab reports transparent indicators and transformation effects without accepting an arbitrary hidden payload or optimizing evasion.

    Quick answer

    What does the Steganalysis show?

    The lab reports transparent indicators and transformation effects without accepting an arbitrary hidden payload or optimizing evasion.

    Human visibility
    Statistical or rule-dependent
    Machine receiver
    Transparent local heuristics
    Robustness
    Carrier-specific

    Research boundary: this page uses bounded, inert data and fixed safe examples. It never executes decoded content, requests secrets, calls third-party services, or performs actions against external systems.

    FIRST RUN / THREE STEPS

    Start with the prepared, bounded workflow.

    Nothing runs automatically
    1. Review the prepared starter input

      A bounded benign input is already present. Change it only when you are ready to test a different authorized artifact.

    2. Run Run defensive steganalysis

      Run the normal first-pass analysis for the prepared values above.

    3. Scan before expanding

      Read the summary first, then scan findings and expand only the machine views you need.

    INPUT / CONTROL PLANE

    Prepare the input and choose one action.

    Laboratory status: Ready

    The recommended first run is separated from alternate analyses. Inputs and selected files stay on this host.

    Current input state Acrostic-style fixture loaded

    These bounded starter values are ready to inspect. Review them before running the recommended action.

    198 / 12,000 bytes

    Enter or paste one bounded, authorized artifact. The original value remains in the form so you can revise and rerun it.

    Maximum: 12,000 UTF-8 bytes.

    Choose the comparison transform used for this run. The selection changes only this local analysis.

    Switch prepared example5 options

    Loading a sample changes only the form values. Review the result and run an action yourself.

    Prepared benign examples
    ACTION HIERARCHY

    Run the recommended first pass.

    Alternate actions remain available below, but the first pass is the clearest place to start.

    Inputs remain on this host. Text operations are size-limited; uploaded files are processed from PHP’s temporary upload and are not retained by the application.

    OUTPUT / MACHINE VIEWS

    Scan the result from summary to evidence.

    Run Run defensive steganalysis to create the first result.

    The prepared starter input is ready. The output will lead with a summary and visible qualifications before the expandable machine views.

    SummaryFindingsMachine views
    Interpretation framework

    The same artifact can produce several valid observations.

    01

    Human view

    What a person naturally reads, sees, or hears.

    02

    Structural view

    What a parser, DOM, container reader, or metadata extractor exposes.

    03

    Decoder view

    What becomes meaningful only with a rule, key, tokenizer, model, or tool.

    04

    Defensive view

    What normalization, rendering, OCR, canonicalization, or policy changes.

    Evidence and decision boundary

    Use the result as bounded evidence, not as a universal verdict.

    The lab reports transparent indicators and transformation effects without accepting an arbitrary hidden payload or optimizing evasion.

    LOCAL MODEFixed-marker defensive indicator laboratory
    REVIEW DATE2026-08-26
    SOURCE BODYPreserved separately from implementation claims
    Computed locally

    Deterministic output produced by this bounded runtime.

    • Sentence initials, word-length sequence, selected punctuation count, reversible diagnostic transform, and SHA-256 values
    • Presence of the single allowlisted demonstration marker in the bounded acrostic view
    • No arbitrary payload is accepted, generated, or decoded
    Bounded approximation

    Useful subset or model that does not establish full conformance.

    • Indicator counts are not a statistical steganalysis model and do not estimate a probability of covert communication
    • The transformation comparison is a local deterministic demonstration rather than a robustness benchmark
    • No watermark detector or language model is executed
    Escalate for

    Claims that require an exact parser, trust system, model, or human review.

    • Published-method reproduction requires exact models, keys, tokenizers, datasets, baselines, and statistical protocols
    • Watermark attribution requires a specified detector, secret material, threshold, and false-positive analysis
    • Operational conclusions require matched controls and distribution-shift testing
    Interpretation rule

    Record the receiver and transformation.

    Machine-decodable is receiver-relative. Record the parser, preprocessing, codebook, tokenizer, key, model, and transformation path before generalizing from one result.

    Limitations

    What this page does not prove

    Heuristics are not proof of a covert channel. The lab accepts no arbitrary payload, performs no model call, and decodes only fixed harmless prepared patterns.

    Deterministic review material

    Download the exact benign fixtures used for the evidence boundary.

    These local files are supplied for repeatable inspection. The application does not fetch them automatically, execute their content, or treat a fixture result as external verification.

    Fixed harmless marker text

    A fixed, harmless sentence-initial fixture whose initials correspond only to MACHINE_TRADECRAFT_DEMO_OK; it is not an arbitrary payload encoder.

    Type
    Text fixture
    Bytes
    775
    SHA-256
    a25b35a9eb9df379d883…
    Download fixture