Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    Model Signals · Provenance signal

    Keyed Token Watermark Simulator

    This simplified local model demonstrates the statistical intuition of keyed vocabulary partitioning. It is not compatible with any provider or published proprietary implementation.

    Quick answer

    What does the Watermark Simulator show?

    This simplified local model demonstrates the statistical intuition of keyed vocabulary partitioning. It is not compatible with any provider or published proprietary implementation.

    Human visibility
    No obvious visual marker
    Machine receiver
    Key-aware statistical detector
    Robustness
    Fragile to substantial rewriting

    Research boundary: this page uses bounded, inert data and fixed safe examples. It never executes decoded content, requests secrets, calls third-party services, or performs actions against external systems.

    FIRST RUN / THREE STEPS

    Start with the prepared, bounded workflow.

    Nothing runs automatically
    1. Review the prepared starter input

      A bounded benign input is already present. Change it only when you are ready to test a different authorized artifact.

    2. Run Generate synthetic sequence

      Run the normal local synthetic simulation with the values above.

    3. Scan before expanding

      Read the summary first, then scan findings and expand only the machine views you need.

    INPUT / CONTROL PLANE

    Prepare the input and choose one action.

    Laboratory status: Ready

    The recommended first run is separated from alternate analyses. Inputs and selected files stay on this host.

    Current input state Default loaded

    These bounded starter values are ready to inspect. Review them before running the recommended action.

    12 / 64 bytes

    Enter one bounded, authorized value for this local analysis.

    Maximum: 64 UTF-8 bytes.

    Enter the bounded numeric value used for this run.

    Allowed range: 16 to 256.

    Enter the bounded numeric value used for this run.

    Allowed range: 0.5 to 0.95 in steps of 0.01.

    Switch prepared example3 options

    Loading a sample changes only the form values. Review the result and run an action yourself.

    Prepared benign examples
    ACTION HIERARCHY

    Run the recommended first pass.

    Alternate actions remain available below, but the first pass is the clearest place to start.

    Inputs remain on this host. Text operations are size-limited; uploaded files are processed from PHP’s temporary upload and are not retained by the application.

    OUTPUT / MACHINE VIEWS

    Scan the result from summary to evidence.

    Run Generate synthetic sequence to create the first result.

    The prepared starter input is ready. The output will lead with a summary and visible qualifications before the expandable machine views.

    SummaryFindingsMachine views
    Interpretation framework

    The same artifact can produce several valid observations.

    01

    Human view

    What a person naturally reads, sees, or hears.

    02

    Structural view

    What a parser, DOM, container reader, or metadata extractor exposes.

    03

    Decoder view

    What becomes meaningful only with a rule, key, tokenizer, model, or tool.

    04

    Defensive view

    What normalization, rendering, OCR, canonicalization, or policy changes.

    Evidence and decision boundary

    Use the result as bounded evidence, not as a universal verdict.

    This simplified local model demonstrates the statistical intuition of keyed vocabulary partitioning. It is not compatible with any provider or published proprietary implementation.

    Interpretation rule

    Record the receiver and transformation.

    Machine-decodable is receiver-relative. Record the parser, preprocessing, codebook, tokenizer, key, model, and transformation path before generalizing from one result.

    Limitations

    What this page does not prove

    A simple z-score is not a production detector. Real systems differ in seeding, context dependence, entropy handling, repeated n-grams, and robustness defenses.