# NULLRADIAL S4 bounded digital screen

> **Failure boundary:** No candidate made a person undetected by both models. This internal digital pilot does not verify “AI cannot see it.”

Evidence type: registered-master, control-relative software evidence on synthetic still scenes—not certification, physical validation, or a universal model claim.

## Frozen identifiers

- Protocol fingerprint: `217e48da5510a3bf347497e4c7d46a1ec9188f66216f64dd5e9a0fde323bd19a`.
- YOLOv10n ONNX SHA-256: `a77dd863933f184a19e84361c64b788228a7c7dacc2c78939239a96ad3efca3b`.
- Quantized DETR-ResNet-50 ONNX SHA-256: `cae09a307ed9247da7e2ce8bcf81522a6817f1ea2e82b9c4dde59f5964b62b4f`.
- Scene `synthetic-editorial-single` SHA-256: `9f17f729a094a277a64f57098a7da1676b97b3301edb004ae4fb18a189df5201`.
- Scene `synthetic-catalog-pair` SHA-256: `74c0a513024b45d738bf2869f5d3233e948828eded84214b4cdd6198011e348c`.
- Report threshold: `0.25`; person-box match IoU: `0.50`; raw inference floor: `0.001`.
- Candidate/control construction: same source and hard garment mask; candidate uses one fixed relative-scale, phase-reset tile; control permutes every final in-mask RGB tuple without replacement using the frozen per-pair seed.

## What was actually tested

- 12 frozen S3 masters plus 3 normalized, hash-locked S4 registered masters × 2 image-generated person scenes × candidate/exact-permutation pairs.
- 2 real pretrained generic object detectors: YOLOv10n and quantized DETR-ResNet-50.
- 90 paired ground-truth-person/detector units.
- Person recall at confidence `0.25` and IoU `0.50`; score misses are retained as zero.
- Demand, preorder count, and aesthetic preference were excluded from every performance calculation.

## Candidate-minus-control results

Negative confidence Δ means the candidate scored lower than its exact RGB-pixel-permutation control. It is not an invisibility percentage.

| Candidate | Mean conf. Δ | Range across units | Recall candidate | Recall control | Recall Δ | Both model means lower? |
|---|---:|---:|---:|---:|---:|:---:|
| Moire Chrysalis | -0.1463 | -0.8111 to -0.0005 | 0.833 | 1.000 | -0.167 | yes |
| Spectral Moss | -0.1259 | -0.7328 to +0.0033 | 0.833 | 1.000 | -0.167 | no |
| Ornamental Basin | -0.1196 | -0.6884 to -0.0012 | 1.000 | 1.000 | +0.000 | yes |
| Voronoi Cathedral | -0.1187 | -0.6400 to -0.0005 | 1.000 | 1.000 | +0.000 | yes |
| Penrose Canopy | -0.1058 | -0.6229 to +0.0065 | 1.000 | 1.000 | +0.000 | yes |
| Interference Bloom | -0.0512 | -0.2736 to -0.0008 | 1.000 | 1.000 | +0.000 | yes |
| L-System Brocade | -0.0439 | -0.1608 to +0.0009 | 1.000 | 1.000 | +0.000 | no |
| Broken Halo II | -0.0338 | -0.1754 to +0.0005 | 1.000 | 1.000 | +0.000 | no |
| Mandelbrot Garden | -0.0294 | -0.1671 to -0.0003 | 1.000 | 1.000 | +0.000 | yes |
| Strange Attractor Velvet | -0.0176 | -0.0845 to -0.0003 | 1.000 | 1.000 | +0.000 | yes |
| Prism Mycelium | -0.0164 | -0.0537 to -0.0016 | 1.000 | 1.000 | +0.000 | yes |
| Multiscale Occlusion Bloom | -0.0137 | -0.0583 to -0.0018 | 1.000 | 1.000 | +0.000 | yes |
| Reaction Diffusion Noir | -0.0135 | -0.0471 to -0.0014 | 1.000 | 1.000 | +0.000 | yes |
| Anisotropic Quasicrystal Veil | -0.0122 | -0.0491 to -0.0002 | 1.000 | 1.000 | +0.000 | yes |
| Recursive Caustic Lattice | -0.0042 | -0.0094 to -0.0005 | 1.000 | 1.000 | +0.000 | yes |

## Hard conclusion

This run can falsify overbroad marketing language but cannot verify ‘AI cannot see it.’ It measures only small, condition-specific candidate/control score changes on two synthetic stills and two detector builds.

No candidate made a person undetected by both models. DETR detected 45/45 candidate person units (scores 0.993–1.000); YOLO detected 43/45. The two YOLO threshold misses were Moire Chrysalis and Spectral Moss on the same single synthetic editorial scene, and neither miss replicated in the second scene.

No candidate is qualified by this run. A lower mean in this tiny digital pilot is a hypothesis for a preregistered, held-out follow-up—not a product claim.

## Failure cases retained

- 6 of 90 person-detector units had higher candidate confidence than the matched control.
- 3 of 15 candidates had detector-family direction disagreement: Spectral Moss, L-System Brocade, Broken Halo II.
- Only 2 of 90 units changed thresholded recall; most pairs therefore do not support a threshold-crossing effect.
- The exact-pixel control destroys spatial shading organization as well as texture organization, so a candidate-control difference cannot be attributed to fractal, radial, ornate, or other named geometry alone.
- Only one locked pixel-permutation draw was used per candidate/scene pair; control-seed variability was not estimated.
- Every candidate was evaluated at one tiled scale and one phase-reset seam state; apparent performance may reverse with range, print scale, folds, camera ISP, or construction seams.

## Exact-control verification

All 30 candidate/control pairs preserve the exact in-mask RGB tuple multiset: **True**. Maximum histogram L1: `0`.

## What blocks a defensible ‘AI cannot see it’ claim

- No physical garment, calibrated camera, measured range, pose sequence, fold state, illumination grid, or print/color-gamut verification.
- Only two detector families; the frozen S3 protocol requires at least six builds across at least three architecture families for a serious digital screen.
- Only two synthetic scenes and three one-annotator boxes; no independent licensed/consented camera corpus, blinded annotation, adjudication, screen holdout, or sealed confirmation set.
- No independently calibrated model thresholds, confidence intervals with a credible number of scene clusters, multiplicity control, or out-of-distribution transfer test.
- No accredited laboratory method or recognized product-certification scheme can convert this digital pilot into universal AI-invisibility certification.

## Next minimum defensible experiment

- Freeze a consented or fully synthetic multi-scene corpus before inference, with independent double annotation and blinded adjudication.
- Use at least six pinned detector builds across one-stage, region-proposal, and transformer families; fix thresholds on a disjoint clean calibration set.
- Evaluate exact-pixel, spectral, layout-ablation, and neutral controls across preregistered scales, seams, camera/ISP profiles, pose, range, folds, motion, occlusion, lighting, and compression.
- Hold out scene identities and backgrounds; keep one confirmation partition sealed until the candidate shortlist and analysis code hashes are registered.
- Then manufacture color-managed swatches/garments and commission a competent independent lab to execute the physical protocol; publish failures and per-condition bounds rather than a universal claim.

See `protocol.freeze.json`, `metrics.csv`, `report.json`, and `artifact-manifest.json` for exact inputs, hashes, conditions, raw paired rows, and limitations.
