🛠️ Current status: Stage 4 | Viability boundaries and protocol hardening · Updated 24 August 2026
Research overview

Rather than presenting only the final result, this section documents how the idea has evolved through experimentation: what we tried, what worked, what failed, what changed, and what each stage taught us.

The work is organised into stages. Each stage begins with a specific research question and ends when we have enough evidence to either advance the approach, change direction, or define a limitation.

How the research works

Development is organised through numbered checkpoints.

A checkpoint usually isolates one question:

Question
    ↓
Experiment or analysis
    ↓
Evidence
    ↓
Decision
    ↓
Next checkpoint

Some checkpoints involve training or evaluation. Others freeze datasets, define protocol behaviour, audit earlier results, document failed approaches, or establish the rules for later experiments. Training, calibration, validation and external evaluation are deliberately separated where possible. Once an untouched evaluation set has been used, we do not continue tuning against it. The individual checkpoints form the detailed research record. These pages instead compile them into the larger story of each stage.


Timeline

StageResearch questionOutcome
1Can a subtle pixel-level signal be embedded and detected blindly after ordinary image processing?Complete
2Does useful protection evidence survive locally when the original image geometry is disrupted?Complete
3Can the system become locally self-sufficient and support defensible PROTECTED, NOT_PROTECTED and INDETERMINATE decisions?Complete
4Does the current GAPP design have a practically useful operating region under real-world, lossy and adversarial conditions?Active

Stage 1

Establishing the first blind signal system

CP001–CP043

Stage 1 tested whether the basic idea was technically plausible. The work progressed from simple pixel perturbations to a low-frequency, multi-carrier signal, a content-adaptive encoder and a blind carrier-aware decoder. By the end of the stage, the system could detect protected images across multiple datasets while generally keeping false positives below 1%. JPEG compression and frame-preserving resizing were handled reasonably well. The major failure was cropping and reframing. The signal depended too heavily on the original image coordinate system. Once part of an image was removed or repositioned, detection deteriorated substantially. That failure defined the next research question.

Outcome: the basic blind signalling mechanism was viable, but the representation was too globally dependent.


Stage 2

Finding and aggregating local evidence

CP044–CP088

Stage 2 asked whether the Stage 1 signal still left useful evidence inside smaller regions of an image. The answer was yes. Correctly aligned local regions retained detectable carrier evidence. The harder problem was finding that evidence blindly: searching many possible positions, scales and alignments also created more opportunities for ordinary image content to resemble the signal. The decoder was progressively redesigned around local evidence, shared-null normalisation and learned residual corrections. A five-model median ensemble became the strongest protected detector. On the full 6,149-image Flowers102 test set, protected detection reached 53.73% at 1.29% false positives. On a frozen 500-image Wikimedia Commons population, it reached 71.82% at 0.20% false positives. Stage 2 also introduced the first research version of a three-state decision system.

Outcome: local evidence was real and useful, but the underlying signal itself was still globally defined and the decision thresholds did not transfer reliably enough across every condition.


Stage 3

Local self-sufficiency and protocol definition

CP089–CP172

Stage 3 changed both the technical architecture and the way GAPP defines its decisions. The global carrier was retired from active development and replaced by a structured overlapping local representation. Surviving image regions could contribute evidence without requiring reconstruction of the original complete frame. The stage also formalised the distinction between three detector outcomes:

PROTECTED
NOT_PROTECTED
INDETERMINATE

These are intentionally asymmetric decisions. Failure to establish PROTECTED does not automatically mean NOT_PROTECTED. A dedicated negative-clearance rule was eventually frozen and tested once on an untouched validation set of 192 protected natural-photo copies across Oxford and VOC. The result was:

Protected false NOT_PROTECTED:  0 / 192
Ordinary NOT_PROTECTED:        97 / 192

However, positive detection remained conservative:

Protected → PROTECTED:          43 / 192
Protected → INDETERMINATE:     149 / 192
Protected → NOT_PROTECTED:       0 / 192

Stage 3 also exposed important limitations. Evidence can be attenuated by some processing chains, structured textures behave differently from natural photographs, blind search is computationally expensive, signals can be transplanted, and the current mechanism does not establish who was authorised to apply a restriction.

Outcome: GAPP reached its first validated, profile-scoped tri-state research system, but not a universal or production-ready protocol.


Stage 4

Viability boundaries and protocol hardening

CP173 onward. Currently in progress.

What GAPP currently claims

The research has narrowed the meaning of the signal over time. A base GAPP signal should currently be understood as an unauthenticated, copy-level request that participating generative AI systems do not transform the received copy.

Key note: It DOES NOT by itself establish:
* Ownership.
* Identity.
* Copyright.
* Provenance.
* Authenticity.
* Legal entitlement.
* Whether the person applying the signal was authorised.

Those are separate problems. This distinction is important because the research is intended to describe what the mechanism actually demonstrates, rather than what we would eventually like it to become.


Page structure

Each stage page follows the same structure:

  1. Stage objective: the question being investigated.
  2. Starting point: what the previous stage established.
  3. What we explored: the major research branches.
  4. What we built: changes to the signal, encoder, decoder or protocol.
  5. Key results: the most useful quantitative evidence.
  6. What worked: approaches supported by the evidence.
  7. What did not work: failed or closed research branches.
  8. What we learned: the stage-level conclusions.
  9. Stage outcome: what was frozen, rejected or carried forward.
  10. Checkpoint record: a compact record of the experiments behind the stage.

The detailed checkpoint history remains the underlying research record. These pages are the readable version of that history.