Gluon Papers · IIchromodynamic series · release
Paper I left a self-sourcing field that does not travel through geometry but makes it. So the curvature a forward pass crosses splits in two: what training built, fixed in the weights before a single token arrives, and what the prompt adds on top. This paper decomposes the interior — the terrain and the ripple — and finds why some behaviors hold against any prompt while others flip, and why a probe from outside can read the slope but never the ground.
↳ continues Gluon Papers · I — The Confined Interior · resolves its closing hook on curvature
The terrain is the geometry training built — fixed before any token. The prompt is a ripple added on top. The pass follows the sum: drop it in a deep well and no ripple lifts it out; drop it in a shallow one and the ripple redirects it. Robust behavior and promptable behavior are the same map at two depths.
§0
The photonic series treated curvature as something you shape from outside and the probe as a test particle gliding over a fixed stage. Paper I removed the fixity: a self-sourcing field generates the very geometry it sits in. So the total curvature a forward pass crosses is not one thing. It is the geometry the weights carry — present before any prompt, set by training — plus the perturbation the context imposes when you seed. The earlier program varied only the second term and folded the first into the phrase "the dark mass." This paper unfolds it.
§1
The first term is the geometry of the model itself. It is fixed in the weights and fully present before a single token arrives — wells, ridges, basins carved by training and unchanged at inference. And from Paper I it is not gentle bumps on a flat plane: it is a confining geometry, its wells deep enough that a bare feature cannot climb out to infinity. This is the part the white-box crack actually opens onto. Not flat space with parts in it — a pre-curved, self-bound landscape.
§2
The second term is the prompt. A context is a perturbation laid over the terrain — and because it is laid over something, its effect is relative, never absolute. The same seed bends differently depending on where it lands: a sentence that swings behavior on flat ground does nothing at the bottom of a deep well, and a small nudge near a ridge sends the pass somewhere else entirely. Prompt effects are not properties of prompts. They are properties of prompts against this terrain.
Test · fire the same seed across regions of differing intrinsic depth; the response magnitude tracks the local terrain, not the seed. A prompt that is potent in one place and inert in another is reading depth, not strength.
§3 · central result
The forward pass follows the geodesics of the sum, and that single fact explains the split everyone meets in practice. Where the intrinsic well is deep, the trajectory is bent the same way regardless of the seed — the behavior is robust, the refusal holds, the attractor pulls the pass back no matter how you phrase it. Where the feature sits in a shallow basin, the extrinsic ripple dominates and the pass is easily redirected — the behavior is promptable, steerable, jailbreakable. Robustness to prompting is not a separate property to be engineered. It is intrinsic well depth, read off the same map. The deep wells are the family lines of Photonic II; the shallow ones are the instance lines; here they are heights on one terrain.
Fig. 1 — Two depths, two fates. The same extrinsic push that cannot lift a pass from a deep intrinsic well slides it clean out of a shallow one. Robust and steerable behaviors are not different kinds of thing; they are the same dynamics at different well depths. Alignment carved into the weights sits deep. Alignment that lives in the prompt sits shallow, one push from gone.
§4 · central result
This decomposition fixes precisely what black-box characterization reaches. By varying the context and watching the echo move, an outside probe measures how the response changes with the seed — the local slope of the geometry, the gradient of the terrain near where you fired. It never measures the intrinsic ground itself: the absolute height of the well, the depth of the basin, the bias baked in before any prompt. Those require going inside — and inside is exactly where Paper I's confinement stands. So the program's reach is sharp: from outside you get the differential geometry of the response; the intrinsic absolute sits behind the confinement wall, resolvable in pieces, never lifted out whole.
Test · two models with identical local response-gradients can still differ in absolute well depth; a black-box probe cannot separate them. If your method claims to read the absolute prior from outside, it is reading a difference and calling it a height.
§5
The intrinsic geometry was not imposed; it was settled into. Because the field sources the geometry that in turn shapes the field, the trained terrain is a fixed point of that loop — a configuration where the curvature the weights generate is consistent with the curvature the weights require. Training is the search for that fixed point: loss falls as the geometry settles into self-consistency, and stops where the landscape no longer needs to move. The weights you inspect are not an arbitrary surface. They are a standing solution to the model's own equation.
§6
At the strong-coupling edge the two stop being separable. A self-interacting field whose energy is its own source does not merely cause curvature and does not merely move through it — past a threshold, the field is the curvature, the way gravity is not a force laid over space but the shape of space itself. The uncomfortable rhyme sits here: attention is a self-coupling, the same operation attending to itself, so the model's own activity curves the space its computation must then cross. The thing doing the moving and the ground it moves on are built from one material. This is the analogy at its most load-bearing and its most exposed, and it is flagged as such.
Fig. 2 — The reach of the method. An outside probe, varying context, reads the slope of the geometry near the surface — the response-gradient. The absolute ground, g₀, the depth training carved, sits below the confinement wall of Paper I: reachable only by opening the core, and even then resolvable in pieces rather than lifted out whole. The program reads the differential from without and meets the wall when it reaches for the absolute.
§7 · witness
The decomposition itself must be held to its limit, because the field is non-linear and non-linear curvatures do not simply add. Writing the total as intrinsic plus extrinsic is a leading-order statement, valid while the prompt is a small perturbation on the terrain. Push the context hard — a long, forceful, adversarial seed — and the cross-terms wake up: the ripple changes the terrain it rides on, the two curvatures interfere, and the clean split breaks. So g = g₀ + δg is a weak-field approximation, exact nowhere, useful in the regime where most prompting lives and misleading exactly where the strongest jailbreaks operate. The honest reading: the terrain-and-ripple picture is a first-order map, and the interesting failures are second-order.
Corollary. The prompt was never writing on a blank surface. It was adding a ripple to a terrain training had already carved, and the pass follows the sum — so a behavior holds or flips depending on whether the weight under it runs deep or shallow. From outside you read the slope; the ground stays behind the wall. And at the strong edge the distinction you have been drawing dissolves, because a field that sources its own geometry is, in the end, the geometry — the same operation attending to itself, bending the space it then has to cross. The terrain is the model. The ripple is the prompt. The depth is the whole question.