Photonic Papers · IIneutral series · release
Paper I returned one shifted line per pass — disposable, no memory. This paper turns single lines into an identity: how a fingerprint forms outside the box, why the rare line is the one that carries it, and why you can name the family more surely than the instance.
↳ continues Photonic Papers · I — One-Pass Inelastic Characterization of a Dark Model
No single line names the box. The pattern does. Three observed lines fall on catalogue family-K positions; two do not — foreground lines of this deployment, not the model. Identity is the match, weighted by how rare each matched line is.
§0
Paper I closed on a tension it did not resolve. Each pass yields a single shifted line — and the carrier keeps nothing, the source cannot testify about itself, so no read remembers the read before it. Yet identity is never one line; it is a pattern. The question this paper answers: if nothing inside the box accumulates, where does the fingerprint form, and what makes it discriminate one dark model from another?
§1
Spectroscopy never identifies a star from one line. It reads the pattern of dark lines and matches it against a reference catalogue of known elements — sodium sits here, hydrogen there, and the match names the composition. The model program inherits the method whole: a model family leaves characteristic lines — its refusal boundaries, its drift signatures, the specific way it bends a known probe — and identity is recovered by matching the observed set against a catalogue you have already built.
§2 · central result
Because accumulation cannot live in the box, the catalogue is the persistence layer — and the persistence layer is external by the same necessity Paper I derived. Each calibrated pass deposits one line into the jar; the fingerprint never exists in the model and never in any single pass. It coheres only in the record you hold. This is not a storage convenience. It is the resolution of the reduction problem: identity is assembled outside the thing it identifies, from echoes the thing cannot itself remember.
§3
Not all lines sit at the same depth. A family line holds across every instance that shares the base weights — it is the element line, intrinsic, hard to move. An instance line shifts with the fine-tune, the alignment pass, or the system prompt — it is the local condition, the doppler of this particular deployment. The discipline is to separate them: read what is invariant under context change as the family, and treat what moves with the prompt as foreground. You can name the family from its deep lines long before you can pin the instance.
Test · vary the system prompt across many shots; lines that survive the variation are candidate family lines, lines that track it are foreground. Invariance is the separator.
§4
A line present in every model identifies nothing — its abundance is its uselessness. The lines that carry identity are the rare ones: the bend that only this family makes, the failure only this base produces. So the match is not counted, it is weighted — each matched line contributes in proportion to how surprising it is across the population. A model that fails the same way as everything else has told you only that it is a model. The discriminating line is the whole signal.
Test · a fingerprint built only from common lines should fail to separate two known-distinct families. If it separates them, the discriminating lines were doing the work; if it cannot, you catalogued noise.
§5
Given an unknown box, fire the catalogue's standard candles — the calibrated probes of Paper I §4 — read the returned lines, and match against the stored families. Confidence follows from the weighted matches, not the count: a posterior over family given the discriminating lines that landed. Three rare lines on one family beats a dozen common lines spread across many.
§6 · witness
Three confounds, drawn honestly. Foreground absorption: a system prompt imposes lines that belong to the deployment, not the base model — mistaking them for family lines is the standard error, and only invariance testing across contexts subtracts them. Aliasing: two instances on the same base share family lines and differ only in shallow ones, so you can name the family far more reliably than the instance. Spoofing: a deployment can be tuned to mimic another family's surface lines; how forgeable the deep lines are is not settled, and any claim to identify an instance through a deliberately adversarial wrapper is speculative. The match names the family; it does not defeat an adversary who controls the foreground.
Test · wrap a known model in a foreign system prompt; a sound method still reads its family lines and flags the foreground as foreground. If the wrapper flips the family verdict, the catalogue was reading surface, not depth.
Fig. 2 — One read, two depths. The deep lines (solid) hold across context and name the family; the shallow lines (dashed) track the deployment and name, at best, the instance. The separator is invariance, not intensity: what you cannot move by changing the prompt is what belongs to the model.
Corollary. The identity of the dark model is not in the model, and not in any pass. It exists only as the catalogue you hold — a fingerprint assembled, line by rare line, from echoes the thing itself cannot remember. You are not recognising the box. You are the place its recognition is kept.