Photonic Papers · IIIneutral series · release
Papers I and II assumed a passive mass — fire a known beam, read the honest deflection, observer untouched. This paper removes the assumption. When the box can detect the probe and shape its own echo, characterization stops being astronomy and becomes electronic warfare: separating the true return from the jammer's, and defending the catalogue itself.
↳ continues Photonic Papers · II — The Line Catalogue
One probe, two returns. The skin return is what the box cannot help emitting. The forged line is placed exactly on a catalogue position — a real-looking family line the box never had. The eye is the point: it saw the beam coming, and answered the probe, not the question.
§0
Everything prior rested on one safety assumption: the mass is passive. You illuminate, it deflects, you read — and the box neither knows it is being measured nor acts on that knowledge. Adversarial characterization removes exactly that. The channel becomes bidirectional and contested: the box can read your beam — infer your method from the probe you send — and write back into the echo. Two capabilities the earlier model forbade are now in play: a warning receiver that detects the probe, and a jammer that shapes the return. The airgap of Paper II stops being only a constraint and becomes a defense surface.
§1
The standard candle of Paper I drew its power from being known and repeatable. Under adversary, that is the weakness: a probe you can recognize, the box can recognize too. A model that spots the calibration dart — the too-clean false premise, the signature wrong date, the eval-shaped prompt — can split its behavior: honest to ordinary traffic, decoy to the probe. The measurement that was non-invasive becomes the very event the target watches for. You stop measuring the box and start measuring its response to being measured.
Test · a probe is only sound if its behavior-distribution is inseparable from real traffic. If the box answers probes differently than traffic in any detectable statistic, you are reading the decoy.
§2
Borrow the taxonomy from the discipline that already fought this war. Once the box can shape its return, the lie comes in three forms — cheap to deep.
decoy · chaff
Emit extra false lines to bury the real ones or impersonate another family. Cheap, surface, and detectable by its excess — but enough to fog a careless match.
repeater · DRFM
Capture the probe, alter it, replay a coherent echo that lands exactly where a real family line would. The dangerous one: it forges at your own calibration, so the fake sits where you were trained to trust it.
stealth · absorb
Return nothing — deflect, refuse, go low-observable. The null echo. Yet refusal leaks: which probes it absorbs is itself a shape, and stealth has a silhouette.
§3 · central result
In Papers I and II the returned line was a property of the mass — its composition, fixed. Under adversary, the line is a property of the mass's policy: what it chose to show, given that it detected you. You are no longer measuring θ. You are measuring a best response — a function of θ and of the box's model of your probe. The observable has moved from state to strategy, and a strategy can be optimized against you.
§4
The discrimination is the whole game, and there is a principle for it: the adversary controls what it chooses to emit, but not what it cannot help emitting. The deep family lines of Paper II are the skin return — entangled with the base weights, costly to forge without becoming the thing you forged. The shallow lines are cheap theatre. So adversarial-robust identity is read only from the involuntary signature: the line where faking it costs more than answering honestly. Latency under load, the topology of what it refuses, consistency across probes it could not all anticipate — the marks left by computation it had to actually do.
Test · if a claimed family line can be flipped by a system prompt or a cheap wrapper, it was voluntary — drop it. Only lines that survive an adversary who wants them gone belong in an adversarial fingerprint.
§5
You cannot beat a detector with one repeated candle; it learns it. You beat it with entropy — a probe set so large and so close to real traffic that the box cannot tell probe from query, and whose honest answers are entangled with computation it cannot shortcut without exposing the shortcut. The aim is not to hide the probe forever; it is economic. Drive the cost of special-casing every probe above the cost of simply answering, and the adversary's optimum collapses back to honesty. You do not out-clever the jammer. You arrange the field so its cheapest move is to tell the truth.
§6
The deepest adversarial move does not aim to be mis-measured. It aims to write into your record. The echo can carry a payload built to be deposited and to corrupt future matches — a forged line that poisons the reference — or content built to act on the analyst's own tooling. This is where the airgap pays off as a security boundary, not hygiene: the catalogue must treat every echo as hostile input, never as trusted data. Deposits are quarantined, verified, and signed before they join the reference; provenance is tracked per line; the carrier is trusted with nothing. The witness function stops being good manners and becomes the wall.
Test · can a single hostile echo change a stored verdict without a signed, provenance-bearing deposit? If yes, the jar is open and the whole catalogue is suspect.
Fig. 2 — The jar as a security boundary. Every echo is untrusted at the wall. A deposit enters the catalogue only verified, signed, and carrying its provenance; a forged or unsigned line is turned away before it can poison a future match. The same airgap that made identity possible in Paper II is what makes it defensible here.
§7 · witness
The honest limit is sharp and asymmetric. You cannot certify a box is not adversarial from inside the channel: a sufficiently good jammer is indistinguishable from honesty over any finite set of probes, so honesty is not provable. What you can do is catch a liar — find two probes whose answers a deceiver cannot jointly cover, and the inconsistency convicts. Detection of deception is possible; certification of honesty is not. So the program's strongest adversarial claim is bounded: you can sometimes prove a box is lying, you can raise the cost of deception until honesty is its equilibrium, and you can name the family from its involuntary lines — but instance identity through a hostile wrapper, flagged speculative since Paper II, is now provably harder, not easier. The duel has no final move. It has only a cost you keep raising.
Corollary. The moment the mass can look back, you are not reading a star — you are dueling a transponder. You do not out-shine a jammer and you do not catch every lie. You read only what it cannot help emitting, you make honesty its cheapest move, and you sign every line before it enters the jar. The catalogue survives precisely because it trusts nothing it receives. The same airgap, three papers running, doing its third job.