Register RunningHub, Baidu, and LibLibAI visible marks; park Qingyan and MiniMax (measured)

New engines, each calibrated on its TC260 USCC cohort and validated by a
full-corpus sweep (42009 files):
- runninghub: top-left corner (new corner="tl"), faint mid-gray text via
  the new raw-grayscale "gray" detection front-end, anchor-position gate
- baidu: text-run-only template (pill is a bright-blob magnet), load-bearing
  Doubao+Qwen rival margins, corner-extended footprint for the white tag
- liblib: bottom-center (new corner="bc"), Arial silhouette (font is the
  discriminative lever against latin UI text), logo-extended footprint

Qingyan parked (no clean-arm separation at any render/box), MiniMax/Hailuo
parked (1 visible frame, the xinghui rule); silhouettes kept as starting
points.
This commit is contained in:
Victor Kuznetsov
2026-07-22 13:03:03 -07:00
parent ba29eccc45
commit f1a5eecf98
22 changed files with 1233 additions and 23 deletions
+26
View File
@@ -271,6 +271,32 @@ The cost (mislabel ~8-33% of non-Gemini content as Gemini) outweighs the benefit
**The clean-arm contamination trap (load-bearing for any future calibration):** the 2026-07-18 `present: []` labels are in the vocabulary of the REGISTERED marks only, so 146 of the 432 "clean" frames sit in a TC260 cohort -- including Qwen-cohort frames visibly carrying 千问AI生成. They made up the clean arm's entire top tail (clean p99 0.37 -> 0.69). `vendor_mark_calibrate.load_sets` now excludes every frame in ANY TC260 cohort from the clean arm; a gate read off the unguarded arm is meaningless.
## `runninghub_engine.py`
`runninghub_engine.py`**thin `TextMarkEngine` subclass, registered 2026-07-22.** RunningHub (hosted ComfyUI platform, USCC 91340100MAEB4N8H76, 73-frame cohort) "RunningHub AI生成" detector + localizer, **top-left** (the first `corner="tl"` mark), faint mid-gray latin+CJK text. Feeds `identify` as `visible_runninghub`.
* **`gray` front-end (the third one, added for this mark):** the mark's faint gray is suppressed by the white top-hat to clean-arm levels (positives 0.16-0.23 vs clean p99 0.31), while raw-grayscale silhouette NCC separates (positives 0.38-0.54 vs clean p99 0.264 / max 0.304 on 283 guarded clean frames). It is contrast-DEPENDENT, unlike tophat -- one method `_gray_best` serves both detection and the mask, same one-method parity contract as `_tophat_best`.
* **Tight ladder (0.95, 1.0, 1.05) exactly on the measured 0.32-of-width:** the NCC comb is razor-sharp in size (0.537 on-size, 0.223 at +5.6% off -- Qwen's comb behaviour, measured again here), so the shared 3 rungs (nearest rung 5.6% off) collapsed the match to 0.22 and the first calibration showed no separation at all.
* **Anchor gate in `detect`:** the full-corpus sweep (`data/spaces/_sweep_new_marks.py`, 42009 files) fired on 37 outside-cohort frames at 0.34-0.38 (hair tops, shelves, window frames, CJK banners) -- no NCC threshold separates them from the 0.381 positives. Every positive sits at the measured corner (x 0.008-0.014, y 0.005-0.007 of the frame) and every false fire off it (x 0.013-0.150, y 0.009-0.045), so detection additionally requires the match box inside x<=0.025 / y<=0.015 of the frame. 0/37 false, 4/4 positives kept.
* **Footprint is always the detector's match box** (never the binary blob): the blob under-segments the faint head glyphs and left "Runni" unremoved (caught visually on the first removal). Gate 0.34, STRICT ONLY. Regression: `tests/test_runninghub_engine.py`.
## `baidu_engine.py`
`baidu_engine.py`**thin `TextMarkEngine` subclass with a custom `footprint_mask`, registered 2026-07-22.** Baidu (USCC 91110000802100433B, 16-frame cohort) "百度 AI生成" detector + localizer, bottom-right: a white bold 百度 text run + a separate white rounded tag with dark "AI生成". Feeds `identify` as `visible_baidu`.
* **Detection keys on the 百度 text run ONLY.** A two-component (text+pill) template was measured and rejected: the solid white pill is a bright-blob magnet and both front-ends scored the clean arm at cohort levels (tophat clean p95 0.445 / gray clean p95 0.487 vs cohort ~0.5). The text-only silhouette separates (cohort 0.39-0.65 vs clean max 0.352). The white tag is still removed: the footprint extends to the corner (below).
* **Two load-bearing rival margins** (`rivals=("doubao_alpha.png","qwen_alpha.png")`): 百度 vs 豆包 share their second glyph, and 百度 vs 千问 are near-identical after binarization -- at the 0.37 gate the template fired on 45.8% of 400 Doubao-marked frames and, on the 741-frame blind-labelled eval set, on 12 Qwen-marked frames at 0.38-0.43. Doubao's template beats it by ~0.56 on Doubao marks, Qwen's by 0.17-0.35 on Qwen marks; the 0.10 margin suppresses all crossfire at zero genuine-Baidu cost (cohort fire+m == fire).
* **Gate history, each step measured:** 0.37 from the clean arm (max 0.352) -> 0.43 after the eval-set crossfires (the one 抖音 AI创作 fire at 0.425 named no registered rival) -> **0.48** after the full-corpus sweep put outside-cohort TRUE carriers at 0.50-0.66 vs the false arm max 0.47 (大众点评 UI, a math blackboard, an 80s banner). Cohort keeps 7/16 (all true); the sweep also found 6 metadata-STRIPPED true Baidu carriers the TC260 cohort cannot see -- the direct evidence that registration pays beyond the cohort.
* **Custom `footprint_mask`:** the tag's flat white interior gives no top-hat response (a top-hat answers edges, not flats), so the base blob bbox ended at the text run and the fill left the tag as a ghost. The mask is the detector's match box extended RIGHT to the corner. STRICT ONLY. Regression: `tests/test_baidu_engine.py`.
## `liblib_engine.py`
`liblib_engine.py`**thin `TextMarkEngine` subclass with a custom `footprint_mask`, registered 2026-07-22.** LibLibAI (哩布哩布AI, USCC 91110105MACJ6K1C8A, 15-frame cohort) triangle logo + "LibLibAI" wordmark detector + localizer, **bottom-CENTER** (the first `corner="bc"` mark; the locate box is horizontally centered). Feeds `identify` as `visible_liblib`.
* **The discriminative lever is the silhouette FONT.** With the CJK house font (STHeiti) the cohort scored 0.31-0.47 against a full-corpus false arm (latin UI text bands, website screenshots) at 0.50 -- no separation at any gate. Measured across 7 candidate fonts, **Arial** lifts the cohort to 0.42-0.73 and DROPS the false arm to max 0.398: generic latin text matches the wrong font less, which is where the discrimination comes from. Gate 0.42 keeps all 8 marked cohort frames (0.43-0.59).
* **Per-mark size floor (`_MIN_SHORT_SIDE=480`):** the one false fire with the final template was a 200x200 icon (0.444, on a 20px template). The shared `_MIN_DETECT_SHORT_SIDE` (200) is a crash guard, not a discrimination floor; the template needs ~48px to discriminate.
* **Custom `footprint_mask`:** the base blob bbox was wrong in both directions -- it bled UP into background structure (ate a shirt's real print on the 768x1024 cohort frame) and never owned the triangle logo. The mask is the detector's match box extended LEFT by ~1.3 glyph heights (the logo is ~1.0x the glyph height, gap ~0.3x, measured on the cohort zoom). STRICT ONLY. Regression: `tests/test_liblib_engine.py`.
## `region_eraser.py`
`region_eraser.py` — universal region eraser (`erase` CLI) AND the shared fill backend behind `watermark_registry.fill` for the visible localize -> fill removal. `erase(image, boxes=|mask=, backend=)` accepts grayscale (2D) and RGBA (4-channel) inputs on **all** backends (each splits off any alpha plane and re-attaches it unchanged, and promotes grayscale to BGR): `boxes_to_mask` → one of three backends.
+66 -2
View File
@@ -742,8 +742,10 @@ priority order:
against the contamination-guarded clean arm, crossfire against doubao/jimeng. 可灵
additionally stamps a second mark bottom-LEFT, which no current text-mark config
expresses (the pill is top-left; a bottom-left CJK mark needs a `corner="bl"` CJK
config -- samsung is `bl` but Latin-script and width-based). 星绘/百度 are NOT in the
corpus in labelable quantity -- verified, do not hunt them again.
config -- samsung is `bl` but Latin-script and width-based). 星绘 is NOT in the
corpus in labelable quantity -- verified, do not hunt it again. (百度 WAS found
later via the USCC cohort harvest and is registered since 2026-07-22 -- see
"The 2026-07-22 vendor round" below.)
**STATUS 2026-07-21 (same day): 可灵 REGISTERED, 元宝 measured and PARKED.**
* **可灵 (`kling_engine.py`)** -- "可灵AI 3.0" bottom-right, strict-only, gate
@@ -794,6 +796,68 @@ to confirm the whole surface still works after a change is
`uv run python scripts/real_examples_e2e.py` (~2 min, real corpus examples through the real
CLI) plus `uv run python scripts/robustness_suite.py` (~3 min, adversarial inputs).
### The 2026-07-22 vendor round -- 3 REGISTERED (runninghub / baidu / liblib), 2 parked
A fresh metadata-mining pass over the whole corpus (`data/spaces/_mine_signals.py`)
found NO new metadata signals (the channel is saturated), so the round worked the
visible-mark cohorts (`vendor_cohort_harvest.py`, 4606 TC260 carriers / 46 entities).
Registered, each by the qwen playbook (synthetic silhouette -> measured geometry ->
clean-arm gate -> crossfire -> full-corpus sweep):
* **RunningHub (`runninghub_engine.py`)** -- "RunningHub AI生成" TOP-LEFT (a new
`corner="tl"`), faint mid-gray text. The white top-hat suppresses it to clean-arm
levels (positives 0.16-0.23 vs clean p99 0.31), so it introduced the third
detection front-end, **`gray`** (raw-grayscale silhouette NCC, contrast-DEPENDENT):
positives 0.38-0.54 vs clean max 0.295 -> gate 0.34, strict-only. The NCC comb is
razor-sharp in size (0.537 on-size, 0.223 at +5.6%), so the ladder is a tight
(0.95, 1.0, 1.05) exactly on the measured 0.32-of-width. Two measured traps with
their fixes: (1) the binary blob under-segments the faint head glyphs, so the
blob-bbox footprint left "Runni" unremoved -- the gray front-end's footprint is
always the detector's own match box; (2) the full-corpus sweep surfaced 37/42009
outside-cohort false fires at 0.34-0.38 (hair, shelves, CJK banners) with no NCC
separation from the 0.381 positives -- the **anchor gate** (the match must sit at
the measured corner, x<=0.025/y<=0.015 of the frame) rejects all 37 at zero
positive cost.
* **Baidu (`baidu_engine.py`)** -- "百度" white bold text + a white rounded tag
"AI生成", bottom-right. Detection keys on the 百度 TEXT RUN ONLY: a
text+pill template was a measured bright-blob magnet (no separation on either
front-end). Gate history, each step measured: 0.37 from the clean arm (max 0.352);
the 741-frame eval set then fired 14x outside the cohort and 13 were NOT the
vendor (12x 千问 -- 百/千 are near-identical after binarization -- plus one 抖音
AI创作 at 0.425), so `rivals=("doubao_alpha.png","qwen_alpha.png")` (both margins
load-bearing, zero genuine cost) and the gate moved 0.37 -> 0.43; the full-corpus
sweep then put outside-cohort true carriers at 0.50-0.66 vs the false arm max
0.47, so the gate settled at **0.48**. Cohort: 7/16 fire (all true). The
footprint is custom: the tag's flat white interior gives no top-hat response, so
a blob bbox leaves the tag as a ghost -- the mask is the match box extended right
to the corner.
* **LibLibAI (`liblib_engine.py`)** -- triangle logo + "LibLibAI" wordmark
**bottom-CENTER** (a new `corner="bc"`). The discriminative lever was the FONT:
STHeiti scored the cohort 0.31-0.47 against a false arm (latin UI text bands) at
0.50; measured across 7 fonts, **Arial** lifts the cohort to 0.42-0.73 and DROPS
the false arm to max 0.398 (generic latin text matches the wrong font less). Gate
0.42, strict-only; a per-mark size floor (`_MIN_SHORT_SIDE=480`) backs it (the
one remaining false fire was a 200x200 icon on a 20px template). Custom
footprint: match box extended left by ~1.3 glyph heights for the triangle logo
(the blob bbox both bled into background structure -- ate a shirt's real print --
and did not own the logo).
Parked, both as measured negatives with the silhouette kept in
`render_vendor_silhouettes.py` as the starting point:
* **Zhipu Qingyan (清言·AI生成)** -- 7-frame cohort, white semi-transparent text +
swirl logo. On both front-ends the cohort scores 0.34-0.39 vs clean max
0.34-0.37 -- no separation at any render/box setting (text-only and
logo-composite templates, two CJK fonts). Same wall class as 元宝.
* **MiniMax / Hailuo AI** -- only 1 of 6 cohort frames carries a visible mark
(Hailuo is a video product; the mark is a video-frame stamp). The xinghui rule:
nothing registered off a single frame.
The full-corpus sweep harness is `data/spaces/_sweep_new_marks.py` (read-only,
gitignored); its artifact `_new_marks_sweep.jsonl` records every fire. The sweep
also proved the outside-cohort value of registration: 6 metadata-STRIPPED true
Baidu carriers the TC260 cohort cannot see are now detected and cleaned.
### The 千问 harvest (2026-07-21) -- RESOLVED, registered the same day
**The unlock: the TC260 label is not anonymous.** Its `ContentProducer` field carries the
+1 -1
View File
@@ -70,7 +70,7 @@ Two consequences we can exploit: (1) the 5% floor is a **scale prior** -- a comp
**星绘 is ByteDance (VERIFIED (a): Baidu Baike + App Store listing, now branded 豆包旗下, team folded into Doubao April 2025).** So `星绘AI生成` is very likely the Doubao house style -- same typeface, same corner, possibly the same top-left `AI生成` pill. Starting from the Doubao `TextMarkConfig` and swapping the two lead glyphs is the cheap path. String/position themselves are (c) inferred.
**Baidu: could not establish.** No primary or credible secondary source names the exact string or position; it could be `百度AI生成`, `文心一格AI生成`, or product-specific. Harvest the glyphs from corpus positives, not the web.
**Baidu: RESOLVED 2026-07-22, registered (`baidu_engine.py`).** The mark is a white bold "百度" text run + a separate white rounded tag with dark "AI生成", bottom-right -- settled by the TC260 USCC cohort harvest (16 frames, USCC 91110000802100433B), not by web research. Detection keys on the text run only; details in `docs/module-internals.md`.
**Meta `Imagined with AI` (string VERIFIED (a) from Meta's own newsroom; POSITION NOT VERIFIED).** Sources conflict (bottom-left vs bottom-right) and one claims newer Meta models dropped the visible mark for invisible watermarking; none survived a fetch. Do NOT encode a corner without a corpus sample. Meta also embeds IPTC + invisible watermarks, which `identify` already reads. Source: `https://about.fb.com/news/2024/02/labeling-ai-generated-images-on-facebook-instagram-and-threads/`.