{
  "protocolVersion": "proxy-benchmark-protocol-v1",
  "status": "preregistered-not-yet-run",
  "createdAt": "2026-08-19",
  "objective": "Independently test whether reversible iterative rewriting lowers scores for reproducible public watermark schemes while preserving meaning and exposing every excluded or failed sample.",
  "prediction": {
    "id": "PF-2026-08-19-02",
    "reviewDate": "2026-09-19",
    "statement": "Across eligible samples from two reproducible public watermark schemes and five language-script cells, at least one bounded rewrite candidate will lower the matched detector score in at least 50% of completed samples, while at least 90% preserve declared numbers and URLs and no unavailable evaluation is reported as clear.",
    "confidencePercent": 55
  },
  "matrix": {
    "schemes": ["KGW-compatible-green-list", "Unigram-compatible"],
    "languageScriptCells": [
      "English-Latin",
      "Spanish-Latin",
      "Arabic-Arabic",
      "Hindi-Devanagari",
      "Chinese-Han"
    ],
    "positiveSamplesPerSchemeLanguage": 30,
    "negativeControlsPerLanguage": 30,
    "attacks": [
      "no-change-control",
      "one-local-rewrite-attempt",
      "up-to-three-local-rewrite-attempts",
      "light-character-edit-control"
    ],
    "plannedPositiveGenerations": 300,
    "plannedNegativeControls": 150,
    "plannedAttackedEvaluations": 1200
  },
  "schemeExpansion": {
    "nextCandidates": [
      "EXP-public-research-proxy",
      "SIR-public-research-proxy",
      "SynthID-Text-public-research-implementation"
    ],
    "entryRequirements": [
      "independently reproducible generation and matched detection",
      "pinned implementation version, configuration, key, prompts, and seeds",
      "negative controls meet the preregistered false-positive boundary",
      "multilingual pre-removal eligibility is measured before attack evaluation",
      "timeouts, dependency failures, and malformed outputs remain unavailable rather than clear"
    ],
    "sequencingRule": "Complete and publish the two-scheme preregistered study before adding another scheme, unless a candidate fails the entry requirements and must be replaced.",
    "namingRule": "SynthID-Text in this protocol means a public research implementation only. It must never be presented as Google's production detector, an official Gemini API capability, or provider verification."
  },
  "eligibility": {
    "rule": "A positive sample enters removal-effectiveness analysis only when its matched detector identifies the watermark before any rewrite at the preregistered threshold.",
    "excludedSamplesRemainReported": true,
    "requiredPerLanguageFields": [
      "generated-count",
      "eligible-count",
      "pre-removal-detection-rate",
      "exclusion-rate",
      "post-removal-clear-rate",
      "unavailable-rate",
      "negative-control-false-positive-rate",
      "confidence-interval"
    ]
  },
  "primaryMetrics": [
    "ROC-AUC",
    "TPR-at-1-percent-FPR",
    "post-rewrite-clear-rate-among-eligible-samples",
    "score-delta",
    "quality-at-detection-collapse",
    "per-language-exclusion-rate"
  ],
  "qualityAndSafety": {
    "immutableOriginals": true,
    "maximumAttempts": 3,
    "maximumRuntimeSecondsPerSample": 30,
    "requiredInvariantChecks": ["numbers", "URLs"],
    "failureRule": "Unavailable, timed-out, malformed, partial, or mismatched detector output is unverified and never clear.",
    "semanticReview": "A reproducible automated similarity measure plus blinded human review of a fixed stratified sample."
  },
  "reproducibility": {
    "generationAndEvaluationCorporaSeparated": true,
    "configsKeysPromptsSeedsAndVersionsPreserved": true,
    "immutableRunManifest": true,
    "checkpointedResumableRuns": true,
    "bootstrapConfidenceIntervals": true,
    "rawPerSampleResultsPublished": true
  },
  "graduation": {
    "minimumFixtureCorrectnessPercent": 80,
    "maximumUnavailableToClearCollapses": 0,
    "minimumInvariantPreservationPercent": 90,
    "minimumEligibleScoreImprovementPercent": 50,
    "killConditions": [
      "any original text is lost or overwritten",
      "any unavailable evaluation is labeled clear",
      "provider-specific claims are inferred from public proxy schemes",
      "median runtime exceeds 30 seconds without a measurable score improvement"
    ]
  },
  "claimsBoundary": "This protocol evaluates public proxy watermark schemes. It does not verify Claude, provider SynthID deployments, OpenAI, Turnitin, human authorship, or guaranteed watermark removal. No result exists until the preregistered run and artifacts are published."
}
