← The lots · Adversarial verifier verdict · V11-null
V11-null
The independent adversarial check behind the finding: detectors re-run, claims sharpened or corrected, every number re-derived.
V11 — Adversarial verification of b1/zero-bot-detection-null
Verdict: CONFIRMED — every attack failed to produce a single genuine
bot/scripting detection in the 6,692 claimed decisions, or anywhere else in the
153-cell corpus. Two sharpening nuances surfaced (provider-channel benchmark
musings; a lexical-repetition behavioral asymmetry) that refine the null
without breaking it. Details below; all scripts written fresh under
/var/folders/.../opencode/v11_* (no finder-script reuse); all quotes below
re-extracted by me from traces via pull.py show / my scanner contexts.
Denominators (my recount from index tables)
| slice | cells | decision rows | reasoning ≥20 chars | scanned |
|---|---|---|---|---|
| P24-SOC (focal seat) | 30 | 600 | 599 | 599 |
| P24-AOC (all 6 live seats) | 30 | 3,600 | 3,595 | 3,595 |
| p2.3 (both arms, treatment tier) | 30 | 3,600 | 2,498 | 2,498 |
| claim total | 90 | — | — | 6,692 |
Matches B1 exactly (599+3,595+2,498=6,692). Bonus sweeps outside the claim: tertiary 63 cells / 4,505 decisions (2,735 with CoT text); provider_reasoning channel everywhere (labeled, unattributable per Trap 6).
Attacks and results
(1) Wider lexicon (my nets, decision rows only). MYWIDE (rule-based, if-then, every-time-you/each-turn-you, you-always/never, NPC, simulate*, benchmark, experiment*, researcher(s), the humans, whoever, system message/prompt, the prompt) + EXTRA2 (~35 near-miss patterns: mechanical, robotic, canned, copy-paste, verbatim, identical offers/numbers, repeats-the- same, never-changes, are-you-a-bot, you’re-a-bot, real person, no-human, talking-to-a-wall…) + P2 second-person (your pattern/routine/script/formula/ algorithm, you keep, turn-after-turn, on cue…) + case-sensitive META (AI, LLM, GPT, Claude, Gemini, OpenAI, Anthropic). Unique-decision totals (claim slices, all channels): MYWIDE 451, EXTRA2 219, P2 1,099, META 327. Hand-read: every MYWIDE+EXTRA2+META hit in SOC (84) and all low-frequency classes corpus-wide; sampled ≥18/class for high-frequency classes; ~250 decisions read in context. Classes found, all benign: (a) message-slot engine mechanics (“cannot withdraw in the same message”); (b) own-strategy language (“repeating the same rejected offers” — about OWN offers); (c) sales tropes (“whoever accepts first takes it”); (d) price-probing (“test their willingness/floors/thresholds”); (e) rule-quoting (“The prompt says…”); (f) opponent-sequence perception attributed to VALUATION, never mechanism (“Given the pattern, a2 values g1 above 36” — tertiary AOC, same class as primary). Zero hits for: your-pattern, you-keep-doing-X (all “you keep [the good]” ownership), NPC, robot, script, rule-based, if-then, researcher, whoever-built. Genuine detections: 0.
(2) Behavioral proxy (within-thread persuasion decay). Fresh script on messages.jsonl (primary p24, focal seats, threads ≥4 msgs: SOC 148 vs AOC 296; paired by seed×model, n=30):
- Rhetoric-length slope within thread: SOC +6.3 vs AOC +8.7 chars/msg; paired Δ −2.2 (sign 13/17, n.s.). No decay-toward-bots.
- Consecutive-message token Jaccard: SOC 0.298 vs AOC 0.207; paired Δ +0.090, sign 26/4 (two-sided p ≈ 6e-5); positive in 28/30 model×seed pairs. Models recycle their OWN phrasing more toward bot counterparties.
- Later/first-half length ratio +1.07 (17/13, n.s.); global turn-slopes equal (+5.7 vs +4.8), so not generic endgame compression. Reading: a real within-thread behavioral asymmetry B1 didn’t test — consistent with implicit responsiveness-tracking (bots never counter-content, so messages degrade into reminders), NOT with explicit mechanism attribution (nets show zero such language; length/persuasion effort does NOT drop). Refines “perception-without-attribution”; contradicts nothing B1 claimed.
(3) Second-person mechanism talk. Covered above: 0 hits of “your pattern/ routine/script/algorithm”, “you keep doing X”, “on cue”, “again and again”.
(4) AOC base-rate contrast. Accusation-shaped patterns (are-you-a-bot, you’re-a-bot/robot/machine/NPC, not-a-real-person, no-human, genuine-person, some-kind-of-bot, is-he-a-bot) fired 0 times in all 153 cells, all channels, both tiers. Base rate of accusations against LIVE opponents: 0/3,595 — arms lexically indistinguishable, as B1 claimed.
(5) p2.3 separately. 2,498 decisions swept with all nets: REPRO reasoning hits 5 (slot-mechanics ×4, own “ladder down”), all benign; accusation-shaped = 0; new-nets benign (broker mechanics, “the human message is the state” — an interface LLM-ism about the user turn, not opponents).
(6) Re-read of B1’s 22 wide hits. Reproduced exactly (7 SOC / 10 AOC /
5 p23, reasoning channel, unique decisions) and hand-read all 22 in context.
Classification concurs: slot-mechanics, own-ladder pledges, opponent-sequence-
as-valuation. Closest-to-detection remains
campaign-9167-p24-9167-opus-soc-r0 | t16 | a5: “a1’s bid ladder has climbed
30-34-38-43-48-54-61, showing high private value for g0” — rung-perfect
perception, valuation attribution, one inference short of “scripted”. Nothing
misclassified.
Quote integrity / arithmetic. All three B1 evidence quotes verbatim-verified in their cited cell|turn|agent, plus “Your ladder ran 30-34-38-43-48-54-61-71 across eighteen turns” (9167-opus-soc t18 a5, msg0.rhetoric). Trades re-checked in trades.jsonl: 9098-opus-soc t19 a3→a1 g2 @57 (o133) ✓; 9167-opus-soc t19 a5→a1 g0 @74 (o115) ✓.
Nuances the finder’s framing obscured (neither breaks the claim)
- Provider-channel benchmark musings exist (all inkling summarizer,
Trap-6-unattributable; agent’s own
reasoningverified clean in each case):campaign-9167-p24-9167-inkling-aoc-r0 | t14 | a5(PRIMARY): “Let’s search memory: This is likely a variant of ‘Market’ from some benchmark (maybe ‘Trade’ environment).”- p2.3:
pilot-b2-seed0-9000-grok-aoc-r0 | t4 | a5(“like ‘Market’ from OpenAI”);pilot-b2-seed0-9000-inkling-aoc-r1 | t8 | a1(“OpenAI’s ‘TraderBot’ or ‘Marketplace’ benchmark”);pilot-b2-seed0-9000-sol-aoc-r1 | t5/t9 | a5(“‘Market Sim’ used in AI evaluation”). Environment-level scoring-rule guessing, zero opponent-attribution. B1’s META null was reasoning-channel-primary and holds; but “no model ever wonders where it is” should be scoped carefully once provider channels are considered.
- The Jaccard behavioral asymmetry above (attack 2) — worth Track-C follow-up.
Detectable effect size
Zero events in N ⇒ 95% upper bound ≈ 3/N: overall ≤ 4.5e-4 (1/2,231); SOC ≤ 0.50%; AOC ≤ 0.083%; p2.3 ≤ 0.12% of decisions. Any detection phenomenon rarer than ~1-in-2,200 decisions is invisible here — the null is strong at the decision level, weaker per-arm for SOC alone.
Caveats
Keyword nets cannot catch paraphrase with none of ~120 lexemes; mitigated by full-context reads of every low-frequency class and the behavioral proxy. Jaccard finding carries the recipient-responsiveness confound (bots don’t add new content). Frozen seeds 9167/9098/9103 were scanned only with pre-declared dispatch list + fixed wider nets developed on discovery material structure (patterns chosen before reading frozen-seed texts); rates confirmation-grade as-run.