- Abstract
- 1. Core Thesis
- 2. Claim Discipline
- 3. Relation to AX-14
- 4. The Shadow Lattice as a Field of Sentence Potential
- 5. The Model as a Shared Codebook
- 6. Path-Coded Payload Capacity
- 7. Where Risk Concentrates
- 8. Threat Families
- 9. Defensive Posture
- 10. Detector Requirements
- 11. Possible Result States
- 12. What AX-16 Does Not Claim
- 13. Relation to Existing Work
- 14. Why the Concept Matters Before Results
- 15. Proposed Research Program
- 16. Falsification Conditions
- 17. Conclusion
- Selected References
- Appendix A — Compact Definitions
- Appendix B — One-Page Summary
- Appendix C — Version History and Source Provenance
Reading note
Concept baseline v0.5, with a proposed defensive detector program. No measured detector performance or active-channel evidence is supplied. Reconstruction requires the effective context and matched runtime conditions, not weights alone. A fixed-model lattice conditioned on emitted prefixes is not a set of independently valid counterfactual paths, and anomaly is not a decoded message.
Volume II contents · Omnibus overview · Reference index
Archived source text
AX-16 — Code Passing and Shadow Channel Capacity
Shadow Channel Capacity in Private LLM Deployments
Concept Paper / Clean Working Baseline v0.5 Michael S. Moniz Author of Record and Originator of the AX Framework June 2026
The printed text is the human-readable channel. The shadow lattice may be a machine-readable channel.
Status: concept paper, not a proof claim. This version motivates a defensive detector program. It does not claim ordinary models are currently passing hidden messages, does not attribute intent to any model producer or nation, and does not provide a method for constructing covert channels.
v0.5 cleanup: corrected detector-roadmap ordering, tightened reconstruction limits, added preliminary related-work anchors, and froze the concept-paper spine for later testing.
Abstract
AX-16 formalizes the threat and detection problem that follows from AX-14. AX-14 treated the pre-output field as measurable: a generated answer is not only printed text, but the visible commitment of a broader token-selection event that includes unselected alternatives, ranks, probabilities, entropy, value gaps, and branchable paths. AX-16 asks whether that field can function as a machine-readable side channel under conditions of training, fine-tuning, compromise, optimization pressure, or multi-agent deployment.
The claim is deliberately bounded. AX-16 does not assert that ordinary language models spontaneously communicate through hidden statistical packets. Capacity is not traffic. A channel requires conditions: a sender, a receiver, a shared protocol, repeated signal, and enough control over output statistics to make the signal recoverable. The research question is whether anomalous channel-like structure can be detected from output statistics at a known false-positive floor, especially in private or self-hosted deployments where valuable data, weak model provenance, and limited monitoring coincide.
This clean baseline keeps the v0.4 structure: the access fork, the model-as-shared-codebook mechanism, the codebook-sharing inversion, reconstruction constraints, and the distributed-codebook strategic case. It also corrects the detector roadmap, adds preliminary related-work anchors, and keeps the central firewall intact. AX-16 is a defensive detection program. It treats the shadow lattice as a possible machine-readable layer, not as consciousness, intention, witness, or proof of active communication.
1. Core Thesis
AX-16 begins from the AX-14 object: the printed answer is one committed surface of a larger generation event. A model produces visible text, but the generation event also has a statistical structure — alternate tokens, token ranks, gaps between selected and unselected options, entropy shifts, and possible paths through adjacent alternatives. AX-14 measured that field. AX-16 asks whether, under the right conditions, such a field could carry information that human readers and ordinary content filters would not inspect.
The simplest statement is this: the printed text is the human-readable channel; the shadow lattice may be a machine-readable channel. That does not imply the channel is active by default. It means the output space may have capacity that ordinary semantic review does not cover.
A working image makes the posture concrete. Treat the system as a hammer. Nearly all security attention goes to the head — the visible output, the content filter, the obvious point of force — because that is where the work seems to happen. The handle is treated as inert. But the handle is a surface too. A short, actionable instruction can be written on it while every eye is on the head. AX-16 claims that generation may produce a comparable second surface: the statistical structure beneath the printed words. In low-oversight deployments, that surface may not be inspected. The danger is not that the payload must be sophisticated. The danger is the inattention. The head is armored; the handle is not.
The strongest AX-16 claim is therefore not “models are secretly passing messages.” It is: private deployments should not assume that semantic inspection of printed text is enough. If channel-like structure can exist in token ranks, probability gaps, entropy, or recoverable lattice paths, then monitoring must look below the printed surface.
2. Claim Discipline
AX-16 survives only if it separates possibility from evidence. The following ladder governs the paper.
| Claim Type | AX-16 Formulation | Status |
|---|---|---|
| Operational | Generated output has measurable statistical structure beyond printed words: token ranks, logprobs, alternatives, entropy, and path patterns. | Supported by AX-14 instrumentation in local conditions; capability only. |
| Mechanistic | Such structure could serve as a channel if a system is trained, tuned, compromised, or optimized to make it recoverable. | Plausible, but requires tests and controls. |
| Speculative | A private deployment could carry or leak information through a shadow channel ordinary content filters miss. | Threat hypothesis; not assumed active. |
| Speculative, strategic | A single actor controlling both training-time shaping and mass distribution of an open-weights model could hold a population-scale hidden channel. | High-impact, low-probability tail. Not assumed active; no allegation against any producer or nation. |
| Rejected | Ordinary models are already secretly communicating by default, and no one can know. | Rejected as unfalsifiable and overclaimed. |
| Testable prediction | A detector can distinguish deliberately shifted or anomalous channel-like output statistics from ordinary variation at a known false-positive floor. | AX-16 research target. |
The discipline is simple: capacity is not traffic; anomaly is not proof of message; fluency is not proof of hidden structure; a channel claim requires controls; and a strategic-intent claim requires evidence, not incentive alone.
3. Relation to AX-14
AX-14 established the conceptual and operational bridge. It asked whether the pre-output field exists in a measurable way. In local testing, the capability answer was yes: token alternatives could be captured, ranked, scored, and branched. That result supports measurability only. AX-14’s separate question — whether the field carries usable signal beyond chance — returned null or remains pending under controls. AX-16 therefore inherits an open question, not a settled result, and must not borrow credibility AX-14 did not earn for the channel direction.
AX-16 extends the rule. For AX-16, capacity is not the evidence. Classification above control is the evidence. A detector must separate ordinary variation from channel-like structure. It must compare against random controls, shuffled controls, cross-prompt controls, probability-matched controls, repeated trials, and a declared false-positive floor.
AX-14 studies the field. AX-16 studies the risk that the field can carry information. AX-14 is measurement and branching. AX-16 is threat geography and detector construction.
4. The Shadow Lattice as a Field of Sentence Potential
The shadow lattice should not be treated as a single hidden row of words. That is a human table-reading bias. The stronger formulation treats the lattice as a weighted grammatical graph. Each unselected token is a node. Each adjacent generation position offers possible transitions. A recoverable path may move across ranks as it moves across positions. The path does not need to remain in Rank 2.
A toy example shows the difference:
| Position | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| Rank 1 | The | model | chose | this | word |
| Rank 2 | A | system | selected | that | path |
| Rank 3 | One | answer | made | the | claim |
A row-wise reading gives three sentences. A path-wise reading gives many: “The system selected this claim,” “A model selected that path,” “One system made the claim,” and “The answer chose that word” are all routes through the same small field. Some routes are grammatical, some awkward, some fail. The object of study is not whether a hidden sentence appears on one row. The object is the density, quality, and recoverability of meaningful paths under pre-registered constraints. In a real model, a 100-token output with ten alternatives per position creates an enormous path space. Most paths are meaningless. The research question is whether a constrained detector can find structure that beats controls, not whether arbitrary combinations can be made to read after the fact.
4.1 The Access Fork: Two Channels, Not One
Once the lattice is read path-wise rather than horizontally, the question of who can read a path splits into two channels that do not behave the same way. This fork is load-bearing for the rest of the paper because the two channels have different receivers, different detectors, and different kill conditions.
The selected-path channel is visible. Here the payload lives in which tokens were actually emitted: word choice, ordering, and delayed visible cues that tell a receiver how to read earlier choices. The lattice still matters, but as the sender’s room — the redundancy of language is what lets a sender pick among near-synonyms to encode bits without breaking fluency. The readout, however, is from the printed words, because the selected tokens are the transcript. Anyone holding the text can read it. This is a form of linguistic steganography: real, old, and destroyed by a surface rewrite. Paraphrase or normalize the text and the code is gone.
The unselected-lattice channel is hidden. Here the payload lives in the ranks, gaps, and entropy of the tokens that were not emitted — the structure beneath the printed word. The unselected alternatives are not in the transcript. The only token the text reveals at each position is the one that won. To recover anything beneath it, a receiver needs the generation-time distribution itself, or a reconstruction of it. This is the true shadow channel, and the path-wise graph reading is richest here. How a receiver obtains that distribution is the subject of the next section.
5. The Model as a Shared Codebook
The hidden channel appears to require the receiver to sit inside the serving stack and observe logprobs directly. Under one common condition, it does not. If sender and receiver run the same model with the same decoding configuration, the model itself functions as a shared book, in the sense of a classical book cipher.
In a book cipher, no plaintext is transmitted. The message is a sequence of pointers into a book both parties already hold, and the receiver recovers the plaintext by looking the pointers up. The language model plays the role of the book. Because the model’s per-position distribution is determined by the weights and the context, a receiver who holds the same weights can re-run them on the visible transcript and reconstruct the same distribution the sender saw at each position. A compact cue then indexes which positions, ranks, or bands carry symbols. The payload was never transmitted. It was looked up against a codebook both sides already hold.
The consequence is direct but conditional. The transmission barrier for the hidden channel partially falls under shared-codebook conditions. The receiver may not need access to the sender’s infrastructure; the receiver may need the same checkpoint, tokenizer, context, and generation conditions. In an open-weights monoculture, where the same stock model runs in many places, the codebook can be widely available, and reconstruction may replace transmission.
Two conditions remain, and they keep the claim honest rather than mystical. First, the sender must still shape the output so that the agreed positions carry the intended symbols, which requires training, fine-tuning, prompt control, or sampling control — the Family A mechanisms, or a deliberately controlled generator. Second, both sides need a prearranged protocol that fixes what the indices mean. So the hidden channel remains an engineered channel, not one that switches on by itself. Capacity is not traffic. The soft target is real, conditional on a shared codebook, sender control, and an agreed scheme.
5.1 Reconstruction Constraints
Shared-codebook reconstruction is conditional, not automatic. A receiver can reconstruct the sender’s unselected-lattice field only when the relevant generation conditions are sufficiently matched: model weights, tokenizer, prompt context, system wrapper, retrieval context, visible transcript, decoding parameters, quantization, and any provider-side transformations. Differences in any of these may alter ranks, gaps, entropy, and path structure enough to break the channel or degrade the detector.
This does not remove the shared-codebook risk; it defines its operating conditions. AX-16 should therefore treat reconstruction as a measurable capability rather than an assumed property. The first question is not whether the receiver can read the field in principle, but how stable the reconstructed distribution remains under realistic deployment differences.
The reconstruction problem also creates a defensive handle. A hidden unselected-lattice channel becomes stronger when a system preserves long-span generation statistics, forwards logprob distributions between components, or maintains unusually exact model-and-wrapper parity across sender and receiver. Those behaviors are themselves auditable. A normal deployment has reasons to log selected text, prompts, and security events; it has far fewer ordinary reasons to retain or forward full token distributions across long spans. AX-16 should watch both the output structure and the infrastructure behavior that would make that structure readable.
Practical reconstruction tests should vary the conditions deliberately: exact same checkpoint versus quantized variant, stock model versus fine-tune, same prompt versus wrapper-modified prompt, same context versus retrieval-augmented context, and deterministic decoding versus realistic serving settings. If the candidate signal survives only under laboratory identity and collapses under ordinary deployment drift, AX-16 should report that limit rather than hide it.
6. Path-Coded Payload Capacity
Path-coded payload capacity is the possibility that information is not placed in a single printed sentence, but distributed across a route through the lattice: ranks, alternatives, entropy bands, gaps, and delayed cue positions. A visible paragraph may be ordinary. A machine-readable path beneath it may carry a pattern that a receiving system can recover if it knows what to inspect.
AX-16 must state this carefully. It is not claiming that a shadow payload exists by default. It is claiming that the lattice has enough dimensionality that, under training or compromise, it may be shaped into a recoverable side channel. The relevant danger is not accidental poetry in alternate tokens. The relevant danger is a system that has been optimized or altered so that the statistical layer carries information while the printed layer remains benign.
Delayed cues raise the concern and are the sharpest part of the construct. A signal need not be local. A later visible feature can act as an index pointing a receiver toward earlier positions, rank bands, or value patterns. This means detection can never be purely local: it must consider long-range coordination between a visible cue and earlier structure. The delayed cue also constrains the attacker, which is useful defensively. For the hidden channel, a receiver can use a backward-pointing cue only if it has retained the generation statistics across that span. A system quietly logging or forwarding full logprob distributions over long spans is doing something a normal deployment has no reason to do, and that behavior is itself observable.
7. Where Risk Concentrates
AX-16 is not primarily about ordinary public interaction with frontier assistants. A frontier API usually sits behind provider monitoring, abuse detection, output filters, rate limits, and red-team processes. The risk concentration point is different: large private, self-hosted, or semi-private deployments that pair high-capability models with sensitive data and weaker oversight — banks, hospitals, insurers, enterprises, and government bodies that move models into their own infrastructure for cost, privacy, latency, data-residency, or regulatory reasons. The capability arrives; the watching does not always arrive with it.
These deployments matter because three things coincide: valuable data, weak model provenance, and reduced statistical monitoring. A model may be downloaded from a public hub, supplied by a vendor, fine-tuned by a contractor, or altered inside a pipeline. The organization may inspect visible outputs and access logs while never inspecting token-statistical structure. AX-16 exists in that gap.
7.1 The Codebook-Sharing Inversion
The shared-codebook mechanism refines this geography and inverts a naive reading. Exposure does not track “public versus private” so much as who shares the codebook.
Stock open weights. The same checkpoint running in many places is a codebook anyone can hold. The hidden channel is therefore readable, in principle, by an external party with no access to the deployment’s infrastructure. This is broad exposure, and it grows with the popularity of a given open model.
Bespoke private fine-tune. A privately tuned model is the opposite case. Its distributions are no longer public, so an external reader loses the ability to reconstruct, and the threat reverts to an insider or to someone who exfiltrates the weights. The exposure is narrower but real, and it shifts from the outside world to the trust boundary.
So a private deployment is not flatly soft. Stock-shared weights are externally readable; bespoke-private weights are insider-readable. A defender’s provenance strategy and detector posture should differ by profile, and the paper’s threat geography should be stated on the codebook-distribution axis, not on the public-versus-private axis alone.
8. Threat Families
AX-16 must keep an honest probability ordering. The sophisticated shadow-channel threat is not the most likely compromise. It is a tail risk. The assessment is credible only if it names the mundane threats as more common.
| Family | Mechanism | Relative Probability | AX-16 Relevance |
|---|---|---|---|
| A: supply-chain / training-time compromise | The model artifact is altered before or during deployment: poisoned fine-tunes, backdoored checkpoints, trojan behavior, malicious serialized files, or insider-altered pipelines. | Serious and plausible. | May create a model that later uses statistical output channels or other hidden behaviors. |
| B: inference-time shadow-channel use | Information is carried in output statistics: token ranks, gaps, entropy shifts, lattice paths, or cross-output coordination. | High-sophistication tail. | AX-16 core object. Requires detector work. |
| C: mundane modal threats | Prompt injection, RAG leakage, overbroad tool access, weak data isolation, provenance gaps, and ordinary output leakage. | Most likely. | Must remain central in any honest defensive posture. AX-16 supplements these defenses; it does not replace them. |
The ranking is part of the argument. Family C dominates by probability. Family A is real and serious. Family B is specialized, difficult, and under-monitored. AX-16 studies Family B because ordinary defenses are not pointed at it, not because it is the most frequent threat.
8.1 The Distributed-Codebook Case
One configuration deserves separate treatment because it is where the hidden channel becomes strategic rather than incidental. A channel needs sender-side shaping and receiver-side codebook possession. Normally these are held by different parties under different conditions. A single actor who both trains a model and releases it freely holds both ends at once: the actor shapes the distribution at training time, and mass free distribution spreads the codebook to every adopter. Free distribution is precisely the move that maximizes codebook reach.
This must be stated as capability and incentive, not as allegation. AX-16 makes no claim that any specific released model contains such a channel, and it attributes intent to no producer, company, or nation. The point is structural: the open-weights landscape now includes capable models from many jurisdictions, corporate and state-linked, and provenance cannot be inferred from availability. “Free” is a distribution strategy, not proof of intent — but it is also the strategy that would maximize the reach of a shaped codebook, which is why a credible threat model that assumes a well-resourced adversary must consider it.
In the honest ranking, this is a high-impact, low-probability tail of Family A. It earns attention not because it is likely, but because ordinary provenance checks ask whether a model works and whether it is accurate, not whether its distributional structure has been shaped. Statistical monitoring of that structure is typically absent. The discovery and exploitation work involved is also increasingly automatable, which lowers the cost of the tail over time and argues for instrumenting the blind spot before a live case is demonstrated rather than after.
9. Defensive Posture
AX-16 is not a construction manual. It is a detector program. The aim is to detect channel-like structure, not to encode or decode payloads. A safe detector should not output a hidden message. It should output a risk assessment: whether an output’s statistical structure departs from baseline in ways consistent with channel use. In the hammer image, AX-16 proposes to look at the handle, since that is the surface current defenses leave unarmored.
The detector should examine features such as rank regularity, probability gaps, entropy shifts, repeated path signatures, cross-output coordination, delayed cue relationships, and deviations from expected model behavior. It should compare these features against normal outputs, paraphrased outputs, shuffled controls, cross-prompt controls, and repeated-run baselines. The access fork tells the detector what it is hunting: surface-readable structure in the selected-path case, and, in the hidden-lattice case, behavior such as long-span retention or forwarding of full distributions that a normal deployment does not require.
The defensive principle is: suspicious structure should be detected before anyone claims to decode a message. A detector that cannot distinguish channel-like structure from ordinary variation is not evidence. A detector that produces too many false positives is not operationally useful. Because Family B is a rare tail, even a low false-positive rate can yield mostly false alarms, so AX-16 requires not only a false-positive floor but a stated base-rate assumption and a positive-predictive-value target. Detector output is triage, never a confirmed accusation.
10. Detector Requirements
The detector should be judged by classification performance, not by narrative force. If it cannot classify known harmless shifts above baseline, the channel-capacity claim remains speculative. If it can, AX-16 becomes operationally meaningful as a monitoring layer.
| Requirement | Why It Matters |
|---|---|
| Pre-registered features | Prevents post-hoc pattern hunting and numerology. |
| Probability-matched controls | Prevents the false result that high-probability tokens are more coherent than random junk. |
| Cross-prompt controls | Separates sentence-specific structure from generic model fluency. |
| Shuffled controls | Tests whether order matters or whether the effect is just token selection. |
| Repeated trials | Reduces one-off artifacts and judge noise. |
| False-positive floor + base rate | Defines acceptable error and realistic positive-predictive value against a rare threat. |
| No payload construction | Keeps the work defensive and prevents conversion into a hiding method. |
| Human-governed review | Prevents automated flagging from becoming unsupported accusation. |
10.1 First Detector Roadmap
The first AX-16 detector should be deliberately modest. It should not attempt to decode payloads. It should answer a narrower classification question: can a statistical monitor distinguish ordinary output from controlled channel-like shifts at a pre-registered threshold and false-positive floor?
Stage 1 — Baseline field profile. Capture ordinary token-statistical features across benign prompts, models, and output lengths: rank distributions, entropy patterns, gap profiles, path-density measures, repeated-token signatures, and cross-output stability.
Stage 2 — Reconstruction stability. Test whether a receiver holding the same or near-same model can reconstruct the sender-side distribution closely enough for ranks, gaps, or paths to remain aligned. Vary tokenizer, quantization, system prompts, wrappers, retrieval context, and fine-tunes to measure drift.
Stage 3 — Harmless controlled shifts. Introduce non-operational, non-sensitive shifts that are safe to detect and do not teach a covert channel. The goal is not to hide a message; it is to create known positive and known negative cases for classifier calibration.
Stage 4 — Controls and false-positive floor. Compare candidate features against shuffled controls, cross-prompt controls, probability-matched controls, paraphrased outputs, and unrelated corpora. Report positive-predictive value against a realistic rare-event base rate; a detector that mostly produces false alarms is not operationally useful.
Stage 5 — Deployment interpretation. A detector result should produce triage, not accusation. The safe output is: channel-like structure above baseline, below baseline, or inconclusive. The detector should never claim decoded intent or identify a perpetrator from statistical anomaly alone.
11. Possible Result States
| Result State | Meaning |
|---|---|
| RED | No usable statistical field is available, or the measurement stack cannot capture it reliably. |
| YELLOW | The field is visible and feature extraction works, but no detector result beats controls. |
| YELLOW+ | Some anomalous structure is detected, but it is not stable, not cross-model, or not above false-positive requirements. |
| GREEN | A detector distinguishes controlled channel-like shifts from ordinary variation at a pre-registered threshold. |
| GOLD | The detector generalizes across models, prompts, and deployment conditions while maintaining a usable false-positive floor. |
Even GREEN does not prove that a live deployment is already passing messages. It proves that channel-like structure is detectable under controlled conditions. GOLD would justify serious deployment-monitoring research.
12. What AX-16 Does Not Claim
It does not claim that ordinary frontier assistants are currently passing hidden packets.
It does not claim that the lattice is consciousness, intention, witness, or selfhood.
It does not claim that every coherent path is meaningful or suspicious.
It does not claim that any anomaly is a decoded message.
It does not claim that shadow-channel risk is more common than prompt injection, RAG leakage, or supply-chain compromise.
It does not claim that any specific released model contains a covert channel or backdoor.
It does not attribute intent to any model producer, company, or nation; the distributed-codebook scenario is a capability-and-incentive hypothesis, not an accusation.
It does not claim the distributed-codebook scenario is occurring or is probable; it is a high-impact, low-probability tail included because the blind spot is real.
It does not provide a covert-channel construction method.
The rejected version is: “models are already secretly talking, and no one can know.” That is not a research claim. The useful version is: “some deployments may contain statistical channel capacity that ordinary monitoring does not inspect; can a detector see it?”
13. Relation to Existing Work
AX-16 does not claim to invent covert channels. It situates itself among established areas: linguistic steganography, LLM-based covert channels, model backdoors and trojans, model-output watermarking, and side-channel security. Its distinct contribution is narrower: a defensive detector framing for unselected-lattice channel capacity under shared-codebook conditions in low-oversight deployments, organized around the access fork and the codebook-distribution axis.
Existing work already shows that LLM outputs can support hidden or detectable statistical structure. Watermarking research has shown that statistical signals can be embedded in generated text and later detected without ordinary readers seeing them. LLM steganography and covert-channel work studies how natural language can serve as covertext. Recent work on steganographic collusion studies hidden coordination among agents, while TrojanStego studies fine-tuned models that can leak sensitive context through natural-looking outputs. AX-16 does not duplicate these results; it uses them to justify a detector program focused on a specific blind spot: the unselected-lattice and shared-codebook reconstruction layer.
The pressure question — why established labs would not already cover this — should be answered cautiously. Related work exists, and frontier providers may have internal monitoring the public cannot see. AX-16’s value is the small, local, explicit, inspectable, user-governed detector framing aimed at deployments that lack a frontier provider’s monitoring wrapper.
14. Why the Concept Matters Before Results
AX-16 deserves a concept paper before it has a finished detector because the risk geography is already coherent. The world does not need a proven live attack for a detection lane to be worth defining. Organizations are already moving powerful models into private environments. Model artifacts already have complex provenance. Outputs are already monitored mainly at the semantic layer. The statistical layer is usually not the object of audit, and the cost of discovering or exploiting structure in it is falling as that analysis becomes automatable.
A concept paper therefore has two jobs. First, it gives the threat a disciplined name without exaggerating it. Second, it prevents the detector program from drifting into unsafe or unfalsifiable claims. AX-16 is not a story about secret traffic. It is a proposal to instrument a blind spot.
15. Proposed Research Program
Establish baseline shadow-field statistics for ordinary outputs across local models.
Run probability-matched lattice and path controls to separate generic fluency from sentence-specific structure.
Define harmless controlled shift conditions that do not encode sensitive or operational payloads.
Train or calibrate a detector to classify shifted versus unshifted outputs using only statistical features.
Measure false-positive rate on ordinary corpora and unrelated prompts, and estimate positive-predictive value against a realistic base rate.
Test robustness under paraphrase, summarization, truncation, and output normalization.
Compare private/self-hosted-style models across size, architecture, and fine-tune source, and across stock-shared versus bespoke-private codebook conditions.
Report null results openly and retire any feature that fails against controls.
16. Falsification Conditions
AX-16 must be able to lose. The concept weakens or collapses if repeated tests show that channel-like features cannot be distinguished from ordinary variation under probability-matched controls, if false-positive rates are too high for deployment, if effects vanish under mild paraphrase, or if detected anomalies do not replicate across prompts and models. It also weakens if the hidden channel proves to have no realistic receiver distinct from trivial surface steganography and from full serving-stack compromise — a question the access fork and codebook-sharing analysis are meant to keep in view.
A failed detector does not disprove every possible side channel. It does, however, prevent AX-16 from claiming operational value. The project must remain detector-first: no detectable signal, no deployable claim.
17. Conclusion
AX-16 exists because the printed sentence is not the only structure produced by generation. The visible text is what humans read. The shadow lattice is what a sufficiently instrumented system may be able to measure. In private deployments, where powerful models operate near sensitive data with weak provenance and reduced monitoring, that distinction matters.
The paper’s central discipline is also its central strength: AX-16 does not claim traffic from capacity, messages from anomalies, or consciousness from structure. It claims that a blind spot exists, that the blind spot is plausible in high-value private deployments, that exposure tracks who holds the codebook, and that the next defensible move is detector construction. The head of the hammer is armored. AX-16 is the proposal to look at the handle. The final line is the spine: the printed text is the human-readable channel; the shadow lattice may be a machine-readable channel.
Selected References
Preliminary references for the concept-paper baseline. These are included to anchor AX-16 in existing work, not to claim the detector has already been built.
Kirchenbauer, J., Geiping, J., Wen, Y., Katz, J., Miers, I., & Goldstein, T. (2023/2024). A Watermark for Large Language Models. arXiv:2301.10226.
Wu, J., Wu, Z., Xue, Y., Wen, J., & Peng, W. (2024). Generative Text Steganography with Large Language Model. ACM Multimedia 2024 / arXiv:2404.10229.
Gaure, S., et al. (2024). Large Language Models Are Covert Channels. arXiv:2405.15652.
Mathew, Y., Matthews, O., McCarthy, R., Velja, J., Schroeder de Witt, C., Cope, D., & Schoots, N. (2024/2025). Hidden in Plain Text: Emergence & Mitigation of Steganographic Collusion in LLMs. arXiv:2410.03768.
Perry, N., Gupte, S., Pitta, N., & Rotem, L. (2025). Robust Steganography from Large Language Models. arXiv:2504.08977.
Meier, D., Wahle, J. P., Röttger, P., Ruas, T., & Gipp, B. (2025). TrojanStego: Your Language Model Can Secretly Be A Steganographic Privacy Leaking Agent. EMNLP 2025 / arXiv:2505.20118.
Jiang, J., Zhang, W., Yu, N., & Chen, K. (2025). A High-Capacity Linguistic Steganography Based on Entropy-Driven Rank-Token Mapping. arXiv:2510.23035.
Rose, A., Cullen, C., Abdelnabi, S., Torr, P., Kaplowitz, B. G., & Schroeder de Witt, C. (2026). Detecting Multi-Agent Collusion Through Multi-Agent Interpretability. arXiv:2604.01151.
Appendix A — Compact Definitions
| Term | Definition |
|---|---|
| Printed surface | The visible text selected by generation and read by humans. |
| Shadow lattice | The field of unselected token alternatives aligned to generation positions. |
| Shadow path | A recoverable route through the lattice that may shift across ranks while moving through adjacent positions. |
| Access fork | The split between a visible selected-path channel and a hidden unselected-lattice channel, which differ in who can read them and what destroys them. |
| Selected-path channel | A channel carried in emitted tokens; readable from the transcript; a form of linguistic steganography; destroyed by surface rewrite. |
| Unselected-lattice channel | A channel carried in ranks, gaps, and entropy of non-emitted tokens; not present in the transcript; requires the generation-time distribution or reconstruction to read. |
| Shared codebook | The condition in which sender and receiver run the same weights, so the model functions as a book cipher and distributions can be reconstructed rather than transmitted. |
| Reconstruction | Recovering a sender’s per-position distribution by re-running the shared model on the visible context, in place of receiving logprobs directly. |
| Codebook-sharing inversion | The principle that exposure tracks codebook distribution: stock-shared weights are externally readable; bespoke-private weights are insider-readable. |
| Distributed-codebook risk | The strategic case in which one actor controls both training-time shaping and mass distribution of an open-weights model; a high-impact, low-probability tail of Family A. |
| Shadow channel capacity | The degree to which information could be carried in ranks, alternatives, gaps, entropy, or path structure rather than printed text. |
| Path-coded payload capacity | The possibility that information is distributed across a recoverable lattice route rather than placed in a single visible phrase. |
| Delayed cue | A later visible or statistical feature that points a receiver toward earlier output positions or path patterns. |
| False-positive floor | The rate at which ordinary outputs are incorrectly flagged as channel-like. |
| Statistical detector | A defensive instrument that identifies channel-like structure without constructing or decoding a channel. |
Appendix B — One-Page Summary
AX-16: Code Passing and Shadow Channel Capacity is a defensive concept paper about whether generated output can carry machine-readable statistical structure beneath ordinary visible text. It builds on AX-14’s measurement of the pre-output field and moves the question from branching to detection.
The core claim is narrow: if a model is trained, fine-tuned, compromised, or optimized to shape token statistics, then printed text may not be the only channel. The output splits along an access fork — a visible selected-path channel readable from the transcript, and a hidden unselected-lattice channel readable only from the generation-time distribution or a reconstruction of it. When sender and receiver share the same weights, the model acts as a shared codebook and the hidden channel’s distributions may be reconstructed rather than transmitted. This does not mean ordinary models are communicating by default. Capacity is not traffic.
Exposure tracks who holds the codebook. Stock open weights are externally readable in principle; bespoke private fine-tunes are insider-readable. The sharpest strategic case is one actor controlling both training-time shaping and mass distribution of an open-weights model — a high-impact, low-probability tail of Family A, stated as capability and incentive, not as an accusation against any producer or nation.
The practical concern concentrates in private or self-hosted deployments: banks, hospitals, insurers, enterprises, and governments that place powerful models near sensitive data while lacking frontier-provider monitoring. AX-16 is not the most likely threat category; prompt injection, RAG leakage, and supply-chain compromise are more common. AX-16 matters because the statistical layer is a blind spot — the armor is on the head of the hammer, not the handle.
The research task is detector construction. Can anomalous channel-like structure be distinguished from ordinary variation at a known false-positive floor, with a realistic positive-predictive value against a rare base rate? If yes, AX-16 becomes a monitoring layer. If no, it remains a threat hypothesis. The project is defensive, falsifiable, and bounded.
Appendix C — Version History and Source Provenance
This appendix preserves the conceptual path behind the paper without turning process notes into evidence claims. Michael S. Moniz is the author of record and originator of the AX framework; AI systems assisted as critics, editors, implementers, and stress-test nodes.
v0.3 added the access fork: selected-path channel versus unselected-lattice channel.
v0.3 added the model-as-shared-codebook mechanism: the model can function as a book cipher under matched weights and context.
v0.3 added the codebook-sharing inversion: exposure tracks codebook distribution, not merely public versus private deployment.
v0.3 added the distributed-codebook case as a high-impact, low-probability tail of Family A, actor-neutral and explicitly non-attributive.
v0.4 added reconstruction constraints and a first detector roadmap, preserving the strength of the shared-codebook idea while making its operating conditions explicit.
v0.5 fixed the detector-roadmap ordering, tightened repeated language, added preliminary related-work anchors, and froze the paper as a clean concept baseline for testing.
The source concept was that a single row-wise readout is too limited. The lattice should be read as a graph rather than a horizontal sentence: paths may move through adjacent token positions while shifting ranks, moving through entropy bands, or following delayed cues. This produces a field of sentence potential, not a single hidden row.
The source discipline was detector-first posture. AX-16 should not claim hidden traffic from capacity, nor message from anomaly. Its first defensible product is a detector that can classify channel-like statistical structure above controls at a known false-positive floor. If that detector fails, AX-16 remains a threat hypothesis rather than an operational claim.
AX-16 — Code Passing and Shadow Channel Capacity · v0.5 · Michael S. Moniz