EXHIBIT 10

A FAILED ATTRIBUTION EXPERIMENT

Can you name the encoder from one symbol?

Some implementations leave measurable traces. Try a held-out sample, then compare your guess with a random-forest classifier trained on disjoint payloads.

CORRECTED MULTI-SEGMENT PARSER / FIVE ENCODERS / CONTROLLED DATA

ATTRIBUTION GAME

Make a guess

The QR's payload is shown after your answer. The game samples are held out from classifier training.

SAMPLE

TRUE ENCODER

Hidden until you guess

CLASSIFIER PREDICTION

Hidden until you guess

MODEL CONFIDENCE

OVERT PAYLOAD

Hidden until you guess

Choose an encoder.

CORRECTED FIVE-WAY ACCURACY
RANDOM BASELINE
UNSEEN TEST SYMBOLS
SKIPPED SYMBOLS

PER-ENCODER RECALL

One encoder is identifiable. The others are barely separable.

How often each encoder's own held-out symbols were named correctly. The red line is the 20% random baseline.

    CONFUSION MATRIX

    Interesting is not identification

    Rows are true encoders; columns are predictions. A reliable identity signal would concentrate near the diagonal for every encoder.

    THE FOUR QUESTIONS

    Ask four questions of a symbol with nothing hidden.

    WHAT THE SCANNER SEES

    An ordinary payload, revealed after you guess. The held-out samples carry no hidden channel at all.

    WHAT CHANGED UNDERNEATH

    Nothing was altered. The only signal is which encoder's defaults produced the symbol.

    WHAT A SECOND READER CAN RECOVER

    No second message. A classifier recovers a guess at provenance: 53.52% five-way accuracy against a 20% baseline, and only segno separates reliably, at 91.2%.

    HOW AN ANALYST CAN NOTICE

    Train on disjoint payloads, test on held-out symbols, and read the confusion matrix rather than the headline accuracy. The off-diagonal mass is what shows the signal is too weak to identify an issuer.

    FINDING

    Better than chance is not strong forensic attribution.

    Loading corrected experiment results.

    Segno remains the easiest outlier. The other implementations overlap heavily, payload construction influences the features, and even the controlled one-vs-rest profiles have unacceptable false-reject rates. These traces can support investigation; they do not authenticate an issuer.

    Read the methods and limitations