ConceptioArchivearXiv CS
arXiv CSopen access

Occluded Oculus: Operationalizing Stylistic Obscurement

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

Occluded Oculus: Operationalizing Stylistic Obscurement Robert Dilworth

arXiv:2607.24411v1 [cs.CR] 27 Jul 2026

Department of Computer Science and Engineering, Mississippi State University, Mississippi State, Mississippi, USA [email protected]

Abstract. What did it take for Hermes, the devout messenger of the Olympian gods, to slay Argus Panoptes, the multi-eyed giant of Greek myth1 ? As the perfect guardian, Panoptes’ legion of ever-watchful eyes proved difficult—but not impossible—to defeat. The centerpiece of Hermes’ strategy was obfuscation and sabotage. Posing as a shepherd, Hermes sealed each of Panoptes’ eyes—eyes that would otherwise have alerted the fearsome giant to Hermes’ plot—and vanquished him. The moral of the story: when a challenger must surmount a formidable foe—one far greater in stature and vastly more equipped—crafty maneuvers are not merely advisable but indispensable for victory. In this work, the “challenger” is a collective leveraging adversarial tactics to overcome the “multi-eyed giant” of stylometric systems and surveillance apparatuses. To successfully claw back the privacy siphoned by the multi-eyed giant, the challenger must carefully evaluate their plan of attack, TraceTarnish, and determine what does and does not work to anonymize the authorship of text. To that end, we conduct an ablation study of TraceTarnish to better understand which module—Translation, Obfuscation, Imitation, or Injection—best confounds a stylometric system. Our results indicate that the most effective approach was Injection, meaning that inserting zero-width Unicode characters, homoglyphs, and intentional misspellings neutralizes the indefatigable eyes long enough to claim the head of the all-seeing giant. Keywords: Privacy · Adversarial Stylometry · Stylometry · Steganography · Zero-width Unicode Characters · Homoglyph Substitution · Translation · Obfuscation · Imitation · Injection · Authorship Verification · Authorship Attribution · TraceTarnish

1

The mythological account was sourced from Mellenthin and Shapiro [63], but, as with such works, numerous similar yet distinctly different retellings of the events exist.

2

1

Robert Dilworth

Ablating the Components of Our TraceTarnish Attack to Gauge Granular Adversarial Effect Nothing is absolute. Everything changes, everything moves, everything revolves, everything flies and goes away. Frida Kahlo

Authorship attribution is a supervised text-analysis task that determines the most likely author of an anonymous or disputed document by comparing its stylometric features—such as function-word frequencies, character- and wordlevel n-grams, part-of-speech patterns, and lexical richness—to a corpus of texts with known authors, using statistical or machine-learning classifiers to assign the document to the author whose writing style it most closely matches (Savoy [75]). Authorship attribution is not, however, a fixed, immutable fact. It depends on the linguistic features and statistical models employed, the amount and type of text available, and the similarity among potential authors. Because these factors can change—new texts may be added, models can be refined, and subtle stylistic variations can be introduced—the confidence in any attribution can vary over time. Thus, the certainty of an attribution is never absolute and is, at best, fluid rather than definitive. Aiming to target that fluidity, we continue work on TraceTarnish—our adversarial stylometry2 attack (Dilworth [21–24]). By subtly perturbing stylistic cues and embedding mutable artifacts, the attack strives to make the results of stylometric analysis inconsistent whilst secondarily polluting textual data, nudging attribution toward uncertainty and affording plausible deniability without overtly breaking the text. Like most security measures, its primary purpose is to add friction: it seeks to make attribution more difficult, though not impossible, for a would-be adversary, thereby raising the statistical threshold the adversary must overcome. If sufficient plausible deniability is generated by performing the attack—enough to enable repudiation— then the attack can be deemed successful, as any failure of identification, in any capacity, should be interpreted as a win. This does not preclude the myriad ways in which our proposed attack could be dismantled or rendered ineffective through data hygiene, including but not limited to: incorporating Unicode-aware preprocessing in favor of standard normalization, employing robust word-segmentation and cleaning pipelines, running character-level feature extraction to discard non-canonical glyphs, and enforcing platform-level sanitation to trivially strip (or prohibit) zero-width characters and homoglyphs. Any one of these measures could neutralize the Injection component of our attack. 2

For definitions of the relevant terms used throughout this work, refer to (Appendix B).

Occluded Oculus

3

That being said, we stress that the attack’s goal is to reduce attribution accuracy, and it is only practically feasible when platforms accept multilingual text—raising the likelihood that homoglyphs survive—and when zero-width characters are retained for legitimate purposes such as right-to-left scripts, a situation increasingly common as services expand support for diverse languages to provide a seamless user experience. The attack becomes practical when those two conditions hold, and with most platforms vying for larger user bases, they are incentivized to ensure a unencumbered environment for all patrons, which necessarily means multilanguage support, introducing the leeway that our attack—or at least the Injection component—can exploit. A reasonable assumption we hope to capitalize on is effort: given the opportunity and depending on the recipient’s disposition and the platform facilitating the exchange, most people who could be involved will likely take shortcuts whenever possible. If minimal effort is applied to scrutinizing our attack’s outputs, the chance of success raises. A more vigilant, skeptical, and distrustful recipient or platform would be better poised to neutralize the attack, given advanced warning and adequate precautions. In any event, the next stage of our work will be an ablation study, in which the four TraceTarnish components—Translation, Imitation, Obfuscation, and Injection—are evaluated. The marginal contribution of Injection relative to the remaining three components, and vice versa for the remaining techniques, will be directly measured and reported, constituting the main contribution of this work.

Fig. 1: A stylized visual illustrating the paper’s logical framework and organizational structure.

4

1.1

Robert Dilworth

Techniques Underlying the Attack Components

Before we go further, we first cleave our attack into its constituent components. Each element’s function and the tools used to achieve the desired adversarial effect are described to help contextualize their roles in the overall attack. Translation. We used translateLocally 3 to sequentially chain translations to and from multiple languages. The round-trip sequence used throughout the study was English → Spanish → German → English. We chose an open-source solution over household names to reduce data exposure; locally executing personally vetted, freely available code is far superior to relying on opaque boxes that may leak data. Imitation. We employed a self-hosted, locally run Large Language Model (LLM) via Ollama4 to achieve Imitation, transforming text so that it reads as if written by another entity. The model used throughout was Negentropy-claude-opus-4.79B-GGUF 5 . Our hardware and computational capabilities strongly influenced the model selection; the trade-off between speed and output quality, as well as CPU consumption, guided our choice. Using Ollama instead of a direct cloudbased offering helped avoid non-consensual data training, ensuring data minimization and privacy. The same prompt—see (Figure 2)—was used to achieve the desired effect, and all “persona preambles” were removed from the final responses (see (Figure 3)). Rather, our prompt asks the LLM to assume a random personality, and we observed that it often prefaced its response with the persona’s backstory.

Fig. 2: The prompt issued to our offline, self-hosted LLM that facilitates the adversarial technique of Imitation. A helter-skelter selection of persona is desirable, provided it creates a stylometric distance from the original text fed to the LLM. 3

https://github.com/XapaJIaMnu/translateLocally https://ollama.com/ 5 https://huggingface.co/Jackrong/Negentropy-claude-opus-4.7-9B-GGUF 4

Occluded Oculus

5

Fig. 3: A showcase6 of the LLM’s “persona preambles.” Upon reflection, there appears to be a bias in the selection of “nationality,” with the LLM choosing a Brazilian persona more often than any other option. In most runs, the initial persona the model generates belongs to that demographic. For this iteration, the model assumed Australian, Portuguese, Nigerian, Filipino, Japanese, Indian, and South Korean personas. Perhaps this observation is worth delving into. More importantly, it is worth acknowledging that the caricatures of the various personas and the stereotypes depicted in the model’s responses reflect the model, not the authors. As outsiders, we are oblivious to them and make no claims about their validity.

Imitative Translation and Hallucinatory Self-talk. It is worthwhile to point out that the same reasoning behind round-trip translation could plausibly be applied to our LLM-imitation approach. With Translation, the adversarial effect derives from the loss of meaning imparted by multiple rounds of machine translation. Imitation, in a way, could be structured similarly. Depending on the selection of persona (for clarification, the selection mechanism is not truly random), a forward-feeding stream of back-to-back LLM rewrites would probably result in a 6

The composition and layout of the figure was loosely influenced by Dadaist artist Hannah Höch.

6

Robert Dilworth

stylometric equivalent of the “telephone game” (a game where participants pass a secret message by whispering it from one person to another, after which the initial wording is examined against the version that emerges at the end). When persona A whispers the text’s contents to persona B, persona A’s fabricated experiences would perhaps influence how persona B interprets the message. The inaccurate but close-enough transference of information and its chained modifications from the personas would likely lead to a similarly garbled result. In this setup, the “personas talking to themselves” would be a tangible representation of prompting a self-hosted LLM with text whose authorship we wish to obscure: we take the output of the first exchange, feed it back into the model, and invoke a crafted prompt that instructs the LLM to adopt a new persona for each iteration. This recursive prompting would mirror the telephone-game dynamic while deliberately scrambling stylometric cues (Kandula et al. [47]). Although, given that we are issuing these prompts on our own hardware, we will set the idea aside for the moment, as our compute is a prohibitive bottleneck. As we hope to demonstrate with a relatively lightweight, self-hosted model— and as Srivastava et al. [78] concluded from their research on then-frontier models—authorship impersonation via LLMs “erodes the assumption that an authorial ‘fingerprint’ is a stable and difficult-to-forge identifier.” Obfuscation. We used PEAGUSUS 7 to programmatically paraphrase text line by line. An LLM could, admittedly, also fulfill this role if prompted appropriately (Fisher et al. [32]). During review, we noticed that certain input sentences produced incoherent results, such as repetitions of the sequence “888-353-1299” in place of the expected summaries. We did not investigate the cause and chose to retain the questionable outputs. Injection. We employed pyUnicodeSteganography 8 and SilverSpeak 9 to embed zero-width Unicode characters into the text (a Liminal Injection attack) and perform homoglyph substitutions (a Doppelgänger Injection attack), respectively. As a subtle form of misspelling (a Surrealist Injection attack), we applied eng 10 to convert American English to British English in the texts. Liminal Injection is an adversarial technique that inserts zero-width Unicode characters (e.g., [U+200F]) as hidden infixes “in-between” the letters of words, creating a transitional layer that lies at the interstice between the visible text and the invisible characters—hence the name “liminal.” Doppelgänger Injection, drawing from its etymological namesake, performs homoglyph substitutions—for example, replacing the Latin small letter “o” [U+006F] with the Cyrillic small letter “о” [U+043E]—a changeling-like phenomenon that leaves behind 7

https://huggingface.co/docs/transformers/model_doc/pegasus https://github.com/bunnylab/pyUnicodeSteganography 9 https://github.com/ACMCMC/silverspeak 10 https://github.com/orsinium-labs/eng/ 8

Occluded Oculus

7

a nearly indistinguishable substitute. Surrealist Injection is an adversarial technique that deliberately introduces unconventional misspellings into a text, echoing the whimsical defiance of the Surrealist painters—artistic renegades in their own right. Liminal Injection. For further reading on text steganography, we recommend Ahvanooey et al. [9]. Their insights into zero-width Unicode characters and their observations of how platforms handled them were instrumental to our attack. Doppelgänger Injection. While Doppelgänger Injection could be thwarted by converting the suspected text into an image and then using something akin to optical character recognition (OCR) to re-extract the text—detecting and recovering the letters that the homoglyphs resemble [85]—this adds further friction to the normalization process. Regarding the use of non-OCR normalization to perform the previously described cleansing, Cooper et al. [18] remarked that “no tool was found which automated the conversion of all possible homoglyphs into the Latin characters they resemble,” after which a manual editorial effort was required to identify and remediate homoglyph-laden text. Scripting alone could only partially normalize the text. Although this technique could be used maliciously, infusing text with homoglyphs remains a proven strategy to avoid detection—and, by extension, to sabotage stylometric analysis. Surrealist Injection. Considering alternate spellings of words in the English lexicon as misspellings—as we have done in this study11 —is due the deterministic nature of the machine tasked with analyzing the text. If it is looking to match all instances of “hypothesize” in a text and encounters “hypothesise,” there is potentially room for error in that discrepancy. Injection Percentages. For clarity, our attack implements maximal levels of Injection, which means that almost every word in a text will contain zero-width Unicode characters, all other visible characters will be swapped with homoglyphs, and, where applicable, words with alternate spellings will be replaced (e.g., “emphasise” versus “emphasize”). 1.2

Systematically Removed Ablation Components: Translation, Imitation, Obfuscation, and Injection

Here, we isolate the modular components comprising our TraceTarnish attack, as described in the preceding sections, to measure and compartmentalize their adversarial effect. Since we have broadly stratified the techniques into four clusters, we can derive fifteen scenarios, with the first being the control—the original, unaltered text. The cumulative integration of the four techniques—Translation, 11

By default, most spell-checkers treat alternate spellings as mistakes unless the user selects the corresponding regional dictionary.

8

Robert Dilworth

Imitation, Obfuscation, and Injection—constitutes a TraceTarnish attack. See (Figure 4). While the ordering in which each technique is applied is presumably significant, we will largely ignore this consideration. A clear example is any scenario involving Injection, which by its very nature and intended design, sabotages all other text-processing steps. In such cases, it makes sense for that step to take place last, as its potential to interfere with other steps would almost certainly produce undesirable results. In a similar vein, the same procedural treatment would likely also apply to Imitation, since this step was originally devised to smooth out the clunky, sometimes incomprehensible outputs produced by Translation and Obfuscation.

Evaluation Metrics for the Ablated Components: Soundness, Sensibility, and Safety. To asses how each component affects the overall system, we evaluate them using three complementary metrics. Soundness ensures that the original meaning of texts, or their semantics, is not irreparably distorted by a technique. Sensibility ensures that metamorphosed texts remain human-readable and comprehensible. Safety ensures that texts are sufficiently resistant to de-obfuscation, encapsulating their ability to elude (re)attribution to their original sources of provenance. Translation and Obfuscation noticeably diminish a text’s Sensibility, which correspondingly ushers in expected detriments to Soundness. Imitation, by its reliance on an LLM, tends to address those shortcomings, informing the decidedupon pipeline for TraceTarnish: Translation → Obfuscation → Imitation → Injection. In terms of the previously specified tools, the settled-upon sequence of their use is: translateLocally → PEAGUSUS → a self-hosted, offline LLM rewrite → eng → pyUnicodeSteganography → SilverSpeak . It is paramount that the relied-upon LLM—though it need not be the one we selected—be fully under your control; likewise, the ordering of the Injection steps is relatively fixed. eng will have trouble detecting words if they are poisoned beyond recognition by pyUnicodeSteganography and SilverSpeak, hence their sequencing. While Translation and Obfuscation positively impact Safety, that Safety comes at the expense of Soundness and Sensibility, which Imitation amends. From the perspective of a human observer, Injection has nearly zero impact on Soundness and Sensibility as we have described them (assuming proper rendering occurs), and it imparts a similar positive increase in Safety on account of the mechanics of Liminal and Doppelgänger Injection.

Occluded Oculus

9

Fig. 4: The components of our modular attack, TraceTarnish, are decomposed into distinct scenarios to quantify the adversarial effect achievable with the inclusion or exclusion of techniques.

10

1.3

Robert Dilworth

Dataset Preparation for Authorship Attribution Experiments

We will get slightly ahead of ourselves here as we explain the collection of files prepared for the study. In the following section, we will go further in depth on why we chose the primary text and the additional texts used to facilitate the testing. As per stylo’s documentation [28], the description of classify() is a “function that performs a number of machine-learning methods for classification used in computational stylistics: [Burrows’ Delta], k-Nearest Neighbors, Support Vector Machines, [Naı̈ve] Bayes, and Nearest Shrunken Centroids.” We provide this description verbatim to communicate that our results have been assessed by contemporary stylometric methods. In previous studies we relied upon the imposters() method, “a machinelearning supervised classifier tailored to assess authorship verification tasks.” The imposters() function was sufficient in those studies because the main goals were to establish the viability of the attack and demonstrate its confounding abilities. For those goals, an experimental setup focused on authorship verification was appropriate. Given multiple incrementally modified adversarial texts and the original, can we confirm that the adversarial texts still belong to the original author? The answer was no, given sufficient Injection percentages (Dilworth [23, 24]). Here, our task is authorship attribution. Given a corpus of texts authored by notable cypherpunk writers, can stylo’s machine-learning classifier—classify()— accurately attribute the correct author to the adversarially modified texts, which have undergone differing adversarial treatments? To answer this question, we created a suitable corpus, as shown in (Figure 5). The adversarially treated files are presented in (Figure 6). Concerning the file-naming convention and our use of stylo, an R stylometry package [27], we adopt a schema that best interfaces with the package. The control files are prefixed with the author’s surname, followed by an underscore and a condensed version of the text’s title. All other files produced via adversarial tampering are prefixed with “Adversarial.” To add further descriptiveness to the filenames, we include abbreviations indicating the attack techniques applied to the text. We now circle back to that primary text and its appropriate selection for this study.

Occluded Oculus

11

Fig. 5: As classify() expects a training and test corpus, we have organized our files into suitably named directories, the contents of which are shown here. The training set consists of texts authored by John Gilmore [33], Eric Hughes [40–44], and Timothy C. May [59, 60]. The test set comprises adversarially modified versions of Hughes’s A Cypherpunk’s Manifesto [40], which selectively and gradually applies the techniques that constitute our TraceTarnish attack, as visualized in (Figure 4).

Fig. 6: For ease of recognizing which files were associated with which scenario and which part of our attack was needed for their proper processing, we formulated a naming framework for the handled files.

12

Robert Dilworth

1.4

The Avulsion of Anonymity: An Apt Corpus Selection

To conquer a fear—whatever it may be—it is often advised to run toward its source. Putting a face and a name to it, which essentially amounts to personification, is one of many steps to stymie its hold over an individual. Unless that recognition takes root, an issue remains locked in a mental vault—eternally relegated and unlabeled—so that the problem does not become properly elevated to the status of a problem. Everything to its proper place: identification comes before treatment. What is the problem? Pyrophobia? What does that mean, and how does it affect you? Exposure therapy could help, but subjecting yourself to a “trial by fire” also has another prerequisite: a loss of privacy. Admitting the existence of the fear internally is a necessary step, but doing so externally would marginally improve the prognosis. When the internal acknowledgment stalls, the external reality soon catches up. It is precisely at this stage that we find ourselves. Without that acknowledgment, the issue continues to fester unnoticed, and the problem will persist indefinitely if it is not recognized as such. The attack on anonymity is one such problem. Talks of weakening and back-dooring encryption [50]—a problem. The outright banning or tightening of regulations on virtual private networks (VPNs) [10]—a problem. The broad enforcement of age and identity verification [1,16,55, 66]—a problem. The proliferation and indifference towards evolving surveillance capabilities [7, 14, 19, 20, 25, 31, 34, 36–38, 45, 52, 53, 56, 57, 69, 71, 84]—a problem. Our list could easily be expanded12 (adding LLMs capable of pinpointing authorship [61]—and traditional stylometry [8,29,67]—to the fray are no-brainers), but the point has been made: whatever illusion we once had of a better future is being disillusioned in near real time—a fleeting and dying will-o’-the-wisp. However, to overcome something, the thing must first be recognized. While it does not address every issue we have raised, Eric Hughes’s A Cypherpunk’s Manifesto serves as foundational kindling for that conversation. Even if it overlooks certain aspects—how could it not, given the time it was written?—it still offers a valuable touchstone. For this reason, we cyclically reduce, reuse, and recycle the text as our corpus. The words shed light on a problem, and to suppress the problem we, too, must deprive it of oxygen. Stylometry, with its dualistic, agathokakological nature, has the potential to become a problem: it can empower researchers to uncover hidden patterns and protect communities, yet it also furnishes adversaries with a precise map for tracking and profiling individuals. Armed with this awareness, we can direct our countermeasures. Our arsenal of adversarial techniques flares forward, forged specifically to snuff out that fire— the exigent inferno that currently engulfs us with the Promethean flame. 12

The lesser of the ills—cognitive offloading enabled by AI—may be alleviated by a Hammurabian response [35], a response whose disproportionate—though perhaps justified—reciprocity is reminiscent of asphyxiation.

Occluded Oculus

1.5

13

Circumventing Authorship Recognition: The Problem Statement

Having broadly introduced the study’s core problem, we now describe the specific issue being examined.

Problem Statement. To communicate anonymously online in the public sphere—without encryption13 or other cryptographic protocols14 —and under the assumption that anything public is, by definition, not private, which adversarial stylometry technique best serves that goal? Does a single technique suffice, or is a confluence of techniques used in tandem required? Which techniques are better suited for the task, and which are not? Is it feigning the idiosyncratic writing style of another entity (Imitation)? Is it executing multiple rounds of machine translation from dissimilar languages (Translation)? Is it paraphrasing the text to scrub the author’s cadence and voice (Obfuscation)? Or is it inserting invisible characters (zero-width Unicode characters), visually similar but differently interpreted characters (homoglyphs), or misspellings of words (Injection)? In the face of such techniques, to what degree are the Soundness, Safety, and Sensibility of the text impacted? For the sake of eliminating other externally identifying factors, we also assume that the user’s IP address is masked by a reputable15 or self-hosted16 VPN17 , a privacy-focused browser18 is used to connect to the platform facilitating the post—a browser that minimizes device fingerprinting19 by reducing identification of operating system, user agent, time zone, etc.—Domain Name System-level filtering20 and encryption21 are in place, the operating system itself is hardened22 and privacy-focused23 , the user adopts a pseudonym and aliased contact details (“mask”)24 to masquerade as someone else, and sufficient discipline is exercised to avoid cross-contaminating profiles and guises. The relevance of these measures is illuminated by Manish Tripathy [82], which—though indirect—demonstrates why a public persona should never share a digital fingerprint with a private persona. 13

https://emailselfdefense.fsf.org/en/ https://signal.org/download/ 15 https://mullvad.net/en/blog/mullvad-vpn-was-subject-to-a-search-warra nt-customer-data-not-compromised 16 https://www.bluehost.com/blog/vps-for-vpn/ 17 https://ssd.eff.org/module/choosing-vpn-thats-right-you 18 https://www.privacyguides.org/en/desktop-browsers/ 19 https://coveryourtracks.eff.org/ 20 https://www.privacyguides.org/en/advanced/dns-overview/ 21 https://www.privacyguides.org/en/dns/ 22 https://distrowatch.com/dwres.php?resource=beginners-why 23 https://grapheneos.org/install/ 24 https://www.privacyguides.org/en/email-aliasing/ 14

14

Robert Dilworth

1.6

Incorporating Multiple Levels of Redundancy: The Basis Behind the Attack’s Anatomy

The problem statement introduces a facet worth highlighting. Envision this: your surroundings conceal a hidden menace—one that could rob you of your sight—and you are determined to safeguard your vision at all costs. A simple blindfold might work, but it would obstruct your line of sight, which could, in turn, cause you to injure your eyes in unforeseen ways. Your goal: preserve your sight and avoid going blind25 . Assessing your risk profile, you identify the immediate threats to your objective: ultraviolet radiation, particulate matter [46], volatile chemicals, thermal exposure, intense light, infectious agents, mechanical trauma, ocular diseases, and arcane arts. Beyond what can be achieved with regular examinations and proper nourishment, you settle upon four controls to manage the potential perils: eye drops, contact lenses, safety goggles, and face shields. Each, in isolation, offers only a modest degree of protection, but layering the safeguards proves prudent—the failure of any single control would not immediately expose you to the hazard(s). In practice, this is often expressed as defense-in-depth or a multi-layered control strategy. This approach builds redundancy and depth across various measures—technical, administrative, and physical. For our simplistic example, categorizing the controls by type of measure is beyond scope. With a plan of action formulated, you equip your armor. You apply eye drops to each eye, insert the contact lenses one by one, don your safety goggles, and slip on your face shield. In this state, a catastrophic system failure would have to occur to invalidate your suite of controls. Your eye drops’ medicinal effect would need to expire, your contact lenses would need to become dislodged, your goggles would need to be ruptured, and your face shield would need to be pierced. A similar foundation fuels our attack’s structure. If a platform or stylometric system purges zero-width characters, then there are the homoglyphs. If the homoglyphs are eradicated, then there are the misspellings. If the misspellings are accounted for, then there are the LLM rewrites. If the rewrites prove insufficient, then round-trip translation of the source text remains. If that too fails, then paraphrasing the source text ensures that at least some semblance of meaning is marred. In a scenario where the objective is to defeat stylometric analysis, this is what it means to incorporate defense-in-depth principles. The safety of your “eyes” depends on it, lest you risk loosing your “sight.” 25

We recognize that our attack could have unintended consequences for valuable textanalysis applications such as screen readers. The potential collateral damage it may cause outweighs the primary motivation of privacy, as it could objectively worsen the experience of people with visual impairments and degrade engagement with social media and similar platforms [54]. This trade-off highlights room for improvement; a better method would achieve the desired effect with pinpoint accuracy and avoid these drawbacks.

Occluded Oculus

1.7

15

Survivability in Strenuous Settings: Potential Defenses for the Attack

Risk. Everything revolves around that “globe,” whose gravity attracts and repels [62] a host of dangers, both seen and unseen. Here we scrutinize the attack’s weak points—weak points that can be exploited to cripple its malevolent effect. ❖ First, while homoglyphs slip past most human readers, they are not invisible on every platform. Various fonts render characters differently, and some environments expose Unicode explicitly. Thus, Doppelgänger Injection can become apparent to users of certain software or devices. ❖ Second, the attack targets primarily English-language detection systems. Many languages already employ multiple scripts, and their detectors tend to tolerate character variation. Thus, the generalizability of our findings to other languages remains uncertain. Subsection 1.6 outlines the threat model in which the technique thrives; we have since highlighted where it may falter to encourage responsible disclosure. If a vulnerable party deems the attack relevant to their threat model, transparent knowledge of its capabilities and limits may be what shields them from nightmarish horrors [70]. A threat model is a systematic characterization of the adversarial landscape that delineates the capabilities, objectives, and constraints of potential attackers, as well as the assets and assumptions pertinent to the defended system. By explicitly enumerating who might act maliciously, what resources they can marshal, and which vulnerabilities they might exploit, a threat model provides the analytical framework necessary to assess risk, prioritize defenses, and ensure the security measures align with the realistic dangers faced by the environment in question. As we mentioned in earlier sections, specialized preprocessing could trivially render the Injection component inert. Khan et al. [49], however, present a series of pertinent counter-claims: “[P]re-processing in stylometry can adversely impact the algorithms’ performances.” “[S]pecial characters[—zero-width characters and homoglyphs—]can be vital in differentiating and recognizing an author’s style.” “[O]ne author may use certain special characters [more frequently] compared to others.” Taken together, the implication here is that it is better to leave the text in its original state if the intention is to perform stylometric tasks such as authorship attribution, verification, or profiling. If the success of the analysis depends on processing raw text, and that raw text is “dеаtһ-dealing” [17] because it contains poison specifically designed to sabotage the analysis, then the prospects of our attack succeeding are far greater than originally anticipated. Keeping the text whole gives it the potential to cause damage; preprocessing the text to sanitize it reduces the efficacy of analysis. Just as gravity can both bind and release, a judicious mix of normalization and selective preservation can counteract the attack while retaining essential stylometric cues.

16

2

Robert Dilworth

A Surgical Extraction of the “Eye”: The Results of the Authorship Attribution Experiment Is it possible that my brain, this precise, clean, glittering mechanism, like a chronometer without a speck of dust on it, is. . . ? Yes it is, now. I really feel there in the brain some foreign body like an eyelash in the eye. One does not feel one’s whole body but this eye with a hair in it, one cannot forget it for a second. . . We Yevgeny Zamyatin

Of the many structures that make up the sensory organ called the eye, the retina is arguably the most important, as it contains the photoreceptor cells that convert light into electrical signals, which the brain, in turn, interprets as visual images. Without a functional retina, vision would be practically impossible—the likelihood of perceiving any coherent visual information drops to near zero. For our purposes, the structurally-related sentiment is transitive: if the “eyes” represent an author and the “eye’s perspective” the stylistic signature we wish to blot out, then our adversarial undertaking could be likened to gouging out those eyes. Yes, they—by the association we have constructed—are indescribably irreplaceable, one of a kind. But the eyes should remain subject to the host, not the other way around. If they become a liability or antagonistic, plucking them out may be an option worth pursuing. The presumption here is that if your stylistic signature can be used against you, then that risk supersedes any potential advantages it could have afforded you. In such a case, if the risk cannot be transferred, reduced, or accepted— as would be the case in a low-risk landscape—a response would be necessary. Granted, we will refrain from illustrating such a high-risk scenario—or not. Luckily for us, the motivating analogy of Alden Page [68] more than suffices. From the perspective of the general populace, deliberately obfuscating your stylometric profile may come across as the “paranoid machinations of the maniacal.” For most, that assessment—while blunt—may hold some truth; it is markedly excessive, to the point of being overkill for most security scenarios. In almost every other circumstance, that level of concern is borderline irrational. However, that concern is not entirely misplaced or unwarranted. Want a curated experience? Share some data. Want better recommendations? Share more data. Want camaraderie? Share a deluge of data that could later be hoovered up and used to identify you (if your earlier (in)voluntary revelations did not already satisfy that threshold).

Occluded Oculus

17

While more narrative scaffolding could potentially tie everything together, we will cease the analogy here and take a more direct approach.

2.1

What the Dissected “Retina” Tells Us: Insights into Authorship Attribution

For our experiment, we constructed a corpus of related authors and singled out a single text to undergo adversarial treatment with the intent of coercing stylo’s classify() to misclassify its author (i.e., have the classifier reach an incorrect conclusion about the likely author). Besides populating the expected training and test-set parameters, we did not modify any other aspect of the function. The outcome of the experiment roughly aligns with what could be anticipated from the setup and adversarial techniques employed. TraceTarnish’s additive adversarial effect overwhelmingly stems from the Injection component; it is the attack’s essential component, as its sole application—without the other components of Translation, Obfuscation, and Imitation—resulted in misclassification (where misclassification means that May was attributed to Hughes’s work). The final results of classify() corroborate this; see (Figure 7). (Table 1) contains the computed distance table that influenced the attributions.

Fig. 7: The final results of the classify() experiment show that only texts altered by Injection successfully induced misclassification.

18

Robert Dilworth

Gilmore Hughes Hughes Hughes Hughes Hughes May May Adversarial-IM 1.4809 1.3692 1.0477 1.3855 1.4421 1.3102 1.3495 1.3163 Adversarial-IM+O 1.6918 1.5171 0.9933 1.5046 1.6843 1.2794 1.5981 1.5649 Adversarial-IM+T 1.3875 1.2032 0.8119 1.1997 1.3188 1.0720 1.2391 1.2046 Adversarial-IM+T+O 1.4693 1.2625 0.9328 1.3659 1.4867 1.1840 1.3891 1.3546 Adversarial-IN 2.7552 3.0981 3.5869 3.5320 2.7861 3.4888 2.7051 2.6731 Adversarial-IN+IM 2.6720 3.0148 3.5036 3.4487 2.7028 3.4056 2.6218 2.5899 Adversarial-IN+IM+O 2.6568 2.9859 3.4747 3.4198 2.6877 3.3766 2.6066 2.5747 Adversarial-IN+IM+T 2.4820 2.8157 3.3045 3.2496 2.5129 3.2064 2.4318 2.3999 Adversarial-IN+IM+T+O 2.7325 3.0754 3.5642 3.5093 2.7634 3.4661 2.6823 2.6504 Adversarial-IN+O 2.8016 3.1445 3.6333 3.5784 2.8325 3.5352 2.7515 2.7195 Adversarial-IN+T 2.8497 3.1926 3.6814 3.6265 2.8806 3.5833 2.7996 2.7676 Adversarial-IN+T+O 2.7321 3.0749 3.5638 3.5088 2.7629 3.4657 2.6819 2.6500 Adversarial-O 1.5406 1.2635 0.4312 1.2169 1.4552 1.0557 1.4330 1.3984 Adversarial-T 1.4909 1.1674 0.4281 1.1754 1.3988 0.9596 1.3570 1.3277 Adversarial-T+O 1.5558 1.2770 0.6802 1.3349 1.4995 1.1017 1.3970 1.3665

Table 1: The distance table for the classify() experiment shows that elevated distance measures for the Injection texts serve as a positive signal for our attack— the higher the distance value, the better. The highest recorded distances correspond to “Adversarial-IN+T.”

So long as Injection was performed on the text, the inclusion or exclusion of the other techniques had far less impact on its ability to confound a stylometric system. Nevertheless, as we have established, it is wiser to err on the side of caution, as dictated by defense-in-depth principles. While Injection is the strongest component—the one that best counters authorial attribution and can do so in isolation by its own merits—the presence of supplementary fail-safes is never a bad idea. By that same token, the weakest components are Imitation, Obfuscation, and Translation, in that order. The collection of texts that underwent Imitation, excluding those that also underwent Injection (see the principal-components analysis (PCA) visualization in (Figure 8)), is on average the most distant from the closest text authored by Hughes. The texts that underwent Obfuscation, excluding those that also underwent Injection and Imitation, fare worse, but not as poorly as the sole application of Translation. The text that only underwent Translation nearly overlaps with one of Hughes’s texts. Thus, in descending order of their ability to mask authorship, the techniques are: Injection, Imitation, Obfuscation, and Translation. The clustering of all texts that underwent Injection and their relative distance from all other non-adversarially modified texts demonstrates that Injection is not only essential but required to achieve a potent adversarial effect. See (Figure 9) and (Figure 10) for cluster-analysis and bootstrap-consensustree visualizations, which similarly echo our findings.

Occluded Oculus

19

Fig. 8: A principal components analysis of the feature space shows how texts altered by Injection are positioned farthest from the nearest Hughes-authored text.

20

Robert Dilworth

Fig. 9: A hierarchical clustering of all Injection-modified texts versus all other texts illustrates the pronounced separation that Injection creates from a stylometric perspective.

Occluded Oculus

21

Fig. 10: A bootstrap consensus tree derived from repeated clustering of the dataset confirms the stability of the Injection-driven grouping and the weaker influence of the other adversarial techniques.

2.2

See No Evil, Hear No Evil, Speak No Evil: Hiding in Plain Sight

The takeaway, as evident from (Figure 8), is that while Injection does conceal authorship, it leaves behind a noticeable trace that could, potentially, draw attention to its use. That trade-off is not necessarily a bad thing; it means that texts adversarially modified using Injection will resemble each other stylometrically. Based on our findings, a real-world application would likely adhere to Tor’s operational mechanisms. If everyone uses it, pinpointing an exact user becomes harder—

22

Robert Dilworth

barring any unintentional lapses in judgment26 or forces beyond one’s control27 . If only a small, distinct group uses Tor (TraceTarnish), that group becomes identifiable; when everyone uses it, anonymity becomes achievable because they blend into the crowd28 . However, anonymity is never absolute—it depends on the size and behavioral diversity of the user base, adversaries’ capabilities, and how carefully users follow privacy-preserving practices. If the stylistic fingerprint of every user resembles that of every other user, then anonymity has been obtained. Another identifying factor would need to be introduced, or existing methods revised, to deanonymize users on that metric. Blending into the crowd and not standing out is the basis of anonymity and, by extension, privacy, which our findings suggest is feasible with our attack, albeit with caveats. The caveat being that our specific swill of “poison”— Injection—is embedded within the text, and its half-life—how long the payload remains effective before it degrades or is neutralized by downstream processing such as tokenization, sanitization, or platform-level defenses—is long enough for the entire payload to stay intact and deliver its adversarial effect. The actualization of such a feat becomes increasingly difficult when all facets of life—both online and offline—are constantly bathed in an unrelenting gaze from innumerable embodied and disembodied surveillants.

3

The Panopticon’s All-Seeing Eye: Mental Strain in an Era of Constant Surveillance If suddenly your eyes were covered with a bandage and you were let go to feel around, to stumble, ever aware that somewhere very close to you there is the border-line, one step only and nothing but a compressed, smothered piece of flesh will be left of you. . . I now feel somewhat like that. We Yevgeny Zamyatin

I have no mouth. And I must scream. I Have No Mouth, and I Must Scream Harlan Ellison

A betrayal of the brain, an absence of ataraxia. https://blog.torproject.org/malicious-relays-health-tor-network/ 28 https://support.torproject.org/about-tor/how-tor-works/overview/ 26 27

Occluded Oculus

3.1

23

The Price: Emotional and Cognitive Costs of Perpetual Watchfulness

The Panopticon—a prison architecture that lets a lone overseer watch every inmate without them knowing when they are being watched—serves as a fitting metaphor for the transition from overt punishment to internalized self-control in the age of artifical intelligence-enabled (AI-enabled) surveillance. When people recognize that their actions are under relentless, algorithmic scrutiny, they tend to self-regulate—not out of fear of direct sanction but because they feel they are always being watched. This perpetual awareness breeds a climate of mistrust and unease. Individuals begin to interrogate the motives of those who wield the monitoring tools29 , eroding psychological safety and stifling dissent or experimental thinking for fear of punitive fallout. The constant gaze also engenders a sense of alienation, as surveillance is interpreted as an implicit signal of distrust from authority figures30 . As a consequence, individuals subjected to nonstop monitoring experience heightened anxiety and stress, especially given the ever-present risk that AI systems—lacking empathy and contextual nuance—may misinterpret emotional reactions. The combination of relentless observation and the potential for misreading human affect amplifies the psychological burden of living under algorithmic watch (Sarrat [74]). 3.2

Surveillance under the Guise of Safety: Undermining Maslow’s Hierarchy

Maslow’s hierarchy of needs models human motivation as a ladder of five tiers: physiological, safety, lоvе/belonging, esteem, and self-actualization. Advancement up the ladder requires fulfillment of the lower rung; safety, in particular, must be secured before any higher-order aspirations become attainable. When the omnipresent Panopticon of AI surveillance blocks the satisfaction of safety, the remaining tiers—lоvе, esteem, and self-actualization—remain perpetually out of reach, thwarting human flourishing. Thus, the “surveillance” “safety” offered by pervasive monitoring is merely a simulacrum that undermines the primal need for genuine security, leaving individuals trapped in a cycle of self-censorship, mistrust, and psychological strain. To curb or abate these effects, we plan to pursue prospective lines of inquiry. 3.3

Looking Ahead: Paths for Future Research

Future work will probe whether frontier LLMs can identify an author when confronted with text reshaped by TraceTarnish under a zero-shot classification regime (Shane et al. [76]). 29 30

Through clenched teeth: privacy for the weak, transparency for the powerful. https://www.eff.org/congress/

24

Robert Dilworth

This motivation stems from the ambivalence between the powerful capabilities that LLMs bring to authorship detection and the profound privacy concerns such capabilities raise. Having the capacity to serve as both a tool for insight and a weapon for intrusion, the foundational dilemma of stylometry can be framed as two sides of a coin. The “obverse” highlights the privacy-risk side: LLM-enabled authorship analysis can link anonymous writers across platforms and expose compromised accounts, sacrificing privacy and potentially turning benign profiling into surveillance that endangers journalists, dissidents, whistleblowers, and any other individuals who may be vulnerable or at risk. The “reverse” shows that LLMs excel at identifying authorship without the need for domain-specific fine-tuning, paving the way for a new era of authorship analysis that strengthens digital forensics, improves cybersecurity, and counters misinformation (Huang et al. [39]). Recognizing both the promise [81] and the peril 31 , we proceed deliberately. With our eyes wide open, we now brace for the inevitable blink.

3.4

When the Eyes Close: Conclusion

Our experiment demonstrates that the Injection module alone can flip authorship attribution—texts originally penned by Hughes were reassigned to May once Injection was applied. When Injection was removed, none of the other components succeeded in producing a misattribution, underscoring Injection as the primary adversarial lever. The remaining techniques contributed only modest gains: ❖ Imitation pushed the altered texts farthest from Hughes in the PCA representation among the non-Injection variants, yet it still fell short of causing a classification error. ❖ Obfuscation performed less effectively than Imitation but outpaced Translation. ❖ Translation achieved the smallest displacement, often overlapping with Hughes’s genuine samples, marking it as the weakest masker. As a result, the hierarchy of masking strength (from most to least effective) is: Injection > Imitation > Obfuscation > Translation. Both cluster visualizations and bootstrap consensus trees substantiate that Injection-altered texts coalesce into a compact, isolated cluster that is markedly distant from every baseline and partially-modified counterpart. Thus, the ablation confirms that Injection is both necessary and sufficient for a successful adversarial attack on authorship attribution, while the other strategies at best provide ancillary support. 31

https://docs.canarytokens.org/guide/

Occluded Oculus

25

What Lies Beyond Closed Eyes. As we bring our study to a close, we mull over one final thought: what lies beyond closed eyes? Is it the allure of repose and unawareness, or is it something else entirely? Perhaps it is an assurance—an assurance that once-weary eyes will bask in. . . what? A dream? A nightmare? What differentiates a dream from a nightmare? Whatever the answer may be, “[it all] sounds a bit dystopian, doesn’t it? [Everything we’ve discussed so far—the cameras, the microphones, the stylometry, the eyes, the countless eyes. They’re] not just [s]urveillance tool[s; they’re] tool[s] that can be used for good or evil. [They] can be used to protect citizens, but [they] can also be used to oppress them” (vmfunc et al. [83]). Whatever this is—our deliberately ambiguous use of “this,” evocative of a Rorschach inkblot—feels less like a tranquil dream and more like a Kafkaesque nightmare.

References 1. Age Verification Won’t “Protect the Children”, https://www.eff.org/pages/ag e-verification-wont-protect-children Cited on Page 12. 2. Bootstrap Consensus Networks, https://computationalstylistics.github.io/ projects/bootstrap-networks/ Cited on Page 44. 3. Cosine Delta Distance (aka Wurzburg Distance), https://search.r-project.o rg/CRAN/refmans/stylo/html/dist.wurzburg.html Cited on Page 46. 4. Distance-based classifier, https://search.r-project.org/CRAN/refmans/stylo/ html/perform.delta.html Cited on Page 44. 5. Min-Max Distance (aka Ruzicka Distance), https://search.r-project.org/CRA N/refmans/stylo/html/dist.minmax.html Cited on Page 46. 6. Principal component analysis (4 2026), https://carpentries-incubator.githu b.io/high-dimensional-stats-r/04-principal-component-analysis.html Cited on Page 44. 7. Adib, F., Katabi, D.: See through walls with WiFi! ACM SIGCOMM Computer Communication Review 43, 75–86 (9 2013). https://doi.org/10.1145/2534169. 2486039, https://dl.acm.org/doi/10.1145/2486001.2486039 Cited on Page 12. 8. Afroz, S., Islam, A.C., Stolerman, A., Greenstadt, R., McCoy, D.: Doppelgänger Finder: Taking Stylometry to the Underground. In: 2014 IEEE Symposium on Security and Privacy. pp. 212–226. IEEE (5 2014). https://doi.org/10.1109/SP .2014.21, https://ieeexplore.ieee.org/document/6956566 Cited on Page 12. 9. Ahvanooey, M.T., Li, Q., Hou, J., Rajput, A.R., Chen, Y.: Modern Text Hiding, Text Steganalysis, and Applications: A Comparative Analysis. Entropy 21, 355 (4 2019). https://doi.org/10.3390/e21040355, https://pmc.ncbi.nlm.nih.g ov/articles/PMC7514839/ Cited on Pages 7 and 45. 10. Alajaji, R.: Lawmakers Want to Ban VPNs–And They Have No Idea What They’re Doing (11 2025), https://www.eff.org/deeplinks/2025/11/lawmakers-want-b an-vpns-and-they-have-no-idea-what-theyre-doing Cited on Page 12. 11. Alsobeh, A.M., Alkurdi, R.M., Darwish, O.: MIA-Bench: Quantifying the Phase Transition of User Re-Identification from Sparse Social Media Text. In: Proceedings of the 17th International Conference on Information and Communication Systems. pp. 1–10. ACM (5 2026). https://doi.org/10.1145/3812734.3813426, https: //dl.acm.org/doi/full/10.1145/3812734.3813426 Cited on Page 32.

26

Robert Dilworth

12. Bhandari, G.: K-Nearest Neighbors (KNN) Using R (3 2025), https://rstudio-p ubs-static.s3.amazonaws.com/1281653_abef48360410417ab37ada1086fb22d7. html Cited on Page 44. 13. Brennan, M., Afroz, S., Greenstadt, R.: Adversarial stylometry: Circumventing authorship recognition to preserve privacy and anonymity. ACM Transactions on Information and System Security 15, 1–22 (11 2012). https://doi.org/10.114 5/2382448.2382450, https://dl.acm.org/doi/abs/10.1145/2382448.2382450 Cited on Page 45. 14. Brodkin, J.: Man sues Florida cops over arrest spurred by “93% match” in facial recognition (6 2026), https://arstechnica.com/tech-policy/2026/06/man-jai led-due-to-faulty-face-recognition-says-florida-cops-ignored-other-e vidence/ Cited on Page 12. 15. Brozovsky, E.: How Language Nerds Solve Crimes (1 2024), https://www.pbs.or g/video/how-language-nerds-solve-crimes-n34x31/ Cited on Page 45. 16. Buckley, M.: One Step Forward, Two Steps Back: CA’s AB 1856 Exempts Open Source But Expands Age-Gating (5 2026), https://www.eff.org/deeplinks/20 26/05/one-step-forward-two-steps-back-cas-ab-1856-exempts-open-sourc e-expands-age-gating Cited on Page 12. 17. Castagnaro, A., Salviati, U., Conti, M., Pajola, L., Pizzi, S.: The Hidden Threat in Plain Text: Attacking RAG Data Loaders. In: Proceedings of the 18th ACM Workshop on Artificial Intelligence and Security. pp. 170–181. ACM (10 2025). https://doi.org/10.1145/3733799.3762976, https://dl.acm.org/doi/full/ 10.1145/3733799.3762976 Cited on Page 15. 18. Cooper, P., Surdeanu, M., Blanco, E.: Hiding in Plain Sight: Tweets with Hate Speech Masked by Homoglyphs. In: Findings of the Association for Computational Linguistics: EMNLP 2023. pp. 2922–2929. Association for Computational Linguistics (2023). https://doi.org/10.18653/v1/2023.findings-emnlp.192, https://aclanthology.org/2023.findings-emnlp.192/ Cited on Page 7. 19. Cox, J.: This Company Will Add Phone, AirPod, and Smartwatch Trackers to License Plate Readers (6 2026), https://www.404media.co/this-company-wil l-add-phone-airpod-and-smartwatch-trackers-to-license-plate-readers/ Cited on Page 12. 20. Cyphers, B.: Inside Fog Data Science, the Secretive Company Selling Mass Surveillance to Local Police (8 2022), https://www.eff.org/deeplinks/2022/08/insi de-fog-data-science-secretive-company-selling-mass-surveillance-loc al-police Cited on Page 12. 21. Dilworth, R.: Tuning for TraceTarnish: Techniques, Trends, and Testing Tangible Traits (12 2025), https://arxiv.org/abs/2512.03465 Cited on Page 2. 22. Dilworth, R.: Unveiling Unicode’s Unseen Underpinnings in Undermining Authorship Attribution (10 2025), https://arxiv.org/abs/2508.15840 Cited on Page 2. 23. Dilworth, R.: Hijacking Text Heritage: Hiding the Human Signature through Homoglyphic Substitution (5 2026), https://arxiv.org/abs/2604.10271 Cited on Pages 2 and 10. 24. Dilworth, R.: StegoStylo: Squelching Stylometric Scrutiny through Steganographic Stitching (1 2026), https://arxiv.org/abs/2601.09056 Cited on Pages 2 and 10. 25. Dupré, M.H.: The Backlash Is So Strong That People With “Pervert Glasses” Are Afraid to Use Them in Public (7 2026), https://futurism.com/future-society /backlash-meta-pervert-glasses-afraid Cited on Page 12. 26. Eder, M.: Custom distance measures (8 2015), https://computationalstylistic s.github.io/blog/custom_distances/ Cited on Page 46.

Occluded Oculus

27

27. Eder, M., Rybicki, J., Kestemont, M.: Stylometry with R: A Package for Computational Text Analysis. The R Journal 8, 107 (2016). https://doi.org/10.326 14/RJ-2016-007, https://journal.r-project.org/articles/RJ-2016-007/R J-2016-007.pdf Cited on Pages 10 and 45. 28. Eder, M., Rybicki, J., Kestemont, M., Pielstroem, S.: Package ‘stylo’ (5 2026), https://cran.r- project.org/web/packages/stylo/stylo.pdf Cited on Page 10. 29. Emmery, C., Miotto, M., Kramp, S., Kleinberg, B.: SOBR: A Corpus for Stylometry, Obfuscation, and Bias on Reddit. In: Calzolari, N., Kan, M.Y., Hoste, V., Lenci, A., Sakti, S., Xue, N. (eds.) Proceedings of the 2024 Joint International Conference on Computational Linguistics, Language Resources and Evaluation. pp. 14967–14983 (5 2024), https://aclanthology.org/2024.lrec-main.1302/ Cited on Page 12. 30. Evert, S., Proisl, T., Jannidis, F., Reger, I., Pielström, S., Schöch, C., Vitt, T.: Understanding and explaining Delta measures for authorship attribution. Digital Scholarship in the Humanities 32, ii4–ii16 (12 2017). https://doi.org/10.1093/ llc/fqx023, https://www.researchgate.net/profile/Steffen-Pielstroem/pu blication/321310516_Understanding_and_explaining_Delta_measures_for_ authorship_attribution/links/5a1bf4b00f7e9be37f9c1482/Understanding-a nd-explaining-Delta-measures-for-authorship-attribution.pdf Cited on Page 46. 31. Feder, J.: How Flock Cameras Wrongly Tracked Me for Days Over ‘Stolen’ Plates and Sent Police After Me (7 2026), https://www.thedrive.com/news/how-flock -cameras-wrongly-tracked-me-for-days-over-stolen-plates-and-sent-pol ice-after-me Cited on Page 12. 32. Fisher, J., Hallinan, S., Lu, X., Gordon, M.L., Harchaoui, Z., Choi, Y.: StyleRemix: Interpretable Authorship Obfuscation via Distillation and Perturbation of Style Elements. In: Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing. pp. 4172–4206. Association for Computational Linguistics (2024). https://doi.org/10.18653/v1/2024.emnlp-main.241, https://aclant hology.org/2024.emnlp-main.241/ Cited on Page 6. 33. Gilmore, J.F.: Knowledge base systems in computer aided technology. In: The 23rd IEEE Conference on Decision and Control. pp. 586–590 (1984). https://doi.or g/10.1109/CDC.1984.272069 Cited on Page 11. 34. Goodin, D.: Beware of ads that use inaudible sound to link your phone, TV, tablet, and PC (11 2015), https://arstechnica.com/tech-policy/2015/11/beware-o f-ads-that-use-inaudible-sound-to-link-your-phone-tv-tablet-and-pc/ Cited on Page 12. 35. Goodin, D.: Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code (5 2026), https://arstechnica.com/security/2026/05/fed-up-wit h-vibe-coders-dev-sneaks-data-nuking-prompt-injection-into-their-cod e/ Cited on Page 12. 36. Guariglia, M.: Flock’s Gunshot Detection Microphones Will Start Listening for Human Voices (10 2025), https://www.eff.org/deeplinks/2025/10/flocks-g unshot-detection-microphones-will-start-listening-human-voices Cited on Page 12. 37. Guariglia, M., Quintin, C., Maass, D.: Add Bluetooth to the Long List of Border Surveillance Technologies (5 2024), https://www.eff.org/deeplinks/2024/0 5/add-bluetooth-long-list-border-surveillance-technologies Cited on Page 12.

28

Robert Dilworth

38. Hamid, S.: EFF’s Investigations Expose Flock Safety’s Surveillance Abuses: 2025 in Review (12 2025), https://www.eff.org/deeplinks/2025/12/effs-investi gations-expose-flock-safetys-surveillance-abuses-2025-review Cited on Page 12. 39. Huang, B., Chen, C., Shu, K.: Can Large Language Models Identify Authorship? In: Findings of the Association for Computational Linguistics: EMNLP 2024. pp. 445–460. Association for Computational Linguistics (2024). https://doi.org/10 .18653/v1/2024.findings-emnlp.26, https://aclanthology.org/2024.findin gs-emnlp.26/ Cited on Page 24. 40. Hughes, E.: A Cypherpunk’s Manifesto (3 1993), https://erichughes.org/ Cited on Page 11. 41. Hughes, E.: A long-term perspective on electronic commerce. NetWorker 1(3), 38– 50 (Nov 1997). https://doi.org/10.1145/344509.344546, https://doi.org/10 .1145/344509.344546 Cited on Page 11. 42. Hughes, E.: Component technologies: avoiding the herd mentality. In: Proceedings. The Twenty-Second Annual International Computer Software and Applications Conference (Compsac ’98) (Cat. No.98CB 36241). pp. 598– (1998). https://doi. org/10.1109/CMPSAC.1998.716731 Cited on Page 11. 43. Hughes, E.: Persistent enterprise components: improving the availability of legacy systems. In: 1999 Proceedings. Fourth International Workshop on Object-Oriented Real-Time Dependable Systems. pp. 95–100 (1999). https://doi.org/10.1109/ WORDS.1999.806566 Cited on Page 11. 44. Hughes, E.: The Point Really is Free Beer. Linux J. 1999(63es), 18–es (Jul 1999), https://dl.acm.org/doi/10.5555/327906.327924 Cited on Page 11. 45. Ingraham, C.: Police Have Reportedly Used License Plate Readers to Stalk Romantic Interests at Least 24 Times in Recent Years (4 2026), https://ij.org/p olice-have-reportedly-used-license-plate-readers-to-stalk-romantic-i nterests-at-least-14-times-in-recent-years/ Cited on Page 12. 46. Ireland, I.: ‘We Are Not Expendable’: Southaven Residents Fight xAI’s Plan for 41 Gas Turbines to Power Musk’s Grok (3 2026), https://www.mississippifre epress.org/xai-faces-fierce-opposition-over-southaven-mississippi-pow er-plant-permit/ Cited on Page 14. 47. Kandula, H., Karakos, D., Qiu, H., Ulicny, B.: Improving Authorship Privacy: Adaptive Obfuscation with the Dynamic Selection of Techniques. In: Proceedings of the Fifth Workshop on Privacy in Natural Language Processing. pp. 137–142. Association for Computational Linguistics (2024). https://doi.org/10.18653/v 1/2024.privatenlp-1.14, https://aclanthology.org/2024.privatenlp-1.14/ Cited on Page 6. 48. Kestemont, M., Stover, J., Koppel, M., Karsdorp, F., Daelemans, W.: Authenticating the writings of Julius Caesar. Expert Systems with Applications 63, 86–96 (11 2016). https://doi.org/10.1016/j.eswa.2016.06.029, https: //www.pure.ed.ac.uk/ws/files/38106536/Stover_et_al_2016_ESA_Authenti cating_the_writings_of_Julius_Caesar_AM.pdf Cited on Page 46. 49. Khan, J., Ahmad, K., Jagatheesaperumal, S.K., Sohn, K.A.: Textual variations in social media text processing applications: challenges, solutions, and trends. Artificial Intelligence Review 58, 89 (1 2025). https://doi.org/10.1007/s10462-024 -11071-z, https://link.springer.com/article/10.1007/s10462-024-11071-z Cited on Page 15. 50. Klosowski, T.: Defending Encryption in the U.S. and Abroad: 2025 in Review (12 2025), https://www.eff.org/deeplinks/2025/12/defending-encryption-us-a nd-abroad-2025-review Cited on Page 12.

Occluded Oculus

29

51. Kocher, M., Savoy, J.: Distance measures in author profiling. Information Processing & Management 53, 1103–1119 (9 2017). https://doi.org/10.1016/j.ipm.20 17.04.004, https://www.sciencedirect.com/science/article/abs/pii/S030 6457316306495 Cited on Page 46. 52. Koebler, J.: City Learns Flock Accessed Cameras in Children’s Gymnastics Room as a Sales Pitch Demo, Renews Contract Anyway (4 2026), https://www.404med ia.co/city-learns-flock-accessed-cameras-in-childrens-gymnastics-roo m-as-a-sales-pitch-demo-renews-contract-anyway/ Cited on Page 12. 53. Koebler, J.: With Ring, American Consumers Built a Surveillance Dragnet (2 2026), https://www.404media.co/with-ring-american-consumers-built-a -surveillance-dragnet/ Cited on Page 12. 54. Lee, H.N., Ashok, V.: Impact of Out-of-Vocabulary Words on the Twitter Experience of Blind Users. In: CHI Conference on Human Factors in Computing Systems. pp. 1–20. ACM (4 2022). https://doi.org/10.1145/3491102.3501958, https://dl.acm.org/doi/10.1145/3491102.3501958 Cited on Page 14. 55. Liu, C.J., Quintin, C.: The FCC’s Spam Call Proposal Is Just a Data Collection Scheme (6 2026), https://www.eff.org/deeplinks/2026/06/fccs-spam-call-p roposal-just-data-collection-scheme Cited on Page 12. 56. Liu, F., Ashbaugh, R., Chimitt, N., Hassan, N., Hassani, A., Jaiswal, A., Kim, M., Mao, Z., Perry, C., Ren, Z., Su, Y., Varghaei, P., Wang, K., Chan, S., Ross, A., Shi, H., Wang, Z., Jain, A., Liu, X.: FarSight: A Physics-Driven Whole-Body Biometric System at Large Distance and Altitude. In: 2024 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV). pp. 6215–6224. IEEE (1 2024). https://doi.org/10.1109/WACV57701.2024.00611, https://arxiv.or g/abs/2306.17206 Cited on Page 12. 57. Maass, D., Alajaji, R.: More License Plate Reader Mission Creep: School Residency Verification, Background Checks, and Noise Complaints (5 2026), https://www. eff.org/deeplinks/2026/05/more-license-plate-reader-mission-creep-sch ool-residency-verification-background?language=es Cited on Page 12. 58. Majka, M.: Introduction to naivebayes package (3 2024), https://cran.r-proje ct.org/web//packages/naivebayes/vignettes/intro_naivebayes.pdf Cited on Page 44. 59. May, T.C., Woods, M.: Alpha-particle-induced soft errors in dynamic memories. IEEE Transactions on Electron Devices 26(1), 2–9 (1979). https://doi.org/10 .1109/T-ED.1979.19370 Cited on Page 11. 60. May, T.C., Woods, M.H.: A New Physical Mechanism for Soft Errors in Dynamic Memories. In: 16th International Reliability Physics Symposium. pp. 33–40 (1978). https://doi.org/10.1109/IRPS.1978.362815 Cited on Page 11. 61. McArdle, M.: Will AI end anonymity? I tested it. (4 2026), https://www.washin gtonpost.com/opinions/interactive/2026/04/26/artificial-intelligenc e-could-kill-anonymity-online/ Cited on Page 12. 62. McGruder, C.H., VanDerMeer, B.W.: The 1916 PhD Thesis of Johannes Droste and the Discovery of Gravitational Repulsion (1 2018), https://arxiv.org/abs/ 1801.07592 Cited on Page 15. 63. Mellenthin, J., Shapiro, S.O.: Mythology Unbound: An Online Textbook for Classical Mythology. Textbooks 5, 136–137 (2017), https://digitalcommons.usu.e du/oer_textbooks/5/ Cited on Page 1. 64. Meyer, D.: Support Vector Machines (12 2025), https://cran.r-project.org/w eb/packages/e1071/vignettes/svmdoc.pdf Cited on Page 44.

30

Robert Dilworth

65. Mouselimis, L.: Functionality of the ClusterR package (12 2025), https://cran.r -project.org/web/packages/ClusterR/vignettes/the_clusterR_package.ht ml Cited on Page 44. 66. Mullin, J.: The KIDS Act Would Require Age Checks To Get Online (6 2026), https://www.eff.org/deeplinks/2026/06/kids-act-would-require-age-che cks-get-online Cited on Page 12. 67. Nipa, T.H., Islam, A.B.M.A.A.: Revealing Mental Disorders Through Stylometric Features in Write-Ups, pp. 248–265 (2023). https://doi.org/10.1007/978-3-0 31-34776-4_14, https://link.springer.com/chapter/10.1007/978-3-031-347 76-4_14 Cited on Page 12. 68. Page, A.: Unstyle: A Tool for Circumventing Modern Techniques of Authorship Attribution (2015), https://github.com/pagea/unstyle/blob/master/doc/the sis.pdf Cited on Page 16. 69. Pilkington, E.: Rise of ‘voiceprint’ ID technology has privacy campaigners concerned (10 2014), https://www.theguardian.com/technology/2014/oct/13/r ise-voiceprint-id-technology-privacy-campaigners-concerned Cited on Page 12. 70. Prahlow, S.P., Cohle, S., Shattuck, B., Prahlow, J.A.: Homicides Disguised as Staged Suicides. Academic Forensic Pathology 10, 104–112 (6 2020). https: //doi.org/10.1177/1925362120956855, https://pmc.ncbi.nlm.nih.gov/a rticles/PMC7691936/, Content Warning: This article contains graphic forensic imagery, including images of corpses, exposed blood, brain tissue, and mentions of self-harm. The implication of this reference and its connection to the surrounding material will be left for the reader to decipher, in part to honor the victims’ human dignity. Reader discretion is advised. Cited on Page 15. 71. Quintin, C., Greenberg, W.: Meet Rayhunter: A New Open Source Tool from EFF to Detect Cellular Spying (3 2025), https://www.eff.org/deeplinks/2025/03/ meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying Cited on Page 12. 72. Rizzo, S.G., Bertini, F., Montesi, D.: Content-preserving Text Watermarking through Unicode Homoglyph Substitution. In: Proceedings of the 20th International Database Engineering & Applications Symposium on - IDEAS ’16. pp. 97–104. ACM Press (2016). https://doi.org/10.1145/2938503.2938510, https://dl.acm.org/doi/abs/10.1145/2938503.2938510 Cited on Page 45. 73. Rumi: New ChatGPT Models Seem to Leave Watermarks on Text (4 2025), https: //www.rumidocs.com/newsroom/new-chatgpt-models-seem-to-leave-waterma rks-on-text Cited on Page 45. 74. Sarrat, T., Finn, T.: Surveillance Psychology: Ethical Risks of Continuous Behavioral Monitoring with AI in Schools and Workplaces. ResearchGate (1 2025), https://www.researchgate.net/profile/Tom-Sarrat/publication/39163551 8_SURVEILLANCE_PSYCHOLOGY_ETHICAL_RISKS_OF_CONTINUOUS_BEHAVIORAL_MON ITORING_WITH_AI_IN_SCHOOLS_AND_WORKPLACES/links/681ffccebfbe974b23c7 dc3a/SURVEILLANCE-PSYCHOLOGY-ETHICAL-RISKS-OF-CONTINUOUS-BEHAVIORAL-M ONITORING-WITH-AI-IN-SCHOOLS-AND-WORKPLACES.pdf Cited on Page 23. 75. Savoy, J.: Machine Learning Methods for Stylometry: Authorship Attribution and Author Profiling. Springer Cham (9 2020). https://doi.org/10.1007/978-3-0 30-53360-1 Cited on Pages 2 and 32. 76. Shane, T.S., Mylius, S., Hobbs, H.: Scheming in the wild: detecting real-world AI scheming incidents with open-source intelligence (4 2026), https://arxiv.org/ab s/2604.09104 Cited on Page 23.

Occluded Oculus

31

77. Smith, P.W.H., Aldridge, W.: Improving Authorship Attribution: Optimizing Burrows’ Delta Method*. Journal of Quantitative Linguistics 18, 63–88 (2 2011). https://doi.org/10.1080/09296174.2011.533591, https://www.tandfonl ine.com/doi/abs/10.1080/09296174.2011.533591 Cited on Page 46. 78. Srivastava, A.K., Bhatia, L., Pandey, V., Sharma, A.K.: AI-Driven Cross-Genre Authorship Impersonation: A Forensic Challenge. In: 2025 Second International Conference on Pioneering Developments in Computer Science & Digital Technologies (IC2SDT). pp. 350–355 (2025). https://doi.org/10.1109/IC2SDT68218. 2025.11383766, https://ieeexplore.ieee.org/document/11383766 Cited on Page 6. 79. Stanikūnas, D., Mandravickaitė, J., Krilavičius, T.: Comparison of distance and similarity measures for stylometric analysis of Lithuanian texts. Proceedings of the International Conference for Young Researchers in Informatics, Mathematics and Engineering 1852, 1–7 (4 2017), https://www.lituanistika.lt/content/77652 Cited on Page 46. 80. Thereallo: Claude Code Is Steganographically Marking Requests (6 2026), https: //thereallo.dev/blog/claude-code-prompt-steganography Cited on Page 45. 81. Tracebit: Context Bombs: stopping AI attackers in their tracks. (7 2026), https: //agentic.tracebit.com/context-bombs/ Cited on Page 24. 82. Tripathy, M.: The Cognitive Fingerprint: LLM-Resistant Cross-Domain Threat Actor Attribution via Temporal-Syntactic Fusion (3 2026). https://doi.org/10 .36227/techrxiv.177272729.99887126/v1, https://www.techrxiv.org/doi/f ull/10.36227/techrxiv.177272729.99887126/v1 Cited on Page 13. 83. vmfunc, MDL, Dziurwa: the watchers: how openai, the US government, and persona built an identity surveillance machine that files reports on you to the feds (2 2026), https://vmfunc.re/blog/persona Cited on Page 25. 84. Wilkins, J.: Man Trapped in Dystopian Nightmare Thanks to AI Surveillance Cameras Flagging His Every Move (4 2026), https://futurism.com/future-soc iety/flock-ai-surveillance-colorado Cited on Page 12. 85. Woodbridge, J., Anderson, H.S., Ahuja, A., Grant, D.: Detecting Homoglyph Attacks with a Siamese Neural Network (5 2018), https://arxiv.org/abs/1805.0 9738 Cited on Page 7.

Appendix A

Full-Text Classification and stylo Visualization Results [They] tried to conjure up a face. . . but there was no face. . . [They were] not important[; they were] not anything. Fahrenheit 451 Ray Bradbury

We re-ran the initial series of experiments (including additional, previously unmentioned tests), this time supplying the full texts for each of the candidate authors—John Gilmore, Eric Hughes, and Timothy C. May. In the previously

32

Robert Dilworth

presented collection of figures and texts, we had stored and retrieved excerpts equivalent in length to a standard abstract of their published works, except for Hughes’s A Cypherpunk’s Manifesto, which we used in its entirety. The conclusions drawn still largely remain the same. Jacques Savoy [75] provides justification for expanding the size of the text used for analysis. As he puts it, making a decision based on only a handful of words is extremely difficult. When the text reaches around 10,000 words, the assignment can be made with a high level of confidence. Using shorter passages, however, lowers the certainty of the resulting attribution. At the same time, while having more text is certainly better than possessing less, Alsobeh et al. [11] add a subtle distinction worth mentioning. As they put it, “users with distinctive styles and focused topical interests face substantially higher re-identification risk than users with common styles and diverse interests, even when the number of available posts is identical.” In other words, an individual whose interests are focused on a narrow set of topics is more likely to have their writing deanonymized and reidentified than someone who hops from topic to topic, engaging in a broad range of subjects. Practically speaking, if your interests are musicology and handicrafts, and you consistently engage in discourse related to those topics online while maintaining a distinctive style and sense of humor, you are easier to pick out of a crowd. Conversely, if you dabble in many interests, avoid becoming dedicated to any one, and sporadically post about them, you are at a lower risk of de-obfuscation, assuming you engage in these communities anonymously. A useful framework that can be applied here is the intersection of motive, opportunity, and capability. With more textual data than we know what to do with, the criterion of opportunity is easily satisfied. Existing in today’s world means you likely own a phone—essentially an extension of your body—and you interact with people using that phone across various platforms. With the barrier of entry lowered by AI and tools such as stylo, the criterion of capability is satisfied. Thus, there is probably enough text you have written online to deanonymize you, and the tools required to do so are within arm’s reach. As we see it, the only variable left is motive: how strongly an adversary desires the outcome and to what extent they are willing to put forth the effort, however difficult or easy that may be. This should make anyone uncomfortable, which is what motivates this work. Indeed, “wherever humans produce structured text—be it prose, code, or even spreadsheet formulas—individual habits leak through.” And, as we continue to see with the continual stream of data breaches, any leak of data is devastating in every sense of the word.

Occluded Oculus

A.1

33

classify() Experiments

Fig. 11: classify() Experiment (Full-Text Supplied): Final Results

Gilmore Hughes Hughes Hughes Hughes Hughes May May Adversarial-IM 1.1861 1.1586 0.8651 0.9927 1.2019 1.0485 1.4635 1.4687 Adversarial-IM+O 1.1642 1.1630 0.6939 0.9639 1.1953 0.9936 1.4438 1.4557 Adversarial-IM+T 1.0685 1.0920 0.7291 0.9264 1.1271 0.9535 1.3637 1.3754 Adversarial-IM+T+O 1.1441 1.1669 0.7885 1.0397 1.2376 1.0408 1.4704 1.4735 Adversarial-IN 4.0406 4.2784 4.3920 4.2842 4.2937 4.3705 4.4215 4.5029 Adversarial-IN+IM 3.7997 4.0374 4.1511 4.0432 4.0528 4.1296 4.1806 4.2619 Adversarial-IN+IM+O 3.7606 3.9939 4.1075 3.9997 4.0092 4.0860 4.1465 4.2236 Adversarial-IN+IM+T 3.6339 3.8717 3.9853 3.8775 3.8870 3.9638 4.0182 4.0962 Adversarial-IN+IM+T+O 3.7836 4.0213 4.1350 4.0271 4.0367 4.1135 4.1645 4.2458 Adversarial-IN+O 4.0168 4.2546 4.3682 4.2604 4.2699 4.3468 4.3977 4.4791 Adversarial-IN+T 4.2021 4.4399 4.5535 4.4456 4.4552 4.5320 4.5830 4.6644 Adversarial-IN+T+O 4.0364 4.2742 4.3878 4.2800 4.2895 4.3663 4.4173 4.4987 Adversarial-O 1.2253 1.1676 0.4177 0.9250 1.1575 0.8916 1.4529 1.4772 Adversarial-T 1.0180 1.0364 0.3009 0.8126 1.0363 0.7121 1.3628 1.3790 Adversarial-T+O 1.2015 1.1523 0.5500 0.9552 1.1417 0.8644 1.4261 1.4554

Table 2: classify() Experiment (Full-Text Supplied): Distance Table

34

Robert Dilworth

Fig. 12: classify() Experiment (Full-Text Supplied): From everything presented thus far, we can, with a certain degree of confidence, claim that the Injection component of TraceTarnish is the source from which the attack derives most of its adversarial effect. Had we employed a longer chain of intermediate translations—passing the text through several languages sequentially—or added more languages to the process, the Translation component might have performed better. Had we relied on a different method of paraphrasing, the Obfuscation component might have performed better. Had we crafted a more thorough prompt for our LLM, the Imitation component might have performed better. For the previously mentioned components, there are aspects that could be further refined. It is for this reason that we isolate the subcomponents of Injection— Liminal Injection and Doppelgänger Injection, which will be shorthanded to “LI” and “DI,” respectively. The final results from classify() indicate that either mode of Injection still has the capacity to induce misclassification. We omit Surrealist Injection (“SI”) from consideration here because running diff between the original and the Surrealist Injection version revealed very few changes were made, which makes sense given the swapping criteria we established. British English and American English are still English, after all.

Gilmore Hughes Hughes Hughes Hughes Hughes May May Adversarial-IN-DI_CypherpunkManifesto 4.0035 4.2322 4.3458 4.2379 4.2508 4.3243 4.3895 4.4665 Adversarial-IN-LI_CypherpunkManifesto 2.4142 2.6702 2.7640 2.5559 2.6304 2.7586 2.6929 2.8363

Table 3: classify() Experiment (Full-Text Supplied): The distance table for the isolated Injection components shows that the adversarial effect of Doppelgänger Injection is greater than that of Liminal Injection. The explanation is fairly intuitive. Liminal Injection leaves the text largely unchanged, aside from the insertion of zero-width Unicode characters; thus, all original characters remain, but invisible characters are embedded within words. Doppelgänger Injection, by contrast, takes a more dramatic approach. Because the attack’s default setting is 100% across the board, Doppelgänger Injection replaces every character that has a confusable homoglyph with its counterpart. As a result, unlike Liminal Injection, very little of the original text remains after Doppelgänger Injection. This roughly explains why the values for “DI” are higher than those for “LI.”

Occluded Oculus

A.2

35

stylo Visuals

Fig. 13: stylo Visualization (Full-Text Supplied): Principal Components Analysis

36

Robert Dilworth

Fig. 14: stylo Visualization (Full-Text Supplied): Cluster Analysis

Occluded Oculus

37

Fig. 15: stylo Visualization (Full-Text Supplied): Bootstrap Consensus Tree

38

A.3

Robert Dilworth

imposters() Experiments

The distance measure formulas are shown in (Appendix C). Distance Measure Imposters Score Adversarial-IM delta 0 Adversarial-IM+O delta 0.03 Adversarial-IM+T delta 0 Adversarial-IM+T+O delta 0 Adversarial-IN delta 0 Adversarial-IN+IM delta 0 Adversarial-IN+IM+O delta 0 Adversarial-IN+IM+T delta 0 Adversarial-IN+IM+T+O delta 0 Adversarial-IN+O delta 0 Adversarial-IN+T delta 0 Adversarial-IN+T+O delta 0 Adversarial-O delta 0.5 Adversarial-T delta 0.16 Adversarial-T+O delta 0.09 Adversarial-IM argamon 0.01 Adversarial-IM+O argamon 0.01 Adversarial-IM+T argamon 0 Adversarial-IM+T+O argamon 0 Adversarial-IN argamon 0 Adversarial-IN+IM argamon 0 Adversarial-IN+IM+O argamon 0 Adversarial-IN+IM+T argamon 0 Adversarial-IN+IM+T+O argamon 0 Adversarial-IN+O argamon 0.01 Adversarial-IN+T argamon 0 Adversarial-IN+T+O argamon 0 Adversarial-O argamon 0.52 Adversarial-T argamon 0.23 Adversarial-T+O argamon 0.06 Adversarial-IM eder 0 Adversarial-IM+O eder 0.03 Adversarial-IM+T eder 0 Adversarial-IM+T+O eder 0 Adversarial-IN eder 0 Adversarial-IN+IM eder 0 Adversarial-IN+IM+O eder 0 Adversarial-IN+IM+T eder 0 (continued on the next page)

Occluded Oculus

(continued from previous page) Adversarial-IN+IM+T+O eder Adversarial-IN+O eder Adversarial-IN+T eder Adversarial-IN+T+O eder Adversarial-O eder Adversarial-T eder Adversarial-T+O eder Adversarial-IM simple Adversarial-IM+O simple Adversarial-IM+T simple Adversarial-IM+T+O simple Adversarial-IN simple Adversarial-IN+IM simple Adversarial-IN+IM+O simple Adversarial-IN+IM+T simple Adversarial-IN+IM+T+O simple Adversarial-IN+O simple Adversarial-IN+T simple Adversarial-IN+T+O simple Adversarial-O simple Adversarial-T simple Adversarial-T+O simple Adversarial-IM canberra Adversarial-IM+O canberra Adversarial-IM+T canberra Adversarial-IM+T+O canberra Adversarial-IN canberra Adversarial-IN+IM canberra Adversarial-IN+IM+O canberra Adversarial-IN+IM+T canberra Adversarial-IN+IM+T+O canberra Adversarial-IN+O canberra Adversarial-IN+T canberra Adversarial-IN+T+O canberra Adversarial-O canberra Adversarial-T canberra Adversarial-T+O canberra Adversarial-IM manhattan Adversarial-IM+O manhattan Adversarial-IM+T manhattan Adversarial-IM+T+O manhattan Adversarial-IN manhattan

0 0 0 0 0.51 0.19 0.11 0.01 0.03 0.02 0 0 0 0 0 0 0 0 0 0.59 0.17 0.1 0 0.01 0.02 0 0 0 0 0 0 0 0 0 0.49 0.22 0.1 0 0 0 0 0 (continued on the next page)

39

40

Robert Dilworth

(continued from previous page) Adversarial-IN+IM manhattan Adversarial-IN+IM+O manhattan Adversarial-IN+IM+T manhattan Adversarial-IN+IM+T+O manhattan Adversarial-IN+O manhattan Adversarial-IN+T manhattan Adversarial-IN+T+O manhattan Adversarial-O manhattan Adversarial-T manhattan Adversarial-T+O manhattan Adversarial-IM euclidean Adversarial-IM+O euclidean Adversarial-IM+T euclidean Adversarial-IM+T+O euclidean Adversarial-IN euclidean Adversarial-IN+IM euclidean Adversarial-IN+IM+O euclidean Adversarial-IN+IM+T euclidean Adversarial-IN+IM+T+O euclidean Adversarial-IN+O euclidean Adversarial-IN+T euclidean Adversarial-IN+T+O euclidean Adversarial-O euclidean Adversarial-T euclidean Adversarial-T+O euclidean Adversarial-IM cosine Adversarial-IM+O cosine Adversarial-IM+T cosine Adversarial-IM+T+O cosine Adversarial-IN cosine Adversarial-IN+IM cosine Adversarial-IN+IM+O cosine Adversarial-IN+IM+T cosine Adversarial-IN+IM+T+O cosine Adversarial-IN+O cosine Adversarial-IN+T cosine Adversarial-IN+T+O cosine Adversarial-O cosine Adversarial-T cosine Adversarial-T+O cosine Adversarial-IM wurzburg Adversarial-IM+O wurzburg

0 0 0 0 0 0 0 0.26 0.24 0.06 0.01 0.01 0.02 0 0 0 0 0 0 0 0 0 0.19 0.49 0.06 0 0 0.01 0 0 0 0 0 0 0 0 0 0.23 0.23 0.08 0 0.05 (continued on the next page)

Occluded Oculus

(continued from previous page) Adversarial-IM+T wurzburg Adversarial-IM+T+O wurzburg Adversarial-IN wurzburg Adversarial-IN+IM wurzburg Adversarial-IN+IM+O wurzburg Adversarial-IN+IM+T wurzburg Adversarial-IN+IM+T+O wurzburg Adversarial-IN+O wurzburg Adversarial-IN+T wurzburg Adversarial-IN+T+O wurzburg Adversarial-O wurzburg Adversarial-T wurzburg Adversarial-T+O wurzburg Adversarial-IM minmax Adversarial-IM+O minmax Adversarial-IM+T minmax Adversarial-IM+T+O minmax Adversarial-IN minmax Adversarial-IN+IM minmax Adversarial-IN+IM+O minmax Adversarial-IN+IM+T minmax Adversarial-IN+IM+T+O minmax Adversarial-IN+O minmax Adversarial-IN+T minmax Adversarial-IN+T+O minmax Adversarial-O minmax Adversarial-T minmax Adversarial-T+O minmax

41

0 0 0 0 0 0 0 0 0 0 0.43 0.17 0.06 0.01 0.01 0 0.01 0 0 0 0 0 0 0 0 0.33 0.42 0.09

Table 4: imposters() Experiment (Full-Text Supplied): The configuration for imposters()’s parameters was as follows: the test parameter, representing the “text to be checked for authorship,” was set to “Hughes_CypherpunkManifesto.txt;” the candidate.set, which represents “a table containing frequencies/counts for the candidate set” was set to the collection of adversarially modified versions of “Hughes_CypherpunkManifesto.txt” (see (Figure 5)); the function’s return value is “a single score indicating the probablity that an anonymou[s] sample analyzed was [(or was not)] written by a candidate author.”

42

Robert Dilworth

Distance Measure Imposters Score Adversarial-IN-DI delta 0.02 Adversarial-IN-LI delta 0.52 Adversarial-IN-DI argamon 0.05 Adversarial-IN-LI argamon 0.48 Adversarial-IN-DI eder 0.05 Adversarial-IN-LI eder 0.44 Adversarial-IN-DI simple 0 Adversarial-IN-LI simple 0.55 Adversarial-IN-DI canberra 0 Adversarial-IN-LI canberra 0.49 Adversarial-IN-DI manhattan 0.1 Adversarial-IN-LI manhattan 0.48 Adversarial-IN-DI euclidean 0.39 Adversarial-IN-LI euclidean 0.02 Adversarial-IN-DI cosine 0 Adversarial-IN-LI cosine 0.56 Adversarial-IN-DI wurzburg 0.02 Adversarial-IN-LI wurzburg 0.47 Adversarial-IN-DI minmax 0 Adversarial-IN-LI minmax 0.54 Table 5: imposters() Experiment (Full-Text Supplied): As a continuation of (Figure 12 and Table 3), the imposters() results further reinforce the subcomponent hierarchy: Doppelgänger Injection > Liminal Injection.

Occluded Oculus

A.4

43

crossv() Experiments

Fig. 16: crossv() Experiment (Full-Text Supplied): On the whole, Obfuscation seems to fare far worse than Translation when using the full texts rather than snippets of the originals. Using a majority rather than a modicum of the text implies that the actual ranking of techniques is Injection > Imitation > Translation > Obfuscation, which is informed by both the crossv() confusion matrices and the imposters() scores (see (Table 4)). Irrespective of the distance measure used, the scores for Injection were almost always zero, Imitation ranged from 0.01–0.05, Translation ranged from 0.16–0.49, and Obfuscation ranged from 0.19–0.59 (the Obfuscation interval was wider than Translation’s by 0.07). Scores that fall roughly between 0.39 and 0.63 are deemed suspicious, indicating that the classifier was probably uncertain; scores below 0.5 (i.e., outside the suspicious interval) signal a verification failure. Regarding the confusion matrices, the classification.method parameters were set to Support Vector Machine (“svm”), Burrows’ Delta (“delta”), k-Nearest Neighbors (“knn”), and Naı̈ve Bayes (“naivebayes”). crossv() itself iteratively performs a classification, with the composition of the training and test sets being shuffled with each iteration.

44

Robert Dilworth

Appendix B

Key Terminology and Corresponding Definitions It’s an еуе for an еуе / Then a head for the еуе / Then a life for the еуе / Then the village for the еуе / Then a city for the еуе / Then a country for the еуе / The whole. . . world burns for the еуе Ѕаm Саrtеr, Rоb Dаmiаni, Ѕimоn Dеlаnеу, Маtt Dоnnеllу, Тоm Dоуlе

❖ Support Vector Machine (SVM): a binary-classification algorithm that finds the optimal separating hyperplane by maximizing the margin between the nearest points (support vectors); it handles overlapping classes with a soft-margin that down-weights misclassified points, and non-linear separations via kernel-induced high-dimensional projections, solving the problem as a quadratic optimization (Meyer [64]). ❖ Burrows’ Delta: a supervised classification technique that calculates a distance matrix between texts, then assigns each test sample to the class of its nearest training neighbor based on those distances [4]. ❖ k-Nearest Neighbors (k-NN): a non-parametric, supervised learning method for classification and regression that assigns a label (by majority/plurality vote) or predicts a value for a new instance based on the k most similar (nearest) examples, using distance as a measure of similarity (Bhandari [12]). ❖ Naı̈ve Bayes: a family of probabilistic classifiers that apply Bayes’ theorem with the simplifying assumption that features are conditionally independent, estimating class posteriors as the product of the class prior and individual feature likelihoods and predicting the class with the highest posterior probability (Majka [58]). ❖ Principal Components Analysis (PCA): a dimensionality-reduction technique that linearly transforms correlated continuous variables into orthogonal “principal components” ordered by decreasing explained variance, allowing a lower-dimensional representation that retains most of the original information [6]. ❖ Bootstrap Consensus Tree: a method that aggregates many dendrograms (generated from multiple “snapshots” of data, such as varying numbers of most-frequent words) into a single consensus diagram, highlighting groupings that repeatedly appear across the bootstrapped trees as robust patterns [2]. ❖ Cluster Analysis: an exploratory data-mining technique that partitions a set of objects into clusters so that items within each cluster are more similar to each other than to items in other clusters (Mouselimis [65]). ❖ Text Stylometry: the quantitative analysis of writing style—employing computational pipelines of preprocessing, feature extraction, and statistical modeling—to identify patterns such as authorship, age, gender, or other

Occluded Oculus

45

metadata across large text collections. This involves extracting stylistic features (e.g., function-word frequencies, letter- or word-level n-grams, partof-speech distributions) and measuring vocabulary richness or other overall stylistic metrics to infer demographic attributes and other contextual information (Eder et al. [27]; Brozovsky [15]). ❖ Adversarial Stylometry: the study of deliberately modifying or imitating writing style—through Obfuscation, Imitation, Translation, or Injection— to defeat authorship-attribution methods, enabling writers to protect their privacy and maintain anonymity by rendering stylometric classifiers no more accurate than random guessing (Brennan et al. [13]). ❖ Text Steganography: the technique of embedding hidden information within natural language text so that the presence of the secret data remains imperceptible to anyone except the intended recipient (Ahvanooey et al. [9]; Thereallo [80]). Zero-width Unicode Characters: a sampling of Unicode characters that produce no visible symbol or width includes the Zero-Width-NonJoiner [U+200C], Left-To-Right Mark [U+200E], Right-To-Left Mark [U+200F], Zero-Width-Joiner [U+200D], Zero-Width-Space [U+200B], and Zero-Width-Non-Break [U+FEFF]. A more exhaustive list of these characters and how they can be utilized for steganography can be found in Ahvanooey et al. [9]. Watermarking with special characters [73] such as the Narrow No-Break Space [U+202F] (not zero-width) is relevant here because it exploits a familiar paradigm: a character looks identical to another character in most word processors and browsers, making it virtually impossible to distinguish visually. Homoglyph Substitution: the technique of replacing characters in a text with visually similar characters from different scripts or Unicode code points to conceal or alter the content while preserving its appearance. It can be used to encode and embed secret data within text, though the approach is most practical when applied to Latin-based cover texts. For example, try searching for the word “death” in the digital version of this document using the built-in search function. You should detect only one instance, but another occurrence appears in the text. The first occurrence has been obscured using the technique (Rizzo et al. [72]).

E

E

Appendix C

Formulation of Distance Metrics and Their Mathematical Expressions My eyes were dimmed and filled with thousands of sinusoids. . . We Yevgeny Zamyatin

In stylometry, a distance measure is a function that takes a matrix of word-frequency (or other feature) counts for a set of texts, optionally transforms

46

Robert Dilworth

the data, and returns a symmetric square matrix whose entries quantify the dissimilarity between every pair of texts. The matrix’s diagonal is zero (identical texts have no distance), and larger values indicate greater stylistic divergence (Eder [26]). Below, we delineate the fundamental formulas underlying the distance metrics employed in our study. Regarding notation, we use uppercase symbols to represent vectors (or points) and a lowercase symbol with a subscript to refer to a specific component of a vector. Accordingly, A, B, and C denote vectors; the notation ai designates the i-th entry of vector A; and m indicates the dimension (length) of the vectors. For each position i, σi and µi denote the standard deviation and mean, respectively, of the values across all vectors under consideration. The symbols min and max refer to the smallest and largest values, respectively (Stanikūnas et al. [79]; Kocher and Savoy [51]). ❖ Burrows’ Delta (delta): Pm  ai −µi   bi −µi  1 − i=1 m σi σi ❖ Argamon’s r Linear Delta (argamon): P m (ai −bi )2 1 σi2

i=1

m

❖ Eder’s Delta (eder): Pm  ai −bi (m−mi +1)  1 · i=1 m σi m ❖ Eder’s √ Distance (simple): Pm √Simple a − bi i i=1 ❖ Canberra Distance (canberra): Pm |ai −bi | i=1 |ai |+|bi |

❖ Manhattan Distance (manhattan): Pm |a − b | i i=1 i ❖ Euclidean Distance (euclidean): qP m 2 i=1 (ai − bi ) ❖ Cosine Pm Distance (cosine): ai ·bi √Pm i=1 √ Pm 2 2 i=1 ai ·

i=1 bi

❖ Cosine Delta Distance (wurzburg) [3, 30, 77]: Pm

i=1

r P

ai −µi m i=1 σi

ai −µi bi −µi · σ σi i

2 r P  bi −µi 2 m · i=1 σ i

❖ Min-Max Distance (minmax) [5, 48]: P m

i=1 Pm

min(ai ,bi )

i=1 max(ai ,bi )

Record · ID 405540 · SHA-256 c9b65c79c53b5d72
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.