How does the style algorithm score text?
Version zyphh-raid-linear-2.0.0 uses a logistic-regression classifier with 20,000 word and two-word phrase features. Training fits TF-IDF weights on the training split only, using sublinear term frequency and L2 normalization. At inference, the weighted feature sum plus an intercept passes through a sigmoid and is displayed on a 0–100 scale. The sigmoid output has not been calibrated as an authorship probability.
Training uses eligible English prose from the public RAID train_none.csv dataset. Source IDs determine a fixed 70/15/15 hash split so related generator outputs and their human source stay together. Normalized duplicate texts are removed before capped sampling. The final splits contain 12,477 training documents, 2,541 validation documents and 2,643 test documents, with no shared source IDs or normalized text.
We selected regularization C=3 from 0.3, 1 and 3 using validation AUROC. Validation data also set the bands: fewer AI-like patterns below 34.66, mixed signals from 34.66 to below 65, and more AI-like patterns from 65. The displayed score is rounded; bands use the unrounded value. These are operating thresholds, not confidence intervals.
Six separate descriptive measurements cover sentence-length regularity, repeated two-word openings, repeated four-word sequences, listed phrases, vocabulary concentration and transition openings. They do not add up to the learned score. Exact highlights mark observable phrasing and repetition, not AI-authored sentences. Inputs need 80–3,000 words, five sentences and no more than 20,000 characters; unsupported language and code-heavy samples remain inconclusive.
How does the Unicode inspector work?
The inspector runs in the browser using JavaScript Unicode categories and an explicit list of control characters. Character names come from a static data table derived from Python's Unicode database. It records zero-based code-point offsets and one-based lines and columns. Those differ from UTF-8 byte positions and from JavaScript UTF-16 sentence spans, so each report states its units.
The mixed-script lookalike table is limited and falls well short of a full Unicode confusables implementation. The payload decoder supports only the binary and tag formats described on the watermark checker page. A negative result therefore means these checks found nothing, which is different from saying the passage can't contain steganography or a watermark.
What does selective cleanup change?
Cleanup transforms only the categories you select. It keeps the original input, logs every character replacement or deletion, and reports whether optional NFC normalization also changed the string. A before-and-after character count and a remaining-finding count describe the outcome. Removing every scanned feature doesn't mean a statistical watermark is gone.
Joiners and variation selectors can be essential to language and emoji, and bidi controls affect text direction. The interface flags those effects and leaves the categories unselected by default. There's no automated transliteration of mixed-script letters and no blanket accent removal.
How does watermark verification work here?
The public site defines an internal contract for an authorized watermark verifier. An operator can connect a separate service that owns a compatible detector and configuration. That's an extension interface, and we don't claim it implements a private Claude or Gemini endpoint. Without a service, statistical verification is "not tested."
A configured verifier supplies a provider, a scheme, a status and an explanation of its evidence. An exact model name is optional and has to come from the verifier itself. The site never infers a model version from a provider name, writing style, punctuation or an AI-classification score. Operators should check the adapter's authorization and calibration before enabling it.
How does the rewriter choose edits?
Version zyphh-rewrite-rules-1.0.0 uses a curated rule table. The clear and natural styles shorten selected phrases and use synonyms limited by context, and natural also adds selected negative contractions. Formal expands selected contractions. There are no random choices, no neural generation, no online thesaurus and no external API.
Matches are collected against the original source, filtered against protected ranges, sorted and resolved so that no two edits overlap. Before an edit is applied, the tool checks that its original substring still matches. Suggestions don't chain through the output, and no global whitespace normalization touches untouched text. Readers can accept or reject each edit in the interface.
Protection covers recognized quotations, code, links, citations and several structured-text patterns. Numeric-string counts must stay unchanged. Those checks don't prove semantic equivalence or cover every possible format. If no rule matches, nothing changes, and unsupported English context returns the original with an explanation.
Has the detector been tested for accuracy?
Yes, on a source-grouped holdout from RAID’s public training data. This is our held-out evaluation, not a submission to RAID’s official hidden test. The 2,643 accepted test passages include 1,323 human and 1,320 AI examples across eight domains. No test examples were used to choose model parameters or thresholds.
- AUROC: 0.936, compared with 0.718 for the previous six-rule score on the same passages. AUROC measures ranking across thresholds; it is not a percentage accuracy.
- High-signal band: 923 of 1,320 AI passages flagged, a recall of 69.9%.
- Human false positives: 30 of 1,323 human passages flagged, a rate of 2.3%.
- Mixed band: 516 of 2,643 passages. Mixed results are not counted as correct human predictions in the interface.
The reported binary high-band metrics treat everything below the high threshold as unflagged, including mixed signals. They describe this selected benchmark distribution. Newer models, non-native English, edited outputs, adversarial paraphrases and mixed authorship were not separately validated. Performance varies by domain; see all domain and generator breakdowns in the machine-readable model card.
We have not run a matched comparison with ZeroGPT or GPTZero. No superiority claim is made. Functional tests separately cover source offsets, import boundaries, edit protection, score implementation and consent controls. Those tests do not measure authorship accuracy.
Are results reproducible?
The same input and rules produce the same output within the same sentence-segmentation implementation. Browser Unicode and segmentation versions can differ, so note the runtime alongside the engine version in any formal experiment. A report contains your original text and can be sensitive even though the analysis ran locally.
To report a problem, include the tool, the engine version and enough non-sensitive context to reproduce it. Corrections about provider watermarking should come with a primary source. The contact page lists the operator's public address once it's configured.
How are document uploads handled?
TXT and Markdown imports support UTF-8 and BOM-marked UTF-16, preserving original line endings. DOCX extraction reads the main document body, including paragraphs, tabs and tables; it excludes deleted text and does not reproduce page layout, headers, footers, comments or text in images. PDF.js extracts selectable text page by page. Multi-column layout, reading order, ligatures and spacing can differ from the displayed page, so review the result before checking it.
Files are limited to 10 MB, PDFs to 100 pages and extracted text to 200,000 characters. Each tool has a smaller analysis limit displayed by the input. Over-limit files produce an error instead of silently dropping text. Scanned and password-protected PDFs, old .doc files and unsupported formats get conversion guidance. Imports can be cancelled and do not overwrite an existing draft when they fail.
The parser runs with external PDF evaluation disabled and reads Word XML without custom entity expansion. Import libraries load when needed. Documents are processed as described in Privacy.