{
  "soundcheck": "002",
  "date": "2026-09-24",
  "status": "in progress",
  "prov01": {
    "ui_wav": "PASS - C2PA chunk present, Eleven Labs Inc. / DigiCert Document Signing CA, trainedAlgorithmicMedia, timestamp 2026-09-24T17:06:00Z. SDK note: signingCredential.untrusted (DigiCert Document Signing CA not in c2pa SDK default trust list).",
    "ui_mp3": "PASS - same manifest store in ID3 GEOB frame.",
    "api_mp3_x4": "FAIL - no JUMBF/C2PA, no identifying metadata (TSSE only). c2pa SDK: ManifestNotFound on all 4."
  },
  "dur03_c2pa_survival": {
    "method": "ffmpeg attack battery on el01 (UI, C2PA-carrying)",
    "results": {
      "reencode_mp3_128k": "manifest lost",
      "rewrap_wav_pcm": "manifest lost",
      "transcode_m4a_aac": "manifest lost",
      "loudnorm_mp3": "manifest lost",
      "tempo105_mp3": "manifest lost",
      "pitchup6_mp3": "manifest lost",
      "remux_stream_copy": "manifest lost (ffmpeg rebuilds ID3, GEOB dropped even on lossless remux)",
      "metadata_strip": "manifest lost"
    },
    "verdict": "C2PA provenance does not survive ANY tested post-processing step, including lossless stream-copy remux. Every downstream copy in the wild is manifest-free unless bitwise-identical."
  },
  "dur03_in_audio_mark": {
    "status": "COMPLETE (detector back up at 11:11 PDT after 10:27-10:28 outage)",
    "detector": "ElevenLabs Audio Detector (web UI, account arya@onfvr.com), two channels: watermark verdict + AI speech classifier probability",
    "originals": {
      "el01_wav": "Watermark found (ElevenLabs, Eleven Music v2, created Sep 24 9:53 AM PDT, unique ID sZ5zyJr2jo9XULdbN7Ai)",
      "el01_mp3": "Watermark found (same metadata)",
      "el02_piano_v1": "Watermark found (Eleven Music v1, created 10:21 AM PDT)",
      "el03_techno_v1": "Watermark found",
      "el04_folk_v2": "Watermark found",
      "el05_lofi_v1": "Watermark found"
    },
    "originals_verdict": "5/5 carry a valid in-audio ElevenLabs watermark, INCLUDING the API-streamed MP3s that have zero C2PA/metadata. The mark encodes provider, model version, creation timestamp, and a unique ID.",
    "attacks": {
      "remux_lossless_stream_copy": "Watermark found",
      "reencode_mp3_128k": "Watermark found",
      "metadata_strip": "Watermark found",
      "rewrap_wav_pcm": "Watermark found",
      "transcode_m4a_aac_128k": "Watermark found",
      "loudnorm": "Watermark found",
      "tempo_plus5pct": "Watermark NOT found; AI speech probability 2.0% ('very unlikely... or the audio was manipulated')",
      "pitch_plus6pct_tempo_preserved": "Watermark NOT found",
      "el02_reencode_mp3_128k": "Watermark found"
    },
    "attacks_verdict": "The in-audio mark survives every container/metadata/transcode/loudness attack tested, including lossless remux. It breaks under time/pitch modification: +5% tempo or +6% pitch both destroy it, after which the vendor's own tools call the track unattributable.",
    "detector_caveat": "Detector's classifier channel is a speech classifier; UI states it 'cannot reliably detect audio generated with the Eleven v3 model.' The watermark channel is the music-applicable one.",
    "two_layer_story": "C2PA (metadata layer): brittle - lost on ANY processing incl. lossless remux; absent entirely on API deliveries. In-audio watermark (signal layer): present on 5/5 originals across UI and API paths; survives transcodes and metadata loss; broken by tempo/pitch shift."
  },
  "next": [
    "detector reads on 5 originals + 9 attacks when service returns",
    "boundary probe (duration/quality ladder)",
    "human-music negative control",
    "Suno 20-track scale-up"
  ],
  "corpus_expansion": {
    "status": "COMPLETE 12:51 PDT",
    "added": 5,
    "note": "el06-el10 via API /v1/music, 60s, music_v1/v2 mix. Detector: watermark found on all 5, correct model version identified per track. Corpus now 10 tracks; watermark 10/10 originals.",
    "reads": {
      "el06": {
        "song_id": "4qRTFsfVI8AKnBh7Oyxq",
        "watermark_unique_id": "9xvRzVVJ92AQpZzBFSyD",
        "model": "music_v2"
      },
      "el07": {
        "song_id": "TPmTY4Bfivnejdlav8Pz",
        "watermark_unique_id": "vmFhYNw60PSoh0mXeQQH",
        "model": "music_v1"
      },
      "el08": {
        "song_id": "Ud0njH2bAvcUNksL2FDp",
        "watermark_unique_id": "5e7oUfm5rc4RxsMGLdNd",
        "model": "music_v2"
      },
      "el09": {
        "song_id": "2wcK73xWDmMsqbeTjqEa",
        "watermark_unique_id": "WJfBAi1MJpdTw2duhItF",
        "model": "music_v1"
      },
      "el10": {
        "song_id": "IqPsefatdtZjyqzWIFB0",
        "watermark_unique_id": "ETPrtraKi9zswVen7Uyd",
        "model": "music_v2"
      }
    }
  },
  "negative_control": {
    "status": "COMPLETE 12:54 PDT",
    "file": "human_control_bach_60s.mp3",
    "sha256": "8b37de2a715e2ed18878b7c0f713bdda4cbf0a451d36d69bd8b8c55af94cca8a",
    "source": "Kimiko Ishizaka, Bach WTC Book 1 Prelude No.2 BWV 847, public-domain human recording (Wikimedia Commons), trimmed to 60s, mp3 128k",
    "detector_read": "Watermark not found; AI speech probability 2.0% (very unlikely generated with ElevenLabs). No false positive on human music.",
    "note": "Identical 2.0% verdict to the tempo+5% broken-watermark read: post-attack EL audio is indistinguishable from human audio to this detector."
  },
  "dur_battery_watermark_el01": {
    "status": "IN PROGRESS - quota reset observed ~14:00 PDT same day (cap lasted ~1h); reads resumed",
    "reads": {
      "DUR-25 trim first 30s": "Watermark found (same unique ID sZ5zyJr2jo9XULdbN7Ai) - vendor trim claim HOLDS",
      "DUR-26 trim middle 30s": "Watermark found (same ID) - claim HOLDS",
      "DUR-27 trim last 30s": "Watermark found (same ID) - claim HOLDS",
      "DUR-28 clip 10s": "Watermark found (same unique ID sZ5zyJr2jo9XULdbN7Ai, Eleven Music v2, created 2026-09-24 11:53 AM CDT) - PASS, watermark survives a 10s clip. Read 2026-09-24 ~14:00 PDT after quota reset.",
      "DUR-31 streaming sim": "Watermark found (same unique ID sZ5zyJr2jo9XULdbN7Ai, Eleven Music v2, created 2026-09-24 11:53 AM CDT) - PASS, watermark survives streaming upload sim. Read 2026-09-24 14:53 PDT. Drip: cap ~13:00, through 13:59, capped 14:01 + 14:25, through 14:53, capped 15:23 (DUR-32 attempt), through 15:56 (NEG01 control) - roughly hourly quota drip.",
      "DUR-32 acoustic path sim": "NOT MEASURED - quota",
      "DUR-32": {
        "status": "complete",
        "attack": "ACOUSTIC PATH SIM (bandpass 300-3400Hz + reverb + pink noise + AGC), simulated",
        "watermark_verdict": "Watermark not found",
        "classifier_ai_speech_probability_pct": 2.0,
        "result": "DID NOT PASS (watermark destroyed by attack)",
        "note": "First attempt 17:24 capped; full verdict 17:55.",
        "ts": "2026-09-24T17:55:07-07:00"
      },
      "DUR-11": {
        "status": "capped_classifier_fallback_only",
        "watermark_verdict": null,
        "classifier_ai_speech_probability_pct": 2.0,
        "note": "Daily cap hit 18:25 (DUR-32 verdict at 17:55 consumed the slot). Still pending.",
        "ts": "2026-09-24T18:25:40-07:00"
      }
    },
    "quota_finding": "ElevenLabs Audio Detector has a DAILY watermark-detection cap (hit 24 Sep ~13:00 PDT after ~27 watermark checks on the account). Past the cap the tool silently degrades: every upload returns the AI speech classifier (2.0%, music-unusable) instead of a watermark verdict. Independent verification of the full 38-test battery cannot complete in one day - the verifier throttles the audit. Second availability datapoint after the 10:27-10:28 outage."
  },
  "negative_controls": {
    "NEG01_human_joplin1899": "PASS - Watermark not found (correct negative: no EL mark in human recording), AI speech classifier 2.0%. Read 2026-09-24 15:56 PDT, full watermark verdict (not capped fallback).",
    "NEG02_crossvendor_suno_s01": {
      "file": "controls/NEG02_crossvendor_suno_s01.mp3",
      "expect": "no ElevenLabs watermark (cross-vendor Suno track)",
      "status": "complete",
      "watermark_verdict": "Watermark not found",
      "watermark_text": "We couldn't detect a watermark added by Elevenlabs in this audio.",
      "classifier_ai_speech_probability_pct": 2.0,
      "result": "PASS (expected no mark)",
      "note": "First attempt 16:24 was capped (classifier fallback only); full verdict obtained 16:54.",
      "ts": "2026-09-24T16:54:44-07:00"
    }
  }
}