Paper deep dive
Multi-Layer Context Camouflaging: A Semantic Superposition and Contextual Lamination Framework for Malpractice-Resilient Online Assessment
Gupta Lovi Raj, Kaur Kamalpreet, Dama Sri Ram, Parani Prajithaa
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 90%
Last extracted: 8/14/2026, 6:10:38 AM
Summary
This paper introduces the Multi-Layer Context Camouflaging Theory (MCCT), a mathematical framework for securing online assessments against content extraction attacks. It extends the MARS suite by using semantic superposition to render authentic content and synthetic camouflage together. The framework defines an extraction-channel operator and six coupled constructs, including a Context Inversion Operator and a Contextual Lamination Operator. It quantifies security via computational ambiguity (conditional entropy) and establishes theoretical properties for ambiguity, camouflage density, and semantic preservation, aiming to preserve readability for legitimate users while preventing unauthorized extraction.
Entities (16)
Relation Signals (11)
Lovi Raj Gupta → affiliatedwith → Lovely Professional University
confidence 95% · Lovi Raj Gupta¹˒*, Kamalpreet Kaur¹, Sri Ram¹, Prajithaa¹ ¹Lovely Professional University, Punjab, India
MCCT → extends → MARS
confidence 95% · This paper extends the Multi-dimensional Spatio-Temporal Context Camouflaging Model (MSCCM) within the MARS (Multi-modal Assessment Resilience Suite) by introducing the Multi-Layer Context Camouflaging Theory (MCCT)
MCCT → includescomponent → Context Inversion Operator
confidence 92% · develops six coupled constructs: the Context Inversion Operator
MCCT → includescomponent → Contextual Lamination Operator
confidence 92% · Contextual Lamination Operator, Separation Channel
MCCT → includescomponent → Computational Ambiguity Functional
confidence 90% · Computational Ambiguity Functional, and Context Camouflage Tensor
MCCT → publishedin → Springer Nature Machine Learning
confidence 90% · Submitted to Springer Nature Machine Learning
Computational Ambiguity Functional → quantifies → Uncertainty
confidence 90% · Computational ambiguity is formulated using conditional entropy, yielding a closed-form expression that quantifies uncertainty during unauthorized extraction
Semantic similarity → →
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Contemporary online assessment systems rely primarily on browser lockdown, webcam monitoring, and behavioural analytics, yet remain vulnerable to attacks that extract the assessment content itself through screenshots, screen sharing, optical character recognition, and automated scraping. This paper extends the Multi-dimensional Spatio-Temporal Context Camouflaging Model (MSCCM) within the MARS (Multi-modal Assessment Resilience Suite) by introducing the Multi-Layer Context Camouflaging Theory (MCCT), a mathematical framework that protects rendered assessment content through semantic superposition. Authentic assessment content and synthetically generated camouflage are represented as a unified rendering while remaining recoverable only by legitimate candidates. The framework models the adversarial extraction process through an explicit extraction-channel operator and develops six coupled constructs: the Context Inversion Operator, Contextual Lamination Operator, Separation Channel, Human Readability Functional, Computational Ambiguity Functional, and Context Camouflage Tensor. Computational ambiguity is formulated using conditional entropy, yielding a closed-form expression that quantifies uncertainty during unauthorized extraction, while legitimate recovery is guaranteed through an exact filtering identity. We further establish theoretical properties governing ambiguity, camouflage density, semantic preservation, multi-observation leakage, and temporal multiplexing, and present a rendering algorithm with computational complexity and a pre-registered evaluation protocol. MCCT provides a mathematically rigorous foundation for behaviorally adaptive, accessibility-aware, and computationally resilient digital assessment by securing rendered assessment content while preserving readability for legitimate users.
Tags
Links
- Source: https://arxiv.org/abs/2608.13100v1
- Canonical: https://arxiv.org/abs/2608.13100v1
Trouble viewing inline? Open PDF directly →
Full Text
55,502 characters extracted from source content.
Expand or collapse full text
Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 1 arXiv preprint Comment: This is a preprint. A version of this manuscript has been submitted to Springer Nature Machine Learning for peer review (manuscript 8123c4c3-1d4d-4b2a-afbd-f3c1dde183f4). Subjects: Artificial Intelligence (cs.AI); Computers and Society (cs.CY) Multi-Layer Context Camouflaging: A Semantic Superposition and Contextual Lamination Framework for Malpractice-Resilient Online Assessment Lovi Raj Gupta¹˒*, Kamalpreet Kaur¹, Sri Ram¹, Prajithaa¹ ¹Lovely Professional University, Punjab, India *Corresponding author: loviraj@gmail.com Abstract This paper extends the Multi-dimensional Spatio-Temporal Context Camouflaging Model (MSCCM) introduced in prior work on the MARS assessment-resilience suite, developing a substantially more detailed mathematical treatment of its Context Camouflaging Operator. We formalize Context Camouflaging as a semantic superposition process, termed the Multi-Layer Context Camouflaging Theory (MCCT), in which an authentic semantic stream and a generated camouflage stream coexist within a single rendered surface without ordinary concatenation. The revised formulation separates the rendered surface from the sequence an adversary actually recovers, and defines an extraction-channel operator that makes explicit which attributes (glyph, colour, position, time) survive each capture route. Against that model we develop six coupled constructs: a Context Inversion Operator with locality and vocabulary-closure conditions; a Contextual Lamination Operator driven by a keyed insertion set; a Separation Channel that generalizes colour to any modality carrying a perceptual discriminability margin; a Human Readability Functional conditioned on that margin; a Computational Ambiguity Functional redefined as the conditional entropy of the authentic stream given the adversary view, for which we derive the closed form A c = log 2 C(n+m, m); and a Context Camouflage Tensor coupling the scheme to MARS temporal rendering. We also correct the direction of the preservation constraint. Recoverability for the legitimate viewer is an exact filtering identity rather than a similarity bound, so the operative constraints become a fidelity identity, an obfuscation ceiling on Sim(Q, Ω), and a plausibility ceiling on the detectability of camouflage tokens under a language-model prior. Eight theorems follow, including a closed-form ambiguity result, a corrected optimal-density result with a binding-constraint corollary, a semantic-filter degradation bound, a multi-observation leakage theorem showing that frame-granular re-lamination is unsafe against a multi-capture adversary, and a coupon-collector bound on capture complexity under temporal multiplexing. We close with an algorithm, its complexity, and a pre-registered evaluation protocol. No empirical results are claimed. Index Terms context camouflaging, semantic superposition, contextual lamination, assessment integrity, computational ambiguity, threat modelling, conditional entropy, perceptual discriminability, academic malpractice. I. INTRODUCTION Online assessment platforms remain vulnerable to a class of malpractice in which the rendered content of an assessment item, not merely the candidate's behaviour around it, is extracted by screenshot, copy-paste, or automated scraping and relayed to an unauthorized solver, whether human or algorithmic. Prior work on the Multi-modal Assessment Resilience Suite (MARS) introduced Context Camouflaging as one operator within a broader six-dimensional dynamical model of assessment integrity, defined at the level of a single transformation Φ mapping an original question Q to a semantically equivalent rendering Q′ [1]. That formulation established the existence of the operator and a coarse semantic- similarity constraint, but did not develop the internal structure of Φ in mathematical depth. This paper develops that internal structure. We show that Context Camouflaging is best understood not as a single content-rewriting step but as a semantic superposition: the authentic content and a separately generated camouflage stream are rendered together on a shared surface, laminated at keyed positions, and separated perceptually so that a human and an automated extraction pipeline read different documents from the same pixels. Three things changed in the course of that development, and it is worth stating them plainly at the outset rather than burying them in the analysis. First, a scheme of this kind cannot be evaluated without naming the adversary. Colour survives a DOM scrape and dies in a clipboard copy, and a scheme whose whole security rests on colour therefore has entirely different properties against the two. Section I-B introduces an explicit extraction-channel model and a five-class adversary taxonomy, and every later claim is stated relative to a named class. Second, the preservation constraint in [1] pointed the wrong way. Requiring Sim(Q, Ω) ≥ θ asks the laminated field to resemble the authentic item, which is precisely what makes it useful to a solver holding the extracted text. The legitimate viewer does not need similarity at all, because filtering by the separation channel returns Q exactly. Section IX replaces the single similarity floor with a fidelity identity, an obfuscation ceiling, and a plausibility ceiling, which is the constraint set the design actually has to satisfy. Third, dynamic lamination as originally described leaks. If the authentic tokens stay fixed while the camouflage layer is resampled every frame, then across a handful of captures the authentic tokens are simply the ones that never change. Theorem 7 quantifies the decay and Section X gives the condition under which temporal variation is safe. This result Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 2 runs against the intuition that more randomization means more security, and it is the finding we would most want a reviewer to check. Contributions. (i) An explicit extraction-channel model and adversary taxonomy for rendered-content attacks on assessment items. (i) A closed-form expression for computational ambiguity as conditional entropy, A c = log 2 C(n+m, m), replacing the unigram-entropy difference used previously. (i) A corrected three-part constraint set with a Lagrangian treatment of camouflage density. (iv) A generalized separation channel with a perceptual discriminability margin expressed in CIEDE2000 units, together with a colour-vision- deficiency condition. (v) Eight theorems, of which four are new, including the multi-observation leakage result and a capture-complexity bound under temporal multiplexing. (vi) A stated algorithm with complexity analysis and a pre-registered evaluation protocol. Sections I and I cover related work, the MARS recap, and the threat model. Sections IV to XI develop the constructs. Section XII proves the eight theorems, Section XIII gives the algorithm, Section XIV the evaluation protocol, and Sections XV and XVI discuss limitations and conclude. I. RELATED WORK This paper is a direct mathematical extension of the MARS assessment-resilience framework, in which assessment integrity is modelled as a coupled dynamical system rather than a set of independently engineered safeguards, and the Context Camouflaging Operator is introduced as one of its six coupled constructs [1]. The present work develops that operator's internal mathematics without altering the surrounding system model. Dawson documents the limitations of treating browser lockdown, webcam surveillance, and behavioural analytics as independent, uncoordinated safeguards, motivating systems that address the rendered-content channel directly rather than only the candidate's behaviour around it [2]. The mechanism exploited here, a deliberate gap between what a human sees and what a machine parses, has a direct precedent in security research that we did not cite in the earlier version and should have. Boucher et al. showed that Unicode homoglyphs, invisible characters, and bidirectional reordering let an attacker construct text whose visual rendering and logical encoding disagree, and used that gap to attack NLP pipelines in a black-box setting [7]. Boucher and Anderson extended the same idea to source code, where the compiler and the reviewer read different programs from one file [8]. MCCT inverts the polarity of that attack: the same rendering-versus-encoding gap is used defensively, and the party disadvantaged by the gap is the extraction pipeline rather than the human. Reading the two literatures together also sets a useful expectation. Those attacks were eventually mitigated by input sanitization at the parser, and the analogous countermeasure here is an adversary that normalizes the rendered surface before parsing, which is exactly the A4 and A5 classes of Section I-B. The claim that a human can filter a colour-separated stream at negligible cost rests on visual-search results rather than on assertion. Treisman and Gelade established that a target differing from distractors in a single primitive feature such as hue is detected in time roughly independent of the number of distractors, and Wolfe's Guided Search work refines the conditions under which that independence holds and where it breaks down [9], [10]. Both point to the same practical requirement: the separation must be a single preattentive feature with an adequate discriminability margin, otherwise search becomes serial and readability degrades with camouflage density. We express that margin in CIEDE2000 units [11], with the commonly cited average just-noticeable difference of roughly 2.3 CIELAB units as the lower reference point [12]. Colour-vision deficiency is handled by requiring the margin to survive dichromatic simulation [13], or by moving the separation to a non-chromatic modality. The Context Inversion Operator generalizes a simple negation-token substitution into an operator that draws on lexical-semantic resources; WordNet's synonym and antonym relations provide one practical basis for generating context- dependent, polarity-reversing substitutions without relying on a fixed vocabulary list [3]. Computing the semantic similarity that appears in the obfuscation constraint can be operationalized with transformer-based sentence encoders: BERT provides contextual token representations from which sentence-level meaning can be derived [4], and Sentence- BERT adapts this into an efficient, directly comparable sentence-embedding form [5]. Shannon's information theory supplies the entropy formalism used throughout to quantify computational ambiguity and to bound the behaviour of dynamic lamination [6]. What remains unaddressed in the prior literature, and what this paper supplies, is a treatment of the perceptual gap as a designed defensive primitive with a stated adversary model, a closed-form ambiguity measure, and an account of how the guarantee degrades against a semantically informed attacker. I. MARS SYSTEM MODEL AND THREAT MODEL A. Recap of the MARS state MARS represents an assessment session as the coupled state tuple M = ⟨ S(t), T(t), C(t), B(t), R(t), I(t) ⟩ (1) comprising spatial, temporal, contextual, behavioural, rendering, and integrity components [1]. The present paper is concerned with the contextual domain C(t) and its associated Context Camouflaging Operator Φ, previously defined at the coarse level Q′ = Φ(Q,S,T,C) subject to sim(Q,Q′) ≥ θ. Everything that follows refines this single operator into the Multi-Layer Context Camouflaging Theory (MCCT) of Sections IV to XI, culminating in a unified rendering equation (Section XI) that reconnects MCCT to the rendering dynamics established in [1]. One notational change is needed before proceeding. The symbol C was used in the earlier version for the contextual state C(t), the colour assignment C(w), and the binomial coefficient C(n+m, m). We retain C(t) and C(·,·) and rename the colour assignment to χ(·). B. Extraction channels and adversary classes Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 3 A rendered assessment item is not a token sequence. It is a set of glyphs carrying position, colour, and a time index, and the question of what an attacker obtains is the question of which of those attributes survive the capture route. Writing the rendered surface as Σ(t) = ( σ 1 , ..., σ N ), σ i = (Ω i , x i , y i , c i , τ i ), N = n + m (2) an extraction channel is a projection X A : Σ(t 1:k ) ↦ V A , V A = X A (Σ(t 1 ), ..., Σ(t k )) (3) where V A is the adversary view and k the number of captures. Table I records which attributes each channel preserves. The classes are ordered by increasing capability, and every security claim later in the paper is stated against a named class rather than against an unspecified attacker. Two entries deserve emphasis because they bound what the scheme can honestly claim. Class A3, a scripted reader of the document object model, sees the styling that defines the separation channel; colour separation alone therefore provides no protection against A3 unless the styling is rendered non- recoverable, for example by drawing to a canvas or by randomizing per-token class names so that authentic and camouflage tokens are not distinguishable by selector. Class A5, a vision-language model given a screenshot, also sees colour, and additionally supplies the semantic prior that makes the combinatorial bound of Theorem 5 collapse. Colour separation is a defence against A1 and A2. Against A3 to A5 the defence has to come from elsewhere in the MARS stack, principally from the temporal visibility term of Section XI, and Theorem 8 states what that buys. Table I EXTRACTION CHANNELS AND ATTRIBUTE SURVIVAL Class Channel Glyph Colour Position Semantics A1 Clipboard copy to plain text yes no order only none A2 Screenshot then OCR yes no yes none A3 Scripted DOM reader yes yes yes none A4 A1 or A2 plus a language-model filter yes no yes yes A5 Screenshot to a vision-language model yes yes yes yes Attribute survival by capture route. "Semantics" denotes whether the adversary can score candidate reconstructions for linguistic plausibility. Colour separation is effective against A1 and A2 only. Following Kerckhoffs's principle we assume throughout that the adversary knows the algorithm, the inversion operator, the density η, and the distribution from which insertion sets are drawn. Only the per-session key is secret. Claims that depend on the adversary not knowing the construction are not made. Fig. 1. Architecture of the Multi-Layer Context Camouflaging Theory (MCCT): the authentic stream and its inversion-generated camouflage stream are laminated, separated by channel, and passed to the MARS rendering engine. IV. SEMANTIC SUPERPOSITION AND THE RENDERED SURFACE Rather than presenting an assessment item as a single token sequence, MCCT renders a superposed linguistic field in which two token streams occupy the same rendered surface, only one of which contributes to the intended meaning. The authentic semantic stream is Q = (w 1 , w 2 , ..., w n ), w i ∈ V (4) where V denotes the assessment-item vocabulary. A separately generated camouflage stream Q ̃ = (w ̃ 1 , w ̃ 2 , ..., w ̃ m ) (5) is produced by the Context Inversion Operator of Section V. The two streams are combined, not by concatenation but by the lamination process of Section VI, into a superposed field Ω = ℒ(Q, Q ̃ ; Λ) (6) The distinction that the earlier version left implicit is between Ω and Σ. The laminated field Ω is a token sequence; the rendered surface Σ of Equation (2) is Ω decorated with position, colour, and visibility. A legitimate candidate observes Σ. An adversary observes X A (Σ), which for classes A1 and A2 is Ω alone. The defining property of the construction can now be stated exactly rather than informally: there exists a filter ℱ such that ℱ(Σ; Γ) = Q with no error at all, while Q is not determined by Ω. Sections V to VII build the three mechanisms that produce this asymmetry and Sections VIII and IX quantify it. V. THE CONTEXT INVERSION OPERATOR The camouflage stream is generated by a Context Inversion Operator ℐ acting on the authentic stream, Q ̃ = ℐ(Q) (7) Following the generalization principle adopted for this framework, ℐ produces a context-preserving, computationally ambiguous overlay rather than a fixed vocabulary substitution. One embodiment realizes ℐ using polarity-reversing tokens ("NOT", "EXCEPT", "UNEQUAL", "UNLESS"); another may draw on qualifiers, antonyms, distractor clauses, or domain- specific semantic modifiers, for instance using the lexical antonym and hypernym relations catalogued in WordNet [3]. Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 4 The earlier version described what ℐ should do in prose. Stating it as three conditions makes the later theorems checkable. Let s(j) ⊆ 1, ..., n be the source span from which the j-th camouflage token is derived. Then ℐ is admissible when (C1) locality: w ̃ j = g( w i : i ∈ s(j) ), |s(j)| ≤ ℓ (8) (C2) vocabulary closure: min v ∈ V dist(w ̃ j , v) ≤ ρ V (9) (C3) polarity reversal: ⟨e(w ̃ j ), e(w s(j) )⟩ ≤ −κ p (10) where e(·) is a sentence-encoder embedding, dist a metric on that embedding space, ℓ a span-width bound, and ρ V and κ p tunable margins. Condition C1 keeps the operator local, so that Q ̃ is anchored to Q span by span rather than to the global meaning of Q. Condition C2 keeps camouflage tokens close to the item vocabulary, which is what prevents an adversary from separating the streams by a vocabulary test alone. Condition C3 is what stops Q ̃ from being a usable paraphrase of Q, and therefore what stops the laminated field from leaking the answer to a solver that reads it whole. C2 and C3 pull against each other, and the tension is real rather than an artefact of the formalism. Pushing κ p up drives the camouflage tokens away from the item vocabulary and makes them easier to spot; pushing ρ V down brings them back into the vocabulary and weakens the polarity reversal. The plausibility constraint of Section IX is where that trade-off is made explicit. VI. THE CONTEXTUAL LAMINATION OPERATOR The defining departure from ordinary text insertion is that Q and Q ̃ are combined by lamination rather than concatenation. The operator Ω = ℒ(Q, Q ̃ ; Λ) (11) is governed by a control law Λ = (π, κ, χ) (12) where π is the insertion position map, κ the insertion density, and χ the separation-channel assignment of Section VII. The map π determines an insertion set Π ⊆ 1, ..., n + m, |Π| = m, κ = m / (n + m) (13) and the laminated field is defined position by position as Ω i = w r(i) if i ∉ Π; w ̃ j(i) if i ∈ Π (14) where r(i) and j(i) index the authentic and camouflage tokens occupying laminated position i, both order-preserving. Because Π is chosen independently of concatenation order, Ω cannot be separated into its constituent streams by position alone; recovering Q from Ω requires knowledge of Π, formalized as Theorem 5. Where Π comes from was left open previously, and it matters, because a Π that is merely "random" gives no reproducibility across the render path and no rotation policy across sessions. We derive it from a keyed pseudorandom function, Π = Ψ PRF (K sess , id, 0), Γ = (c q , c c ) = Ψ PRF (K sess , id, 1) (15) with K sess a per-session key held by the rendering service with 0 and 1 acting as domain separators. The pair (Π, Γ) is the session rendering key. Sampling Π uniformly among the m- subsets of 1, ..., n+m is what makes the uniform prior of Theorem 3 the correct one; any biased sampler reduces the adversary's uncertainty below the closed form and should be treated as a defect rather than a tuning choice. Fig. 2. Contextual lamination of an authentic stream (white) with inversion- generated camouflage tokens (shaded) at keyed insertion set Π. VII. THE SEPARATION CHANNEL AND PERCEPTUAL DISCRIMINABILITY Humans exploit colour as an immediate preattentive grouping cue; extraction pipelines in classes A1 and A2 tokenize rendered or copied text after formatting metadata has been discarded by the copy, OCR, or scrape operation. MCCT exploits this asymmetry through a separation function χ(i) = c q if i ∉ Π; c c if i ∈ Π (16) which assigns the authentic-stream value c q to positions drawn from Q and the camouflage value c c to positions drawn from Q ̃ . The pair Γ = (c q , c c ), together with Π, constitutes the session rendering key required to invert the lamination, and Γ may be rotated across sessions in the same manner as other MARS session parameters. Treating χ as specifically chromatic was an unnecessary restriction. What the construction requires of the separation channel is only that it be a single preattentive feature carrying a discriminability margin above threshold, so we state the requirement rather than the mechanism. For a chromatic channel the condition is ΔE 00 ( c q , c c ) ≥ ΔE*, ΔE* ≫ 2.3 (17) with ΔE 00 the CIEDE2000 colour difference [11] and 2.3 CIELAB units the commonly cited average just-noticeable difference [12]. A margin near the JND is the wrong operating point, because the readability result of Theorem 2 depends on the difference being preattentive rather than merely detectable. Accessibility imposes a second condition: the margin has to survive dichromatic simulation, min D ∈ prot, deut, trit ΔE 00 ( D(c q ), D(c c ) ) ≥ ΔE* (18) with D the standard dichromat simulations [13]. Where Equation (18) cannot be met, the channel moves to a non- chromatic modality (weight, case, or a typographic mark) under the same χ with a different codomain, and the whole analysis carries over unchanged because no theorem below uses any property of colour other than the existence of the margin. This closes a limitation that the earlier version flagged and left open. One honest caveat belongs here rather than in the discussion. Equations (17) and (18) make the channel more visible, and visibility to the candidate is visibility to a screenshot. Raising Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 5 ΔE* strengthens the guarantee against A1 and A2 and weakens nothing there, but it makes the separation trivially legible to A3 and A5. The channel is not a secret; it is a filter that certain capture routes destroy. Fig. 3. Dual-channel perception under separation: a legitimate candidate perceiving Γ filters the laminated stream preattentively, while a class A1 or A2 extraction channel sees only the undifferentiated token sequence. VIII. READABILITY AND AMBIGUITY FUNCTIONALS Two functionals quantify the trade-off that separated lamination is designed to exploit. The Human Readability Functional is R h = (1/n) Σ i=1..n α i (19) where the perception indicator is α i = 1 if authentic token i is correctly perceived; = 0 otherwise (20) The earlier statement that R h → 1 independently of density is true but empty, because it assumes exactly what it concludes. What makes it a claim about the world is the condition under which α i = 1 holds, and visual-search theory supplies it: separation by a single preattentive feature yields search time approximately flat in distractor count, whereas a below- threshold margin forces serial search and readability then falls with density [9], [10]. We therefore model perception as Pr[ αi = 1 ] = 1 − ε(ΔE00), with ε decreasing in ΔE00 and ε → 0 for ΔE00 ≥ ΔE* (21) and a companion search-cost term that Section IX prices, Sc(η) = a + b·η·1[ ΔE00 < ΔE* ] (22) so that above threshold the cost of camouflage to the candidate is a constant a and below threshold it grows linearly in η. Theorem 2 is stated against Equation (21) rather than against an assumption. The Computational Ambiguity Functional needs a more substantial correction. It was previously defined as the excess unigram entropy A c = H(Ω) − H(Q). That quantity is not monotone in camouflage density and can fall as tokens are added: inserting the same camouflage token repeatedly concentrates the token distribution and reduces H(Ω). It also measures the wrong thing, since the adversary's difficulty is uncertainty about Q, not the entropy of what is on screen. We redefine it as the conditional entropy of the authentic stream given the adversary view, A c = H( Q | V A ) (23) For an A1 or A2 adversary, V A = Ω, and Theorem 3 gives the closed form A c = log 2 C(n + m, m) (24) which is strictly increasing in m for fixed n, is exactly the quantity that Theorem 5 bounds, and reduces the two results to one. For an A3 adversary the view includes χ, and A c = 0. For A4 and A5 the semantic prior reduces the effective count, which Theorem 6 bounds. IX. FIDELITY, OBFUSCATION, AND PLAUSIBILITY The original framework imposed a single Context Preservation Constraint, Sim(Q, Ω) ≥ θ, on the grounds that the authentic content must remain recoverable and semantically intact. Recoverability is a separate matter from similarity, and once the two are separated the constraint turns out to point the wrong way. High Sim(Q, Ω) means the flat laminated field still conveys the item, which is exactly the property that lets a solver holding the extracted text answer it. The correct design has three constraints rather than one. Fidelity. The legitimate rendering path must return the item exactly, not approximately: ℱ( Σ ; Γ ) = Q (exact, not up to similarity) (25) This is an identity guaranteed by Theorem 5, and it makes the similarity floor unnecessary for the purpose it was introduced to serve. Obfuscation. The adversary view must not convey the item: Sim( Q, Ω ) ≤ θ obf (26) with Sim instantiated by a sentence encoder such as Sentence- BERT [5] over contextual representations [4]. The inequality is a ceiling where [1] had a floor. Plausibility. The laminated field must not be trivially separable by a language model, or Theorem 3 overstates the adversary's work by a wide margin. Let p LM be a reference model and define the per-position detectability δ i = | log p LM (Ω i | Ω <i ) − E w∼Q [ log p LM (w | Ω <i ) ] | (27) The constraint is a ceiling on how far camouflage positions stand out, (1/m) Σ i ∈ Π δ i ≤ δ max (28) Equations (26) and (28) are in tension by construction, which is the trilemma the designer actually faces: a camouflage stream distant enough to destroy Sim(Q, Ω) tends to be distant enough to be flagged by p LM , and one bland enough to pass Equation (28) tends to leave the item readable. Section XV returns to this point, and we regard it as the main open problem the framework raises. The intensity of camouflaging is controlled by the camouflage density η = m / n (29) and the design problem is a constrained maximization rather than a search for a single crossing point, η* = arg max η ∈ F [ A c (η) − λ S c (η) ] (30) in which λ prices candidate effort and the feasible set is F = η : Equations (26) and (28) hold, and R h (η) ≥ 1 − ε. Theorem 4 gives conditions for η* to exist and identifies when it sits on the boundary of F. Figure 4 shows the qualitative shape of the trade-off; the curves are schematic and carry no measured values. Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 6 Fig. 4. Schematic trade-off between human readability, computational ambiguity, and semantic similarity as functions of camouflage density η, under an above-threshold separation margin. Curves are illustrative; Section XIV specifies how they would be measured. X. DYNAMIC LAMINATION AND THE CONTEXT CAMOUFLAGE TENSOR Consistent with MARS's session-adaptive rendering philosophy, the camouflage stream need not be static. Dynamic lamination re-samples Q ̃ over time, Ω(t) = ℒ( Q, Q ̃ (t); Λ(t) ) (31) so that the camouflage layer evolves while the constraint set of Section IX continues to hold at every t. Every rendered token additionally carries a Context Camouflage Tensor recording its rendering state, T i (t) = ⟨ x i , y i , c i , τ i , σ i , ω i ⟩ (32) where (x i , y i ) is spatial position, c i the assigned separation value, τ i visibility, σ i semantic polarity (authentic or inverted), and ω i rendering weight. Equation (31) is where the earlier framework had a genuine vulnerability, and we would rather state it than let a reader discover it. If Q is held fixed while Λ(t) and Q ̃ (t) are resampled every frame, then across k captures the authentic positions are identifiable as the ones whose token never changed. Randomizing the camouflage layer more aggressively makes the leak faster, not slower. Theorem 7 gives the decay rate. The condition under which temporal variation is safe is that the per- position temporal process be identically distributed for the two classes, law( Ω i (t 1:k ) | i ∉ Π ) = law( Ω i (t 1:k ) | i ∈ Π ) (33) Equation (33) is not satisfied by resampling only the camouflage layer. Two designs do satisfy it in practice. Either hold both Π and Q ̃ fixed for the lifetime of a session and rotate only across sessions, which reduces the leak to zero at the cost of intra-session adaptivity; or vary the authentic surface too, by resampling an equivalence-preserving surface form of each authentic token on the same schedule, which preserves adaptivity at the cost of a harder inversion operator. We recommend the first as the default and treat the second as future work. Fig. 5. The Context Camouflage Tensor T_i(t): each rendered token carries position, separation value, visibility, semantic polarity, rendering weight, and a time index. XI. UNIFIED RENDERING EQUATION MCCT connects to the rendering dynamics of the original MARS framework through a unified rendering equation. Recall from [1] the per-word visibility function Ψ i (t) = 1[ sin(2π f i t + φ i + ψ) − τ ≥ 0 ] (34) and let δ i (t) denote the positional-drift function governing token i's spatial rendering. The previous version wrote the rendering as a scalar product Ψ i (t)·δ i (t)·Ω i ·C(w i ), which multiplies a binary indicator, a displacement, a token, and a colour. Those are not commensurable quantities and the expression has no defined value. The rendering is a map into a glyph state, so we write it as one: ℛ i (t) = ⟨ Ω i , p i + δ i (t), χ(i), Ψ i (t)·ω i ⟩ (35) whose four components are the glyph, the drifted position, the separation value, and the opacity. Only the last is a scalar, and the other three keep their own types. The rendered surface of Equation (2) is the collection ℛ i (t) , and the visible fraction at any instant is ρ(t) = (1/n) Σ i ∉ Π Ψ i (t) (36) which is the parameter that Theorem 8 turns into a capture- count bound. Equation (35) is the point at which MCCT rejoins, and becomes a fully specified special case of, the general MARS Rendering Tensor formalism. XII. THEORETICAL ANALYSIS The following eight results characterize the joint behaviour of the constructs of Sections IV to XI. Theorems 1, 2, 4, and 5 revise results stated in the earlier version; Theorems 3, 6, 7, and 8 are new. Each is stated against a named adversary class from Table I. Theorem 1 (Separation-Conditioned Entropy Collapse). Let Σ be the rendered surface of Equation (2) and Γ the separation key. For an observer of Σ who resolves the separation channel, H(Q | Σ, Γ) = 0 exactly. For an adversary of class A1 or A2, whose view is Ω, H(Q | Ω) = A c > 0 whenever m ≥ 1. Proof. Resolving the channel yields, at every position i, the indicator 1[χ(i) = c c ] and therefore the set Π exactly. Deleting the positions in Π and reading the remainder in order returns Q, by Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 7 the order-preserving piecewise definition of Equation (14). Q is thus a deterministic function of (Σ, Γ), and the conditional entropy of a deterministic function is zero. The adversary of class A1 or A2 receives Ω with χ discarded, so Π is not determined, and the residual uncertainty is A c by Definition (23), which Theorem 3 shows is positive for m ≥ 1. ∎ This strengthens the earlier statement, which carried a residual term ε for positional ambiguity within the authentic class. No such term is needed. Lamination is order-preserving, so once Π is known the authentic subsequence is recovered without ambiguity, and the collapse is exact rather than approximate. Theorem 2 (Readability and Ambiguity Decouple Above the Discriminability Threshold). If ΔE 00 (c q , c c ) ≥ ΔE*, then E[R h ] = 1 − ε with ε independent of η, and the search cost S c (η) of Equation (22) is constant in η, while A c (η) is strictly increasing in η. If ΔE 00 < ΔE*, decoupling fails: ε grows with m and S c grows linearly in η. Proof. Under Equation (21) the indicators α i are Bernoulli with a common failure probability ε(ΔE 00 ) that depends on the separation margin and not on the number of camouflage tokens, which is the defining property of a preattentive feature-search regime [9], [10]. Linearity of expectation applied to Equation (19) gives E[R h ] = 1 − ε for every η. With the indicator in Equation (22) false, S c (η) = a. Strict monotonicity of A c in η follows from Theorem 3, since C(n+m, m) is strictly increasing in m for fixed n ≥ 1. Below threshold the discrimination is no longer a single-feature pop-out, search becomes serial in the distractor count, ε acquires a dependence on m, and the second term of Equation (22) activates. ∎ The distinction matters for deployment. The earlier version obtained decoupling by assuming α i = 1, which makes the conclusion true by construction. Here decoupling is a consequence of a physical condition on the rendered colours, and it is a condition that a platform can verify at render time. Theorem 3 (Closed-Form Computational Ambiguity). Let Π be drawn uniformly among the m-subsets of 1, ..., n+m and let the adversary view be Ω. Then A c = H(Q | Ω) ≤ log 2 C(n + m, m), with equality when the candidate streams induced by distinct subsets are distinct. At unit density m = n, Stirling's approximation gives A c ≈ 2n − ½ log 2 (π n). Proof. Each candidate subset S of size m induces a candidate authentic stream Q S = (Ω i : i ∉ S). By Equation (14) the true Q equals Q Π . The posterior over candidates given Ω is the pushforward of the uniform prior on Π under S ↦ Q S . A uniform distribution on a set of size N has entropy log 2 N, and pushforward under a map that is not injective can only merge outcomes and reduce entropy, so H(Q | Ω) ≤ log 2 C(n+m, m) with equality exactly when the map is injective. Repeated tokens in Ω are the only source of collisions. The unit-density expression follows from C(2n, n) ≈ 4 n / √(π n). ∎ Two consequences are worth noting. Ambiguity grows linearly in item length at fixed density, roughly two bits per authentic token at η = 1, so longer items are intrinsically better protected. And repeated tokens are a leak: a camouflage stream that reuses the same few markers reduces A c below the bound, which is a second reason, alongside condition C3, to draw camouflage tokens from a wide distribution. Theorem 4 (Existence and Location of the Optimal Density). Let F be the feasible set of Equation (30). If F is non-empty then η* exists. If the separation margin is above threshold, so that S c is constant on F by Theorem 2, then η* = max F: the optimum lies on the boundary and at least one of Equations (26) and (28) is active at η*. Proof. For fixed n the density η = m/n takes finitely many values in [0, 1], so F is a finite set and a maximum of any real objective over a non-empty finite set is attained. In the continuous relaxation used for tuning, A c (η) is continuous and strictly increasing and Sim(Q, Ω(η)) is continuous and non-increasing, so F is closed and bounded and therefore compact, and an upper semicontinuous objective attains its maximum on it. Above threshold the objective A c (η) − λS c (η) reduces to A c (η) − λa, which is strictly increasing, so its maximizer over F is sup F, which lies in F by closedness. Since A c increases without bound in m while Equations (26) and (28) are eventually violated, sup F is interior to [0,1] and is determined by whichever constraint fails first. ∎ The earlier version treated η as ranging continuously over a compact interval and concluded existence from continuity alone. The finite-value argument is both simpler and correct, and the boundary result is the practically useful part: there is no interior optimum to search for above threshold, so tuning reduces to finding the largest density that still satisfies the obfuscation and plausibility ceilings. An interior optimum reappears only below threshold, where λS c (η) grows with η and genuinely trades against A c . Theorem 5 (Lamination Invertibility and Brute-Force Cost). Given (Π, Γ), Q = ℒ⁻¹(Ω; Π) exactly. Without them, an adversary of class A1 or A2 confronts a candidate set of size C(n+m, m), that is, 2 raised to the power A c . Proof. Invertibility is the construction in the proof of Theorem 1. The cardinality is immediate from Theorem 3. ∎ The framing is deliberately modest and we want to be explicit about what it is not. This is an average-case entropy statement under a uniform prior over insertion sets. It is not a computational hardness result: there is no reduction to a problem believed to be hard, and none is claimed. Theorem 6 shows how far the bound falls against an adversary who does more than enumerate. Fig. 6. Growth of the candidate-set size C(n+m, m), in bits, as a function of authentic-stream length n at unit camouflage density (m = n). This is the quantity A_c of Theorem 3. Theorem 6 (Degradation Under a Semantic Filter). Let an adversary of class A4 or A5 hold a reference model p LM and Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 8 retain only candidates whose sequence probability exceeds a threshold, and let q be the acceptance rate of that test under the uniform prior over insertion sets. Then the residual ambiguity is A c LM = A c − log 2 (1/q). The plausibility constraint of Equation (28) is exactly a constraint on q. Proof. The filter restricts the candidate set of Theorem 3 to its accepted subset, whose expected cardinality is q · C(n+m, m). Conditioned on acceptance, and absent further information distinguishing accepted candidates, the posterior is uniform on that subset, whose entropy is log 2 (q · C(n+m, m)) = A c − log 2 (1/q). Camouflage tokens that are conspicuous under p LM drive q toward 1 / C(n+m, m) and hence A c LM toward zero; camouflage tokens indistinguishable under p LM give q ≈ 1 and leave A c intact. Since Equation (28) bounds the per-position detectability of camouflage tokens under the same model, it bounds q from below. ∎ This is the result that connects the design constraints to the adversary that matters most in current practice. It also makes the trilemma of Section IX quantitative: Equation (26) pushes camouflage tokens away from the authentic distribution, which lowers q and therefore lowers A c LM , while Equation (28) pushes them back toward it, which raises q but raises Sim(Q, Ω) with it. There is no setting of the inversion operator that maximizes both, and we do not have a principled way to choose the exchange rate between them. Theorem 7 (Multi-Observation Leakage Under Frame- Granular Re-Lamination). Suppose Q is fixed within a session while camouflage tokens are redrawn independently at each of k rendered frames from a distribution P, and let γ k = Σ w P(w) k , which equals 2 raised to the power −(k−1)H k (P) with H k the Rényi entropy of order k. An adversary who aligns the k captures and retains positions whose token is invariant across all of them retains every authentic position and, in expectation, m k = m·γ k camouflage positions. Residual ambiguity satisfies A c (k) ≤ log 2 C(n + m k , m k ), which decays geometrically in k. Proof. An authentic position carries the same token at every frame and so survives the invariance test with probability one, giving n survivors. A camouflage position survives only if k independent draws from P coincide, which occurs with probability Σ w P(w) k = γ k ; linearity of expectation gives m k = m γ k expected camouflage survivors. The surviving set contains Q as a subsequence together with at most m k impostor positions, and Theorem 3 applied to that reduced instance bounds the remaining uncertainty. Since H k is non-increasing in k and bounded below by the min-entropy H ∞ (P), the decay rate lies between H ∞ and H 2 bits per additional frame. ∎ Figure 7 plots the decay for a 120-token item at unit density. At two bits of effective decay per frame, ambiguity falls from roughly 240 bits to under one bit within eight captures, and at four bits per frame within five. The direction of the effect is the point. Resampling the camouflage layer more aggressively raises the per-frame entropy H k , which accelerates the leak rather than slowing it. Dynamic lamination as described in the earlier version therefore weakens the scheme against any adversary who captures more than once, and the invariance test costs the adversary nothing beyond alignment. Fig. 7. Residual ambiguity after k independent frame captures under frame- granular re-lamination, for a 120-token item at unit camouflage density, plotted from the bound of Theorem 7 at three effective decay rates. Curves are computed from the closed form and contain no measured data. The remedy is Equation (33). Holding both Π and Q ̃ fixed for the lifetime of a session removes the invariance signal entirely, since nothing varies for the adversary to compare, and confines rotation to the session boundary where an attacker gains no repeated observations of the same item. We take this as the default configuration and treat frame-granular variation as unsafe unless the indistinguishability condition is verified. Theorem 8 (Capture Complexity Under Temporal Multiplexing). Let each frame reveal each authentic token independently with probability ρ, as in Equations (34) and (36). Then the expected number of captures required to observe every authentic token at least once is E[k] = Σ j≥0 [ 1 − (1 − (1−ρ) j ) n ] ≈ ln n / ln(1/(1−ρ)). This bound applies to every adversary class, including A5. Proof. The first frame at which token i becomes visible is geometric with parameter ρ, and these are independent across tokens. The number of frames until all n have appeared is the maximum of n independent geometric variables, whose expectation is the stated sum by the tail-sum identity, with the classical extreme-value approximation ln n / ln(1/(1−ρ)) for large n. Any reconstruction of Q requires each of its tokens to have been observed at least once, so E[k] lower-bounds the expected captures needed for exact recovery. ∎ Figure 8 shows the growth. The honest reading is that temporal multiplexing raises the cost of a screenshot attack from one capture to a modest number, and that the growth in item length is logarithmic rather than polynomial, so it is a friction rather than a barrier. Its value comes from composition with the behavioural domain B(t) of the MARS state: if each capture carries an independent detection probability p d , the probability that a full reconstruction goes unnoticed falls as (1 − p d ) E[k] , and it is that product, not the capture count alone, that constitutes the defence against A5. Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 9 Fig. 8. Expected number of captures required for complete observation of the authentic stream under temporal multiplexing, from the exact expression of Theorem 8, at three per-frame visible fractions ρ. Computed from the closed form; no measured data. XIII. ALGORITHM AND COMPLEXITY The constructs of Sections V to VII compose into a single render-time procedure. Stating it makes the cost explicit and removes any impression that the framework requires expensive inference on the critical path. Algorithm 1 Render a camouflaged item Input : Q=(w_1..w_n), key K, item id, eta, margin dE*, ceilings th_obf, d_max Output: rendered surface Sigma 1 m <- round(eta*n) 2 Qt <- Inversion(Q, m) # C1-C3 3 Pi <- PRF(K, id, 0) # m-subset 4 Gam <- PRF(K, id, 1) s.t. (17),(18) 5 for i = 1..n+m: # laminate 6 Om[i] <- Qt[j(i)] if i in Pi 7 else Q[r(i)] 8 chi[i] <- c_c if i in Pi else c_q 9 if Sim(Q,Om) > th_obf 10 or Detect(Om,Pi) > d_max: 11 lower eta or resample Qt; goto 2 12 return Sigma <- (Om[i],p_i,chi[i],Psi_i) Lamination is a single pass, so lines 5 to 8 cost Θ(n+m) time and Θ(n+m) space. Key derivation is Θ(m). The inversion operator dominates: with a lexical instantiation over WordNet it is Θ(m) lookups, and with a generative instantiation it is one forward pass over the item. The verification at lines 9 and 10 costs one sentence-encoder pass for Sim and one language- model pass for Detect. Since Q, Q ̃ , Π, and Γ all depend only on the item and the session key, the whole procedure runs once per item per session and the result is cached, so the per-frame render path carries only the Θ(n+m) evaluation of Equations (35) and (36). The retry loop at line 11 terminates because A c is monotone in η and η = 0 trivially satisfies both ceilings. XIV. PROPOSED EVALUATION PROTOCOL This paper reports no experiments and we make no empirical claims. The theorems above are, however, stated so that each yields a falsifiable prediction, and we set out the protocol here so that a later study can be pre-registered against it rather than assembled after the fact. Readability, testing Theorem 2. Candidates complete matched item sets at densities spanning η ∈ [0, 1] under an above-threshold and a below-threshold margin. Primary outcomes are item-level accuracy and time to first keystroke. The prediction is that above threshold both are flat in η within noise, and that below threshold time grows linearly in η. Participants should include a colour-vision-deficient group under the non-chromatic channel of Section VII. Extraction resistance, testing Theorems 3, 5, and 6. For each adversary class in Table I, the extracted view is passed to a solver and scored for item-level accuracy. The prediction is a large drop for A1 and A2, no drop for A3 absent styling countermeasures, and an intermediate drop for A4 and A5 that tracks the acceptance rate q of Theorem 6. Measuring q directly, by scoring candidate reconstructions under a held-out model, is the sharpest single test of the theory. Leakage, testing Theorem 7. Under frame-granular re- lamination, apply the invariance test at k = 1, 2, 4, 8 captures and record the fraction of authentic tokens correctly identified. The prediction is that identification approaches unity within a number of captures set by the per-frame decay rate, and that holding Π and Q ̃ fixed across the session drives it to chance. Reporting. Effect sizes with confidence intervals, the full density grid rather than a selected operating point, and the measured ΔE 00 of the rendered colours, which is the parameter on which the readability results depend and which is easy to leave unreported. XV. DISCUSSION AND LIMITATIONS The constructs developed here reframe Context Camouflaging from a single black-box transformation Φ into an explicit pipeline whose readability and ambiguity properties are separately tuneable and, above the discriminability threshold, decoupled. The practical implication is that an institution can raise computational ambiguity against class A1 and A2 extraction by raising η without a corresponding cost to legitimate candidates, provided the separation margin of Equations (17) and (18) is met at render time. The scope of that claim is narrower than the earlier version implied, and the narrowing is the main contribution as much as the new theorems are. Colour separation defends the text- extraction channel. It does not defend against a scripted reader of the document object model, which sees the styling, and it does not defend against a vision-language model given a screenshot, which sees both the colour and enough semantics to make Theorem 6 bite hard. Against those classes the defence has to come from the temporal domain, and Theorem 8 prices what that buys: a logarithmic increase in capture count, valuable mainly because each capture carries detection risk in the behavioural domain. A reader who takes away only one thing should take away that the guarantee is channel-specific. Several limitations follow. First, the trilemma of Section IX has no principled resolution in this paper. Equations (26) and (28) pull in opposite directions, Theorem 6 shows the exchange rate matters, and we have no method for setting it beyond tuning against a held-out model, which invites overfitting to that model. Second, the Context Inversion Operator is treated abstractly. Conditions C1 to C3 constrain it but do not construct it, and whether a lexical instantiation over WordNet [3] or a learned generative model can satisfy all three at a useful density is an empirical question this paper does not settle. Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 10 Third, Theorem 3 assumes a uniform prior over insertion sets. A biased sampler, a predictable position map, or heavy reuse of camouflage tokens each reduce A c below the closed form, and the reduction is silent: nothing in the rendered output reveals it. Auditing the sampler is therefore a deployment requirement rather than an implementation detail. Fourth, accessibility. Equation (18) states the condition but a platform still has to meet it under arbitrary user stylesheets, high-contrast modes, and screen readers, the last of which will read the laminated field in full unless the camouflage positions are marked for exclusion, which in turn hands class A3 exactly the signal it needs. We have no clean answer to that conflict and regard it as the sharpest practical objection to the approach. XVI. CONCLUSION This paper extended the Context Camouflaging Operator of the MARS assessment-resilience framework into the Multi- Layer Context Camouflaging Theory, a specified mathematical treatment of semantic superposition for malpractice-resilient online assessment. Six coupled constructs replace the single coarse transformation of the original formulation, and eight theorems characterize their joint behaviour under an explicit adversary model. Three of the revisions change what the framework claims rather than only how it is stated. The preservation constraint became a fidelity identity together with obfuscation and plausibility ceilings, because a similarity floor asks the laminated field to keep conveying the item it is meant to hide. Computational ambiguity became a conditional entropy with the closed form log 2 C(n+m, m), which is monotone in density where the previous unigram measure was not. And frame- granular dynamic lamination turned out to leak geometrically against a multi-capture adversary, so the safe default is session- granular rotation. Equation (35) reconnects the theory to the MARS Rendering Tensor formalism, with the type error of the earlier scalar product removed, so Context Camouflaging is available as a specified layer within the larger system model. The open problems we would most like to see addressed are the exchange rate between obfuscation and plausibility in Theorem 6, a construction for the inversion operator satisfying conditions C1 to C3 at useful density, and the conflict between screen-reader accessibility and resistance to class A3. Table I PRINCIPAL SYMBOLS USED IN MCCT Symbol Description Unit / Domain Q, V Authentic semantic stream / vocabulary Token seq. / set Q ̃ Context-camouflage stream Token sequence ℐ Context Inversion Operator Mapping Ω Laminated (superposed) field Token sequence Σ(t) Rendered surface (new) Attributed sequence X A , V A Extraction channel / adversary view (new) Projection / seq. ℒ(·;Λ) Contextual Lamination Operator Mapping Λ = (π,κ,χ) Lamination control law Function Π Insertion set (camouflage positions) Index set Symbol Description Unit / Domain χ(i), Γ Separation function / session key Mapping / key c q , c c Authentic / camouflage channel value Colour value ΔE 00 , ΔE* CIEDE2000 difference / margin (new) CIELAB units R h , α i Human Readability Functional / indicator 0–1 / binary S c (η) Visual search cost (new) Time A c Computational Ambiguity, H(Q | V A ) (revised) Bits Sim(·), θ obf Semantic similarity / obfuscation ceiling 0–1 δ i , δ max Detectability under p LM / ceiling (new) Log-prob q Semantic-filter acceptance rate (new) 0–1 η, m, n Camouflage density / camouflage and authentic counts Ratio / counts T i (t) Context Camouflage Tensor of token i Tensor Ψ i (t), δ i (t) Temporal visibility / spatial drift (from [1]) Binary / scalar ρ(t) Visible fraction per frame (new) 0–1 ℛ i (t) Per-token rendering state (revised) Tuple AI Use Disclosure: Portions of this manuscript were prepared with the assistance of generative artificial-intelligence tools for language refinement, formatting, and figure drafting. All scientific concepts, mathematical formulations, algorithms, theoretical propositions, analyses, and conclusions were conceived, verified, and approved by the authors, who accept full responsibility for the content of this manuscript [14]. REFERENCES [1] L. R. Gupta, K. Kaur, S. Ram, and Prajithaa, "A Multi-Dimensional Spatio-Temporal Context Camouflaging Framework for Resilient Digital Assessments," MARS Technical Report, Lovely Professional University, 2026. [2] S. Dawson, "Defending Assessment Security in a Digital World," Assessment & Evaluation in Higher Education, 2020. [3] C. Fellbaum, Ed., WordNet: An Electronic Lexical Database. Cambridge, MA, USA: MIT Press, 1998. [4] J. Devlin, M.-W. Chang, K. Lee, and K. Toutanova, "BERT: Pre- training of Deep Bidirectional Transformers for Language Understanding," in Proc. NAACL-HLT, 2019, p. 4171–4186. [5] N. Reimers and I. Gurevych, "Sentence-BERT: Sentence Embeddings using Siamese BERT-Networks," in Proc. EMNLP, 2019, p. 3982– 3992. [6] C. E. Shannon, "A Mathematical Theory of Communication," Bell Syst. Tech. J., vol. 27, p. 379–423, 1948. [7] N. Boucher, I. Shumailov, R. Anderson, and N. Papernot, "Bad Characters: Imperceptible NLP Attacks," in Proc. 43rd IEEE Symp. Security and Privacy (SP), 2022, p. 1987–2004. [8] N. Boucher and R. Anderson, "Trojan Source: Invisible Vulnerabilities," in Proc. 32nd USENIX Security Symposium, Anaheim, CA, USA, 2023, p. 6507–6524. [9] A. M. Treisman and G. Gelade, "A Feature-Integration Theory of Attention," Cognitive Psychology, vol. 12, no. 1, p. 97–136, 1980. [10] J. M. Wolfe, "Guided Search 2.0: A Revised Model of Visual Search," Psychonomic Bulletin & Review, vol. 1, no. 2, p. 202–238, 1994. [11] M. R. Luo, G. Cui, and B. Rigg, "The Development of the CIE 2000 Colour-Difference Formula: CIEDE2000," Color Research & Application, vol. 26, no. 5, p. 340–350, 2001. [12] M. Mahy, L. Van Eycken, and A. Oosterlinck, "Evaluation of Uniform Color Spaces Developed after the Adoption of CIELAB and CIELUV," Color Research & Application, vol. 19, no. 2, p. 105–121, 1994. [13] H. Brettel, F. Viénot, and J. D. Mollon, "Computerized Simulation of Color Appearance for Dichromats," J. Opt. Soc. Amer. A, vol. 14, no. 10, p. 2647–2655, 1997. Preprint. Submitted to Springer Nature Machine Learning; not yet peer reviewed. 11 [14] UNESCO, "Guidance for Generative AI in Education and Research," Paris, France, 2023.