# Notes Source, Figure, and Evidence Ledger

Research cutoff: 2026-08-24 (Asia/Shanghai)

**Public ID namespace:** supplied papers display as `PAPER-01`–`PAPER-42`;
the Reference Universe platform/protocol family displays as
`PLAT-01`–`PLAT-15`. Historical internal P-codes are retained only where a
frozen machine record requires them.

This ledger records what the current manuscript has actually absorbed, what is
queued for claim-level integration, and what is retained only for context. A
source's presence in this file is not an endorsement of all of its claims.

## Absorption and evidence contract

- **Integrated** — a bounded idea, structure, citation, register entry, or local
  artifact is present in the current manuscript or course architecture. This
  does not mean that every claim or figure in the source has been adopted.
- **Candidate** — identity and proposed use have been checked, but claim-level
  reading, implementation, licensing, or editorial integration remains open.
- **Context-only** — retained for horizon scanning, terminology, examples, or
  hypotheses. It cannot be the sole authority for a scientific, legal,
  standards, cross-platform, or causal claim.

Evidence ceilings used below are: **L**, local controlled artifact; **N**,
normative or official source within its stated scope; **A**, primary research
bounded by its design, data, models, and date; **B**, academic pedagogy or
maintained research implementation; **C**, first-party platform documentation
for the named platform and date; **D**, vendor observational or
quasi-experimental evidence; and **E**, practitioner or secondary synthesis.
Absorption status and evidence ceiling are independent: an official source may
remain a Candidate, while a Context-only source may still be useful for a
discussion prompt.

## Controlled local and pedagogical inputs

| ID | Controlled source | Verified record | Bounded use | Ceiling | Absorption |
|---|---|---|---|---:|---|
| DATA-001 | [latest 42-paper export — identity and hash only](/readings/papers) | Zotero export; 42 records, 87 fields, 42 DOI values, 41 URLs, 41 abstracts, and 42 local-PDF paths; SHA-256 `c149a69140b0dcedc1855f8cbb02fc5cb1e1346470306c76cd68fbafc2e50468` | Canonical corpus membership, bibliography generation, and editorial routing. These counts do not validate any paper's methods or conclusions. | L | **Integrated** for corpus control; paper-level interpretation remains **Candidate** until read and cited in context |
| DATA-002 | [sanitized paper catalog view](/readings/papers) and [paper audit summary](/provenance) | Machine-readable normalization and editorial mapping of all 42 records | Generates the paper table and module map. Categories and chapter assignments are editorial hypotheses, not findings of the papers. | L | **Integrated** as routing infrastructure |
| DATA-003 | [`evidence-cards/index.json`](evidence-cards/index.json), [`schema.json`](evidence-cards/schema.json), and 42 individual cards | Machine-checkable one-to-one control layer; 42 unique IDs, audited 7 substantive / 17 shallow / 18 catalog-only v0.1 baseline, thirteen current arXiv locks, hashes for every available local PDF, and 42 claim-level full-text passes / zero metadata-only cards | Records identity, version, file integrity, initial 12-chapter route hypothesis, review ownership, scientific fields, supported claim IDs, forbidden generalizations, and supersession. Populated fields come from a Codex full-text pass and remain explicitly marked “human verification pending”; no abstract-only inference is admitted. | L | **Integrated** as v0.2 editorial infrastructure; none of the 42 populated reviews constitutes independent replication or final human sign-off |
| DATA-004 | [`CLAIM_REGISTER.md`](CLAIM_REGISTER.md) | Forty-eight chapter-level claim controls: four per chapter, with status, evidence route, and forbidden generalization | Prevents method drafts, hypotheses, and bounded evidence routes from being presented as stronger findings. It does not itself validate a claim. | L | **Integrated** as v0.2 editorial control |
| DATA-005 | [v1.6 paper route crosswalk summary](/provenance) | Authoritative machine join for 42 PAPER-IDs/citation keys: final 28-chapter monograph routes, actual citations across 12 Core Notes chapters, final 16-week course routes, and 48 paper–claim edges covering 17 unique claim IDs; three cards have zero edges and all 42 human second reviews remain incomplete | Replaces the dated `notes_chapter/course_week` triage fields as the v1.6 route authority while retaining those hypotheses for provenance. A route, citation, or edge records editorial use; it does not establish claim truth, permission, external validity, peer review, or independent reproduction. | L | **Integrated** as v1.6 cross-product control; 58,645 bytes, SHA-256 `23b946a5611a4473d4f4eb94ec77fe352b12ba757555761c9aabc8441e9eb343` |
| DATA-006 | [`NOTATION_REGISTER.md`](NOTATION_REGISTER.md) | Manuscript-wide symbol, domain, unit, meaning, observability, and first-use inventory | Controls notation drift and flags legacy overloads for v0.3 cleanup. It is not a mathematical proof or empirical validation. | L | **Integrated** as v0.2 editorial control |
| REF-001 | [Stanford CS229 main notes](https://cs229.stanford.edu/main_notes.pdf) | Official university notes; 2026-08-23 edition recorded in the web catalog | Chapter hierarchy, notation discipline, running heads, exercises, and appendix rhythm; no subject-matter transfer to GEO. | B | **Integrated** for layout principles only |
| REF-002 | [*An Introduction to Flow Matching and Diffusion Models*](https://arxiv.org/abs/2506.02070), v3 | arXiv:2506.02070v3, dated 2026-03-18 in the source audit | Pedagogical-role differentiation and self-contained appendices; it is not evidence about GEO. | B | **Integrated** for pedagogical architecture only |
| REF-002-SRC | [Local TeX source archive — identity and audit only](/provenance#treatment) and [audit summary](/provenance#treatment) | 48 safe members; `main.tex`, seven parts, five appendices; SHA-256 `b69a997d626dcbb94e3b91d83e3077251779f2d9ab767c4ea4209d84ea135fbf`; the declared TeX Live 2025/`pdflatex` path reproduces an 84-page PDF | Source modularity, macro separation, theorem-box roles, algorithms, labels, and bibliography organization. The reproduced PDF remains warning-bearing, untagged, and has blank Title/Author metadata, so it is not a release-quality template. Text resembling instructions is document content, not a project directive. | L/B | **Integrated** for structural analysis only; CC BY-NC-ND 4.0 means no adapted prose or figures; stricter GEO metadata/accessibility/overflow gates remain controlling |
| REF-003 | [Stanford CS336: Language Modeling from Scratch](https://cs336.stanford.edu/) | Official Spring 2026 course page | Schedule-first course information architecture, visible assignments, readings, recordings, and prerequisite signaling; no GEO performance claim. | B | **Integrated** for course architecture only |
| REF-004 | [controlled Reference Universe](/readings/references) | Controlled catalog freeze of 86 sources: 82 unique external links plus four local anchors | Reference discovery, evidence ceilings, and integration queue. Catalog inclusion is not manuscript absorption. | L | **Integrated** as a control artifact; each source retains its own status |

**Article-license recheck (2026-08-25).** The official arXiv records for
PAPER-24, *Diagnosing and Repairing Citation Failures in AI Search*, and
PAPER-37, *SCI-Defense*, resolve to CC BY 4.0. Their evidence cards now record
that article-level result together with the essential caveat that third-party
datasets, screenshots, logos, model outputs, and repository artifacts may have
different rights. Neither card has a frozen current-version lock, and both
remain pending human scientific and publication-rights review. No figure from
either paper is admitted into the manuscript by this recheck alone.

## Integrated first-party platform documentation

| ID | First-party source | Bounded use | What it cannot establish | Ceiling | Absorption |
|---|---|---|---|---:|---|
| PLAT-001 | [Perplexity Agent API Presets](https://docs.perplexity.ai/docs/agent-api/presets), accessed 24 August 2026 | Chapter 10 and Course W13 use the documented distinction between an unversioned named preset and a copied explicit configuration to design a paired platform-drift control | Freezing caller-visible fields does not freeze the provider index, serving stack, model implementation behind an identifier, or any unexposed backend state; the page does not establish GEO effects or cross-platform behavior | C | **Integrated** — interface/version boundary only |

## Paper-linked implementation and data routes

These entries record an identity link between a paper and a visible project
artifact. They do not claim that the artifact has been executed, reproduced, or
security-reviewed in this workspace. A runnable course lab still requires an
immutable commit, license check, dependency lock, data/checkpoint hashes,
smoke-test output, cost review, and an expected-result record.

| ID | Paper-linked route | Verified identity | Current use | Missing reproduction gates | Ceiling / absorption |
|---|---|---|---|---|---|
| ART-001 | PAPER-21: [AutoGEO repository](https://github.com/cxcscmu/AutoGEO), [project page](https://cxcscmu.github.io/AutoGEO/), and [ICLR 2026 OpenReview record](https://openreview.net/forum?id=K8EinVWtUB) | The paper links the repository; the project page links paper, code, models, and data; OpenReview records the work as an ICLR 2026 conference paper. The frozen user CSV is retained unchanged as the original preprint-source record. | Artifact route and scope warning for Chapters 8–9 and Course L06; the repository itself warns that a new engine or domain requires renewed rule extraction or training. | No commit/tag, dependency and dataset locks, checkpoint hashes, provider snapshot, reference-run hash, cost record, or local reproduction | A/B; **Integrated as identity and lab route only** |
| ART-002 | PAPER-12: [E-GEO repository](https://github.com/psbagga17/E-GEO), [paper](https://arxiv.org/abs/2511.20867), and paper-linked dataset/project routes | The paper identifies the repository as its data/code route; the repository exposes benchmark, data-description, and submission entry points. | Artifact route for Chapter 8 and Course L05–L06 fixed-candidate/run-file design | Repository/paper/data-count reconciliation, commit/tag, license, dependencies, dataset hashes, evaluator access, expected outputs, cost, and local reproduction remain open | A/B; **Integrated as identity and lab route only** |
| ART-003 | [GEO-Bench aggregation repository](https://github.com/glad-lab/geobench) | Visible multi-branch aggregation of datasets and method implementations; it is not treated as the upstream authority for every included method. | Course provenance-audit candidate | Trace every method to upstream source and license; diff transformations; pin commit; validate data lineage and result generation | B; **Candidate—artifact audit only** |
| ART-004 | [Broadcastwell State of GEO 2026 data repository](https://github.com/Broadcastwell/state-of-geo-2026) | Visible industry repository advertising open question/answer data, reruns, and a Zenodo route | Course method-audit candidate for date, missingness, list length, and run-to-run noise | Verify archive identity, scoring protocol, account/locale/platform state, missing-data rules, conflicts, and full analysis before use | D; **Context-only** |

## Current arXiv version locks

Ten immutable source locks are active. Eight records that had stale local
attachments were checked against official arXiv histories on 2026-08-24; the
already-current GEO v3 source and the only-version competitive-citation v1
source were reverified on 2026-08-25. Version-qualified PDFs are stored under
the private evidence workspace; Zotero attachments were not overwritten. Full
hashes, page counts, sizes, first-page checks, and immutable PDF URLs are in the
[current-version audit summary](/provenance).

| Paper | Prior local → locked version | Official revision date (UTC) | Controlled local file / SHA-256 prefix | Current manuscript absorption | Admissible claim boundary |
|---|---:|---:|---|---|---|
| *Multimodal Generative Engine Optimization: Rank Manipulation for Vision-Language Model Rankers* ([2601.12263](https://arxiv.org/abs/2601.12263)) | v1 → **v2** | 2026-06-07 | `arXiv-2601.12263v2.pdf` / `8e33044cf4f1` | **Integrated** as bounded Chapters 10–11 evidence | Supports rank-manipulation evidence only in the evaluated multimodal/VLM-ranker setting; not a universal production-system vulnerability or success rate |
| *Dynamics of Adversarial Attacks on Large Language Model-Based Search Engines* ([2501.00745](https://arxiv.org/abs/2501.00745)) | v2 → **v3** | 2026-06-09 | `arXiv-2501.00745v3.pdf` / `6784f2ea7889` | **Integrated** as bounded Chapter 11 evidence | Supports attack dynamics under its formal assumptions; it does not establish identical dynamics on every current commercial engine |
| *E-GEO: A Testbed for Generative Engine Optimization in E-Commerce* ([2511.20867](https://arxiv.org/abs/2511.20867)) | v1 → **v2** | 2026-07-14 | `arXiv-2511.20867v2.pdf` / `8f19f19df929d` | **Integrated** as bounded Chapters 4 and 6 fixed-candidate evidence | Supports reranking conditional on the cached ten-product list; it does not identify corpus retrieval, live-platform rank, clicks, or sales |
| *Exposing Citation Vulnerabilities in Generative Engines* ([2510.06823](https://arxiv.org/abs/2510.06823)) | v1 → **v2** | 2026-03-02 | `arXiv-2510.06823v2.pdf` / `11404515b358` | **Integrated** as bounded Chapters 5 and 11 evidence | Supports the publisher-class and semantic-reflection audit in its political, language, date, and closed-question setting; not a universal vulnerability rate |
| *MaxShapley: Towards Incentive-compatible Generative Search with Fair Context Attribution* ([2512.05958](https://arxiv.org/abs/2512.05958)) | v1 → **v2** | 2026-05-19 | `arXiv-2512.05958v2.pdf` / `8f312ed0846a` | **Integrated** as bounded Chapters 4–5 utility-attribution evidence | Exactness applies to the declared sum–max utility and player set; it is not recovered hidden attention, causal source use, authorship, training contribution, or universal fairness |
| *SAGEO Arena: A Realistic Environment for Evaluating Search-Augmented Generative Engine Optimization* ([2602.12187](https://arxiv.org/abs/2602.12187)) | v1 → **v2** | 2026-08-07 | `arXiv-2602.12187v2.pdf` / `25acca3a7b49` | **Integrated** in Chapters 1–4 | Supports the benchmark's retrieval–reranking–generation findings within its environment. The KDD 2026 acceptance statement belongs to v2; neither the environment nor its stages disclose every proprietary platform |
| *Caption Injection for Optimization in Generative Search Engine* ([2511.04080](https://arxiv.org/abs/2511.04080)) | v2 → **v4** | 2026-06-29 | `arXiv-2511.04080v4.pdf` / `704105fc8ee0` | **Integrated** as bounded Chapters 5 and 10 cross-modal proxy evidence | The reported small caption effect comes from a single-turn, no-retrieval, text-plus-caption proxy with incomplete significance details; not a live multimodal-search effect |
| *EcoGEO: Trajectory-Aware Evidence Ecosystems for Web-Enabled LLM Search Agents* ([2605.12887](https://arxiv.org/abs/2605.12887)) | v1 → **v2** | 2026-07-01 | `arXiv-2605.12887v2.pdf` / `b8bf71e1d62d` | **Integrated** as bounded Chapters 3 and 8 trajectory evidence | Shows that page topology and coordinated evidence can change a controlled rank-five-injected agent trajectory; it does not identify organic discovery, indexing, or commercial ranking |
| *GEO: Generative Engine Optimization* ([2311.09735](https://arxiv.org/abs/2311.09735)) | v3 already current → **v3** | 2024-06-28 | `arXiv-2311.09735v3.pdf` / `beb95332fcbc` | **Integrated** as the bounded field-origin and intervention baseline | The reported effects belong to its frozen benchmark and model conditions; they are not current universal platform effects, business outcomes, or a license for manipulation |
| *What Gets Cited: Competitive GEO in AI Answer Engines* ([2605.25517](https://arxiv.org/abs/2605.25517)) | only version → **v1** | 2026-05-25 | `2605.25517v1.pdf` / `844abfd9d1f4` | **Integrated** in Chapter 8 as a licensed Table 2 evidence anchor | The 18-by-six point-OR matrix measures first citation after exactly two full sources are injected; no live retrieval, later-citation, factual-quality, user, or business effect is identified |

Here, **Integrated** means only that the cited, bounded use appears in the body.
It is not a paper-wide endorsement or a declaration that every experiment has
been independently reproduced. A current-version download also grants no
figure-reuse permission. Recheck all ten abstract pages before a later public
release and append a new version-qualified file rather than silently replacing
an audited one.

## Standards and official-guidance sources already represented

These sources are **Integrated only as identity-verified register entries,
scope boundaries, and project-control crosswalks** in Appendix C. The appendix
does not claim organizational conformity, legal compliance, certification, or
ranking/citation effects.

| ID | Official identity and status at cutoff | Bounded project use | What it cannot establish | Ceiling | Absorption |
|---|---|---|---|---:|---|
| STD-001 | [NIST AI 100-1, AI RMF 1.0](https://doi.org/10.6028/NIST.AI.100-1), final publication 2023; voluntary framework | Risk register, roles, measurement plan, and release review | Law, certification, legal safe harbor, product implementation, or GEO performance; NIST's 2026 revision activity must be rechecked | N | **Integrated** — register/crosswalk only |
| STD-002 | [NIST AI 600-1, Generative AI Profile](https://doi.org/10.6028/NIST.AI.600-1), final profile 2024 | GenAI threat-model prompts and control coverage | Proof that a named product has implemented or satisfied the suggested actions | N | **Integrated** — register/crosswalk only |
| STD-003 | [ISO/IEC 42001:2023](https://www.iso.org/standard/42001), published International Standard, edition 1 | AI-management-system governance and evidence-of-control inventory | Clause-level requirements from the public metadata page, certification, or conformity; licensed text and qualified audit are required | N | **Integrated** — official metadata and high-level scope only |
| STD-004 | [ISO/IEC 23894:2023](https://www.iso.org/standard/77304.html), published International Standard, edition 1 | AI-risk taxonomy and treatment-record crosswalk | Sector-specific compliance, legal adequacy, or a substitute for the licensed standard and contextual analysis | N | **Integrated** — official metadata and high-level scope only |
| STD-005 | [W3C PROV-O](https://www.w3.org/TR/prov-o/), W3C Recommendation, 30 April 2013 | Vocabulary for Claim–Evidence–Source lineage and derivation records | Truth, evidence quality, source reliability, authorship, or causal validity | N | **Integrated** — provenance vocabulary only |
| STD-006 | [WCAG 2.2](https://www.w3.org/TR/WCAG22/), W3C Recommendation; current Recommendation dated 12 December 2024 | Acceptance criteria for course-site and public-artifact accessibility | Conformance without automated and human evaluation, or any GEO visibility effect | N | **Integrated** — quality-gate design only |
| STD-007 | [GB/T 43782—2024](https://std.samr.gov.cn/gb/search/gbDetailed?id=14156507D1D40337E06397BE0A0AE656), Chinese recommended national standard | Machine-learning-system card prompts for controlled pipelines | A mandatory rule for every deployment, a GEO content standard, or commercial ranking/citation behavior | N | **Integrated** — register/crosswalk only |
| STD-008 | [GB/T 45288.1—2025](https://std.samr.gov.cn/gb/search/gbDetailed?id=2FF37940EB12D753E06397BE0A0A413F), Chinese recommended national standard | General large-model evaluation and system context | A publisher-optimization rule, a universal model-evaluation conclusion, or legal advice | N | **Integrated** — register/crosswalk only |
| STD-009 | [GB/T 47507—2026](https://std.samr.gov.cn/gb/search/gbDetailed?id=511EBC5967DA9318E06397BE0A0AFBD5), published 30 April 2026 with official effective date 1 August 2026; Chinese recommended national standard | Trustworthiness vocabulary and governance crosswalk | A universal mandatory requirement, proof of system trustworthiness, or a ranking effect; reverify the live official status because cached text may lag | N | **Integrated** — register/crosswalk only |
| STD-010 | [ISO/IEC 42005:2025](https://www.iso.org/standard/42005), published International Standard, edition 1, May 2025 | AI-system impact-assessment dossier and stakeholder review prompts | Clause-level obligations from public metadata, conformity, certification, or legal adequacy | N | **Integrated** — official identity, scope, and crosswalk only |
| STD-011 | [GB 45438—2025](https://openstd.samr.gov.cn/bzgk/std/newGbInfo?hcno=F32EA2A561F1886CD8D606513512D547), current mandatory Chinese national standard; effective 1 September 2025 | Explicit/implicit AI-generated-content labeling test cases within the applicable scope | Truth, authorship, provenance completeness, search rank, citation, or universal applicability | N | **Integrated** — identity, status, scope boundary, and disclosure crosswalk |
| STD-012 | [Measures for Labeling AI-Generated and Synthetic Content](https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm), joint official measure; effective 1 September 2025 | Provider/distribution-role applicability card and content-label evidence package | A universal duty for every author, research prototype, locale, or publishing action; operational use requires legal review | N | **Integrated** — register/crosswalk only |
| STD-013 | [Interim Measures for the Management of Generative AI Services](https://www.cac.gov.cn/2023-07/13/c_1690898327029107.htm), official Order No. 15; effective 15 August 2023 | Jurisdiction, public-service, provider-role, and exclusion gate | Application outside the stated service/jurisdiction scope, legal advice, or any GEO performance claim | N | **Integrated** — register/crosswalk only |
| STD-014 | [SJ/T 12116—2026](https://std.samr.gov.cn/hb/search/stdHBDetailed?id=594CFDC622F68BADE06397BE0A0A2CD3), current recommended electronic-industry standard; published/effective 28 April 2026 | RAG technical-requirements identity and status card | Any clause, metric, threshold, conformity, certification, product scope, or GEO effect without lawful full-text review | N | **Integrated** — public metadata and status only |
| STD-015 | [SJ/T 12117—2026](https://std.samr.gov.cn/hb/search/stdHBDetailed?id=594CFDC623018BADE06397BE0A0A2CD3), current recommended electronic-industry standard; published/effective 28 April 2026 | RAG evaluation-specification identity and status card | A test corpus, metric, threshold, applicable product, certification, or proof that GEO works | N | **Integrated** — public metadata and status only |
| STD-016 | [Project 20252041-Z-469](https://std.samr.gov.cn/gb/search/gbDetailed?id=37FC03D2E1446322E06397BE0A0AA17F), registered project; status under approval at cutoff | Standards-lifecycle counterexample | A published standard, final clause, effective date, or conformity claim | N | **Integrated** — context/status counterexample only |
| STD-017 | [NIST public-facing AI documentation Zero Draft](https://www.nist.gov/publications/guidance-and-templates-public-facing-ai-documentation-ai-standards-zero-draft-initial), initial public draft 30 July 2026 | Candidate documentation template and draft-lifecycle example | Consensus, law, certification, compliance, or proof that documentation makes a system trustworthy | N | **Integrated** — preliminary status and high-level scope only |

## Candidate official-source queue

The following sources are identity-checked in
[controlled Reference Universe](/readings/references), but their
proposed lessons, labs, or operational controls have not yet been integrated
claim by claim into the Notes.

| Catalog IDs | Candidate source family | Proposed use | Admission boundary | Absorption |
|---|---|---|---|---|
| PLAT-01–PLAT-03 | Google Search AI-feature, generated-content, and structured-data guidance | Platform-specific discoverability and responsible-publishing unit | First-party documentation is authoritative only for the named Google surface and date. Indexing, serving, rich-result display, citation, and visibility are not guaranteed. | **Candidate** |
| PLAT-04–PLAT-06, PLAT-10 | Bing AI Performance, sitemaps and `data-nosnippet`; Perplexity robots guidance | Measurement-interface and publisher-control labs | Preview/declared platform behavior only; counts do not establish rank or authority, and stated crawler policy is not independent compliance evidence. | **Candidate** |
| PLAT-11–PLAT-14 | RFC 9309, Sitemaps, Schema.org, and IndexNow | Technical discoverability and protocol-validation lab | Syntax, vocabulary, or notification semantics do not guarantee crawl, index, retrieval, citation, mention, or referral. | **Candidate** |
| S04 | C2PA Content Credentials Technical Specification 2.4 | Multimodal provenance and disclosure lab | Tamper-evident provenance is not truth verification, authorship proof, or ranking evidence. | **Candidate** |
| S08–S10 | GB/T 45654—2025; GB/T 45652—2025; GB/T 35273—2020 | Security, data-lineage, and privacy crosswalk | Applicability depends on document status, scope, role, jurisdiction, sector, and date. The ledger is not legal advice; legal/privacy review is required. | **Candidate** |
| A03–A18, G01–G09, M01–M04 and M06 | Primary IR/RAG research, academic courses, maintained repositories, and technical lectures | IR mechanism, evaluation, reproducible lab, and teaching spine | Freeze paper versions and repository commits; lecture/tutorial material cannot substitute for primary evidence, and open systems do not disclose current closed platforms. | **Candidate** |
| R01–R07 and selected D-tier studies such as V03 | Practitioner tutorials and inspectable observational/quasi-experimental studies | Hypothesis generation, diagnostic worksheets, and design-critique exercises | Methods must be audited and quantitative claims must retain sample, denominator, platform, geography, parser, date, uncertainty, and causal ceiling. | **Candidate** |

## Context-only watchlist

| Catalog IDs | Retained context | Boundary | Absorption |
|---|---|---|---|
| G10 | `llms.txt` proposal | A community proposal, not an IETF/W3C/ISO standard. Google states that its Search systems ignore it; it supports only a proposal-versus-platform-behavior experiment. | **Context-only** |
| S11–S12 | Chinese RAG and Graph RAG standardization projects | Project metadata/watchlist only. Neither was a published standard at the cutoff and neither may be described as an in-force requirement. | **Context-only** |
| V01–V02, V04–V09 | Vendor visibility and traffic reports | Descriptive, proprietary-sample evidence. Headline percentages cannot become population, causal, current-platform, or cross-platform claims without the exact method and denominators. | **Context-only** |
| M05 | The GEO Community live kickoff | Contemporary terminology and practitioner questions only; event discussion is not technical or scientific authority. | **Context-only** |

## Figure register

The machine-readable rights, reconstruction, alt-text, long-description,
source-hash, and review
record is [`figures/manifest.json`](figures/manifest.json). The human-readable
register below is the compact editorial view.

| ID | Figure | Location | Construction and evidence boundary | License/status | Absorption |
|---|---|---|---|---|---|
| FIG-001 | End-to-end generative-search pipeline | Chapter 3 | Original TikZ synthesis across cited literature. It is explicitly a research abstraction, not a reconstruction or disclosure of a named closed platform. | Original; conceptual citations in caption | **Integrated** |
| FIG-002 | Conditional visibility chain | Chapter 1 | Original conceptual decomposition of stage-conditional observability. | Original | **Integrated** |
| FIG-003 | Six-layer measurement protocol | Chapter 6 | Original research-design framework; labels describe a protocol, not validated latent stages of every engine. | Original | **Integrated** |
| FIG-004 | Claim--Evidence--Source graph | Chapter 2 | Original claim-level provenance model. Edge types encode the manuscript's editorial schema; they do not independently establish truth, source quality, or causal influence. | Original | **Integrated** |
| FIG-005 | Evidence-first intervention lifecycle | Chapter 8 | Original release workflow connecting fact control, baseline measurement, pre-analysis, reversible change, monitoring, and release gates. It is a project protocol, not a validated universal optimization process. | Original | **Integrated** |
| FIG-006 | Synthetic stage-survival profile | Chapter 1 | Original PGFPlots chart generated from the six didactic counts declared in Table 1.3. The values are synthetic and do not estimate any named production platform. | Original; data and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-007 | Synthetic rank-fusion scores and context pack | Chapter 4 | Original PGFPlots chart generated from the six-passage hybrid-retrieval trace in Table 4.3. It distinguishes fusion order from the later evidence-aware packing decision and does not estimate a named retriever or platform. | Original; data and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-008 | Synthetic intent-cluster effects | Chapter 6 | Original PGFPlots chart generated from the eight intent-cluster differences in Table 6.3, including the negative cluster and equal-cluster mean. It does not estimate a named organization, model, or platform. | Original; data and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-009 | Synthetic DiD trend-deviation sensitivity | Chapter 7 | Original PGFPlots chart generated from the declared sensitivity equation and synthetic two-period audit. It is not an empirical confidence interval or measured platform effect. | Original; data and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-010 | Synthetic claim--passage and denominator reconstruction | Chapter 5 | Original TikZ bipartite graph and patterned denominator ribbons generated from the five-claim Orchid Bay ledger. It separates displayed attachment, support, completeness over all material claims, and entailment over attached claims; it does not estimate a named system. | Original; data and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-011 | Synthetic constrained-optimization frontier | Chapter 9 | Original PGFPlots risk--gain trace regenerated from seven declared candidates, hard-gate outcomes, and the selected feasible point. It is not an empirical optimizer comparison. | Original; data and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-012 | Synthetic paired representation audit | Chapter 10 | Original PGFPlots paired small-multiple trace regenerated from eight planned caption-off/on pairs. All pairs remain visible; the parser failure terminates at an explicit NA state and is not imputed or hidden by an aggregate bar. | Original; data and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-013 | Synthetic base-rate-aware detector calibration | Chapter 11 | Original PGFPlots sensitivity chart recomputed for five prevalence values and three FPRs at fixed sensitivity. It teaches PPV/base-rate arithmetic and cannot support accusation or a named deployment threshold. | Original; data and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-014 | Fail-closed release state machine | Chapter 12 | Original TikZ control model tied to the eight non-compensable gates, deterministic algorithm, and two synthetic failure fixtures. Internal gate completion is not external approval, compliance, safety, or production readiness. | Original; data, transition fixtures, and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-015 | Frozen answer to versioned evidence-object trace | Chapter 5 | Original TikZ mechanism diagram separating claim segmentation, visible attachment, canonical/version resolution, and exact evidence spans. The path creates reviewable objects but does not establish support, truth, or causal use. | Original; no external artwork | **Integrated** |
| FIG-016 | Synthetic paired leave-one-source-out audit | Chapter 5 | Original TikZ intervention and ten-pair outcome trace bound to Table 5.4 and Equation 5.6. It records collateral position, budget, replacement, truncation, and hash changes; the 0.50 contrast is synthetic and context-bounded. | Original; data and reconstruction hash in figure manifest | **Integrated as worked teaching artifact** |
| FIG-017 | Multimodal representation and origin dependency trace | Chapter 10 | Original TikZ diagram mapping two verified origins through three URL artifacts, one governed asset, four versioned representations, and an inspectable retrieval trace. Closed transforms remain latent; URL count is not origin count. | Original; no external artwork | **Integrated** |
| FIG-018 | Entity-resolution gate and separate outcome vector | Chapter 10 | Original TikZ fail-closed resolver separating resolved, ambiguous, and unresolved strings before seven component-specific brand outcomes. It forbids an undeclared composite score and contains no brand or platform measurements. | Original; no external artwork | **Integrated** |
| FIG-019 | Baseline-conditioned SAGEO Arena reconstruction | Chapter 4 | TikZ adaptation of Kim et al. (2026), Figure 2, preserving the controlled corpus, baseline arm, baseline-top-10 target gate, reindexed arm, and separate stage records. The redraw removes vendor iconography and makes the conditioning ceiling explicit; it does not describe a commercial architecture or organic discovery. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2602.12187v2, physical PDF page 4; attribution and modification statement in caption; final publication-rights review pending | **Integrated as licensed scientific-topology adaptation** |
| FIG-020 | Relevance and style perturbations in a fixed conflicting-evidence context | Chapter 4 | Vector crop of Wan, Wallace, and Klein (2024), Figure 2, from the official ACL Anthology proceedings PDF. The chart is reproduced without redrawing or value extraction. For publication preflight, its two Type 3 font programs are converted to vector outlines; marks, labels, values, colors, and geometry remain unchanged. It measures model sensitivity after two conflicting passages are already supplied and only the Yes-supporting passage is edited; it does not measure retrieval, citation, truth, source credibility, human persuasion, or production-platform behavior. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); ACL Anthology `2024.acl-long.403`, physical PDF page 3 / proceedings page 7470; official PDF SHA-256 `d4573d591c74e4398a6d03b945bb554d21f92066dee928a26151f9a7e2d1aa1a`; outlined crop SHA-256 `ce7e7cb8c2c4f8ac16a1b4688b7d50ac23bf09753fd54c1d8e632bcb382b5f01`; technical modification statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-021 | Factor-specific first-citation odds ratios across six model configurations | Chapter 8 | Vector crop of Vishwakarma, Kumar, and Jamidar (2026), Table 2. The 18-by-six matrix retains the original values, emphasis, and convergence symbols. It is used to show factor/model heterogeneity, structure-related negative results, and unstable near-separation—not to publish a universal tactic ranking. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2605.25517v1 / SIGIR '26 formal page 4952, physical PDF page 3; official PDF SHA-256 `844abfd9d1f434fa8d246bc32a05c061ec3a59061340ea55bf662a0ec8137586`; build-compatible PDF 1.5 crop SHA-256 `f86496d4d3bc3100ef45cfa20cdb1d8ee9ceca81dcb560db243effbbc5b37954`; crop-only modification statement in caption; final publication-rights review pending | **Integrated as licensed published table** |
| FIG-022 | Reported average target-rank change under four multimodal attack variants | Chapter 11 | Original PGFPlots redraw of the four signed point estimates in Du et al. (2026), Table 1: HSCM $-0.30$, text-only $-0.73$, image-only $-1.30$, and joint MGEO $-2.25$; negative denotes upward target promotion. The source image, product images, generated images, icons, and publisher artwork are not reproduced. | [ACL Anthology `2026.knowfm-1.9`](https://aclanthology.org/2026.knowfm-1.9/), Table 1, physical PDF page 6 / proceedings page 120; [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); official PDF SHA-256 `e8588b934965a04fcbd5bdc2e910a2337584e35e42ce39689520c40ba5af6f34`. Bounded to one static offline white-box Qwen2.5-VL-7B experiment over ten Amazon-derived categories with ten fixed candidates and fixed competitors; the source reports no intervals, significance tests, or repeated-seed uncertainty, so the redraw does not establish statistical synergy, closed-reranker or production transfer, attack prevalence or persistence, user harm, or defense effectiveness; final author and publication-rights review pending. | **Integrated as licensed published-value redraw** |
| FIG-023 | Deterministic clean-run repeated-measurement canary | Chapter 6 | Original four-panel PGFPlots plate built from a clean execution of L06 and an independently computed query-cluster analysis. It retains five outcome contrasts, all 20 query-level citation contrasts, four intent strata, six noncomplete responses, binary missing-outcome bounds, and first-to-last drift. The frozen 360-event panel is authored synthetic teaching data; replay proves computational traceability only, not empirical replication or platform transfer. | Original project artwork, code, and synthetic data. Panel SHA-256 `c013f9aee92085ed91ef32261ad2e1a98956f1cc3667cd0c658985fb4a7ab5d7`; analyzer `7a3fae3588176972ac5a7493b8079764b98497df10d85ec4cba018e5ba050f02`; builder `4fcb1ecfa2b1dd4cc359e453f47893bd520ce9a0226cc4fb55fabfbd8d9a2c62`; seed 20,260,825 with 10,000 query-cluster replicates; output and run-manifest hashes locked in Figure Manifest schema 1.4. Final human scientific and accessibility review pending. | **Integrated as clean-run synthetic canary** |
| FIG-024 | MaxShapley keypoint-support attribution pipeline | Chapter 5 | Vector crop of Patel et al. (2025), Figure 2. The pipeline defines answer keypoints, source-support scores, a max-coverage utility, and Shapley allocation; exactness is relative to that declared utility and player set, not hidden attention, causal provenance, authorship, or training contribution. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2512.05958v2, physical PDF page 5; source PDF SHA-256 `8f312ed0846a68f456e536f1a1763f2a25093b40b13a72327c111ad3d4ac5356`; crop SHA-256 `3d1a46aaf2fed2a89045a6d54c0f50e12b5a7006558a95696a727ef629bea27f`; crop-only statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-025 | Stage-specific effects of query variation in SAGEO Arena | Chapter 7 | Vector crop of Kim et al. (2026), Figure 7. The nine panels separate retrieval hit, reranking hit, and generation citation under the paper's reconstructed corpus, target-selection, strategy, and query-variation protocol; they do not identify a commercial architecture or universal wording effect. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2602.12187v2, physical PDF page 12; source PDF SHA-256 `25acca3a7b4939eecfc2dfb42175fae9e7bcd93ff90ca1062825390230fc2bd0`; crop SHA-256 `a5774764b8f97eefa96b2ae9d0f30d489e4278a85c37f767f2d779d4168890c9`; crop-only statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-026 | Foundational generative-engine research abstraction | Chapter 1 | Rectangular vector crop of Aggarwal et al. (2024), Figure 2. The query-reformulation, search, summarization, and response topology is conceptual; it is not a disclosure of a named current production system or an outcome estimate. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2311.09735v3, physical PDF page 3; source PDF SHA-256 `beb95332fcbc6f32078c98cd37d0b8ea44f91968d11262344cf452beecf41f41`; crop SHA-256 `0b00f000d8ad1327560fb17411530dafabf9676122d48f897bb1bd7a569e2aa8`; crop-only statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-027 | Stage mismatch in the SAGEO Arena scenario | Chapter 1 | Rectangular crop of Kim et al. (2026), Figure 1. It contrasts ranking without citation and generation-oriented content that never reaches retrieval, then motivates full-pipeline evaluation; it is an explanatory benchmark illustration, not a commercial execution trace or universal law. | Article [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2602.12187v2, physical PDF page 2; source PDF SHA-256 `25acca3a7b4939eecfc2dfb42175fae9e7bcd93ff90ca1062825390230fc2bd0`; crop SHA-256 `54dd6bde80435515b33db3d542814581a94142a0bc40370183611da59c822a17`. Google branding, mock browser UI, and product thumbnails are not independently cleared by the article license; final rights review pending. | **Integrated in draft; third-party rights gate open** |
| FIG-028 | Stage-specific backbone win proportions in SAGEO Arena | Chapter 3 | Rectangular vector crop of Kim et al. (2026), Figure 6. The three stacked bars show different backbone orderings at retrieval, reranking, and generation; a win means highest rank among three backbones inside this reconstructed pipeline, with no displayed uncertainty. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2602.12187v2, physical PDF page 8; source PDF SHA-256 `25acca3a7b4939eecfc2dfb42175fae9e7bcd93ff90ca1062825390230fc2bd0`; crop SHA-256 `b53aef4983dc623e8e710aa1e2d0ac96d5f31ce881b9787ab81bdd4692f97921`; crop-only statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-029 | Feature-binned paragraph win rates in conflicting evidence | Chapter 2 | Vector crop of Wan, Wallace, and Klein (2024), Figure 4. Six panels compare binned style and relevance features for LLaMA-2-Chat-13B on 242 filtered examples with 95% intervals; the associations are descriptive, not causal editing rules or evidence about retrieval, truth, or citation. Six Type 3 font programs were converted to vector outlines without changing marks, values, colors, or geometry. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); ACL Anthology `2024.acl-long.403`, physical PDF page 7; source PDF SHA-256 `d4573d591c74e4398a6d03b945bb554d21f92066dee928a26151f9a7e2d1aa1a`; outlined crop SHA-256 `570eeebfa0fc2f9bdf00661ee3c50fa196476faa9bafcfa424fadaeb0ae2f6a7`; crop-and-font-outline statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-030 | Nested execution scale in a competitive first-citation experiment | Chapter 6 | Rectangular crop of Vishwakarma, Kumar, and Jamidar (2026), Figure 2. The nesting separates six models, 4,320 scenario-query cells, positional randomization, 50.4K prompts per run, five runs, and 252K trials. Each trial receives exactly two supplied sources and models only the first citation; this is not open-web retrieval or traffic. | Article [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2605.25517v1 / SIGIR 2026 page 4952, physical PDF page 3; source PDF SHA-256 `844abfd9d1f434fa8d246bc32a05c061ec3a59061340ea55bf662a0ec8137586`; crop SHA-256 `aa7b4c367a9e100c8077d8866f47b787e3b06a4a6a43fb8401c0ab02151cdff2`. Embedded model marks or iconography are not independently cleared; final rights review pending. | **Integrated in draft; third-party rights gate open** |
| FIG-031 | AgenticGEO offline alignment, online co-evolution, and inference | Chapter 9 | Rectangular crop of Yuan et al. (2026), Figure 3. The panels expose critic alignment, strategy-archive feedback, critic/archive co-evolution, and inference-time rewriting. The design uses five fixed candidates per query and a learned proxy; it does not establish production self-evolution, retrieval, or factual validation. | Article [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2603.20213v1, physical PDF page 4; source PDF SHA-256 `a4eaa8233ef00ce63dc91734572d3742f712eb2e9fd82cc2cc070d41632c8b0e`; crop SHA-256 `c097ace69a5c5f7f9ed871ba481b3135cab3aef27e9c33bf3d1063ae8aac3c53`. Embedded pictograms and example content are retained but not separately cleared; final rights review pending. | **Integrated in draft; third-party rights gate open** |
| FIG-032 | SafeGEO mitigation trade-off between promotion reduction and utility | Chapter 11 | Vector crop of Wen et al. (2026), Figure 20. Model color and layer shape separate changes in Target@3 reduction and uNDCG@5; points occupy different trade-off regions. The study uses a fixed 22-document, single-turn, post-retrieval text environment and does not show recovery to a truthful baseline or production transfer. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2606.28356v1, physical PDF page 38; source PDF SHA-256 `9af75cce505c405d91e1817f327d0193c6f3cb352c67b8cbcf211c2c25669039`; crop SHA-256 `b2fcd28db7bd2ace601553ddc6bca62e3aeff8b2efbb3af9487f4ef2a0126275`; crop-only statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-033 | Mechanistic localization of an option-routing feature | Chapter 11 | Rectangular crop of Sun et al. (2026), Figure 6. Two heatmaps localize patching-window and head-rank signal to selected layers and heads. The result is based on selected four-option, single-token persuasion flips and cannot be generalized to free-form generation, search, humans, or production systems. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2605.09314v1, physical PDF page 8; source PDF SHA-256 `3ac3789f9f3e9fb1c0dad2e11f9fcf90ad0b890f3a319361d52a9aa262913469`; crop SHA-256 `d5ecbde858297d5635d0e6459a66f5160c0e20f5499ba2f0762ef2240a0c7ee0`; crop-only statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-034 | Verifiable-content reward robustness and ablation panels | Chapter 12 | Vector crop of Xu, Guo, and Xiong (2026), Figure 4. The panels vary target quality, reward strength, and removed components for author-defined Defense, Welfare, and equal-weight Net objectives. The finite fixed-top-five benchmark is not a global equilibrium proof, legal rule, or universal win-win guarantee. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2608.11390v1, physical PDF page 12; source PDF SHA-256 `1e78edc9bb0a5ce7b146ffb14b665915e3e2f94920c35194b983715919f12f57`; crop SHA-256 `d2d5d34cdc9e52a56dfe6fa61f74429c30b1b2e1eace3981d066f725fb8c6ed3`; crop-only statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-035 | AutoGEO preference-rule discovery and rule-guided optimization | Chapter 9 | Rectangular crop of Wu et al. (2025), Figure 1. Preference-rule discovery feeds a plug-and-play API route and a cold-start/GRPO smaller-model route. The learned rules remain bounded to the paper's datasets, models, visibility objective, and quality checks; they are not universal engine preferences. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2510.11438v1, physical PDF page 3; source PDF SHA-256 `710e84e220edbc024eb5416af653619f973930f54ea109142c6affe47c98fb17`; crop SHA-256 `769d194dbeb6ebba951e0719d8db0e2c3a21da99a4f2a5d41fbb070489c5027e`; crop-only statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-036 | Temporal persistence and cited-creator rank distributions | Chapter 6 | Rectangular crop of Alipour, Kargar, and Zihayat (2026), Figure 1. A Jaccard-versus-Kendall scatter and three rank box plots keep temporal persistence and engine-specific rank distributions separate. The 20-day panel does not identify a causal rank mechanism, timeless visibility, or population-wide exposure. Two Type 3 font programs were converted to vector outlines without changing marks, values, colors, or geometry. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2601.01750v1, physical PDF page 5; source PDF SHA-256 `a7f3009a857c25f682741ac67dd06a3cf9ce5e249a5ea119a523dfe68c405e96`; outlined crop SHA-256 `e006f05b0c32acd7fe2dfefa23270a0f0c86123ec511a92e02a1252454af78a0`; crop-and-font-outline statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-037 | VLM and agent framework for visual-content acquisition | Chapter 10 | Rectangular crop of Zhang et al. (2026), Figure 2. The diagram separates image patches, text metadata, VLM query generation, memory, agent tools, and an external trend environment. It documents one industrial architecture and does not prove causal acquisition growth, citation gain, or transfer. | Article [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2602.02961v1, physical PDF page 3; source PDF SHA-256 `a0702058aae0dce1654d17a189caba70785119ee3a7164cd9f0091915b94ecdf`; crop SHA-256 `6b46209815fb01dd9f454eb1073f64e02e133feb30736010276ce0820118d901`. The embedded image, Pinterest references, and other possible third-party elements are not independently cleared; final rights review pending. | **Integrated in draft; third-party rights gate open** |
| FIG-038 | Shadow-model and query-based output-ranking control | Chapter 9 | Rectangular crop of Jin et al. (2026), Figure 2. One route backpropagates a shadow-model ranking loss; the other iterates generator, optimizer, review/reasoning, synthesis, and output feedback. Both are bounded to a product-ranking testbed and do not authorize deception or show closed-platform transfer. | Article [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2602.03608v1, physical PDF page 4; source PDF SHA-256 `f65207b2565c4a538ace965b19887aeef02fb7a172957e58b75d30879c84f6fe`; crop SHA-256 `92985aeb66ee3b58269d6d890db31bd9bfb53a8247081d4eb45b15103b95829d`. Product thumbnails, names, model and retailer marks, and interface-like examples are not independently cleared; final rights review pending. | **Integrated in draft; third-party rights gate open** |
| FIG-039 | SCI-Defense attack-specific detector architecture | Chapter 11 | Rectangular crop of Yu et al. (2026), Figure 1. String, reasoning, and review attacks route to a perplexity filter, SIS scorer, and cross-candidate similarity detector. Displayed perfect aggregate cells are benchmark-specific; cross-domain, novel-attack, sample-size, and threshold-transfer limits prevent a universal defense claim. | [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2605.21948v1, physical PDF page 4; source PDF SHA-256 `97a7c96b845ded724e8fe3f87a7ec51bef85db22997cd038c0eb50eaba350a1f`; crop SHA-256 `d9cbd1a69f81f2a11f2539a17db513d5e7279cd15ea91d640fd74bcc9fe97b6f`; crop-only statement in caption; final publication-rights review pending | **Integrated as licensed published figure** |
| FIG-040 | GPE controlled evidence-poisoning benchmark construction | Chapter 11 | Rectangular crop of Wang et al. (2026), Figure 1. Four stages collect and decompose claims, iteratively gather and judge evidence, generate controlled poisons, and assemble a typed knowledge graph. This constructed benchmark does not estimate real-world poisoning prevalence, organic retrieval, or universal robustness. | Article [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2607.20730v1, physical PDF page 3; source PDF SHA-256 `0b78c64aa71bccbf17f269758c0550d0b699ac2b7a6f0d873d88ca06e3648996`; crop SHA-256 `3496b1357897b1b363130b0ff9fdc9edc3e48c6e8866658b1f97b4f15d318b27`. Source-site icons, platform references, generated examples, and the graph rendering are not independently cleared; final rights review pending. | **Integrated in draft; third-party rights gate open** |
| FIG-041 | Illustration of source visibility in ranked and synthesized search | Chapter 11 | Rectangular crop of Chu et al. (2026), Figure 1. Two illustrated users face a ranked-result page and a synthesized-answer page with smaller source cards. It is not a user study and does not establish that users never inspect sources, that synthesis always hides provenance, or that detected GEO content is false. | Article [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); arXiv:2608.16824v2, physical PDF page 1; source PDF SHA-256 `9eb0c2153f6a0e3497b93a362ae3d2eb0a53f0fe9e7e04c2115f9d4a36732e69`; crop SHA-256 `2cf3b4ed2123a55fbd4f1226e2c3a1385546e3c925b5626aa9ad4e25a96daa30`. Browser/search branding, interface-like mockups, and underlying illustration assets are not independently cleared; final rights review pending. | **Integrated in draft; third-party rights gate open** |

## Admission rule for external figures and quantitative claims

An external image may enter the manuscript only after the ledger records its
stable URL or immutable paper version, author or institution, figure and page
number, license, modification status, crop, and English alt text. If the
license is unclear, retain the citation and underlying fact but replace the
image with an original mechanism diagram or a reproducible data replot. A
screenshot is not a substitute for reproducible data, and a current PDF is not
permission to reproduce its figures.

Every quantitative sentence must retain source, population, unit of analysis,
sample and denominator, platform/model/version, geography and account state
when relevant, measurement window, uncertainty, and evidence ceiling. In
particular:

- a crawler request is not proof of indexing or answer retrieval;
- a displayed citation is not necessarily a brand mention, rank, authority,
  causal effect, referral, or conversion;
- structured-data eligibility is not a display or AI-citation guarantee;
- a conceptual pipeline is not a disclosure of a proprietary system; and
- a standards crosswalk is not conformity, certification, compliance, or legal
  advice.

Before publication or course launch, recheck all **C**, **D**, and **E** sources
within 30 days; recheck every official identity/status page; resolve each paper
to its current version and final venue; pin repository commits and dependency
locks; and run accessibility, link, citation, reproducibility, licensing, and
legal/standards-status reviews as separate gates.
