Journal

Putting a watermark gate in front of training

The binary screen accepted 24/25 cleaned images; both known positive controls were detected.

Vlad / experimentos.
The boundary

A model classification is not infallible proof. The excluded image had no visually established remaining overlay location.

The question

A binary watermark screen became a gate in the training workflow. The project checked known positive controls and recorded the excluded image without treating a model label as infallible visual proof.

From the original notebook

User requested image-by-image binary watermark classification with the configured OpenCode DeepSeek credential, then training using accepted images and delivery of new samples.

The classifier requests deepseek-v4-flash at the official DeepSeek Chat Completions API. Every response identifies deepseek-flash; the provider routes the legacy requested alias to its current Flash model. No credentials are stored in this report or classifier records. For each photograph the request includes the native PNG plus top/bottom crops of the same image, and requires exactly watermark on or watermark free. Visible watermark fragments count; physical scene text and garment decoration do not. Two original watermarked source photos were positive controls; both correctly returned watermark on.

Results: 24/25 cleaned training photos returned watermark free; image10 returned watermark on and was conservatively excluded. The binary answer supplies no location or confidence, and visual inspection did not establish a specific remaining overlay in10. This is a model-screened selection, not proof that the classifier is infallible. All15 previous generated samples returned watermark free.

Training uses ONLY the24 accepted original-derived cleaned photos; previous generated samples are diagnostic and are not added to the dataset. Caption text and cleaned pixel hashes are unchanged from v1. Original JPEGs remain intact. Dataset subjects are mixed, as explicitly accepted earlier; this is not verified single-person identity training.

Fresh Qwen Image2.1 base, rank/alpha32, LR1e-4, AdamW8bit, BF16,600 completed steps, 768 buckets (actual608x960), GPU0, cached text/latents, two fixed-seed previews every200. No v1 adapter initialization. GPU2 remains available for the Qwen Studio frontend. All three GPU power limits are245W. Existing service/environment routes are reused.

Run evidence: WORKSTATION/watermark_v2. Per-image classifier records contain requested/returned model, API request ID, label, image SHA-256, dimensions and usage. Exact prompts, images and weights remain outside Git. The15 final sample prompts reuse the previous Mac MLX-enhanced prompts and seeds so v1/v2 can be compared. New samples will also receive binary watermark screening before delivery.

Status: DONE. Training completed;15 reviewed and screened samples plus PNG originals delivered.

Final selection: step600 from600 completed steps; trainer exited0. Selection review: Final600 selected after200/400/600 fixed-seed review. Both outfits/scenes preserved; requested smile is clear. No conspicuous watermark or severe anatomy issue. Full-body framing still crops feet. No general quality or single-identity guarantee. Adapter SHA-256: 9fb17bbb8c9afff146a0f8545731b6ba6fee06af64c840c4924fbe80a6a621af. Installed path: WORKSTATION/susanah_qwen_image_21_lora_v2_screened.safetensors. Tensor audit:384 finite tensors and192 nonzero LoRA B matrices. All15 new samples passed visual review and returned watermark free from DeepSeek. Resolution1024x1536,25steps,CFG1,strength1.0; mean26.15s per image, range26.01–28.03s; total392.29s. Telegram messages: 12778, 12779, 12780, 12781, 12782, 12783, 12784, 12785, 12786, 12787, 12788, 12789, 12790, 12791, 12792, 12793, using the user-authorized Hermes Channel skill. Workflow: WORKSTATION/susanah_v2.json. Shared profile susanah_v2 retains literal trigger susanah; old susanah stays available. Frontend private workstation service remains active; all GPU power limits245W. Shared workflow checks:13 tests passed and both adapter/base graph routes were validated. Sample13 has an awkward brush grip, retained for an honest fixed-seed comparison. An owned stale cleanup marker from the earlier run was reconciled under the host lock after confirming an empty queue. The earlier /free request had succeeded but its empty body was incorrectly parsed as JSON. The new idle-cleanup helper checks HTTP status without parsing that empty body; final unload succeeded and the render admission gate is clear.

The same immutable 15-sample delivery and originals ZIP were resent at the user’s request after the initial delivery: Telegram messages12794–12808 contain the PNGs and12809 contains the ZIP. This is a repeat delivery, not a second generation.

Keep exploring

Original experiment record. Workstation paths have been generalized. Detailed measurements below retain their original workload and validation boundaries.

Follow the evidence

From notebook to finding.

This story is based on the archived experiment at revision 6550ead3945b. Original timestamps, workloads and qualification limits belong to that record.

Original GitHub record
Supporting notebooks (1)

GitHub source links require access to the private archive. The readable notes and aggregate chart exports are included here.

Back to the journal Follow via RSS