发表机构
Centro Nacional de Inteligencia Artificial (CENIA); Barcelona Supercomputing Center (BSC); Pontificia Universidad Católica de Chile(国家人工智能中心(CENIA); 巴塞罗那超级计算中心(BSC); 智利天主教大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文证明曲率上界不能自动保证鲁棒性证书或训练干预的有效性,通过最后一层相对平坦性代理揭示其低估损失超210倍、平移导致无界等问题,并提出行中心化修复方法,实验显示其可逆抑制泛化。
AI 中文摘要
有效的曲率上界本身并不足以证明鲁棒性证书或对内在预测器属性的干预是合理的。我们针对一种在两种设置中均使用的最后一层相对平坦性代理,展示了这一区别。首先,经验风险平稳性并不能消除逐点一阶损失项:在有限的全局经验风险最小值处,保留的证书表达式对损失增加的估计低估了超过210倍。我们推导出一种全局有效、规范不变的特征空间修复方法。其次,常见的行softmax平移保持预测和精确的收缩性,同时使代理无界。即使标准的参考类选择,相对于中心化表示,平均也会使其加倍。对于具有至少三个类别的单一固定特征示例,标量重调通常无法使诱导的概率更新对齐。行中心化给出了轨道最小化界,并恢复了该对称性下的值和全模型梯度不变性。在算法和图像模型上的45对单步测试中,放大的平移区分了原始正则化预测器,而商正则化预测器保持对齐。长时程CIFAR-10实验显示,泛化能力受到显著且可逆的抑制,而记忆后选择性延迟的证据则不太一致。总之,这些结果表明,作为曲率上界的有效性本身并不能证明将其反演为鲁棒性证书或区分为内在训练干预是合理的。
英文摘要
A valid curvature upper bound need not justify either a robustness certificate or an intervention on an intrinsic predictor property. We demonstrate this distinction for a last-layer relative-flatness proxy used in both settings. First, empirical-risk stationarity does not eliminate pointwise first-order loss terms: at a finite global empirical-risk minimum, the retained certificate expression underestimates a loss increase by over $210\times$. We derive a globally valid, gauge-invariant feature-space repair. Second, common-row softmax shifts preserve predictions and the exact contraction while making the proxy unbounded. Even standard reference-class choices double it on average relative to the centered representation. For a single fixed-feature example with at least three classes, scalar retuning generically cannot align the induced probability updates. Row centering gives the orbit-minimized bound and restores value and full-model gradient invariance under this symmetry. Across 45 paired one-step tests on algorithmic and image models, amplified shifts separate raw-regularized predictors while quotient-regularized predictors remain aligned. Long-horizon CIFAR-10 experiments show substantial, reversible suppression of generalization, while evidence for selective delay after memorization is less consistent. Together, these results show that validity as a curvature upper bound does not by itself justify either inversion into a robustness certificate or differentiation into an intrinsic training intervention.
Comments10 pages, 3 figures, 1 table