arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

hZACH-ViT 中的曲率攻击:规范对称性、边界饱和与对抗失败

Curvature Under Attack in hZACH-ViT: Gauge Symmetry, Boundary Saturation, and Adversarial Failure

Athanasios Angelakis, Marta Gomez-Barrero

arXiv 2610.00680首次发表:更新:

发表机构

BioML, Research Institute CODE, University of the Bundeswehr Munich; Amsterdam UMC, University of Amsterdam(慕尼黑联邦国防军大学 CODE 研究所 BioML; 阿姆斯特丹大学阿姆斯特丹医学中心)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究在 hZACH-ViT 中考察曲率对对抗鲁棒性的影响,发现庞加莱头的曲率与尺度、边界效应共同作用,降低曲率虽提升干净性能却显著增加攻击成功率,表明其鲁棒性并非内在属性。

AI 中文摘要

曲率通常被视为表示的内在属性,尽管其经验效应也依赖于坐标尺度、学习的 logit 温度和数值保护措施。我们在 hZACH-ViT 中研究这种相互作用,hZACH-ViT 是一种紧凑型 Vision Transformer,具有欧几里得、庞加莱和球面原型头。主干架构、种子特定初始化、每类 50 个训练子集和优化协议在三个 MedMNIST 数据集和五个种子上匹配。在固定比较曲率 $c=1$ 下,庞加莱头在所有 12 个数据集-预算单元中具有最低的类宏 PGD 攻击成功率,并且在所有三个数据集上在更强的 CE+DLR 多重启攻击下也是如此,但其干净 MacroF1 也最低。端到端曲率干预改变了这一解释。将庞加莱曲率降低到 $c=0.1$ 在全部 15 个配对种子-数据集比较中提高了干净 MacroF1,并消除了硬边界裁剪,但在 OrganAMNIST 上,它将强攻击成功率从 $89.7\%$ 提高到 $99.3\%$(配对差异 $+9.57$ 个百分点;95\% 分层自助法置信区间 $[+5.52,+14.03]$)。在 $c=1$ 时,$40$-$47\%$ 的干净庞加莱特征被硬裁剪,继承映射的径向雅可比矩阵几乎为零,无量纲攻击轨迹异常长且低效。球面头提供了对照:其曲率变化是浮点精度上的精确尺度规范,并产生小得多的攻击差异。这些结果并未确立内在的双曲鲁棒性。它们识别出一个实现敏感的区域,在该区域中,曲率、尺度和与庞加莱边界的接近程度共同组织干净识别和对抗表示运动。

英文摘要

Curvature is often treated as an intrinsic property of a representation, although its empirical effect also depends on coordinate scale, learned logit temperature, and numerical safeguards. We study this interaction in hZACH-ViT, a compact Vision Transformer with Euclidean, Poincare, and spherical prototype heads. The backbone architecture, seed-specific initialization, 50-per-class training subset, and optimization protocol are matched across three MedMNIST datasets and five seeds. At the fixed comparison curvature $c=1$, Poincare has the lowest class-macro PGD attack-success rate in all 12 dataset-budget cells and under a stronger CE+DLR multi-restart attack on all three datasets, but it also has the lowest clean MacroF1. An end-to-end curvature intervention changes the interpretation. Reducing Poincare curvature to $c=0.1$ improves clean MacroF1 in every one of the 15 paired seed-dataset comparisons and removes hard boundary clipping, yet on OrganAMNIST it increases strong attack success from $89.7\%$ to $99.3\%$ (paired difference $+9.57$ points; 95\% hierarchical bootstrap CI $[+5.52,+14.03]$). At $c=1$, $40$-$47\%$ of clean Poincare features are hard-clipped, the radial Jacobian of the inherited map is nearly zero, and dimensionless attack trajectories are unusually long and inefficient. The spherical head provides a control: its curvature change is an exact scale gauge to floating-point precision and produces much smaller attack differences. These results do not establish intrinsic hyperbolic robustness. They identify an implementation-sensitive regime in which curvature, scale, and proximity to the Poincare boundary jointly organize clean recognition and adversarial representation motion.

Comments12 pages, 3 figures, 4 tables. Accepted at NeurReps 2026: Symmetry and Geometry in Neural Representations, NeurIPS 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑