首页 > AI前沿 > Margin-Drop Coordinates for Cross-Budget Robustness Evaluation

Margin-Drop Coordinates for Cross-Budget Robustness Evaluation

arXiv机器学习 2026-08-20 22:22 3 阅读 查看原文

Fixed-budget robustness evaluation can select the wrong frozen vision encoder.

An encoder that survives a shallow attack may lose most of that robustness when the same evaluation is strengthened.

We ask whether the shallow evaluation contains enough information to identify this budget fragility.

For each clean-correct sample, the evaluation records the clean pairwise margin, the first-order linearized margin-drop scale, the margin drop from a clean-start one-step attack, and the drop reached by an iterative attack.

Normalizing by that scale gives three margin-drop coordinates capturing clean margin slack, one-step shortfall, and drift, where drift is the additional normalized margin drop the iterative attack reaches beyond the one-step perturbation.

Together, they reconstruct the normalized post-attack margin and therefore the pass-or-fail outcome.

Across 42 pretrained frozen vision encoders, the shallow survival rate carries essentially no rank information about subsequent PGD-10 to PGD-200 collapse, at Spearman -0.006, while the median shallow drift coordinate ranks the same collapse at +0.811.

The result persists in a held-out encoder pool and under an $\ell_\infty$ evaluation.

The full coordinate decomposition further distinguishes cases that share the same fixed-budget residual but diverge at deeper budgets, and separates margin repair from drift repair under interventions, revealing distinct repair paths that endpoint robustness alone does not identify.