the.ai

Adversarial / Regimes

verified

Robustness-Accuracy Tradeoff

Robust models are less accurate on clean data, and not because anyone has been careless. If some genuinely predictive features are also fragile, then refusing to use them costs accuracy — the trade is a property of the data rather than a limitation of current methods.

Viz primitive · loss-curvesteps = 2000 · lr = 0.002 · batch = 64 · params = 1
loss
step 0dashed = held-out2000

Loss over 2000 training steps, starting near 7.2. It falls to about 1.94, with 93% of the total improvement arriving in the first half. A second line shows held-out, ending higher at about 2.14.

Loss on clean data against loss under attack. Drag the attack strength up to watch the two separate — that gap is not an optimisation failure, it is what the data costs once fragile features are refused.

0.15

Reviewed by opendroid · 2026-08-18