Would you sign off on reusing a vendor's per-pixel robustness benchmark as evidence for your face-turnstile deployment?
answer
- scope the assertion, do not widen it
- the paper moves, the scope does not
- name the unevaluated families
- measure in the attacker's own units
basics
~20 sNot as coverage. You can sign a scoped statement — this model resisted a named attack inside a named per-pixel budget — but you cannot sign that it withstands an attacker at the gate, whose budget is pose and occluded area. State what is unmeasured and name who owns it.
solid answer
~50 sSplit the sign-off into what the evidence establishes and what the deployment needs. The benchmark establishes that a stated attack, at a stated radius, in a stated perturbation family, failed at a stated rate on the vendor's data. That claim survives being copied into your file. What does not survive is coverage: your attacker is physically present, bounded by viewing angle and occluded fraction, and wants one targeted acceptance rather than lower average accuracy. Those are different units and a different metric. So I would sign the scoped sentence, record the unevaluated families explicitly, and fund one measurement in the deployment's own units before go-live. Widening the trained union of pixel families is the expensive answer that does not reach this gap; if the residual is unacceptable, it has to be carried somewhere other than the model, with a named owner and a review date.
code
text · 7 linesrobustness summary - face matcher (current release)
attack norm radius steps restarts access robust acc
iterative L-inf 4/255 50 5 white-box 91.3%
iterative L-inf 8/255 50 5 white-box 83.8%
...
not evaluated: L-2, sparse budgets, head pose beyond +/-10 deg,
any occluded fraction of the face, deployed capture pathgo deeper
Know that a robustness claim comes from a specific experiment and cannot be quoted for a different setting without checking what that experiment allowed the attacker to do.
Explain why the benchmark's units and the deployment's attacker budget do not convert into one another, and why the unevaluated families should be listed explicitly rather than implied.
Show how you would turn the gap into a concrete measurement request stated in the deployment's own units, and how you would report the finding so it is actionable rather than argumentative.
Own the assertion. Decide what your organisation states, what it scopes out, who carries each unmeasured family, and whether the money goes into re-measuring, into wider training, or into accepting a documented residual.
## The decision, stated properly The question on the table is not "is this model robust." It is: **what may I assert, in writing, on the strength of a measurement someone else made under their own assumptions?** That reframing is most of the principal-level answer. A robustness benchmark is a scoped empirical statement. Copying it into a different deployment does not widen its scope; it only moves the paper. ## What survives the move, and what does not **Survives:** the model, as delivered, resisted a specific attack, run at a specific strength, inside a specific perturbation family at a specific radius, on the vendor's evaluation data, at the stated rate. That is a real fact about a real experiment. **Does not survive:** - **the units.** Your adversary's budget is a range of head pose and a fraction of the face they may cover. The benchmark's budget is per-pixel magnitude. Neither converts into the other; the honest status of the geometric families is *not evaluated*. - **the metric.** Robust accuracy is an average. The deployment's loss event is one chosen identity accepted once, which an average is structurally insensitive to. - **the capture path.** The benchmark ran on stored imagery. Your gate has its own camera geometry, lighting envelope and enrolment pipeline, and results do not carry across that change for free. - **the vantage.** If the attacker can obtain a released weight file for an earlier generation of the matcher, they hold a stand-in to optimise against offline. Whether the benchmark assumed that is a question you must ask, not assume. ## The sign-off language Write the narrow thing and refuse the broad thing: - **Asserted:** resistance to the named family at the named radius against the named attack, as measured by the supplier on their data. - **Not asserted:** resistance to geometric or area-bounded change; targeted acceptance of a chosen identity; behaviour on the deployed capture path. - **Owner and date** for each unasserted item. That document is defensible later precisely because it does not overreach. "Robust" with nothing attached is what fails a review after an incident, not a modest, scoped sentence. ## The options, and who pays for each 1. **Re-measure in the deployment's units.** Targeted acceptance for chosen identities, across the accepted pose range and occlusion fractions, on the real capture path. This is the cheapest thing that actually answers the question, and it produces a number you own rather than one you inherited. 2. **Widen the trained union of pixel families.** Expensive, slower, and it does not reach a geometric gap — you would be buying coverage in the dimension you already have and not in the one you lack. The clean-accuracy bill also lands unevenly: it falls hardest on the enrolled identities the matcher already found marginal, which quietly worsens service for a subset of real users. Ask who those users are before agreeing. 3. **Carry the residual elsewhere.** If the gap cannot be closed in the model on your timeline, it becomes an accepted risk with a named owner, a stated exposure, and a review trigger. That is a legitimate outcome; an unstated one is not. ## The organisational failure this prevents The common failure is not a bad model. It is a **claim laundering path**: a vendor measures one adversary, a slide says "robust," a reviewer reads the slide, and the deployment inherits a property nobody measured. Every step is individually reasonable and the end state is an unowned assumption in production. Breaking that path is a leadership behaviour, not a technical one: insist that every robustness statement in your organisation carries its family, its radius, its attack and its access, and that any statement missing them cannot be cited as coverage. That rule costs almost nothing to adopt and it is the single highest-leverage thing available here. ## The one-line version Sign what was measured, name what was not, and fund one measurement in the units of the attacker you actually have.
- What exactly would you write on the sign-off line?That the supplier measured resistance to a named attack inside a named per-pixel family at named radii on their own data, and that geometric change, occlusion, targeted acceptance of a chosen identity, and the deployed capture path are unevaluated. Each unevaluated item gets a named owner and a review date.
- The team proposes training against more perturbation families. What is the bill, and who pays it?Compute and schedule, plus clean accuracy — and the accuracy loss is not uniform. It concentrates on the examples the model already found hard, which here means specific enrolled identities getting a worse experience. It also buys nothing against the geometric gap, so you would be paying in the dimension you already cover.
- Is there a case for accepting the benchmark as-is?Yes, if your realistic adversary genuinely is file-level rather than physically present — for example an offline matching pipeline where inputs arrive as stored images. Then the vendor's units are your units. The decision turns on which adversary the deployment actually faces, which is why that question comes before the number.
- How do you stop this recurring across the organisation?Make it a citation rule: no robustness statement may be used as coverage unless it carries its perturbation family, radius, attack, attack strength and assumed access. Statements missing those may be recorded but not relied upon. It is cheap to adopt and it closes the path by which "robust" propagates as an unowned assumption.
saying these in an interview costs you the question
- Signs the word "robust" without a scope attached
- Treats a supplier benchmark as coverage for a different adversary
- Assumes more adversarial training closes a geometric gap
- Leaves the unevaluated families unnamed and unowned
- Ignores that the accuracy bill lands on already-marginal identities