skip to content

Does scaling data and model size close the clean-accuracy gap that training against a fixed perturbation budget opens?

level: middleimportance: should knowfreq 50%

answer

  1. narrowed, not closed
  2. a different objective, not a harder one
  3. right over a region, not at a point
  4. some predictive features must be given up
  5. and the capacity itself is not free

basics

~20 s

No. More data and capacity narrow the gap without closing it: staying correct across a neighbourhood of every input is a strictly harder objective than being correct at the point, and that capacity is not free.

solid answer

~50 s

It narrows and it does not close, because the two objectives ask for different functions. An ordinary fit only has to be right at each observed input; a fit hardened against an adversary who may move that input anywhere inside a stated edit budget has to be right across the whole region around it. Some features are genuinely predictive on honest traffic and also cheap for an adversary to move; the harder objective forces the model off them, and that costs accuracy on the traffic those features were helping. On constructed distributions the most accurate classifier is provably not the most robust one, so this is not merely a sample-size shortfall. Extra data and capacity do shrink the gap — more room to fit a harder objective — but the harder objective is still harder, and capacity spent there is capacity not spent on clean accuracy.

go deeper

for a junior

Recall the headline: hardening a model costs clean accuracy, and scaling data or model size reduces that cost without removing it. Do not claim the trade-off disappears.

for a middle

Explain the mechanism: being right across a region around each input is a strictly stronger requirement than being right at the input, and predictive-but-easily-moved features have to be given up. Separate the statistical part scale fixes from the structural part it does not.

for a senior

Demonstrate that you would price the residual gap rather than plan to eliminate it, and that you would demand per-slice clean numbers before accepting a report claiming near-parity.

for a principal

Own the budgeting consequence: buying accuracy back with data and capacity converts an accuracy bill into a recurring training and serving compute bill, and someone has to fund that every retrain.

## The claim being tested A very common senior answer is 'the robustness–accuracy trade-off is a data and compute problem; scale it up and it goes away.' The correcting fact is narrower and more useful: **more data and more capacity narrow the gap and do not close it.** The interviewer is checking whether you understand that hardening changes the *objective*, not just the difficulty of hitting the old one. ## What the harder objective actually is Take a model behind a marketplace ranking surface, where the adversary is a seller who can edit the fields of their own listing within a bounded set of moves the platform permits. Two fits are available: - **Fit the point.** For each training example, be right on the example as it was submitted. - **Fit the neighbourhood.** For each training example, be right on *every* variant of it that the seller could reach inside the permitted edit set. The second contains the first — every constraint of the first is still there, plus a great many more. It is a strictly stronger requirement on the same function class, and strictly stronger requirements do not come free. That is the whole mechanism, and it is worth saying in exactly those terms in an interview. ## Why it is not only a sample-size problem There are two separable reasons the gap exists, and conflating them is what produces the wrong answer. 1. **A statistical reason, which scale does attack.** Learning a function that is stable over regions plausibly needs more examples than learning one that is right at points. This part genuinely improves with more data, including cheaply-obtained unlabelled or weakly-labelled data, and with more capacity. This is why the gap *narrows*. 2. **A structural reason, which scale does not attack.** On distributions that can be written down explicitly, the most accurate predictor and the most robust predictor are *different functions* — the accurate one leans on features that carry real signal but sit inside the adversary's reach, and the robust one cannot use them. No amount of data recovers accuracy you gave up by refusing to use a genuinely predictive feature. This is why the gap *does not close*. Both are true at once. The honest summary is: scale buys you a better position on the frontier; it does not delete the frontier. ## Capacity is not free anywhere There is a second, more practical half to the answer. Even where extra capacity does help, that capacity has a bill of its own: the hardened training run costs substantially more compute than an ordinary one because each step has to consider worst cases rather than the given example, and a larger model costs more at serving time on every request. So 'just scale it' is not a free move even in the regime where it works — you are paying training compute and serving cost to buy back accuracy points, on top of the accuracy points you are still short. ## Direction errors to avoid - **Do not say the gap is an artefact of poor tuning.** It is reproducible across model families and data scales; treating it as a hyperparameter search failure wastes weeks. - **Do not read a narrowed gap as a closed one.** A report showing a hardened checkpoint within a hair of the baseline's clean score, on aggregate, is exactly the case where you ask for the per-slice numbers — the loss concentrates on rare classes, thin-data segments and marginal cases, and an aggregate can hide it. - **Do not generalise across budgets.** Whatever accuracy you bought back was bought at one stated perturbation set. Robustness to one family transfers poorly to another, and a claim quoted without the family and its size is not a claim at all. - **Do not confuse this with an ordinary capacity argument.** Capacity, underfitting and overfitting as learning theory are a separate topic; here the point is specifically that an adversary's reach around each input adds constraints that a non-adversarial fit never faced. ## The answer in one paragraph 'Scaling narrows it. It does not close it, because hardening is a different objective, not a harder instance of the same one: the model must be right across a region rather than at a point, and it has to give up features that are predictive on honest traffic precisely because they are cheap for the adversary to move. Extra data and capacity buy back part of the loss, and they cost training and serving compute to do it. I would plan for a residual gap and price it, not plan to eliminate it.'

  • Which part of the gap does extra data genuinely fix?
    The statistical part. Learning a function that stays stable over a region around each input plausibly needs more examples than learning one that is only right at points, so more data — including cheaply-obtained unlabelled data — measurably shrinks the gap. What it does not fix is the structural part: where the most accurate predictor and the most robust one are different functions, no sample size returns the accuracy you gave up.
  • A hardened checkpoint reports clean accuracy within 0.2 points of the baseline. What do you check before believing the trade-off went away?
    Per-slice numbers, first. Aggregate accuracy can hold flat while rare categories, thin-data segments or marginal cases carry the whole loss. Then check that the clean evaluation set is the same one, unshifted, and that the perturbation set the hardening was trained against is stated — a tiny budget produces a tiny gap and also a tiny amount of robustness.
  • Is the extra training compute for hardening a one-off cost?
    The training compute is per run, so it recurs on every retrain, which for a ranking surface may be frequent. If you also bought capacity back by enlarging the model, that part is a per-request serving cost forever. So 'scale it away' converts a standing accuracy bill into a standing compute bill; it does not make the bill disappear.

saying these in an interview costs you the question

  • Says enough data and compute erase the trade-off
  • Calls the gap a tuning or hyperparameter failure
  • Treats aggregate parity as proof the gap closed
  • Assumes robustness bought at one budget generalises
  • Ignores the training and serving compute the fix costs

context