Rabbit hole · 7 connected questions
When and why does improving worst‑case or distributional robustness require real sacrifices in standard performance, versus being avoidable through better data, model capacity, training objectives, or evaluation choices?
How these converge
These topics converge on a concrete, system‑level explanation: observed robustness–accuracy costs mostly arise from interactions among four factors—how robustness is defined/evaluated (threat model), the data and augmentations available, model capacity/inductive biases, and the training procedure. Determining whether costs are unavoidable requires examining these axes together in context.
Where these converge
Trade‑off depends on model, data, and training
Studies show adversarial or robustness objectives can reduce clean accuracy in many settings, but the magnitude depends on data size/quality, model architecture and overparameterization, and training methods—so the trade‑off is often contingent, not universal.
Evaluation and threat‑model mismatch drives apparent fragility
Robustness testing and adversarial‑defense work emphasize that narrow or mismatched tests (specific attacks, limited shifts) make defenses look costly or ineffective; better-aligned evaluations change conclusions about necessary trade‑offs.
Data augmentation can mitigate or create costs
Cleaning, realistic augmentation, and self‑training can reduce robustness penalties when they cover relevant shifts, whereas poor or synthetic data can distort distributions and worsen trade‑offs—so data quality and coverage are decisive.
Domain specifics determine practical remedies
Robotics illustrates that robustness involves perception, control, and hardware; different failure modes call for different solutions (robust control, certification, hardware changes, or more diverse real data), so trade‑offs and fixes are context‑dependent.
The chain
Keep going: open any topic above to find its own related questions.