acceptodds
Under review as a conference paper at ICLR 2027

A Geometric Obstruction to Robust and Accurate Differentiable Classifiers

Abstract

We ask when a robust and accurate classifier can be represented as a differentiable function. Reading the gradient of a hypothesis as a *sensitivity field*, we observe that a differentiable classifier's field must be conservative — curl-free and path-independent — while robustness under the manifold hypothesis imposes a separate *strong tangency* condition: invariance to perturbations off a data manifold , represented as the zero-set of . Given an accurate hypothesis , we construct the tangent field , where orthogonally projects onto , and show it reproduces exactly on via path integration. We then characterize when remains conservative: testing the antisymmetric part of with arbitrary vectors, it decomposes into bilinear forms whose leading term is governed by the Hessian of , i.e., the curvature of , and vanishes only in degenerate cases (flat manifolds, or normal-normal directions). For the unit circle, this yields a rigidity result under a specific strong tangency condition — any hypothesis continuous at the origin and strongly tangent to must be constant on it — showing the obstruction might be absolute rather than generic. To test our thesis, we relax conservativeness and represent classifiers as path-dependent functionals evaluated by line integrals of a learned field, using an oracle-path scheme for adversarial training and test. On MNIST, FashionMNIST, and CIFAR-10, adversarially trained path-dependent hypotheses achieve substantially higher robust accuracy than gradient-field baselines at comparable clean accuracy, align more closely with a surrogate data-manifold tangent space, and exhibit statistically significant non-zero circulation — direct evidence that the learned fields are not gradients. Together, the theory and experiments indicate that the accuracy–robustness trade-off is, at least in part, a structural consequence of manifold curvature, motivating path-dependent (multi-valued) architectures as a principled alternative to single-valued differentiable classifiers.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.