Same Classifier, Different OOD Decisions: The Hidden-Basis Dependence of Activation Clipping
Abstract
Post-hoc OOD detectors that shape the penultimate representation coordinate by coordinate—REACT, ASH, DICE—are popular because they are nearly free. We show that their verdicts are not a function of the classiffer function alone: they depend on the network’s hidden basis. We ask which reparameterization symmetries such a detector can and should respect, and answer at three tiers. Under the architecture’s own symmetry (positive channel rescaling), no global threshold reproduces REACT’s clipping, however re-calibrated; demanding basis-agnosticism rules out every continuous coordinate-wise map except uniform rescaling and, among continuous pointwise shapers, forces the radial form T(h) = α(∥h∥) h; within radial norm-based constructions, afffne covariance leads to the Mahalanobis geometry of Maha-Radial. Empirically, across random bases of the same classiffer function, REACT’s AUROC swings by up to 15.8 points and an adversarially optimized basis inverts it entirely (0.97 → 0.003), while the exactly invariant, training-free Radial-ReAct and Maha-Radial remove the dependence exactly—Radial-ReAct essentially matching raw energy at ImageNet scale, Maha-Radial exposing a calibration-rank trade-off that covariance shrinkage mitigates. At scale the artifact dominates the benefft: on an untouched ImageNet ResNet-50 over six standard OOD suites, REACT beats raw energy at the trained basis on all six sets, yet on every one its worst of 20 random bases falls below the energy score—reparameterization alone erases the entire gain—and the swing explodes as the penultimate dimension shrinks (23 points at d ≤ 16), exactly where compact deployed heads sit. Code reproducing every result: https: //anonymous.4open.science/r/react_invariance-A33F/.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.