🤖 AI Summary
This study investigates the mechanisms by which curvature and boundary saturation in hyperbolic geometry influence the adversarial robustness of Vision Transformers. Building upon the hZACH-ViT architecture, we employ PGD attacks, stratified bootstrap statistics, and radial Jacobian analysis on the MedMNIST dataset to provide the first end-to-end disentanglement of curvature from numerical safeguarding mechanisms. Our findings reveal that the observed robustness in Poincaré space stems from hard boundary clipping rather than intrinsic geometric properties. Furthermore, while reducing curvature improves clean accuracy, it leads to a sharp surge in attack success rates. These results challenge the prevailing assumption of inherent robustness in hyperbolic spaces and offer novel insights for the security-aware design of geometry-informed models.
📝 Abstract
Curvature is often treated as an intrinsic property of a representation, although its empirical effect also depends on coordinate scale, learned logit temperature, and numerical safeguards. We study this interaction in hZACH-ViT, a compact Vision Transformer with Euclidean, Poincare, and spherical prototype heads. The backbone architecture, seed-specific initialization, 50-per-class training subset, and optimization protocol are matched across three MedMNIST datasets and five seeds. At the fixed comparison curvature $c=1$, Poincare has the lowest class-macro PGD attack-success rate in all 12 dataset-budget cells and under a stronger CE+DLR multi-restart attack on all three datasets, but it also has the lowest clean MacroF1. An end-to-end curvature intervention changes the interpretation. Reducing Poincare curvature to $c=0.1$ improves clean MacroF1 in every one of the 15 paired seed-dataset comparisons and removes hard boundary clipping, yet on OrganAMNIST it increases strong attack success from $89.7\%$ to $99.3\%$ (paired difference $+9.57$ points; 95\% hierarchical bootstrap CI $[+5.52,+14.03]$). At $c=1$, $40$-$47\%$ of clean Poincare features are hard-clipped, the radial Jacobian of the inherited map is nearly zero, and dimensionless attack trajectories are unusually long and inefficient. The spherical head provides a control: its curvature change is an exact scale gauge to floating-point precision and produces much smaller attack differences. These results do not establish intrinsic hyperbolic robustness. They identify an implementation-sensitive regime in which curvature, scale, and proximity to the Poincare boundary jointly organize clean recognition and adversarial representation motion.