Decodable but Not Detectable: A Leakage Fingerprint for Near-OOD Benchmarks 文章

ArXiv CS.CV2026-07-23PAPERen作者: Vishnu Bindu Balachandran

详细信息

来源站点
ArXiv CS.CV
作者
Vishnu Bindu Balachandran
文章类型
PAPER
语言
en
发布日期
2026-07-23

摘要

arXiv:2607.19393v1 Announce Type: cross Abstract: While auditing a perturbation-based OOD detector on a document benchmark, we recorded an AUROC of 0.326 -- well below the 0.5 chance level. The cause is a benchmark leak: the designated "OOD" class is one the model was trained on, so its examples sit inside the in-distribution fit set and the detector is penalized for correctly ranking them as familiar. Deleting the class and retraining 35 models across two domains raises the score to 0.911. We distill the contamination into a leak fingerprint -- near-perfect supervised decodability (AUROC approximately 1) coupled with unsupervised detection collapsed below 0.65 -- and validate it on a controlled battery of 52 settings (20 leaked, 32 clean) across ResNet-50 and ViT-B/16 on CIFAR-10/100, achieving sensitivity 18/20 and specificity 31/32 in embedding space; the matched fit-set-exclusion controls are perfect at 20/20.

相关事件

暂无数据

相关公司

暂无数据

相关人物

暂无数据