{"id":"77b76f16-dddf-4b1b-9eb5-7dabfbda76d5","arxiv_id":"2508.01676","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":5.0,"correctness_risk":"high","formal_verification":"none","parameter_count":3,"one_line_summary":"A claimed ImageNet-wide map of adversarial patch hot-spots and a mask-guided placement heuristic, with the supporting study absent from the supplied manuscript.","lead":"The abstract describes PatchMap, a claimed benchmark built from 150 million ImageNet forward passes that maps where tiny adversarial patches most reliably fool vision models, plus a mask-guided placement heuristic said to lift attack success by 8 to 13 points. The submitted full text, however, is an unrelated mathematics paper, so these claims cannot be checked from the manuscript as provided.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"No PatchMap content in submission: the full text is an unrelated math paper, so the abstract's benchmark and 8–13 point claims are unverifiable as submitted.","rationale":"The reader's verdict of UNVERDICTED is correct: the central claims cannot be verified because the supporting text is absent and replaced by an unrelated manuscript. My strongest concern is the internal mismatch itself, which is even more load-bearing than the specific mask-vulnerability correlation the reader highlighted. The reader did identify the absence of the supporting study in the rationale, but the stated weakest assumption focuses on the segmentation heuristic's correlation with hot-spots. That correlation matters only if the benchmark and the heuristic evaluation exist; without the PatchMap body, even the benchmark's existence is unsupported. The reader's weakest assumption is therefore downstream of the document-integrity failure. I am not alleging misconduct; I am reporting that the submitted artifact, taken as a whole, does not contain the paper it describes. A concrete test is straightforward: locate any PatchMap content in the full text. If none appears, the abstract's quantitative claims are untestable, and the verdict remains UNVERDICTED. If a corrected submission with the actual PatchMap full text is provided, then the more specific concerns about hot-spot definitions, architecture selection, error bars, and evaluation leakage would become the appropriate focus.","tokens_in":56866,"tokens_out":2170,"duration_ms":26723,"concrete_test":"Obtain the actual body of arXiv:2508.01676 and search it for 'PatchMap', 'ImageNet', 'segmentation', and 'hot-spot' outside the abstract; then read the section that defines hot-spots and count the number of architecture-evaluation tables. If no such section exists, the central claims are unsupported by the submission.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is that PatchMap is a working spatially exhaustive benchmark and that a segmentation-guided placement heuristic raises attack success by 8 to 13 points. The only evidence in the submission is the abstract itself. The supplied full text, arXiv:2508.01679v1 [math.AG], is a mathematics manuscript on derived stratifications, p-adic Hodge theory, and singularities; it contains no definition of PatchMap, no hot-spot detection procedure, no evaluation protocol, no architecture details, no code release, and no experimental tables. This is an internal contradiction, not a divergence from consensus: the document cannot support the abstract's quantitative claims while its body is an unrelated paper. The reported 1.5e8 forward passes and 6.5B predictions are similarly unauditable because no evaluation harness is present. The benchmark might exist and the heuristic might work, but nothing in the submitted artifact permits checking either claim, so the appropriate status is unverified.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The submission's abstract claims a computer-vision contribution: PatchMap, a spatially exhaustive benchmark of adversarial patch placement built from 1.5e8 forward passes on ImageNet, revealing systematic hot-spots and a segmentation-guided placement heuristic that improves attack success by 8 to 13 percentage points across five architectures. The full text supplied with the submission, however, is arXiv:2508.01679v1 [math.AG], a mathematics manuscript titled \"Derived Stratifications and Arithmetic Intersection Theory for Varieties with Isolated Singularities.\" That text contains no definition of PatchMap, no hot-spot detection procedure, no evaluation protocol, no architecture-specific results, no confidence intervals, and no code release. The central empirical claims of the abstract are therefore unsupported by any content in the submitted artifact.","tokens_in":56839,"tokens_out":1707,"duration_ms":23618,"significance":"If the abstract's claims were backed by the corresponding methods, data, and code, PatchMap would be a potentially useful resource for location-aware adversarial robustness research, and the reported 8-13 point gain from a gradient-free segmentation-guided placement rule would be a substantive empirical finding. The submitted manuscript provides none of these supporting materials: there is no benchmark definition, no hot-spot computation, no experiment description, no per-architecture numbers, no reproducibility artifacts, and no code link. The manuscript as submitted cannot be assessed for soundness, and no credit can be given for machine-checked proofs, reproducible code, or falsifiable predictions, because none of these elements appear in the supplied text.","major_comments":[{"comment":"The central claims of the paper exist only in the abstract. The abstract states that PatchMap evaluates 1.5e8 forward passes, reveals systematic hot-spots, and boosts attack success by 8 to 13 percentage points across five architectures, yet the full text is an unrelated mathematics paper on derived stratifications, p-adic Hodge theory, and singularities. No methods section, no hot-spot definition, no experiment description, no architecture details, no tables, and no code release appear in the body. This is an internal contradiction in the submitted artifact rather than a presentation issue: the quantitative claims in the abstract cannot be checked against any portion of the manuscript.","section":"Abstract vs. Full Text"},{"comment":"Even taken in isolation, the abstract leaves the load-bearing components undefined. The \"hot-spot\" notion has no threshold or statistical definition; the \"2% of the image\" patch size is ambiguous about area fraction and placement grid; the five architectures are not enumerated; and the claimed 8-13 point improvement from the segmentation-guided heuristic is reported without per-architecture breakdowns, confidence intervals, or a description of the baseline. The abstract itself also separates the proposal of the heuristic from any experimental validation, so the submitted text contains no evidence that segmentation masks correlate with the benchmark-identified hot-spots.","section":"Abstract, heuristic claim"}],"minor_comments":[{"comment":"The abstract promises public release of PatchMap and code but gives no repository URL, version, or license information, so the reproducibility claim cannot be acted on.","section":"Abstract"},{"comment":"The phrase \"as little as 2% of the image\" should specify whether this is patch area relative to image area, and how systematic hot-spots are defined across images and architectures.","section":"Abstract"},{"comment":"The claim that PatchMap is \"the first spatially exhaustive benchmark\" requires a definition of spatial exhaustiveness and comparison with prior placement studies; neither is provided in the manuscript.","section":"Abstract"}],"recommendation":"reject","confidential_remarks":"The submitted artifact does not contain the claimed research: the abstract describes an adversarial-patch benchmark, while the body is a mathematics paper on derived stratifications. As submitted, the manuscript cannot be considered for publication in a computer vision venue; the only option would be a completely new submission with the actual PatchMap methods, experiments, and code. I am therefore recommending rejection rather than major revision, because the missing content is the entire contribution rather than a fixable local defect."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The short version: this submission is not a reviewable paper. The metadata and abstract describe PatchMap, a spatially exhaustive adversarial patch placement benchmark with 150M forward passes and a segmentation-guided placement heuristic that supposedly boosts attack success by 8–13 points. The full text is an entirely different manuscript, a mathematics paper on derived stratifications and p-adic Hodge theory by Jiaming Luo and Shirong Li. The body contains no PatchMap definition, no experiment protocol, no architecture details, no tables, no code. As submitted, the document internally contradicts itself.\n\nWhat is genuinely valuable, if real: the abstract-level idea is worth taking seriously. A spatially exhaustive vulnerability map for ImageNet models, built from a very large number of forward passes, would be a useful measurement resource for adversarial patch research. A gradient-free placement heuristic that leverages off-the-shelf segmentation masks to find vulnerable regions is a plausible and potentially practical contribution. The claimed 8–13 point gain over random or fixed placement is the kind of concrete, falsifiable result the field would care about.\n\nBut none of that is in the artifact I can read. The reader's scorecard gives soundness 1.0, and that is fair. There is no way to check the hot-spot definition, the threshold for what counts as a systematic hot-spot, the five architectures, the patch configurations, or the baseline comparisons. The circularity concern is real but secondary: even if the correct paper were attached, the abstract reports no held-out or cross-benchmark validation separating where hot-spots are discovered from where the segmentation heuristic is tested. That would need to be addressed.\n\nThe mathematics text itself makes ambitious claims about closing gaps in Ohsawa's proof and establishing p-adic comparison isomorphisms. I am not going to evaluate that paper here; it has its own arXiv identifier and authorship, and it is not what this submission claims to be.\n\nWho is this for? Nobody can use this submission as is. It is not a matter of a weak section or a contested interpretation; the claimed contribution is absent. A serious editor should desk reject this artifact. If the authors resubmit the actual PatchMap paper, with methods, results, code, and proper validation, then it deserves a serious referee. But this version does not.","headline":"The submission is an abstract for a patch-placement benchmark stapled to an unrelated math paper; there is nothing to review as submitted.","tokens_in":57534,"tokens_out":1317,"would_cite":false,"duration_ms":17649,"reading_group":"no","serious_thinker":"no","would_accept_peer_review":false},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"PatchMap finds where small adversarial patches do the most damage","keywords":["adversarial patches","patch placement","spatial vulnerability map","ImageNet","segmentation-guided attacks","attack success rate","location-aware defenses","benchmark"],"falsifier":"Re-run the placement comparison on ImageNet and check whether mask-targeted patches consistently beat random and fixed placements by the claimed margin across models with diverse segmentation masks; if they do not, or if the mask-selected regions do not co-locate with PatchMap hot-spots, the central utility claim is refuted. Additionally, the hot-spot maps themselves can be tested against a fresh set of validation images to see whether the same spatial regions remain vulnerable rather than being artifacts of the selected benchmark set.","tokens_in":56466,"feed_emoji":"🎯","tokens_out":3119,"duration_ms":37872,"temperature":0.7,"pith_summary":"This paper aims to establish that where an adversarial patch is placed matters systematically, not just what the patch looks like. It presents PatchMap, which it calls the first spatially exhaustive benchmark of patch placement, built from over $1.5\\times10^8$ forward passes on ImageNet validation images. The benchmark reportedly reveals systematic hot-spots where patches as small as 2% of the image cause confident misclassifications and large drops in model confidence. The paper then proposes a segmentation-guided placement heuristic that uses off-the-shelf masks to target vulnerable regions without gradient queries, reporting 8 to 13 percentage-point gains in attack success over random or fixed placements across five architectures. If correct, the contribution is both a reusable public vulnerability map and a practical gradient-free attack rule.","feed_headline":"PatchMap finds where small adversarial patches do the most damage","feed_subtitle":"Exhaustive benchmark finds hot-spots where 2% patches flip labels, and mask-guided placement gains 8–13 points.","key_machinery":"The central object is PatchMap itself: a spatially exhaustive vulnerability map that records attack success across patch placements on ImageNet-scale images. The map carries the argument by making patch location a measurable axis of attack performance rather than an arbitrary choice. The accompanying machinery is the segmentation-guided placement heuristic, which takes off-the-shelf segmentation masks and uses them to aim the patch at regions the benchmark identifies as vulnerable, thereby converting the spatial map into a gradient-free attack rule.","core_discovery":"PatchMap is introduced as the first spatially exhaustive benchmark of adversarial patch placement, built by evaluating over $1.5\\times10^8$ forward passes on ImageNet validation images. The benchmark reveals systematic hot-spots where small patches, as little as 2% of the image, induce confident misclassifications and large drops in model confidence. To demonstrate utility, the paper proposes a simple segmentation-guided placement heuristic that leverages off-the-shelf masks to identify vulnerable regions without gradient queries. Across five architectures, including an adversarially trained ResNet50, the heuristic boosts attack success rates by 8 to 13 percentage points compared to random or fixed placements. The paper publicly releases PatchMap and its code, with a larger 6.5-billion-prediction benchmark promised for future release.","pith_inferences":["If the hot-spots are driven by dataset biases such as typical object positions or textured background regions, then defenses that harden those regions or augment away those priors could reduce patch vulnerability more efficiently than global adversarial training.","A natural testable extension is to use the released hot-spot maps to train a location-conditional predictor of attack success and check whether its accuracy on new architectures correlates with model similarity to the five benchmarked architectures.","The reported gains of the segmentation heuristic depend on mask quality; replacing off-the-shelf masks with saliency maps or learned proposals and measuring the added gain would test whether the heuristic is capturing genuine spatial vulnerability or merely mask specificity.","Because the benchmark's hot-spots are measured on five architectures, a direct extension would re-run PatchMap on a wider set of backbones to test whether the same spatial locations remain vulnerable across architectural families."],"forward_implications":["If the hot-spots are systematic, attack success depends on patch location as much as on patch content, so defenses that ignore location underestimate exposure.","Segmentation-guided placement offers a practical attack rule that needs no gradients, making it usable in black-box settings where only off-the-shelf masks are available.","Location-aware defenses can be evaluated against PatchMap as a spatial stress test, and adaptive attacks can be built directly from the released maps and code.","The public release lets others reproduce the 8 to 13 point gains and extend the benchmark to additional backbones, with the forthcoming 6.5-billion-prediction bench supporting larger-scale comparisons."],"supporting_citations":[],"fun_headline_variants":["PatchMap maps hot-spots where 2% adversarial patches fool models","New benchmark finds vulnerable zones for adversarial patches","Mask-guided patch placement boosts attacks by 8–13 points","Exhaustive patch benchmark reveals model weak spots","PatchMap: 150M passes map adversarial patch sweet spots"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The benchmark's practical payoff rests on the assumption that off-the-shelf segmentation masks mark the same image regions PatchMap identifies as hot-spots, so placing a patch there raises attack success without gradient information; if that mask-vulnerability link is weak, the reported 8 to 13 point gain collapses even if the benchmark itself is sound.","fun_headline_variants_meta":{"raw":{"variants":["PatchMap maps hot-spots where 2% adversarial patches fool models","New benchmark finds vulnerable zones for adversarial patches","Mask-guided patch placement boosts attacks by 8–13 points","Exhaustive patch benchmark reveals model weak spots","PatchMap: 150M passes map adversarial patch sweet spots"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000287,"raw_usage":{"total_tokens":1640,"prompt_tokens":854,"completion_tokens":786,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":470,"completion_tokens_details":{"reasoning_tokens":705}},"tokens_in":470,"tokens_out":786,"duration_ms":7837,"temperature":1.0,"reasoning_tokens":705,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T05:28:19.592955+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Re-run the placement comparison on ImageNet and check whether mask-targeted patches consistently beat random and fixed placements by the claimed margin across models with diverse segmentation masks; if they do not, or if the mask-selected regions do not co-locate with PatchMap hot-spots, the central utility claim is refuted. Additionally, the hot-spot maps themselves can be tested against a fresh set of validation images to see whether the same spatial regions remain vulnerable rather than being artifacts of the selected benchmark set.","supporting_citations":[],"review_version":1}