{"id":"106747cc-bd9c-459b-b2ea-0faccd394d5b","arxiv_id":"2604.25965","paper_version":2,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":7.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"NTK neural networks achieve minimax optimal adversarial regression rates in Sobolev spaces using gradient flow with early stopping, but minimum norm interpolants are vulnerable in the overfitting regime.","lead":"The paper studies the adversarial robustness of neural tangent kernel (NTK) models in nonparametric regression settings. It proves that early-stopped gradient flow training achieves optimal robustness rates in Sobolev spaces, while overfitted interpolants do not.","discovery_kind":"extension","skeptic_critique":{"model":"grok-4.3","headline":"No significant objection identified","rationale":"The reader's identification of the infinite-width NTK limit as the weakest assumption is accurate for a claim that is explicitly about NTK networks; the abstract supplies no further technical gap that would alter the UNVERDICTED verdict.","tokens_in":1533,"tokens_out":248,"duration_ms":35596,"concrete_test":"Verify whether the early-stopping time t* that achieves the optimal rate is selected using only observable quantities (sample size n and noise level) or whether it requires knowledge of the unknown Sobolev smoothness s or the adversary radius; recompute the excess adversarial risk if t* must depend on s.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The abstract presents a standard two-step structure: first derive minimax rates for adversarial regression over Sobolev balls, then show that the NTK kernel gradient flow with early stopping attains the same rate. The additional statement that the minimum-norm interpolant fails in the overfitting regime is consistent with known kernel interpolation results and does not contradict the main claim. No internal inconsistency, circularity, or unstated assumption that would invalidate the central claim is visible from the given information.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The manuscript establishes minimax optimal rates for adversarial regression over Sobolev balls and shows that NTK neural networks trained by gradient flow with early stopping attain these rates. It further proves that the minimum-norm interpolant fails to be robust in the overfitting regime.","tokens_in":1599,"tokens_out":264,"duration_ms":23909,"significance":"If the derivations hold, the work supplies a clean nonparametric-statistical account of adversarial robustness for kernel methods in the NTK limit, with an explicit separation between early-stopped gradient flow and interpolation. The result is of interest to both the adversarial-robustness and nonparametric-statistics communities.","major_comments":[],"minor_comments":[{"comment":"Abstract: the statement of the Sobolev-ball rates omits the dependence on smoothness index s and dimension d; these parameters should appear explicitly so that the claimed optimality is immediately verifiable.","section":"Abstract"},{"comment":"The transition from the population minimax analysis to the finite-sample NTK gradient-flow analysis would benefit from a short paragraph clarifying the uniform control on the NTK approximation error that is used to transfer the population rates to the empirical setting.","section":null}],"recommendation":"minor_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for their positive evaluation of the manuscript, accurate summary of our contributions, and recommendation for minor revision. We are pleased that the work is viewed as providing a clean nonparametric account of adversarial robustness for NTK methods.","responses":[],"tokens_in":1015,"tokens_out":65,"duration_ms":9594,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The main thing to know is that this paper derives minimax rates for adversarial nonparametric regression over Sobolev balls and then shows that NTK models trained by gradient flow with early stopping attain those rates. It also shows that the minimum-norm interpolant is vulnerable once you enter the overfitting regime.\n\nThe general minimax analysis looks like standard work in this area, but the specific application to NTK with early stopping is the part that stands out. The paper is clear that early stopping is what avoids the robustness failure that hits the interpolant. That distinction is useful and cleanly stated.\n\nThe math follows the usual kernel and Sobolev techniques without obvious gaps from the abstract and stress-test note. No circularity or hidden contradictions appear.\n\nThe soft spot is the infinite-width NTK assumption. Results in that limit do not automatically carry over to finite networks, and the paper would be stronger with even a brief remark on how the rates might degrade or hold outside the limit. The adversarial perturbation model also needs explicit statement in the main claims.\n\nThis is a paper for people working on theoretical robustness or kernel methods in nonparametric settings. A reader who wants precise rates and training-procedure comparisons will find it worth their time.\n\nIt deserves a serious referee. The claims are specific enough to check, and the setup is standard enough that a reviewer can evaluate the proofs directly.","headline":"NTK gradient flow with early stopping matches adversarial minimax rates in Sobolev spaces, while the min-norm interpolant does not.","tokens_in":2033,"tokens_out":349,"would_cite":false,"duration_ms":22122,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"NTK neural networks achieve minimax optimal rates for adversarial regression in Sobolev spaces when trained via gradient flow with early stopping.","keywords":["adversarial robustness","neural tangent kernel","nonparametric regression","Sobolev spaces","minimax rates","gradient flow","early stopping"],"falsifier":"An explicit computation or simulation in which the adversarial risk of an early-stopped NTK estimator exceeds the derived minimax rate by more than a constant factor would falsify the central claim.","tokens_in":2429,"feed_emoji":"","tokens_out":390,"duration_ms":27969,"temperature":0.7,"pith_summary":"The paper tries to establish that neural networks in the neural tangent kernel regime can match the best possible rates for recovering functions from data even when inputs can be adversarially perturbed, provided training uses gradient flow and early stopping. It first derives those optimal rates for Sobolev function spaces and then proves the networks reach them, while showing that the minimum-norm interpolant fails under the same attacks. A sympathetic reader would care because the result separates the robustness properties of properly stopped kernel-like training from the vulnerabilities that arise in the overfitting regime.","feed_headline":"NTK networks match optimal adversarial regression rates","feed_subtitle":"Gradient flow with early stopping attains minimax rates in Sobolev spaces while overfitting interpolants fail.","key_machinery":"Gradient flow training with early stopping inside the neural tangent kernel regime of infinite-width networks.","core_discovery":"NTK neural networks, trained via gradient flow with early stopping, can achieve the minimax optimal rates for adversarial regression in Sobolev spaces. However, in the overfitting regime, the minimum norm interpolant is vulnerable to adversarial perturbations.","pith_inferences":[],"forward_implications":[],"fun_headline_variants":["NTK networks achieve minimax adversarial rates via early stopping","Sobolev adversarial minimax rates attained by gradient flow NTK","Overfitting causes NTK interpolants to fail adversarial robustness","NTK matches optimal rates for adversarial regression in Sobolev spaces"],"cache_read_input_tokens":2112,"weakest_assumption_plain":"The neural tangent kernel limit accurately describes the training dynamics of the networks under study.","fun_headline_variants_meta":{"raw":{"variants":["NTK networks achieve minimax adversarial rates via early stopping","Sobolev adversarial minimax rates attained by gradient flow NTK","Overfitting causes NTK interpolants to fail adversarial robustness","NTK matches optimal rates for adversarial regression in Sobolev spaces"]},"model":"grok-4.3","cost_usd":0.004932,"raw_usage":{"total_tokens":2321,"prompt_tokens":481,"num_sources_used":0,"completion_tokens":67,"cost_in_usd_ticks":49324500,"prompt_tokens_details":{"text_tokens":481,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":1773,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":481,"tokens_out":67,"duration_ms":18619,"temperature":1.0,"reasoning_tokens":1773,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-01T09:00:41.748920+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"An explicit computation or simulation in which the adversarial risk of an early-stopped NTK estimator exceeds the derived minimax rate by more than a constant factor would falsify the central claim.","supporting_citations":[],"review_version":2}