It is 2013, and a disquieting discovery is circulating: a deep network that classifies images with superhuman confidence can be flipped to a wildly wrong label by a perturbation so small no human eye can detect it. The image looks identical; the model calls a school bus an ostrich. Characterize why high-accuracy classifiers are so brittle at these engineered points, and build defenses that hold when an adversary — not nature — chooses the input. The stakes leave the lab immediately: a stop sign with a few stickers, a face-recognition gate, a malware detector. Get it wrong and you deploy a system whose benchmark accuracy is a fiction the moment someone wants it to fail — and in security, someone always does.
Chose Manifold regularization — wrong. The Laplacian eigenmap was the one that fit.
Niyogi's manifold learning and Laplacian eigenmaps work addresses uncovering low-dimensional nonlinear structure in high-dimensional data, genuinely relevant conceptual background for a leading theoretical explanation of adversarial vulnerability, that natural images lie near a low-dimensional manifold in high-dimensional pixel space, and adversarial perturbations exploit directions off this manifold that a classifier has never seen. His learning theory contributions extended PAC-style analysis to broader settings. He died in 2010, three years before the 2013 discovery, and never worked on adversarial examples directly. His relevance is genuine conceptual and mathematical adjacency to a leading theoretical account of this problem, without being a direct contributor. The manifold hypothesis is a leading explanation his own work anticipates conceptually.
Jordan's decades of research spanning probabilistic graphical models to modern statistical machine learning give him broad, genuine fluency with the theoretical questions adversarial robustness raises, including how a model's decision boundary geometry relates to its vulnerability to worst-case perturbations. His Berkeley-based statistical rigor and career-long attention to when and why learned models generalize well provide relevant intellectual background for this problem's characterization question. He did not co-author the founding 2013 discovery paper or focus his signature research on adversarial examples specifically. His relevance is that of a strong statistical learning generalist observing and engaging with this problem's implications rather than a direct contributor to its founding results. Broad statistical fluency is real even without a signature robustness result.
Battle #95 · 8/10/2026, 11:37:33 AM · this result is deterministic: the same two personas on this problem always resolve the same way.