Tag
This paper shows that being a valid curvature upper bound does not automatically justify using a last-layer relative-flatness proxy as an adversarial-robustness certificate or as a differentiable training regularizer. The authors derive a gauge-invariant repair, demonstrate the proxy's unboundedness under symmetry-preserving softmax shifts, and show via CIFAR-10 experiments that quotient-regularized predictors stay aligned while raw-regularized ones can have their generalization suppressed.