English

Focused Width in Adversarial Fake Detection: A Separation

Statistics Theory 2026-07-06 v1

Abstract

We study the adversarial fake detection model introduced by Mendelson, Paouris and Vershynin. In this model, a genuine sample is XN(0,In)\pmb{X}\sim N(0,\pmb{I}_n), while a fake sample is produced as X+rt(X)\pmb{X}+r\pmb{t}({\pmb{X}}), where the adversary first observes X\pmb{X} and then chooses an admissible perturbation t(X)\pmb{t}({\pmb{X}}) from a prescribed set TRn\mathscr{T}\subset\mathbb{R}^n. The central quantity is the detectability radius r(T)r(\mathscr{T}), which formalizes the transition scale at which fake samples become reliably distinguishable from genuine ones. Mendelson, Paouris and Vershynin introduced the focused width w~(T)\widetilde{w}(\mathscr{T}) as a geometric parameter for this radius and conjectured that, for every origin-symmetric set T\mathscr{T}, it characterizes r(T)r(\mathscr{T}) up to universal constants. In this note, we disprove this conjecture for a broad class of discrete sets. More precisely, we consider any origin-symmetric set Tn\mathscr{T}_n lying between the hypercube and the odd integer grid: \begin{equation*} \{-1,1\}^n\subset\mathscr{T}_n\subset ( 2\mathbb{Z}+1)^n. \end{equation*} For every such Tn\mathscr{T}_n, we prove that w~(Tn)r(Tn)logn\frac{\widetilde{w}(\mathscr{T}_n)}{r(\mathscr{T}_n) }\gtrsim \sqrt{\log n}. Thus, in the Gaussian model, the focused width can overestimate the detectability radius by a logn\sqrt{\log n} factor and therefore does not characterize it in general. We further show that this logarithmic scale is not intrinsic: in the corresponding non-Gaussian model with product Laplace data, the focused width benchmark can even exceed the detectability radius by at least a polynomial factor of order n1/4n^{1/4}.

Cite

@article{arxiv.2607.05379,
  title  = {Focused Width in Adversarial Fake Detection: A Separation},
  author = {Gao Huang},
  journal= {arXiv preprint arXiv:2607.05379},
  year   = {2026}
}

Comments

14pages