{"id":"8080bfb5-2de1-4f78-b16a-6112e87b6f5f","arxiv_id":"2607.23318","paper_version":1,"verdict":"ACCEPT","confidence":"HIGH","novelty_score":4.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"An adversary that adapts its noise to the realized computation gains nothing: averaging its conditional noise distributions yields an input-independent strategy with identical acceptance probability and mean-squared error.","lead":"The paper shows that letting an adversarial worker tailor its noise to the actual value being computed gives no extra power in the game of coding: every input-dependent noise strategy can be replaced by a fixed one with the same acceptance probability and estimation error. This unifies the earlier scalar and vector game-of-coding models and preserves the same equilibrium thresholds and utilities.","discovery_kind":"unification","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The negative result rests on Eq. (6) (adversary cannot observe honest noises); this is a scope boundary, not an internal error, but it should be stated as prominently as the theorem.","rationale":"The reader's weakest_assumption is exactly Eq. (6), and my analysis identifies the same condition as the only substantive soft spot. The paper's proof is a clean marginalization; once the conditional independence is granted, Theorem 1 follows. The concern is not that the theorem is false, but that the headline 'input-dependent and input-independent models have identical achievable performance regions' is easy to over-read as covering adversaries that adapt to honest noise realizations. The motivating applications in the Introduction describe attacks that do use information about benign updates, so the gap between the motivating stories and Eq. (6) is material. However, the paper explicitly states Eq. (6) and defines the input-dependent strategy set as depending only on U, so the mathematical claim is sound within its stated model. I therefore keep the reader's ACCEPT verdict, but recommend the authors move the Eq. (6) scope discussion from a one-line assumption to a prominently stated limitation, ideally with a sentence that the reduction does not extend to adversaries observing honest noises.","tokens_in":16168,"tokens_out":11122,"duration_ms":104091,"concrete_test":"Run a two-node scalar instance: h=t=1, d=1, U uniform on {0,1}, N_K uniform on [-Δ,Δ], Δ=1, η=2. (A) Let the adversary observe (U,N_K) and choose N_Q=N_K+c with c=sign(N_K)·ηΔ (and c=ηΔ if N_K=0), so the acceptance range |N_Q-N_K|=ηΔ and midpoint error |N_K+N_Q|/2=|N_K|+ηΔ/2. Compute the PA/MSE pair. (B) Optimize PA/MSE over input-independent N_Q distributions (independent of N_K). If the (A) pair strictly dominates the best (B) pair, Theorem 2's equality of achievable regions fails as soon as Eq. (6) is relaxed; this confirms that Eq. (6) is the load-bearing scope condition.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Theorem 1 is mathematically correct under Eq. (6): if N_K ⊥ U and N_K ⊥ N_Q | U, marginalizing over U gives f_{N_K,N_Q}(x,z)=f_{N_K}(x) E_U[g_U(z)], so the averaged input-independent strategy induces the same joint noise distribution and hence the same PA and MSE. The load-bearing condition is Eq. (6). It is a modeling assumption, not a consequence of the additive representation in the footnote: any report can be written as U+N_Q, but if N_Q is also a function of the realized honest noises, the conditional joint density becomes f_{N_K|U}(x|u) f_{N_Q|N_K,U}(z|x,u), which does not factor as in (6). Then Lemma 2's marginalization step E_U[f_{N_K}(x)g_U(z)] no longer holds, and there is in general no input-independent gbar that reproduces the joint distribution of the noises. The paper states Eq. (6) in Section II but does not flag it as the key scope restriction; the Introduction's motivating examples (adversarial examples, model poisoning with 'available information about benign updates') invite readers to apply the conclusion to adversaries that adapt to more than U. The central claim should be understood as: input dependence on U alone buys nothing; dependence on honest noises is outside the model.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper introduces a unified n-node, d-dimensional 'game of coding' model in which the adversarial noise distribution may depend on the realized ground-truth computation U. The main result (Theorem 1) constructs, for any input-dependent adversarial strategy {g_u}_{u∈U}, an averaged input-independent strategy ̄g = E_U[g_U] that achieves exactly the same probability of acceptance and the same accepted mean-squared estimation error for every threshold η. From this, the authors conclude that the input-dependent and input-independent models have identical achievable performance regions (Theorem 2) and identical Stackelberg equilibria (Theorem 3). The proofs in Appendices B–D are built on the law of total probability and on the observation that both the acceptance event and the midrange estimation error depend only on the noise realizations, not on U.","tokens_in":16478,"tokens_out":7822,"duration_ms":70410,"significance":"If the result stands, this is a clean negative result: allowing adversarial noise to depend on the ground-truth computation U does not enlarge the adversary's power within the modeled class of acceptance/estimation rules. The paper's main technical contribution is an exact averaging reduction, and it provides a useful unification of previous scalar and vector game-of-coding models. The proof is transparent, self-contained, and free of fitted parameters. However, the scope of the claim is narrower than the Introduction's motivating examples suggest, and the formal theorem statements omit a positivity condition needed for the conditional MSE. These issues are correctable but must be addressed before the paper can be accepted.","major_comments":[{"comment":"The equivalence in Theorem 1 relies critically on the factorization f_{N_K,N_Q|U}=f_{N_K}g_u, which excludes adversaries that observe or couple their reports with realized honest noises. The Introduction's motivating examples (adversarial examples, model poisoning with 'available information about benign updates') invite a broader reading. Without (6), Lemma 2's marginalization fails: the joint density becomes f_{N_K|U}(x|u)f_{N_Q|N_K,U}(z|x,u), which cannot generally be written as f_{N_K}(x)\\bar g(z). Please state prominently in the abstract and Section I that only dependence on U is covered, and identify honest-noise-adaptive adversaries as an explicit limitation.","section":"Section II, Eq. (6)"},{"comment":"The proof of Theorem 1, specifically the step at Eq. (80)–(81), establishes MSE equality only under the condition PA(g,η)>0, but the theorem statement claims equality for every η∈Λ_DC with no qualification. When an adversarial strategy makes acceptance probability zero (e.g., reports far outside the threshold), MSE is undefined, so the statement 'MSE(g,η)=MSE(\\bar g,η)' is not a well-formed equality. The same issue affects the definition of the performance region R^σ(η) in (30) and, consequently, Theorems 2–3. Please add the positivity precondition (or a consistent convention for zero-probability acceptance) to the theorem statements and adjust the performance-region definitions accordingly.","section":"Section III, Theorem 1 and Appendix B"}],"minor_comments":[{"comment":"The definition of Λ^ind_AD uses '∃g such that g_u=g' but the symbol g is also used for the averaged PDF in (23) and for the strategy. Please use distinct notation (e.g., g_0 for the common PDF) to avoid confusion.","section":"Section II, Eq. (8)"},{"comment":"The exchange of expectation and integral is justified by Tonelli's theorem (nonnegativity is the applicable condition); please cite Tonelli explicitly rather than writing 'because the integrand is nonnegative'.","section":"Appendix B, Lemma 1, Eq. (54)"},{"comment":"The phrase 'for every family of conditional adversarial-noise distributions' in the abstract should be qualified by the conditional independence assumption (6), so that readers are immediately aware that the adversary cannot adapt to honest noise realizations.","section":"Abstract and Introduction"},{"comment":"The sentence 'Theorem 1 states that the dependence of the adversarial-noise distribution on U can be removed without changing either performance metric' is correct, but it would be helpful to add '(under the standing assumption (6))' to keep the scope in view.","section":"Section III, after Theorem 1"}],"recommendation":"major_revision","confidential_remarks":"The mathematical derivation is sound under the stated assumptions, and the averaging argument is elegant. The main concerns are framed as major comments because the theorem statements need a positivity condition and the paper's Introduction overstates the scope relative to Eq. (6). Both are fixable with careful revision, and I would be willing to look at a revised version. The unification of previous game-of-coding models is a genuine strength."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Main takeaway: Theorem 1 is correct, and it is narrower than the abstract suggests. It shows that if the adversary can adapt its noise distribution to the ground-truth value U but not to the honest noise realizations, then that adaptation buys nothing: averaging the conditional distributions g_u over U gives an input-independent strategy with exactly the same probability of acceptance and accepted mean-squared error. The proof is a short marginalization argument, and it works because the acceptance event and the estimation error depend only on the noise tuple, not on U. That is a real result, and it unifies the earlier game-of-coding models cleanly.\n\nWhat the paper does well: the unified n-node, d-dimensional formulation is genuinely useful, and the appendices hold up. Lemmas 2 and 3 are the right pieces, and the chain from Theorem 1 to Theorems 2 and 3 is sound. There are no fitted parameters, no code, no data, and none are needed. The equivalence is not stated in the cited prior work, though it is a natural consequence of the model.\n\nThe soft spot is Eq. (6), and it is a scope boundary rather than an internal error. Eq. (6) assumes the adversarial noise is conditionally independent of the honest noise given U. If the adversary can see or couple its reports to the realized honest noises, then the joint density becomes f_NK(x) f_NQ|NK,U(z|x,u), which does not factor as in (6), and no input-independent averaged strategy can reproduce the joint distribution. The paper states Eq. (6) but does not flag it as the key restriction. The introduction's motivating examples — adversarial examples, model poisoning with 'available information about benign updates' — invite a broader reading than the model supports. The honest takeaway is: input-dependence on U alone buys nothing; adversaries that adapt to honest noise are outside the model. That sentence should be more prominent, ideally in the abstract.\n\nMinor point: the theorem statements omit the positivity-of-acceptance-probability condition for MSE. The proof includes it, so the fix is easy. If PA = 0, MSE is undefined and the equality needs to be qualified.\n\nWho this is for: people working on game-of-coding or rational-adversary coding, especially equilibrium analysis. It is not going to change practice outside that niche. It deserves a serious referee; it is a clean, honest, small paper that needs a moderate revision to scope its claims.","headline":"Correct but narrower than the abstract suggests: the equivalence holds for adversaries that adapt to U alone, and the paper should say so; worth a serious referee.","tokens_in":16915,"tokens_out":2842,"would_cite":true,"duration_ms":30044,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["94A15","91A80"],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper proves that allowing an adversary to tailor its noise distribution to the realized computation does not enlarge its achievable performance region: every input-dependent strategy has an input-independent counterpart with exactly th","keywords":["game of coding","input-dependent adversarial noise","Stackelberg equilibrium","achievable performance region","probability of acceptance","mean-squared estimation error","decentralized machine learning","rational adversaries"],"falsifier":"Give the adversary access to the realized honest noises (e.g., by observing the honest nodes' reports before submitting its own) and search over conditional strategies g_{u,x_K}; if any such strategy achieves a (P_A, MSE) pair outside the set achievable by input-independent strategies for some threshold η, then the equivalence in Theorem 1 breaks, confirming that the conditional-independence assumption in equation (6) is load-bearing.","tokens_in":16080,"feed_emoji":"🎲","tokens_out":4709,"duration_ms":43758,"temperature":0.7,"pith_summary":"The paper asks whether an adversary who can condition its report noise on the true value being computed can do better than one who must use a fixed noise distribution. It answers no. In a unified n-node, d-dimensional game-of-coding model, the authors show that averaging any input-dependent noise distribution over the distribution of the ground truth yields an input-independent strategy with identical acceptance probability and identical accepted mean-squared error. Therefore the achievable (acceptance, error) region and the Stackelberg equilibrium are unchanged. This matters for decentralized computation, where workers may know or infer the target value; the framework's guarantees survive such adaptive attackers.","feed_headline":"Input-aware adversarial noise buys no advantage in coded computing","feed_subtitle":"Game-of-coding guarantees survive adversaries who tailor noise to the computed value.","key_machinery":"The averaging identity g(z_Q) = E_U[g_U(z_Q)], applied to the joint noise vector. The acceptance rule uses the coordinatewise max–min spread (range) of all reports, and the estimator is the coordinatewise midrange; Lemma 3 shows both are functions of the noise tuple N alone, so the ground truth U cancels. Lemma 2 shows that after averaging, the marginal distribution of honest and adversarial noises is f_{N_K}(x_K) g(z_Q), exactly as under the averaged input-independent strategy.","core_discovery":"The central result is Theorem 1: for any conditional adversarial-noise family {g_u}, the averaged distribution g(z_Q) = E_U[g_U(z_Q)] is a valid noise distribution, and using it unconditionally preserves both P_A(g,η) and MSE(g,η) for every threshold η. The proof rests on two observations: the acceptance event and the midrange-estimator error depend only on the noise realizations, not on U; and marginalizing the joint distribution over U collapses the conditional dependence, leaving the same joint noise distribution as the averaged strategy. Consequently, the input-dependent and input-independent games have identical performance regions (Theorem 2) and identical optimal thresholds and equili","pith_inferences":["The result depends crucially on the adversary not observing the honest noises (conditional independence given U). If the adversary could condition its noise on the honest reports, the factorization in Lemma 2 fails; a carefully constructed input-dependent strategy could then beat any input-independent one. Constructing a counterexample for that variant would delineate the boundary of the theorem.","The same averaging argument may generalize to other acceptance and estimation rules that are shift-invariant in the noise (depend only on report differences), suggesting input-dependent noise is broadly harmless whenever the adversary is blind to honest noise.","In practice, an adversary that knows U but not the honest noise is roughly as powerful as one that knows only the distribution of U; the paper makes this intuition exact for the game-of-coding metrics.","A testable consequence: in simulations where g_u is sharply peaked at values far from U, the averaged strategy should reproduce identical acceptance and error curves, confirming the equivalence."],"forward_implications":["The game-of-coding guarantees proved for input-independent adversaries transfer unchanged to adversaries who can adapt their noise to the computed value.","A data collector can design acceptance thresholds and estimators while ignoring the possibility of input-dependent noise; worst-case behavior is identical.","The achievable (probability-of-acceptance, mean-squared-error) region is the same for both models, so the adversary's best-response utility and the DC's worst-case utility are equal at every threshold.","Prior scalar and two-node vector models are exact special cases, so the result unifies and extends them.","The reduction works for arbitrary U distribution and arbitrary correlation among adversarial nodes, so it covers coordinated multi-node attacks."],"fun_headline_variants":["Input-aware noise gains nothing in coding games","Adversary tailoring noise to input? No edge here","Game of coding: input-dependent noise is a wash","Coded computing resists input-aware adversarial noise"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The entire argument assumes the adversary's noise is conditionally independent of the honest noises given the ground truth; if the adversary can observe or statistically depend on the honest nodes' noise realizations, the averaging reduction and the equivalence of the two models can fail.","fun_headline_variants_meta":{"raw":{"variants":["Input-aware noise gains nothing in coding games","Adversary tailoring noise to input? No edge here","Game of coding: input-dependent noise is a wash","Coded computing resists input-aware adversarial noise"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000105,"raw_usage":{"total_tokens":836,"prompt_tokens":672,"completion_tokens":164,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":416,"completion_tokens_details":{"reasoning_tokens":115}},"tokens_in":416,"tokens_out":164,"duration_ms":2485,"temperature":1.0,"reasoning_tokens":115,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-31T23:44:33.815713+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Give the adversary access to the realized honest noises (e.g., by observing the honest nodes' reports before submitting its own) and search over conditional strategies g_{u,x_K}; if any such strategy achieves a (P_A, MSE) pair outside the set achievable by input-independent strategies for some threshold η, then the equivalence in Theorem 1 breaks, confirming that the conditional-independence assumption in equation (6) is load-bearing.","supporting_citations":[],"review_version":1}