Real evaluation data · no live model
Where representations
actually collapse.
A trained ResNet was profiled layer by layer with a Gaussian-mixture density fit at five depths, then scored against 84,957 real images: 10,000 clean CIFAR-100 test images, three out-of-distribution sources (SVHN, LSUN, iSUN), and three white-box adversarial attacks (FGSM, PGD, AutoAttack). Pick a source below and watch, layer by layer, whether a single layer's density alone can actually tell it apart from clean input — or not.
Interactive
Per-layer separability
Muted fill is the real clean-input (ID) distribution at that layer. The colored line is the selected source, laid over the same axis — where the two shapes overlap, that layer alone can't tell them apart.
Out-of-distribution
Adversarial attack
Loading real evaluation data (~15 KB)…
L1
—
L2
—
L3
—
L4
—
L5
—
How this works
How the data was produced.
Unlike the TRNG and Viyog demos, this page doesn't run a model in your browser — the underlying repo profiled five layers of a ResNet with a per-layer Gaussian mixture, then scored it once against 84,957 real images across seven categories. That per-sample output — gmm_scores11thdec.csv, ~8.6 MB — is the project's actual research artifact; no trained checkpoint was ever exported alongside it.
What ships with this page is a ~15 KB aggregate: a 44-bin histogram and an AUROC-based separability score per layer per category, computed directly from that real CSV (10,000 ID, 26,032 SVHN, 10,000 LSUN, 8,925 iSUN, 10,000 each of FGSM/PGD/AutoAttack). Every bar is a real bin count, and each "separates" or "near chance" label comes from the AUROC value.
AUROC here is the probability a random sample from the selected source scores higher, at that layer, than a random clean ID sample. 0.5 means the layer's density genuinely can't tell them apart; the further from 0.5 in either direction, the more separable the two are — direction just says whether the source scores tend higher or lower than clean input.
The real pattern in this data: adversarial attacks stay close to chance (AUROC 0.40–0.55) at every single layer — no one layer's density alone catches them. Out-of-distribution sources separate strongly at the first two and last layers, but collapse toward chance at layer 3 before recovering — the "representation collapse" the project's tagline refers to.