Cowardly refusing to serialize non-leaf tensor
Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. This entry explains how to confirm the cause, apply the fix, and separate it from adjacent pytorch-fsdp-ddp failures.
Cowardly refusing to serialize non-leaf tensor means Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. Preserve the first preceding error, then run the targeted control below.
- Symptom
Cowardly refusing to serialize non-leaf tensor- Root cause
- Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. The decisive evidence is the first log line that precedes "Cowardly refusing to serialize non-leaf tensor" and differs from a healthy run.
- Recommended fix
- detach before saving.detach() on the offending tensor, or save model.state_dict() rather than tensors captured from the training loop.
- How Denpex helps
- Denpex investigates Cowardly refusing to serialize non-leaf tensor using the evidence you provide or your connected workload collects. Earlier rank, host or application evidence is needed to distinguish an initiating failure from a downstream report.
What this failure is
The literal signature is "Cowardly refusing to serialize non-leaf tensor". It is a distributed training failure associated with PyTorch Distributed, FSDP, DDP, and TorchElastic. The line identifies the failing operation or subsystem, while the surrounding evidence decides whether it is the initiating fault or a downstream symptom.
Is this what broke your run? Paste your log.
You're reading about Cowardly refusing to serialize non-leaf tensor. Paste your own traceback and relevant evidence for an investigation of your workload, with a next action or a specific missing fact. A reference entry does not establish your cause. No account or card for the free diagnosis. Review data handling before submitting sensitive logs.
Before uploading, review cloud data handling and local options.
Why it happens (the mechanism)
Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. The failure becomes visible at this call site because the operation first requires the missing resource, valid state, healthy peer, or correct result. Earlier log lines and a known-good control carry more causal value than the final wrapper exception.
What you'll observe
- The workload stops or loses forward progress after emitting "Cowardly refusing to serialize non-leaf tensor".
- A retry on the same configuration reproduces the failure because the causal state has not changed.
- The outer framework exception can hide the rank, node, allocation, or dependency that failed first.
- Increasing timeouts or reducing workload size can suppress the symptom without correcting the cause.
Common symptoms and what they mean
| Symptom | Why it happens |
|---|---|
| Cowardly refusing to serialize non-leaf tensor | Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. |
| The same operation fails at a consistent stage of PyTorch Distributed, FSDP, DDP, and TorchElastic. | The decisive evidence is the first log line that precedes "Cowardly refusing to serialize non-leaf tensor" and differs from a healthy run. |
| The first related warning appears before the final exception and names the causal subsystem. | A nearby failure remains a competing hypothesis until a control separates configuration, capacity, transport, and hardware causes. |
| A known-good control changes one variable and either reproduces or clears the failure. | Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. |
Which systems are affected
- PyTorch Distributed, FSDP, DDP, and TorchElastic
- production-shaped multi-accelerator workloads
- containerized and bare-metal deployments of the same stack
How to confirm this is the problem
Use this checklist to test the hypothesis against a small reproduction. No single line proves the root cause, so preserve the preceding events and compare one variable at a time.
- ✓Find the first occurrence of "Cowardly refusing to serialize non-leaf tensor" and preserve at least 100 lines before it.
- ✓Identify which rank, node, device, or process emitted the first related warning.
- ✓this is almost always a metric or a buffer accumulated inside the loop without detaching (running loss, a cached activation) that ended up in the checkpoint dict. Print which keys carry requires_grad: [k for k,v in sd.items() if torch.is_tensor(v) and v.requires_grad].
- ✓Repeat the same input after the targeted change and require the signature to disappear.
- ✓Resume from the previous good checkpoint only after the control passes.
Root cause
- Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly.
- The decisive evidence is the first log line that precedes "Cowardly refusing to serialize non-leaf tensor" and differs from a healthy run.
- A nearby failure remains a competing hypothesis until a control separates configuration, capacity, transport, and hardware causes.
The fix and how to prevent it
Searchable error signature
Cowardly refusing to serialize non-leaf tensorUse this text as a lookup key in logs and upstream issue trackers. It is not presented as a captured customer log. Confirm the cause from your own preceding events, versions, configuration and the cited references.
The fix and the prevention pattern
The root cause is on this page and stays free. A free account adds the exact remediation steps, saved history, and the fix on every entry in the encyclopedia.
Sign up free. Unlock the full analysisNo credit card. Daily allowance follows verified trust tier. Instant access.
Why the recommended fix works
detach before saving.detach() on the offending tensor, or save model.state_dict() rather than tensors captured from the training loop. This changes the condition in the causal diagnosis instead of hiding the outer exception. The repeated control proves ownership before recovery from the previous good checkpoint.
Code examples
# Preserve evidence before restarting
rg -n -i 'error|exception|timeout|failed' <log-file>
nvidia-smi
python -m torch.utils.collect_env
# Find the exact signature in the complete log
rg -n -F -- "Cowardly refusing to serialize non-leaf tensor" <log-file>Adapt the snippet to your framework. The same pattern holds for PyTorch Lightning, Hugging Face Trainer, DeepSpeed, Megatron-LM, and vLLM training wrappers. Where the wrapper exposes a config flag (for examplelr_scheduler_type in Trainer), prefer the flag over the imperative API to keep the schedule declarative and reproducible.
Best practices by model family
| Model / Stack | Recommendation | Notes |
|---|---|---|
| First response | Preserve the first failure | Keep the context before "Cowardly refusing to serialize non-leaf tensor" so aggregation does not erase causality. |
| Confirmation | Change one variable | Use a known-good node, rank, input, or configuration as the control. |
| Recovery | Resume from the previous good checkpoint | Resume only after the literal signature no longer appears in the same control. |
With the fix vs without the fix
| Dimension | With the fix | Without the fix |
|---|---|---|
| Evidence | First preceding error and one controlled comparison | Only the final aggregated exception |
| Fix | detach before saving.detach() on the offending tensor, or save model.state_dict() rather than tensors captured from the training loop. | Retrying the unchanged workload |
| Exit criterion | "Cowardly refusing to serialize non-leaf tensor" is absent in the repeated control | The job happened to run once |
Diagnostic note
“Treat "Cowardly refusing to serialize non-leaf tensor" as a search key and an investigation checkpoint, not as proof of every cause associated with the phrase. The high-value evidence is what changed immediately before it and whether the failure follows the workload, node, or configuration.”
Visual fingerprint
literal error captured
|
v
find first preceding failure
|
v
run one known-good control
|
+-- follows workload --> inspect input or configuration
+-- follows node ------> inspect hardware or platform
+-- disappears --------> validate the targeted fixDiagnose this failure in VS Code
Select the traceback or open the failed terminal, then run Denpex locally to see the initiating rank, collateral failures, exact fix, and verification command without uploading the log.
Install the free VS Code extensionRelated failures to investigate next
Frequently asked questions
Questions engineers and on-call staff commonly ask about this failure.
What does "Cowardly refusing to serialize non-leaf tensor" mean?
Is this line always the root cause?
What should I collect before restarting?
What is the fastest confirmation?
How do I prevent it from recurring?
Don't just read the fix, diagnose your run
The encyclopedia tells you what went wrong. Denpex tells you what went wrong in YOUR training run. With your logs, your config, and your stack.