Cowardly refusing to serialize non-leaf tensor
Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. This entry explains how to confirm the cause, apply the fix, and separate it from adjacent pytorch-fsdp-ddp failures.
Cowardly refusing to serialize non-leaf tensor means Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. Preserve the first preceding error, then run the targeted control below.
What this failure is
The literal signature is "Cowardly refusing to serialize non-leaf tensor". It is a distributed training failure associated with PyTorch Distributed, FSDP, DDP, and TorchElastic. The line identifies the failing operation or subsystem, while the surrounding evidence decides whether it is the initiating fault or a downstream symptom.
Is this what broke your run? Paste your log.
You're reading about Cowardly refusing to serialize non-leaf tensor. Paste your own crash log or traceback below and get the real root cause for YOUR run, not this generic entry. No account, no card. Logs are masked at ingress and never saved to account history.
Want 14 days of full access?
Request a free trial code for unlimited diagnoses, alerts, history, and follow-up questions. No credit card.
Why it happens (the mechanism)
Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. The failure becomes visible at this call site because the operation first requires the missing resource, valid state, healthy peer, or correct result. Earlier log lines and a known-good control carry more causal value than the final wrapper exception.
What you'll observe
- The workload stops or loses forward progress after emitting "Cowardly refusing to serialize non-leaf tensor".
- A retry on the same configuration reproduces the failure because the causal state has not changed.
- The outer framework exception can hide the rank, node, allocation, or dependency that failed first.
- Increasing timeouts or reducing workload size can suppress the symptom without correcting the cause.
Common symptoms and what they mean
| Symptom | Why it happens |
|---|---|
| Cowardly refusing to serialize non-leaf tensor | Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. |
| The same operation fails at a consistent stage of PyTorch Distributed, FSDP, DDP, and TorchElastic. | The decisive evidence is the first log line that precedes "Cowardly refusing to serialize non-leaf tensor" and differs from a healthy run. |
| The first related warning appears before the final exception and names the causal subsystem. | A nearby failure remains a competing hypothesis until a control separates configuration, capacity, transport, and hardware causes. |
| A known-good control changes one variable and either reproduces or clears the failure. | Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly. |
Which systems are affected
- PyTorch Distributed, FSDP, DDP, and TorchElastic
- production-shaped multi-accelerator workloads
- containerized and bare-metal deployments of the same stack
How to confirm this is the problem
Apply the following checklist to a small reproduction: each box below is a positive signal that you are looking at this exact failure rather than a sibling in the same taxonomy.
- ✓Find the first occurrence of "Cowardly refusing to serialize non-leaf tensor" and preserve at least 100 lines before it.
- ✓Identify which rank, node, device, or process emitted the first related warning.
- ✓this is almost always a metric or a buffer accumulated inside the loop without detaching (running loss, a cached activation) that ended up in the checkpoint dict. Print which keys carry requires_grad: [k for k,v in sd.items() if torch.is_tensor(v) and v.requires_grad].
- ✓Repeat the same input after the targeted change and require the signature to disappear.
- ✓Resume from the previous good checkpoint only after the control passes.
Example training logs (fingerprint)
Cowardly refusing to serialize non-leaf tensorTimestamps and exact values vary across runs, but the pattern. An info-level start, an early WARN, an ERROR carrying the symptom. Is the actual fingerprint you should alert on. The Denpex platform flags this combination automatically.
The fix and the prevention pattern
The root cause is on this page and stays free. A free account adds the exact remediation steps, keeps your diagnoses instead of discarding them, and unlocks the fix on every entry in the encyclopedia.
Sign up free. Unlock the full analysisNo credit card · 3 free diagnoses · Instant access
Why the recommended fix works
detach before saving.detach() on the offending tensor, or save model.state_dict() rather than tensors captured from the training loop. This changes the condition in the causal diagnosis instead of hiding the outer exception. The repeated control proves ownership before recovery from the previous good checkpoint.
Code examples
# Preserve evidence before restarting
rg -n -i 'error|exception|timeout|failed' <log-file>
nvidia-smi
python -m torch.utils.collect_env
# Find the exact signature in the complete log
rg -n -F -- "Cowardly refusing to serialize non-leaf tensor" <log-file>Adapt the snippet to your framework. The same pattern holds for PyTorch Lightning, Hugging Face Trainer, DeepSpeed, Megatron-LM, and vLLM training wrappers. Where the wrapper exposes a config flag (for examplelr_scheduler_type in Trainer), prefer the flag over the imperative API to keep the schedule declarative and reproducible.
Best practices by model family
| Model / Stack | Recommendation | Notes |
|---|---|---|
| First response | Preserve the first failure | Keep the context before "Cowardly refusing to serialize non-leaf tensor" so aggregation does not erase causality. |
| Confirmation | Change one variable | Use a known-good node, rank, input, or configuration as the control. |
| Recovery | Resume from the previous good checkpoint | Resume only after the literal signature no longer appears in the same control. |
With the fix vs without the fix
| Dimension | With the fix | Without the fix |
|---|---|---|
| Evidence | First preceding error and one controlled comparison | Only the final aggregated exception |
| Fix | detach before saving.detach() on the offending tensor, or save model.state_dict() rather than tensors captured from the training loop. | Retrying the unchanged workload |
| Exit criterion | "Cowardly refusing to serialize non-leaf tensor" is absent in the repeated control | The job happened to run once |
Real engineering notes
“Treat "Cowardly refusing to serialize non-leaf tensor" as a search key and an investigation checkpoint, not as proof of every cause associated with the phrase. The high-value evidence is what changed immediately before it and whether the failure follows the workload, node, or configuration.”
Visual fingerprint
literal error captured
|
v
find first preceding failure
|
v
run one known-good control
|
+-- follows workload --> inspect input or configuration
+-- follows node ------> inspect hardware or platform
+-- disappears --------> validate the targeted fixDiagnose this failure in VS Code
Select the traceback or open the failed terminal, then run Denpex locally to see the initiating rank, collateral failures, exact fix, and verification command without uploading the log.
Install the free VS Code extensionRelated failures to investigate next
Root cause
- Something still attached to the autograd graph was handed to the checkpoint writer. Saving it would serialise the graph as well as the values, so torch refuses rather than writing a checkpoint that cannot be loaded cleanly.
- The decisive evidence is the first log line that precedes "Cowardly refusing to serialize non-leaf tensor" and differs from a healthy run.
- A nearby failure remains a competing hypothesis until a control separates configuration, capacity, transport, and hardware causes.
The fix and how to prevent it
Unlock the full remediation runbook
14 days on the Scale plan, up to 50 diagnoses a day. Step-by-step remediation, the RMA evidence payload, and multi-node correlation on your own logs. No card, and it does not roll into a subscription.
Frequently asked questions
Twelve targeted questions that engineers and on-call staff most commonly ask about this failure.
What does "Cowardly refusing to serialize non-leaf tensor" mean?
Is this line always the root cause?
What should I collect before restarting?
What is the fastest confirmation?
How do I prevent it from recurring?
Don't just read the fix, diagnose your run
The encyclopedia tells you what went wrong. Denpex tells you what went wrong in YOUR training run. With your logs, your config, and your stack.