arXiv:2512.14170cs.LGcs.LO2025-12

用形式化验证生成对抗样本,提升深度主动学习效果

On Improving Deep Active Learning with Formal Verification

  • 用形式化验证生成违反鲁棒性约束的对抗样本
  • 相比传统梯度攻击,提升模型泛化能力显著
  • 适用于多种主动学习方法,适合研究高效训练

深度主动学习(DAL)通过优先标注最具信息量的未标注样本,降低神经网络训练的标注成本。除了选择标注样本外,一些方法还通过添加无需人工标注的合成输入来提升数据效率。本文研究了使用违反鲁棒性约束的对抗输入扩充训练集对DAL性能的影响。结果表明,通过形式化验证生成的对抗样本,相比标准梯度攻击产生的样本具有更显著的提升效果。我们将该方法应用于多种现代主动学习技术,以及我们提出的一种新方法,在多个标准基准上均显著提升了模型泛化能力。

原文摘要 · Abstract (English)

Deep Active Learning (DAL) aims to reduce labeling costs in neural-network training by prioritizing the most informative unlabeled samples for annotation. Beyond selecting which samples to label, several DAL approaches further enhance data efficiency by augmenting the training set with synthetic inputs that do not require additional manual labeling. In this work, we investigate how augmenting the training data with adversarial inputs that violate robustness constraints can improve DAL performance. We show that adversarial examples generated via formal verification contribute substantially more than those produced by standard, gradient-based attacks. We apply this extension to multiple modern DAL techniques, as well as to a new technique that we propose, and show that it yields significant improvements in model generalization across standard benchmarks.

主动学习对抗样本形式化验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。