arXiv:2605.07551cs.LG2026-05

提出新采样方法DR-IS,对抗标签污染下仍能有效筛选干净样本。

Disagreement-Regularized Importance Sampling for Adversarial Label Corruption

  • 基于代理模型损失排序分歧进行子采样,避免误选恶意高范数样本。
  • 实验证明在高范数攻击下优于EL2N等传统方法,保持鲁棒性。
  • 提供有限样本浓度界和噪声泄露上限,适合数据清洗与鲁棒训练场景。

标准重要性采样在标签污染下会失效,因为被优先选择的高范数样本常为对抗异常值。本文通过ε-污染模型形式化这一偏差,并提出争议正则化重要性采样(DR-IS),一种基于独立代理集成损失排名分歧的子采样方法。理论证明:在概率1−δ下,批量污染样本的经验排名分歧上界与边界干净样本的下界均以速率O(√(log(N/δ)/K))收敛;当两组间结构期望差距Δ'>0且干净集不小于选取子集时,可保证严格分离并控制所选子集的污染率。实验表明,DR-IS在针对高范数的定向攻击下仍稳健,优于基于幅度的方法(如误差L2范数,EL2N)。DR-IS补充了训练动态方法(如边际下面积排序,AUM),在损失对齐场景中提升鲁棒性,同时提供明确的有限样本浓度保证与噪声泄漏上界。

原文摘要 · Abstract (English)

Standard Importance Sampling (IS) collapses under label corruption because high-norm examples, prioritized for variance reduction, are often adversarial outliers. We formalize this misalignment using an $\varepsilon$-contamination model and propose Disagreement-Regularized Importance Sampling (DR-IS), a sub-sampling method based on loss rank-disagreement across independent proxy ensemble. We prove finite-sample concentration bounds showing that the empirical rank disagreement of bulk corrupted examples is bounded above, and that of boundary-clean examples bounded below, both at rate $O(\sqrt{\log(N/δ)/K})$ with probability $1-δ$; when the structural expectation gap $Δ'$ between the two groups is positive and the boundary-clean set is at least as large as the selected subset, these bounds certify strict separation and control the contamination rate of the selected subset. Empirically, DR-IS remains robust under targeted high-norm attacks that break magnitude-based methods such as the Error $L_2$-norm (EL2N) on benchmark datasets. DR-IS complements training-dynamics approaches like Area Under the Margin ranking (AUM), offering improved robustness in the loss-aligned regime alongside explicit finite-sample concentration certificates and a contamination bound limiting noise leakage from the statistical tail of corrupted points.

数据清洗对抗攻击重要性采样鲁棒学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。