AURORA: Attack-Trajectory Uncertainty-Aware Risk Allocation for Long-Tailed Adversarial Training
Abstract
Existing long-tailed adversarial training methods commonly allocate robust supervision using class-frequency priors or empirical endpoint failures. However, class frequency is not a direct measure of adversarial vulnerability, while endpoint failure rates are unreliable under limited class support and discard how failures develop along the attack trajectory. We propose AURORA, an uncertainty-aware framework for estimating class-wise adversarial risk from endpoint outcomes and intermediate attack predictions. Specifically, uncertainty-Aware Risk Anchoring (URA) applies a Wilson-score upper estimate to endpoint failures, allowing class support to affect allocation through estimation uncertainty rather than a predefined frequency-to-weight mapping. First-Passage Trajectory Refinement (FTR) then measures the normalized first-failure iteration among initially correct samples and uses this path information to refine the endpoint anchor. A bounded correction converts the resulting endpoint-to-path profile into class weights for the native robust objective of existing AT methods. Experiments across multiple long-tailed benchmarks and architectures show that AURORA consistently improves tail robustness while retaining competitive overall performance.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.