ReAL: Robustness-Enhanced Active Learning
Abstract
Active learning saves labels by selecting a small part of an unlabeled pool. For adversarial training, a useful batch should represent both the original learning signals and how they change under input attacks. We propose ReAL, which describes every candidate by its clean last-layer gradient and its attack-induced gradient change. Repeated -means++ seeding selects representatives of these signals, and cluster-size weights preserve the number of candidates each representative replaces. We connect the same coverage potential used for selection to approximation of the pool's robust objective. Under an explicit condition linking representation distance to true-label robust loss, its square root bounds the weighted objective's error and its minimizer's excess pool risk. This realized-batch bound holds for every selection; independent restarts additionally provide a high-probability comparison with the best achievable
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.