arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

恶意软件图神经网络在类型偏移下的结构感知校准压力测试

Stress-Testing Structure-Aware Calibration of Malware Graph Neural Networks under Type Shift

Junru Zhu, Yixin Yang, Xiaoqing Ding, Ruoyu Qi

arXiv 2609.28517首次发表:更新:

发表机构

University of Chicago(芝加哥大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究在恶意软件类型偏移下测试结构感知校准器,发现社区协变量增加NLL,提出社区支撑守卫回退机制,有效降低错误并恢复损失。

AI 中文摘要

事后恶意软件校准器可以基于图结构来调节置信度,但在恶意软件类型偏移下,其结构输入可能使验证数据所代表的支撑集发生变化。我们在MalNet-Tiny上研究了这一风险,通过保留四种恶意软件类型中的每一种(跨三个随机种子),冻结图同构网络,并仅基于已知类型的数据拟合事后映射。向通用拓扑校准器添加八个社区协变量使平均负对数似然(NLL)增加了0.1369;类型聚类自助法给出的95%置信区间为[-0.0125, 0.2864]。一个容量匹配的对照组在20次确定性重复中添加了八个与标签无关的干扰变量,仅使NLL增加了0.0415,表明输入数量解释了部分但并非全部的性能退化。随后,我们利用校准数据定义了一个社区支撑守卫:对于校准标准化社区位移超出第95百分位的预测,回退到通用校准器。该守卫将组合NLL降低了0.1133,并将每400样本单元的高置信度错误从43.25降至33.25,同时其NLL仍接近通用基线。这些结果表明,结构协变量如何产生对支撑集敏感的置信度错误,以及无标签回退机制如何恢复由此产生的大部分损失。

英文摘要

Post-hoc malware calibrators can condition confidence on graph structure, but their structural inputs may leave the support represented by validation data under malware-type shift. We study this risk on MalNet-Tiny by holding out each of four malware types across three seeds, freezing a graph isomorphism network, and fitting post-hoc mappings only on known-type data. Adding eight community covariates to a generic-topology calibrator increases mean negative log likelihood (NLL) by 0.1369; a type-cluster bootstrap gives a 95% interval of [-0.0125, 0.2864]. A capacity-matched control adds eight label-independent nuisance variables over 20 deterministic repeats and increases NLL by only 0.0415, indicating that input count explains part but not all of the degradation. We then use calibration data to define a community-support guard: predictions outside the 95th percentile of calibration-standardized community displacement revert to the generic calibrator. The guard reduces combined NLL by 0.1133 and high-confidence errors from 43.25 to 33.25 per 400-sample cell, while its NLL remains close to the generic baseline. These results show how structural covariates can create support-sensitive confidence errors and how a label-free fallback can recover most of the resulting loss.

Comments6 pages, 1 figure, 4 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑