The Confidence Trap: Calibration Attacks for Graph Neural Networks
Cuong Dang, Jiahao Zhang, Hieu Ta Quang, Dung Le, Lu Cheng, Suhang Wang
Abstract
While confidence calibration is essential for trustworthy decision-making in safety-critical applications, the robustness of calibrated GNNs to adversarial structural perturbations remains largely unexplored. However, studying calibration attacks on graphs presents unique technical challenges: (1) the discrete nature of graph structures complicates gradient-based optimization, (2) existing underconfidence objectives fail to drive predictions toward uniform distributions, and (3) GNNs are highly sensitive to edge perturbations, often causing unintended label changes that violate attack constraints. To address these challenges, we propose a Unified Graph Calibration Attack (UGCA) framework designed for worst-case (white-box) analysis of GNN calibration robustness. UGCA introduces a KL-divergence loss to encourage uniform predictive distributions, a reranking mechanism to reduce label flipping, a hybrid loss to recover labels when violations occur, and beam search to explore a broader adversarial search space. We further provide theoretical insights linking model generalization, dataset complexity, and calibration vulnerability, showing that models with higher accuracy or trained on datasets with more classes are more susceptible under this threat model. Extensive experiments demonstrate that UGCA substantially increases Expected Calibration Error while preserving classification accuracy. ://github.com/CaptainCuong/Graph-Calibration-Attack.git Our code is publicly available at GitHub
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 145a7176-ce86-4299-849d-2808ea3a3463Builds on16
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- Be Confident! Towards Trustworthy Graph Neural Networks via Confidence CalibrationXiao Wang, Hongrui Liu, Chuan Shi, Cheng YangNeurIPS 2021 · 158 citations
- Who Should I Trust: AI or Myself? Leveraging Human and AI Correctness Likelihood to Promote Appropriate Trust in AI-Assisted Decision-MakingShuai Ma, Ying Lei, Xinru Wang, Chengbo Zheng et al.CHI 2023 · 139 citations
- Graph Neural Networks for Friend Ranking in Large-scale Social PlatformsAravind Sankar, Yozen Liu, Jun Yu, Neil ShahWWW 2021 · 108 citations
- Linear-Time Graph Neural Networks for Scalable RecommendationsJiahao Zhang, Rui Xue, Wenqi Fan, Xin Xu et al.WWW 2024 · 63 citations
Related papers
- Provably Robust Explainable Graph Neural Networks against Graph Perturbation AttacksJiate Li, Meng Pang, Yun Dong, Jinyuan Jia et al.ICLR 2025
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun et al.CCS 2021 · 30 citations
- Graph Neural Network Explanations are FragileJiate Li, Meng Pang, Yun Dong, Jinyuan Jia et al.ICML 2024 · 20 citations
- GCL: Graph Calibration Loss for Trustworthy Graph Neural NetworkMin Wang, Hao Yang, Qing ChengACM MM 2022 · 16 citations
- Balanced Confidence Calibration for Graph Neural NetworksHao Yang, Min Wang, Qi Wang, Mingrui Lao et al.KDD 2024 · 3 citations
