The Confidence Trap: Calibration Attacks for Graph Neural Networks
Cuong Dang, Jiahao Zhang, Hieu Ta Quang, Dung Le, Lu Cheng, Suhang Wang
摘要
While confidence calibration is essential for trustworthy decision-making in safety-critical applications, the robustness of calibrated GNNs to adversarial structural perturbations remains largely unexplored. However, studying calibration attacks on graphs presents unique technical challenges: (1) the discrete nature of graph structures complicates gradient-based optimization, (2) existing underconfidence objectives fail to drive predictions toward uniform distributions, and (3) GNNs are highly sensitive to edge perturbations, often causing unintended label changes that violate attack constraints. To address these challenges, we propose a Unified Graph Calibration Attack (UGCA) framework designed for worst-case (white-box) analysis of GNN calibration robustness. UGCA introduces a KL-divergence loss to encourage uniform predictive distributions, a reranking mechanism to reduce label flipping, a hybrid loss to recover labels when violations occur, and beam search to explore a broader adversarial search space. We further provide theoretical insights linking model generalization, dataset complexity, and calibration vulnerability, showing that models with higher accuracy or trained on datasets with more classes are more susceptible under this threat model. Extensive experiments demonstrate that UGCA substantially increases Expected Calibration Error while preserving classification accuracy. ://github.com/CaptainCuong/Graph-Calibration-Attack.git Our code is publicly available at GitHub
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper16
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong 等NeurIPS 2020 · 被引用 3,935 次
- Be Confident! Towards Trustworthy Graph Neural Networks via Confidence CalibrationXiao Wang, Hongrui Liu, Chuan Shi, Cheng YangNeurIPS 2021 · 被引用 158 次
- Who Should I Trust: AI or Myself? Leveraging Human and AI Correctness Likelihood to Promote Appropriate Trust in AI-Assisted Decision-MakingShuai Ma, Ying Lei, Xinru Wang, Chengbo Zheng 等CHI 2023 · 被引用 139 次
- Graph Neural Networks for Friend Ranking in Large-scale Social PlatformsAravind Sankar, Yozen Liu, Jun Yu, Neil ShahWWW 2021 · 被引用 108 次
- Linear-Time Graph Neural Networks for Scalable RecommendationsJiahao Zhang, Rui Xue, Wenqi Fan, Xin Xu 等WWW 2024 · 被引用 63 次
相关 Paper
- Provably Robust Explainable Graph Neural Networks against Graph Perturbation AttacksJiate Li, Meng Pang, Yun Dong, Jinyuan Jia 等ICLR 2025
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun 等CCS 2021 · 被引用 30 次
- Graph Neural Network Explanations are FragileJiate Li, Meng Pang, Yun Dong, Jinyuan Jia 等ICML 2024 · 被引用 20 次
- GCL: Graph Calibration Loss for Trustworthy Graph Neural NetworkMin Wang, Hao Yang, Qing ChengACM MM 2022 · 被引用 16 次
- Balanced Confidence Calibration for Graph Neural NetworksHao Yang, Min Wang, Qi Wang, Mingrui Lao 等KDD 2024 · 被引用 3 次
