arXiv · 2609.28517
Stress-Testing Structure-Aware Calibration of Malware Graph Neural Networks under Type Shift
Abstract
Post-hoc malware calibrators can condition confidence on graph structure, but their structural inputs may leave the support represented by validation data under malware-type shift. We study this risk on MalNet-Tiny by holding out each of four malware types across three seeds, freezing a graph isomorphism network, and fitting post-hoc mappings only on known-type data. Adding eight community covariates to a generic-topology calibrator increases mean negative log likelihood (NLL) by 0.1369; a type-cluster bootstrap gives a 95% interval of [-0.0125, 0.2864]. A capacity-matched control adds eight label-independent nuisance variables over 20 deterministic repeats and increases NLL by only 0.0415, indicating that input count explains part but not all of the degradation. We then use calibration data to define a community-support guard: predictions outside the 95th percentile of calibration-standardized community displacement revert to the generic calibrator. The guard reduces combined NLL by 0.1133 and high-confidence errors from 43.25 to 33.25 per 400-sample cell, while its NLL remains close to the generic baseline. These results show how structural covariates can create support-sensitive confidence errors and how a label-free fallback can recover most of the resulting loss.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Junru Zhu, Yixin Yang, Xiaoqing Ding, Ruoyu Qi. 2026-09-22. Stress-Testing Structure-Aware Calibration of Malware Graph Neural Networks under Type Shift. https://arxiv.org/abs/2609.28517
Cite the original work for its findings. Save a collection to share your selection of sources.