arXiv · 2610.10260
PairAudit: Guiding Human Review with Graph Tokens under Distribution Shift
Abstract
Intrusion detectors can confidently misclassify attacks that were not seen during training. Human review can correct these errors, but only a limited number of cases can be checked. Uncertainty-based review may overlook confident errors, while anomaly scores alone do not show whether changing the review plan will correct more errors. We introduce PairAudit to find overlooked errors and improve review under a fixed budget. Its graph tokens capture prediction patterns across connected nodes. Rather than building another predictor through feature aggregation, PairAudit uses unusual relational patterns to uncover potential errors in existing predictions. Human feedback then helps decide whether these findings justify changing review priorities. Experiments across security tasks show that PairAudit corrects more errors on average than uncertainty-based review, including more errors on unseen attacks. These gains account for all review costs and do not require retraining the detector.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Jiran Tao, Binyan Jiang. 2026-10-07. PairAudit: Guiding Human Review with Graph Tokens under Distribution Shift. https://arxiv.org/abs/2610.10260
Cite the original work for its findings. Save a collection to share your selection of sources.