Feature-Context Consistency: Unsupervised Adversarial Detection with Drift Stability on Attributed Graphs
Firas Bayram ⋅ Maxime Cordy
Abstract
Adversarial detection on evolving attributed graphs faces two challenges: fraud labels arrive late or not at all, and natural distributional drift erodes any trained decision boundary. Modern detectors can reach strong detection rates when labels are available and the distribution is stationary; sustaining that quality without labels and under drift is the open problem. We identify \emph{feature-context consistency} --- the alignment between a node's attributes and its aggregated neighborhood attributes --- as a single structural signal that addresses both. We formalize it as the \textbf{Context Boost} (CB) score within a Restricted Boltzmann Machine framework (CB-RBM) and prove two complementary guarantees: a strict separation between legitimate and adversarial CB distributions, with gap growing linearly in model capacity, whenever the adversary lacks legitimate neighborhood context; and a Wasserstein-Lipschitz stability bound under natural drift that prevents false alarms without retraining. We validate on XBlock Ethereum phishing ($\sim$153K nodes) and Reddit banned-user detection ($\sim$11K nodes), with two further datasets in the appendix spanning diverse domains. With zero labels, CB-RBM achieves AUROC~$\geq 0.96$ on four adversarial attacks and keeps FPR close to its calibrated $5\%$ target under drift --- outperforming supervised GNNs (hundreds of labels), unsupervised graph-anomaly baselines, and a standard RBM whose FPR collapses to $89$--$100\%$. What typically requires separate mechanisms --- label-free operation and drift stability --- here follows from a single structural regularity of the data.
Chat is not available.
Successful Page Load