JudgeBlind: Cross-Encoder Feedback Aliasing in GNN-to-LLM Pipelines
Abstract
GNN-to-LLM pipelines expose a cross-encoder gap: a GNN judge approves graph-dependent feedback, while an LLM student learns from raw tokens through a separate encoder. We show that graph–text edits can preserve the judge's complete non-textual decision transcript—exactly for discrete fields and within fixed componentwise tolerances for continuous fields—while harming student learning. The problem is whether unchanged approval decisions imply unchanged training effects. JudgeBlind studies this boundary through a shared attack–diagnosis–defense mechanism. FC-CEFA constructs transcript-invariant paths with graph-side curvature correction; MC-CMCT diagnoses correctability and surviving student exposure; CT-CAFT suppresses that exposure over continuation tubes under IT/PT coverage constraints. Rank and Taylor analysis characterize exposed directions and second-order closure, yielding a cubic relaxed-state judge residual. A conditional finite-round bound separates probe mismatch from student-update approximation error. On five TAG benchmarks and two victims over five seeds, FC-CEFA attains pre-cap gate-pass rates of 73.8–90.0%. Against the matched first-order control on Cora, it raises feasibility from 51.4% to 90.0% and budget-normalized invariant feedback harm from 0.24 to 0.53. MC-CMCT predicts corrector convergence with AUROC 0.87–0.92. CT-CAFT reduces adaptive harm by 52.2–60.0%; on Cora, it improves over the margin control by 16.7 percentage points while halving clean-accuracy loss from 1.4 to 0.7 points. These results distinguish approval stability from learning stability in heterogeneous feedback pipelines.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.