acceptodds
Under review as a conference paper at ICLR 2027

Base-Rate Dilution: A Zero-Cost Attack That ROC-AUC Cannot See

Abstract

Graph anomaly detectors are predominantly evaluated with class-conditional ranking metrics such as ROC-AUC. We identify a threat model these metrics are structurally blind to. An adversary that never touches its own malicious activity can degrade a deployed detector by generating additional genuinely benign events, lowering the base rate of the anomalous class. This base-rate dilution carries no perturbation budget, produces no detectable artifact, and preserves attack functionality exactly; it is therefore outside the scope of existing robustness defenses, which assume the attacker perturbs an input. We give an elementary but consequential characterization: precision decays as Θ(1/m) in the injected volume for any detector with nonzero benign false-positive rate, and is asymptotically invariant if and only if the detector's flagged set is null under the benign generating distribution. We show that ranking-metric invariance requires a separate property score locality under benign augmentation which message-passing architectures do not satisfy, and that the two properties have been conflated. Building on this, we propose feasibility-gated detection: a learned scorer composed with a non-learned hard mask derived from deterministic feasibility constraints, so that the benign-null support property holds architecturally for arbitrary parameter values rather than being encouraged by training. The gate bounds recall by construction; the learned component's role is to separate benign from adversarial constraint violations within the infeasible set, a distinction no fixed rule expresses. We evaluate on DARPA TC E3 provenance graphs against ungated and feature-augmented baselines, measure an empirical dilution exponent with confidence intervals, characterize the recall/robustness frontier, and test an adaptive attacker restricted to the feasible set. We also use the dilution exponent as a diagnostic for benign-noise realism in existing benchmarks, and report results on a second graph anomaly domain to assess generality. Building on Axelsson's base-rate analysis of intrusion detection, we argue that ranking metrics should be reported alongside a dilution-robustness measurement.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.