arXiv AI

LLM-Enhanced Hierarchical Heterogeneous Graph Representation Learning for Malicious Python Package Detection

arXiv:2607. 03350v1 Announce Type: cross Abstract: Malicious Python packages have become a major threat to software supply chain ecosystems due to the widespread adoption of open-source repositories such as PyPI.

arXiv AI
Jul 23

FedLSG: LLM-Enhanced Semantic Calibration for Federated Graph Backdoor Defense

arXiv:2607. 19674v1 Announce Type: cross Abstract: Federated Graph Neural Networks (FedGNNs) are highly vulnerable to backdoor poisoning, yet existing defenses typically rely on rule-based approaches that lack semantic understanding, making them vulnerable to stealthy triggers and harmful to benign structures.

By Chenyu Zhou, Yabin Peng, Wei Huang, Kunlin Li, Shuaishuai Zhang, Xinyuan Miao
arXiv Machine Learning
Sep 18

Evaluating Out-of-Distribution Robustness in Graph-Based Android Malware Classification: A New Principled Benchmark

The paper introduces a new benchmark for assessing out-of-distribution robustness in graph-based Android malware classifiers, highlighting that current models drop up to 45% accuracy on unseen malware variants. It presents two scenarios—MalNet-Tiny-Common for covariate shift and MalNet-Tiny-Distinct for domain shift—and identifies a limitation in existing benchmarks that rely solely on structure-only function call graphs. To address this, the authors propose a semantic enrichment framework that augments graph topology with function-level attributes and LLM-based code embeddings, demonstrating that this data-centric approach improves robustness under distribution shift and complements model-based methods.

By Ngoc N. Tran, Anwar Said, Waseem Abbas, Tyler Derr, Xenofon D. Koutsoukos
arXiv Machine Learning
Aug 24

TH-GNN: Heterogeneous Temporal Graph Neural Networks for LLM-Agent Shilling Attack Detection

TH-GNN is a heterogeneous temporal graph neural network designed to detect shilling attacks generated by large language model (LLM) agents. It combines a two‑layer Heterogeneous Graph Transformer with per‑type and per‑relation attention, learnable sinusoidal temporal encodings, cross‑modal attention that fuses user embeddings with frozen RoBERTa representations of reviews and item descriptions, and a GRU that models log inter‑arrival times. Across five attack families and four benchmark datasets, TH‑GNN achieves a grand‑mean F1 score of 0.870, surpassing the best text‑only baseline on Agent4SR attacks by 10.9 percentage points and 11.5 percentage points at the lowest injection rate.

By Shivam Swarup, Divya Prakash Shrivastava, Rakesh Thakur
arXiv Machine Learning
Aug 24

Trojaning the Alignment: Stealthy Backdoor Attacks against Graph Foundation Models

The paper introduces STAG, a stealthy trojan attack framework targeting Graph Foundation Models (GFMs) that operate on text‑attributed graphs (TAGs). STAG jointly generates graph triggers and soft‑prompt text cues so that both modalities converge to a malicious target class while keeping the trigger subgraph structurally similar to the original and the trigger text readable. Experiments on several TAG datasets and GFMs confirm that STAG achieves high attack success rates while remaining difficult to detect.

By Minhua Lin, Zhicheng Gao, Yilong Wang, Hanqing Lu, Xiang Zhang, Suhang Wang
arXiv Machine Learning
Sep 23

HYDRA: Proactive Android Malware Drift Adaptation via Hierarchical Graph Contrastive Learning

HYDRA is a proactive Android malware drift adaptation framework that learns drift‑invariant representations from hierarchically structured data. It combines fine‑grained Control Flow Graphs and coarse‑grained Function Call Graphs to model applications, then applies a cross‑domain contrastive learning objective to align historical and new data distributions. Experiments on large‑scale, time‑ordered malware datasets show HYDRA achieves lower false negative and false positive rates than state‑of‑the‑art baselines while needing up to 87.5% fewer labeled samples.

By Han Chen, Hanchen Wang, Hongmei Chen, Lu Qin, Wenjie Zhang, Ying Zhang