Evi-VN:用虚拟节点证据注入修正 GNN 反欺诈的盲区
Evi-VN: Hard Region Guided Virtual Node Evidence Injection for GNN-Based Fraud Detection
这篇论文做反欺诈的同学可以看看:Evi-VN 不再造新检测器,而是专门修正各种 GNN 都会误判的那批难样本,还用上了文本、图像、音频证据。
论文指出不同 GNN 在反欺诈任务上会在同一批难样本上重复犯错,这些“共享难区域”隐藏了图结构和常规特征无法捕捉的欺诈证据。作者提出 Evi-VN,通过特征隔离的证据链把结构化记录、文本、图像和音频中的行为、内容与上下文信息连接起来。该方法借助虚拟类别节点,只对疑似难样本注入证据,不改动现有 GNN 的可靠预测和输入设计。实验覆盖机器人账号、虚假评论、退款凭证和电信诈骗四类任务,显示 Evi-VN 能增强通用型、欺诈专用型和未见过的 GNN。
Evi-VN: Hard Region Guided Virtual Node Evidence Injection for GNN-Based Fraud Detection
Online platforms contain growing numbers of bots, deceptive reviewers, and scam accounts that imitate legitimate users. Such camouflage blurs graph neighborhoods and behavioral attributes, making it difficult for graph neural networks (GNNs) to distinguish both well-disguised fraudsters and legitimate users. Across diverse GNNs, we observe overlapping errors on a shared hard region, suggesting the presence of latent fraud evidence that graph topologies and standard features fail to capture. Fraud-specific GNNs can mitigate particular graph pathologies, yet they still make limited use of heterogeneous evidence such as structured records, text, images, and audio; uniform multimodal fusion may also disturb nodes already handled reliably by the graph. We propose Evi-VN to learn and correct these shared blind spots rather than build another fraud detector. To our knowledge, Evi-VN is the first graph fraud detection framework to use feature isolated evidence chains to correct hard regions shared across GNNs. Its evidence chains connect behavior, content, and context across structured, textual, visual, and acoustic sources, helping expose camouflage that graph neighborhoods may miss. Crucially, Evi-VN selectively applies this evidence only to likely hard samples via virtual class nodes, preserving both the reliable predictions and the input design of existing GNNs. Shared hard regions also let Evi-VN enhance generic, fraud-specific, and unseen GNNs even with imperfect evidence models. Experiments across bot, fake-review, refund-evidence, and telecom-fraud tasks validate these advantages.