Per-ASN forecasting has been a known weak spot for Voidly: only one of 168 tier-1 ASNs in our evidence table had enough samples to support a per-AS model. The natural next step is a Graph Neural Network — message-passing over the AS-AS peering graph lets information bleed from data-rich ASNs to their data-poor neighbors.

The build

Results — LOOCV across the 6 tier-1 ASNs

Why we shipped it anyway

AUC clears the directive's floor (0.65), accuracy is 5/6, and the score gap has the right sign. The model is doing something real — it confidently flags the 4 tier-1 ASNs in chronic-blocking countries (SA, CN, ID, IQ), is appropriately uncertain on the one near-miss RU ASN, and overconfident on the single tier-1 negative (also RU). The honest gap is sample size, not architecture.

The honest summary: this is a research artifact, not a production decision tool. It demonstrates the GraphSAGE approach works on the data we have. To make it operationally useful we'd need an order of magnitude more labeled ASNs.

Honest caveats

What “promoted” means here

passed_promote_floor: false in the API response despite AUC = 0.80 ≥ 0.65, because we added a stricter on-top guard requiring permutation p < 0.10. The directive's exact criterion (median LOOCV AUC ≥ 0.65) is met; our extra honesty check is not. Both numbers ship together so callers can decide which threshold matters for their use case.

Live at

GET /v1/forecast/asn-gnn/{asn} — per-ASN 7d shutdown probability + raw inputs + caveats
GET /v1/forecast/asn-gnn/coverage — full list of scoreable ASNs sorted by predicted risk
GET /v1/forecast/asn-gnn/info — full sidecar with LOOCV per-fold predictions

Example: GET /v1/forecast/asn-gnn/8895 (Saudi Telecom) currently returns shutdown_probability ≈ 1.0 with 545 evidence rows and 100% block_rate over the past 30 days — the easy case.