SearcharxivSearch

arXiv subjects

Anyu Wang

Publications and source records attributed to Anyu Wang.

At least 19 recordsLinked to original sources

Robust Watermarks Meet Backdoored Models: Evading Diffusion Semantic Watermarks via Stealthy Backdoor

Although semantic watermarking is considered a promising safeguard for images generated by Latent Diffusion Models (LDMs), the reliance of the watermark detection pipeline on neural networks introduces a critical yet underexplored backdoor attack surface. To systematically study this vulnerability, we propose GhostVAE to plant a stealthy backdoor into the encoder of Variational Autoencoder (VAE), enabling reliable evasion of watermark detection. GhostVAE operates in two stages: it first constructs a universal trigger via power spectrum regularization to improve the trigger robustness, and then trains a backdoored VAE encoder with a parameter-aligned objective. Through extensive evaluations across three state-of-the-art semantic watermarking schemes and three widely adopted LDMs, we show that GhostVAE preserves watermark detection performance on benign images (achieving an average true positive rate of 94.4%), while simultaneously enabling highly effective evasion under trigger activation (achieving an average attack success rate of 94.6%). Moreover, we comprehensively analyze seventeen representative defenses and demonstrate that GhostVAE remains stealthy across the input space, parameter space, and latent space. Our work fundamentally undermines the trustworthiness of semantic watermarking systems and highlights that secure deployment of semantic watermarks requires end-to-end security considerations, particularly for neural network components.

cs.CR

Fuzzy PSI from Symmetric Primitives with Exact Logarithmic Dependence on Distance Threshold

Previous FPSI works have demonstrated a linear scaling with the distance threshold $\delta$, while some recent works have achieved a poly-logarithmic dependence on $\delta$. However, these protocols either support only the $L_\infty$ distance, or they support general $L_{p\in[1,\infty]}$ distances but rely on expensive additive homomorphic encryption (AHE). Achieving exact logarithmic dependence on $\delta$ for general $L_{p\in[1,\infty]}$ distances without relying on costly AHE would constitute a theoretical breakthrough in optimal threshold scaling and a practical advance toward scalable FPSI applications. In this work, we present new FPSI protocols for $L_{p\in[1,\infty]}$ distances that are entirely built from oblivious transfer (OT) and symmetric-key primitives. We propose FPSI protocols based on both the apart and the separate assumptions, which are applicable to low- and high-dimensional settings, respectively. Our constructions achieve strictly logarithmic complexity in $\delta$, which is optimal in the sense that distinguishing all values in an interval of length $O(\delta)$ necessarily requires $\Omega(\log \delta)$ bits of information. Our core idea is to perform fuzzy matching via prefix representation and interactively determine the correct prefix using equality conditions. To this end, we propose a suite of new components that can be implemented efficiently using only OT and symmetric-key operations. We implement our FPSI protocols and compare them with the state-of-the-art FPSI protocols for $L_{p\in[1,\infty]}$ distance. Experiments show that our protocols outperform the prior state-of-the-art by up to $43.7\times$ in runtime and $31.3\times$ in communication.

cs.CR

SN 2023fyq: direct detection of a Type Ibn supernova progenitor and its multi-wavelength environmental constraints

Context. Type Ibn supernovae (SNe) are characterized by narrow helium emission lines arising from ejecta-circumstellar medium interaction, yet their progenitors remain debated, with both massive Wolf-Rayet stars and low-mass helium stars in binaries proposed. Aims. We aim to directly identify the progenitor of the Type Ibn SN 2023fyq and to characterize its environment in order to constrain the progenitor's nature and evolutionary channel. Methods. We search for the SN progenitor based on pre-explosion and late-time HST and JWST images and derive its properties by fitting the spectral energy distribution. We investigate the SN environment by probing the stars, dust, ionized gas and molecular gas with a multi-wavelength dataset including HST and JWST imaging, VLT/MUSE integral-field-unit spectroscopy and ALMA CO (2--1) radio interferometry. Results. We discover a pre-explosion source at the SN position, which is consistent with a hot ($T>$15000 K) and luminous (log($L$/$L_\odot$) $\gtrsim$ 5.5) SN progenitor and a possible host star cluster. The progenitor is confirmed to have disappeared after explosion. Analysis of the SN environment implies that the progenitor likely has an age of log($t$/yr) = 7.1--7.2. These phenomena disfavor a very massive single-star progenitor and instead support a binary scenario involving a low-mass helium star and a compact object; the observed progenitor emission likely arises from binary interaction that began at least $\sim$12 yr before the explosion. Conclusions. SN 2023fyq is the first Type Ibn SN with a directly detected progenitor and a possible host star cluster. It adds to the diversity of Type Ibn SNe in terms of their progenitor channels and mass-loss mechanisms.

astro-ph.SR

Not All Who Wander Are Lost: Early Excess Demographics in the Volume-limited ZTF DR2 SN Ia Sample

Early-time flux excesses in Type Ia supernovae (SNe~Ia) offer a unique insight into their progenitor systems and explosion mechanisms. Although individual early-excess events and larger searches have been reported, demographic studies remain limited by sample size. We present a systematic search for early-time excess emission in a volume-limited sample ($z<0.06$) of SNe~Ia based on the Zwicky Transient Facility Data Release 2 (ZTF DR2). Using ZTF $g$- and $r$-band light curves, we identify candidates showing early-excesses shortly after the explosion time, and we apply conservative coverage and quality requirements to build reliable ``excess'' and ``no-excess'' bump and no-bump catalogs. From an initial sample of 1547 SNe~Ia, our final catalogs contain 42 early-excess and 110 no-excess events. We compare the two populations using SN and host environment parameters from ZTF DR2 and quantify the differences using two-sample statistical tests. We find the strongest differences are in SN light-curve properties: early-excess events have larger SALT2 stretch $x_1$ ($7.91\sigma$) and larger $r$-band secondary-maximum flux $\mathcal{F}_{r_2}$ ($6.25\sigma$), while differences in SALT2 color $c$ are weak ($0.57\sigma$). Early-excess events also favor bluer $(g-z)_{\rm local}$ ($3.41\sigma$) and lower $\log_{10} (M_*/M_\odot)_{\rm local}$ ($2.73\sigma$). Our results connect early excesses with SNe~Ia diversity, and motivate further analyses of upcoming larger samples.

astro-ph.HE

A statistical study of the environmental age of core-collapse supernovae based on VLT/MUSE integral-field-unit spectroscopy

We aim to understand the progenitor channels of CCSNe via a statistical study of the ages of their environments. We compiled a large and minimally biased sample of 128 CCSNe discovered by untargeted wide-field transient surveys and with archival VLT/MUSE integral-field-unit spectroscopy. We measured the local H{\alpha} luminosity within a 300-pc aperture centered on the SN explosion site as an empirical proxy for the environmental age. We find that the mean local H$\alpha$ luminosities are ordered as II(P) $\approx$ IIb $\lesssim$ Ib $<$ Ic. The differences among Types~II(P), IIb and Ib are very small, if any. Type~Ic SNe are located in clearly younger environments than the other types. Our result suggests that Type Ic SNe have much younger and more massive progenitors than the other CCSN types and they likely originate from a distinct progenitor channel. The distinction between Types II(P), IIb and Ib SNe is insensitive to progenitor mass and mainly due to the different binary separation; in contrast, Type Ic SNe predominantly require much higher-mass progenitors accompanied by close companions with large mass ratios and/or much stronger stellar wind that depends sensitively on progenitor mass.

astro-ph.SR

Direct Detection of Type II-P Supernova Progenitors with the $\textit{Euclid}$ and CSST Surveys

Identifying and characterizing supernova (SN) progenitor stars remains a central yet difficult goal in SN research, limited by archival images lacking sufficient depth or spatial resolution and circumstellar dust biasing intrinsic parameter estimates. This field will be revolutionized by $\textit{Euclid}$ and the upcoming Chinese Space-station Survey Telescope (CSST), which conduct deep, wide-field, high-resolution and multi-band imaging surveys. We evaluate their detection capability by comparing model magnitudes of RSG progenitors with detection limits, finding their optical and near-infrared filters highly effective. Monte-Carlo simulations predict that completed $\textit{Euclid}$ and CSST surveys will enable $\lesssim$13 (or 24) progenitor detections per year within the mass range of 8--16 (or 8--25)\,$M_\odot$, an order of magnitude higher than the current detection rate of $\sim$1 per year (primarily based on HST). With the circumstellar dust, the emerging spectral energy distribution (SED) of the SN progenitor is mainly affected by the optical depth and is almost independent of dust temperature in their survey filters. Mock tests demonstrate that the progenitor mass and dust optical depth can be derived simultaneously by fitting the observed SED over 11 survey filters while fixing dust temperature to a typical value. $\textit{Euclid}$ and CSST will significantly enlarge the sample of direct progenitor detections with accurate mass measurements, crucial for resolving the long-standing RSG problem.

astro-ph.SR

Cryptanalysis of LDPC-Based Pseudorandom Error-Correcting Codes

Pseudorandom error-correcting codes (PRCs), a novel cryptographic primitive recently proposed at CRYPTO 2024, are primarily applied in undetectable watermarking schemes for large generative models. However, the security of PRCs has not yet been systematically analyzed. To fill this gap, we present the first cryptanalysis of PRCs. Specifically, focusing on LDPC-PRC, the only known practical instantiation of PRCs, we propose three novel attacks that challenge its undetectability and robustness. To rigorously demonstrate the practical threat, we analyze the concrete attack complexity under realistic parameters and validate the attack effectiveness on both real-world large language models and generative image models, including DeepSeek and Stable Diffusion. Our analysis shows that the claimed security guarantees of LDPC-PRC are undermined across all practically feasible regimes. For example, our attacks can detect the presence of a watermark with overwhelming probability at a cost of $2^{22}$ operations. Beyond attacks, we further propose three defenses: parameter recommendation, implementation suggestion, and a revised key generation function. However, PRC-based watermarking schemes still fail to achieve 128-bit security due to inherent constraints of large generative models, such as the maximum output length of large language models. Overall, our work clarifies the concrete security limits of PRCs in real-world watermarking applications.

cs.CR

Delving into Cryptanalytic Extraction of PReLU Neural Networks

The machine learning problem of model extraction was first introduced in 1991 and gained prominence as a cryptanalytic challenge starting with Crypto 2020. For over three decades, research in this field has primarily focused on ReLU-based neural networks. In this work, we take the first step towards the cryptanalytic extraction of PReLU neural networks, which employ more complex nonlinear activation functions than their ReLU counterparts. We propose a raw output-based parameter recovery attack for PReLU networks and extend it to more restrictive scenarios where only the top-m probability scores are accessible. Our attacks are rigorously evaluated through end-to-end experiments on diverse PReLU neural networks, including models trained on the MNIST dataset. To the best of our knowledge, this is the first practical demonstration of PReLU neural network extraction across three distinct attack scenarios.

cs.CR

LoRA-Leak: Membership Inference Attacks Against LoRA Fine-tuned Language Models

Language Models (LMs) typically adhere to a "pre-training and fine-tuning" paradigm, where a universal pre-trained model can be fine-tuned to cater to various specialized domains. Low-Rank Adaptation (LoRA) has gained the most widespread use in LM fine-tuning due to its lightweight computational cost and remarkable performance. Because the proportion of parameters tuned by LoRA is relatively small, there might be a misleading impression that the LoRA fine-tuning data is invulnerable to Membership Inference Attacks (MIAs). However, we identify that utilizing the pre-trained model can induce more information leakage, which is neglected by existing MIAs. Therefore, we introduce LoRA-Leak, a holistic evaluation framework for MIAs against the fine-tuning datasets of LMs. LoRA-Leak incorporates fifteen membership inference attacks, including ten existing MIAs, and five improved MIAs that leverage the pre-trained model as a reference. In experiments, we apply LoRA-Leak to three advanced LMs across three popular natural language processing tasks, demonstrating that LoRA-based fine-tuned LMs are still vulnerable to MIAs (e.g., 0.775 AUC under conservative fine-tuning settings). We also applied LoRA-Leak to different fine-tuning settings to understand the resulting privacy risks. We further explore four defenses and find that only dropout and excluding specific LM layers during fine-tuning effectively mitigate MIA risks while maintaining utility. We highlight that under the "pre-training and fine-tuning" paradigm, the existence of the pre-trained model makes MIA a more severe risk for LoRA-based LMs. We hope that our findings can provide guidance on data privacy protection for specialized LM providers.

cs.CR

Hard-Label Cryptanalytic Extraction of Neural Network Models

The machine learning problem of extracting neural network parameters has been proposed for nearly three decades. Functionally equivalent extraction is a crucial goal for research on this problem. When the adversary has access to the raw output of neural networks, various attacks, including those presented at CRYPTO 2020 and EUROCRYPT 2024, have successfully achieved this goal. However, this goal is not achieved when neural networks operate under a hard-label setting where the raw output is inaccessible. In this paper, we propose the first attack that theoretically achieves functionally equivalent extraction under the hard-label setting, which applies to ReLU neural networks. The effectiveness of our attack is validated through practical experiments on a wide range of ReLU neural networks, including neural networks trained on two real benchmarking datasets (MNIST, CIFAR10) widely used in computer vision. For a neural network consisting of $10^5$ parameters, our attack only requires several hours on a single core.

cs.CR

JailbreakEval: An Integrated Toolkit for Evaluating Jailbreak Attempts Against Large Language Models

Jailbreak attacks induce Large Language Models (LLMs) to generate harmful responses, posing severe misuse threats. Though research on jailbreak attacks and defenses is emerging, there is no consensus on evaluating jailbreaks, i.e., the methods to assess the harmfulness of an LLM's response are varied. Each approach has its own set of strengths and weaknesses, impacting their alignment with human values, as well as the time and financial cost. This diversity challenges researchers in choosing suitable evaluation methods and comparing different attacks and defenses. In this paper, we conduct a comprehensive analysis of jailbreak evaluation methodologies, drawing from nearly 90 jailbreak research published between May 2023 and April 2024. Our study introduces a systematic taxonomy of jailbreak evaluators, offering indepth insights into their strengths and weaknesses, along with the current status of their adaptation. To aid further research, we propose JailbreakEval, a toolkit for evaluating jailbreak attempts. JailbreakEval includes various evaluators out-of-the-box, enabling users to obtain results with a single command or customized evaluation workflows. In summary, we regard JailbreakEval to be a catalyst that simplifies the evaluation process in jailbreak research and fosters an inclusive standard for jailbreak evaluation within the community.

cs.CR

Have You Merged My Model? On The Robustness of Large Language Model IP Protection Methods Against Model Merging

Model merging is a promising lightweight model empowerment technique that does not rely on expensive computing devices (e.g., GPUs) or require the collection of specific training data. Instead, it involves editing different upstream model parameters to absorb their downstream task capabilities. However, uncertified model merging can infringe upon the Intellectual Property (IP) rights of the original upstream models. In this paper, we conduct the first study on the robustness of IP protection methods under model merging scenarios. Specifically, we investigate two state-of-the-art IP protection techniques: Quantization Watermarking and Instructional Fingerprint, along with various advanced model merging technologies, such as Task Arithmetic, TIES-MERGING, and so on. Experimental results indicate that current Large Language Model (LLM) watermarking techniques cannot survive in the merged models, whereas model fingerprinting techniques can. Our research aims to highlight that model merging should be an indispensable consideration in the robustness assessment of model IP protection techniques, thereby promoting the healthy development of the open-source LLM community. Our code is available at https://github.com/ThuCCSLab/MergeGuard.

cs.CR

FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts

Large Vision-Language Models (LVLMs) signify a groundbreaking paradigm shift within the Artificial Intelligence (AI) community, extending beyond the capabilities of Large Language Models (LLMs) by assimilating additional modalities (e.g., images). Despite this advancement, the safety of LVLMs remains adequately underexplored, with a potential overreliance on the safety assurances purported by their underlying LLMs. In this paper, we propose FigStep, a straightforward yet effective black-box jailbreak algorithm against LVLMs. Instead of feeding textual harmful instructions directly, FigStep converts the prohibited content into images through typography to bypass the safety alignment. The experimental results indicate that FigStep can achieve an average attack success rate of 82.50% on six promising open-source LVLMs. Not merely to demonstrate the efficacy of FigStep, we conduct comprehensive ablation studies and analyze the distribution of the semantic embeddings to uncover that the reason behind the success of FigStep is the deficiency of safety alignment for visual embeddings. Moreover, we compare FigStep with five text-only jailbreaks and four image-based jailbreaks to demonstrate the superiority of FigStep, i.e., negligible attack costs and better attack performance. Above all, our work reveals that current LVLMs are vulnerable to jailbreak attacks, which highlights the necessity of novel cross-modality safety alignment techniques. Our code and datasets are available at https://github.com/ThuCCSLab/FigStep .

cs.CR

Bounds and Constructions for Linear Locally Repairable Codes over Binary Fields

For binary $[n,k,d]$ linear locally repairable codes (LRCs), two new upper bounds on $k$ are derived. The first one applies to LRCs with disjoint local repair groups, for general values of $n,d$ and locality $r$, containing some previously known bounds as special cases. The second one is based on solving an optimization problem and applies to LRCs with arbitrary structure of local repair groups. Particularly, an explicit bound is derived from the second bound when $d\geq 5$. A specific comparison shows this explicit bound outperforms the Cadambe-Mazumdar bound for $5\leq d\leq 8$ and large values of $n$. Moreover, a construction of binary linear LRCs with $d\geq6$ attaining our second bound is provided.

cs.IT

Achieving Arbitrary Locality and Availability in Binary Codes

The $i$th coordinate of an $(n,k)$ code is said to have locality $r$ and availability $t$ if there exist $t$ disjoint groups, each containing at most $r$ other coordinates that can together recover the value of the $i$th coordinate. This property is particularly useful for codes for distributed storage systems because it permits local repair and parallel accesses of hot data. In this paper, for any positive integers $r$ and $t$, we construct a binary linear code of length $\binom{r+t}{t}$ which has locality $r$ and availability $t$ for all coordinates. The information rate of this code attains $\frac{r}{r+t}$, which is always higher than that of the direct product code, the only known construction that can achieve arbitrary locality and availability.

cs.IT

An Integer Programming Based Bound for Locally Repairable Codes

The locally repairable code (LRC) studied in this paper is an $[n,k]$ linear code of which the value at each coordinate can be recovered by a linear combination of at most $r$ other coordinates. The central problem in this work is to determine the largest possible minimum distance for LRCs. First, an integer programming based upper bound is derived for any LRC. Then by solving the programming problem under certain conditions, an explicit upper bound is obtained for LRCs with parameters $n_1>n_2$, where $n_1 = \left\lceil \frac{n}{r+1} \right\rceil$ and $n_2 = n_1 (r+1) - n$. Finally, an explicit construction for LRCs attaining this upper bound is presented over the finite field $\mathbb{F}_{2^m}$, where $m\geq n_1r$. Based on these results, the largest possible minimum distance for all LRCs with $r \le \sqrt{n}-1$ has been definitely determined, which is of great significance in practical use.

cs.IT

Repair Locality From a Combinatorial Perspective

Repair locality is a desirable property for erasure codes in distributed storage systems. Recently, different structures of local repair groups have been proposed in the definitions of repair locality. In this paper, the concept of regenerating set is introduced to characterize the local repair groups. A definition of locality $r^{(\delta -1)}$ (i.e., locality $r$ with repair tolerance $\delta -1$) under the most general structure of regenerating sets is given. All previously studied locality turns out to be special cases of this definition. Furthermore, three representative concepts of locality proposed before are reinvestigated under the framework of regenerating sets, and their respective upper bounds on the minimum distance are reproved in a uniform and brief form. Additionally, a more precise distance bound is derived for the square code which is a class of linear codes with locality $r^{(2)}$ and high information rate, and an explicit code construction attaining the optimal distance bound is obtained.

cs.IT

Repair Locality with Multiple Erasure Tolerance

In distributed storage systems, erasure codes with locality $r$ is preferred because a coordinate can be recovered by accessing at most $r$ other coordinates which in turn greatly reduces the disk I/O complexity for small $r$. However, the local repair may be ineffective when some of the $r$ coordinates accessed for recovery are also erased. To overcome this problem, we propose the $(r,\delta)_c$-locality providing $\delta -1$ local repair options for a coordinate. Consequently, the repair locality $r$ can tolerate $\delta-1$ erasures in total. We derive an upper bound on the minimum distance $d$ for any linear $[n,k]$ code with information $(r,\delta)_c$-locality. For general parameters, we prove existence of the codes that attain this bound when $n\geq k(r(\delta-1)+1)$, implying tightness of this bound. Although the locality $(r,\delta)$ defined by Prakash et al provides the same level of locality and local repair tolerance as our definition, codes with $(r,\delta)_c$-locality are proved to have more advantage in the minimum distance. In particular, we construct a class of codes with all symbol $(r,\delta)_c$-locality where the gain in minimum distance is $\Omega(\sqrt{r})$ and the information rate is close to 1.

cs.IT