SearcharxivSearch

arXiv subjects

Bijaya Dangol

Publications and source records attributed to Bijaya Dangol.

3 recordsLinked to original sources

Untrainable elements determine what physical learning remembers

Physical learning rules such as equilibrium propagation (EP), coupled learning (CL), and adjoint coupled learning (AL) train resistive networks through local measurements. The learned function is decided by where on the solution manifold training lands. Two properties could decide it, and they have not been separated: the circuit's invariance under rescaling every conductance, and the rule's conservation of the mass K = (1/2) sum_e kappa_e^2. We separate them. When every element is trainable, all three vector fields are homogeneous in the conductances, so the initialization scale is provably inert. An element the rule does not adjust breaks that homogeneity whatever its constitutive law. Across twenty topologies the learned function moves with the initialization scale by a median of twelve percent with fixed rectifiers and eight with fixed linear resistors, against 3e-8 when every element is trainable; a single fixed rectifier produces the whole effect. The conservation law is not what protects the function: AL, which we prove dissipates the mass at exactly twice its own loss, remembers its initialization as strongly as the rules that conserve it, and the memory survives in runs where K is conserved to 1e-4. Raising the fixed-element count from one to eight multiplies the conservation drift by five thousand and leaves the memory unchanged, while the all-trainable circuit under AL drifts comparably and remembers nothing. What the rule's conservation structure does control is solution quality: at matched training loss AL is worse than EP and CL in four of six small circuits, by a median of three to seven percent, though the ordering is not stable across checkpoints and does not reproduce at fifty nodes. Physical learning therefore carries two independent inductive biases, one belonging to the circuit and one to the rule, and only the first is a memory of how the device was built.

cond-mat.soft

Conservation capacity of local learning rules in physical networks

How many memories can a local learning rule protect, and what fixes the number? Physical learning rules train resistive networks through local measurements, and the standard rules conserve a mass-like function of the conductances, a law whose general form was posed as an open problem with the expectation that no useful solution theory exists. We answer it, in the direction the expectation ran against, and the answer is a capacity theory. The Tellegen identity behind the conserved mass localizes: the feedback state is pinned to zero at the inputs, so every sector of the circuit that the input electrodes separate carries its own private conserved mass, by an argument consuming only Kirchhoff's law and that boundary condition, hence valid for arbitrary nonlinear branch laws. The number of independent sector masses is a topological property of the circuit, bounded by the number of output electrodes. An untrainable element can destroy the mass of its own sector and of no other, which says where fixed nonlinear components may be placed; per-edge learning rates select which functionals are conserved and never how many; and adjoint coupled learning, which clamps its outputs before measuring, drains every output-carrying sector at a rate set by the squared output multipliers. In linear circuits we then classify the identities: exact rational computation over all 502 circuits on up to five vertices with two inputs and one or two outputs, and hundreds of larger ones, yields a closed-form count, proved on that family and conjectured in general, with the sector statement a theorem at every circuit size. The anticipated series-parallel polynomial laws appear as exactly the series-class cubic differences, and the number the opening question asks for is a budget: one designed mass per sector, the differences the topology donates, and one broadcast scalar for each protected functional beyond.

cond-mat.dis-nn

From Privacy to Workflow Integrity: Communication-Graph Metadata in Autonomous Agent Interoperability

Agent-interoperability protocols such as A2A and MCP standardize what agents say to one another but assume address-based transport. Whether over HTTP(S) or a content-protecting binding such as MLS-based SLIM, these transports protect message content yet leave the communication graph exposed: which agent contacts which, when, and how often. In agent systems this graph is more consequential than a privacy framing suggests. Endpoints are capability-labeled, workflows are structured and chained, and interactions are coupled to actions, so an observer recovers more than past relationships: it can recognize a recurring pending workflow from its opening and, at machine speed, act on it before it completes. The threat is one of workflow integrity, not privacy alone. We give a threat model for the communication graph and locate what makes its metadata distinctively consequential: not stronger fingerprinting but exposure across independent trust domains, coupled to autonomous action. We define transport- and bootstrap-layer privacy properties, give them an indistinguishability-game semantics, evaluate transports, and give an A2A case study where a metadata-protecting binding surfaces its implicit identity assumptions. On a corpus of real multi-agent A2A traffic from the official reference agents, on a live A2A binding, and with a generative model as a controlled instrument, a label-blind classifier recovers a task's class from passive metadata at 6x chance, and from only its opening; a defense-aware adversary does not overturn this, and only the full set of properties drives recovery toward chance. Acting on the leak is distinct from recoverability: under a fixed budget an adversary captures 0.63 of a clairvoyant attacker's advantage on the corpus (0.41 from a workflow's opening), governed by top-ranked precision rather than overall accuracy, so integrity and privacy come apart under defense.

cs.CR