SearcharxivSearch

arXiv subjects

Chijin Zhou

Publications and source records attributed to Chijin Zhou.

12 recordsLinked to original sources

Diagnose Before You Compress: Prediction-Independent Bottleneck Witness Refinement for LLM Serving Traces

Production LLM serving generates millions of diverse requests, making full-trace replay across serving configurations increasingly expensive. Existing trace reduction methods mainly preserve workload distributions or representative requests, but bottleneck-revealing workloads may be rare and non-representative. Moreover, evidence for one component cannot compensate for missing evidence in another, while using predicted bottlenecks as target truth creates circular evaluation. These limitations make it necessary to preserve evidence for every bottleneck component rather than rely on workload representativeness alone. We propose Bottleneck-Preserving Witnessing (BPW), a quality-constrained framework for compact and diagnostically reliable LLM serving replay suites. BPW first performs Workload Candidate Nomination using response-blind workload features and closed source-side measurements. This stage identifies workloads that may expose scheduler, prefill, decode, or KV-cache bottlenecks. Coverage-Priority Sequence Construction then organizes multi-component proposals as reusable hyperedges and prioritizes weak and uncovered dimensions. Finally, Bottleneck Truth Verification derives prediction-independent labels solely from direct target-system measurements. The verified results determine the earliest prefix satisfying the direct two-witness requirement for every component. Experiments on BurstGPT, ServeGen, and Mooncake show that BPW reaches the verified gate with a compact workload set and outperforms 16 policies, achieving relative improvements of 2.3% and 16.3% in Mean prefix Macro-F1 and WBRC-AUC, respectively. Stage-resolved and sensitivity analyses confirm the distinct contributions and local stability of its three stages. Our code is publicly available at https://github.com/llmllmllm/BPW

cs.AI

Statistical equivalence of reduced gravity and enhanced friction in granular packings

Using X-ray tomography, we compare granular packings prepared under buoyancy-reduced effective gravity with normal gravity packings of particles with systematically varied friction. We show that reducing gravity lowers the random loose packing limit in a manner analogous to increasing friction. Granular packings under reduced gravity and with enhanced friction exhibit identical volume distributions, compactivity, and entropy, indicating that both routes sample statistically equivalent Edwards volume ensembles of mechanically stable states. This equivalence originates from a common relaxation of the mechanical stability constraint: under both conditions, fewer particles are required to participate in the underlying load-bearing bridge structures, leading to a lower contact-number requirement and a higher density of mechanically stable states. Nevertheless, reduced gravity retains a distinct contact-scale signature through more isotropic contact orientations. These findings identify gravity as a physical control governing the statistical accessibility of mechanically stable states within the Edwards framework and provide a unified statistical description of granular packings formed through different physical routes.

cond-mat.soft

A Unified Glassy Rheology for Granular Matter

Granular flows are ubiquitous in nature and industrial applications, yet a complete continuum theory remains a long-standing challenge. The leading empirical approach, {\mu}(I) rheology, lacks microscopic foundations and becomes multivalued in dense, slowly sheared flows where nonlocal corrections are required. Exploiting state-of-the-art high-speed X-ray tomography to investigate microscopic dynamics of dense granular flows in a Couette geometry, we establish a new, universal constitutive law spanning quasi-static to inertial regimes based on structural relaxation, resolving the fundamental difficulty in the original {\mu}(I) framework. By further establishing a non-equilibrium statistical framework for granular flows, we demonstrate an intrinsic analogy between driven granular matter and hard-sphere liquids owing to their identical Carnahan-Starling equation of state, naturally explaining our rheological approach and the emergence of glassy behaviors. Our framework unifies granular rheology with the broader physics of disordered systems and provides a complete, microscopically-based theoretical framework for dense granular flow.

cond-mat.soft

Evaluating Privilege Usage of Agents with Real-World Tools

Equipping LLM agents with real-world tools can substantially improve productivity. However, granting agents autonomy over tool use also transfers the associated privileges to both the agent and the underlying LLM. Improper privilege usage may lead to serious consequences, including information leakage and infrastructure damage. While several benchmarks have been built to study agents' security, they often rely on pre-coded tools and restricted interaction patterns. Such crafted environments differ substantially from the real-world, making it hard to assess agents' security capabilities in critical privilege control and usage. Therefore, we propose GrantBox, a security evaluation sandbox for analyzing agent privilege usage. GrantBox automatically integrates real-world tools and allows LLM agents to invoke genuine privileges, enabling the evaluation of privilege usage under prompt injection attacks. Our results indicate that while LLMs exhibit basic security awareness and can block some direct attacks, they remain vulnerable to more sophisticated attacks, resulting in an average attack success rate of 84.80% in carefully crafted scenarios.

cs.CR

LSPRAG: LSP-Guided RAG for Language-Agnostic Real-Time Unit Test Generation

Automated unit test generation is essential for robust software development, yet existing approaches struggle to generalize across multiple programming languages and operate within real-time development. While Large Language Models (LLMs) offer a promising solution, their ability to generate high coverage test code depends on prompting a concise context of the focal method. Current solutions, such as Retrieval-Augmented Generation, either rely on imprecise similarity-based searches or demand the creation of costly, language-specific static analysis pipelines. To address this gap, we present LSPRAG, a framework for concise-context retrieval tailored for real-time, language-agnostic unit test generation. LSPRAG leverages off-the-shelf Language Server Protocol (LSP) back-ends to supply LLMs with precise symbol definitions and references in real time. By reusing mature LSP servers, LSPRAG provides an LLM with language-aware context retrieval, requiring minimal per-language engineering effort. We evaluated LSPRAG on open-source projects spanning Java, Go, and Python. Compared to the best performance of baselines, LSPRAG increased line coverage by up to 174.55% for Golang, 213.31% for Java, and 31.57% for Python.

cs.SE

Inducing Vulnerable Code Generation in LLM Coding Assistants

Due to insufficient domain knowledge, LLM coding assistants often reference related solutions from the Internet to address programming problems. However, incorporating external information into LLMs' code generation process introduces new security risks. In this paper, we reveal a real-world threat, named HACKODE, where attackers exploit referenced external information to embed attack sequences, causing LLMs to produce code with vulnerabilities such as buffer overflows and incomplete validations. We designed a prototype of the attack, which generates effective attack sequences for potential diverse inputs with various user queries and prompt templates. Through the evaluation on two general LLMs and two code LLMs, we demonstrate that the attack is effective, achieving an 84.29% success rate. Additionally, on a real-world application, HACKODE achieves 75.92% ASR, demonstrating its real-world impact.

cs.SE

Identifying Bridges from Asymmetric Load-Bearing Structures in Tapped Granular Packings

Using high-resolution x-ray tomography, we experimentally investigate the bridge structures in tapped granular packings composed of particles with varying friction coefficients. We find that gravity can induce subtle structural changes on the load-bearing contacts, allowing us to identify the correct load-bearing contacts based on structural information alone. Using these identified load-bearing contacts, we investigate the cooperative bridge structures which are mechanical backbones of the system. We characterize the geometric properties of these bridges and find that their cooperativity increases as the packing fraction decreases. The knowledge of bridges can enhance our understanding of the rheological properties of granular materials.

cond-mat.soft

Microscopic Structural Study on the Growth History of Granular Heaps Prepared by the Raining Method

Granular heaps are critical in both industrial applications and natural processes, exhibiting complex behaviors that have sparked significant research interest. The stress dip phenomenon observed beneath granular heaps continues to be a topic of significant debate. Current models based on force transmission often assume that the packing is near the isostatic point, overlooking the critical influence of internal structure and formation history on the mechanical properties of granular heaps. Consequently, these models fail to fully account for diverse observations. In this study, we experimentally explore the structural evolution of three dimensional (3D) granular heaps composed of monodisperse spherical particles prepared using the raining method. Our results reveal the presence of two distinct regions within the heaps, characterized by significant differences in structural properties such as packing fraction, contact number, and contact anisotropy. We attribute these structural variations to the differing formation mechanisms during heap growth. Our findings emphasize the substantial influence of the preparation protocols on the internal structure of granular heaps and provide valuable insights into stress distribution within granular materials. This research may contribute to the development of more accurate constitutive relations for granular materials by informing and refining future modeling approaches

cond-mat.soft

Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications

Presently, with the assistance of advanced LLM application development frameworks, more and more LLM-powered applications can effortlessly augment the LLMs' knowledge with external content using the retrieval augmented generation (RAG) technique. However, these frameworks' designs do not have sufficient consideration of the risk of external content, thereby allowing attackers to undermine the applications developed with these frameworks. In this paper, we reveal a new threat to LLM-powered applications, termed retrieval poisoning, where attackers can guide the application to yield malicious responses during the RAG process. Specifically, through the analysis of LLM application frameworks, attackers can craft documents visually indistinguishable from benign ones. Despite the documents providing correct information, once they are used as reference sources for RAG, the application is misled into generating incorrect responses. Our preliminary experiments indicate that attackers can mislead LLMs with an 88.33\% success rate, and achieve a 66.67\% success rate in the real-world application, demonstrating the potential impact of retrieval poisoning.

cs.CR

When Fuzzing Meets LLMs: Challenges and Opportunities

Fuzzing, a widely-used technique for bug detection, has seen advancements through Large Language Models (LLMs). Despite their potential, LLMs face specific challenges in fuzzing. In this paper, we identified five major challenges of LLM-assisted fuzzing. To support our findings, we revisited the most recent papers from top-tier conferences, confirming that these challenges are widespread. As a remedy, we propose some actionable recommendations to help improve applying LLM in Fuzzing and conduct preliminary evaluations on DBMS fuzzing. The results demonstrate that our recommendations effectively address the identified challenges.

cs.SE

Industry Practice of Coverage-Guided Enterprise-Level DBMS Fuzzing

As an infrastructure for data persistence and analysis, Database Management Systems (DBMSs) are the cornerstones of modern enterprise software. To improve their correctness, the industry has been applying blackbox fuzzing for decades. Recently, the research community achieved impressive fuzzing gains using coverage guidance. However, due to the complexity and distributed nature of enterprise-level DBMSs, seldom are these researches applied to the industry. In this paper, we apply coverage-guided fuzzing to enterprise-level DBMSs from Huawei and Bloomberg LP. In our practice of testing GaussDB and Comdb2, we found major challenges in all three testing stages. The challenges are collecting precise coverage, optimizing fuzzing performance, and analyzing root causes. In search of a general method to overcome these challenges, we propose Ratel, a coverage-guided fuzzer for enterprise-level DBMSs. With its industry-oriented design, Ratel improves the feedback precision, enhances the robustness of input generation, and performs an on-line investigation on the root cause of bugs. As a result, Ratel outperformed other fuzzers in terms of coverage and bugs. Compared to industrial black box fuzzers SQLsmith and SQLancer, as well as coverage-guided academic fuzzer Squirrel, Ratel covered 38.38%, 106.14%, 583.05% more basic blocks than the best results of other three fuzzers in GaussDB, PostgreSQL, and Comdb2, respectively. More importantly, Ratel has discovered 32, 42, and 5 unknown bugs in GaussDB, Comdb2, and PostgreSQL.

cs.SE

EnFuzz: Ensemble Fuzzing with Seed Synchronization among Diverse Fuzzers

Fuzzing is widely used for software vulnerability detection. There are various kinds of fuzzers with different fuzzing strategies, and most of them perform well on their targets. However, in industry practice and empirical study, the performance and generalization ability of those well-designed fuzzing strategies are challenged by the complexity and diversity of real-world applications. In this paper, inspired by the idea of ensemble learning, we first propose an ensemble fuzzing approach EnFuzz, that integrates multiple fuzzing strategies to obtain better performance and generalization ability than that of any constituent fuzzer alone. First, we define the diversity of the base fuzzers and choose those most recent and well-designed fuzzers as base fuzzers. Then, EnFuzz ensembles those base fuzzers with seed synchronization and result integration mechanisms. For evaluation, we implement EnFuzz , a prototype basing on four strong open-source fuzzers (AFL, AFLFast, AFLGo, FairFuzz), and test them on Google's fuzzing test suite, which consists of widely used real-world applications. The 24-hour experiment indicates that, with the same resources usage, these four base fuzzers perform variously on different applications, while EnFuzz shows better generalization ability and always outperforms others in terms of path coverage, branch coverage and crash discovery. Even compared with the best cases of AFL, AFLFast, AFLGo and FairFuzz, EnFuzz discovers 26.8%, 117%, 38.8% and 39.5% more unique crashes, executes 9.16%, 39.2%, 19.9% and 20.0% more paths and covers 5.96%, 12.0%, 21.4% and 11.1% more branches respectively.

cs.SE