SearcharxivSearch

arXiv subjects

Chun-Ying Huang

Publications and source records attributed to Chun-Ying Huang.

At least 19 recordsLinked to original sources

Harmless Yet Harmful: Neutral Prompting Attacks for Stealthy Hallucination Steering in Agent Skills

LLM-powered coding agents increasingly participate in software development workflows by generating code, selecting dependencies, and producing package installation commands. This creates a new software supply chain risk: when an agent hallucinates a non-existent package, an attacker may register the hallucinated name and later compromise users who install it. Existing package hallucination attacks and defenses primarily focus on naturally occurring hallucinations, targeted dependency steering, or post-hoc package validation. In this paper, we introduce \emph{Neutral Prompting Attack} (NPA), a highly stealthy attack paradigm in which semantically benign instructions, such as encouraging imagination and exhaustiveness, increase package hallucination propensity without containing explicit malicious intent. Unlike targeted dependency steering, NPA does not specify an attacker-chosen package. Instead, it shifts the model's dependency generation behavior toward more speculative package names. We evaluate NPA across multiple coding-oriented LLMs and package hallucination benchmarks. Our results show that NPA increases both \emph{Hallucination ASR} and \emph{Pip Install ASR}, changes the distribution of hallucinated package names, and evades existing static-analysis, LLM-based, and agent-based Skill defenses. These findings reveal that harmless-looking prompts can covertly manipulate hallucination behavior and create downstream software supply chain risks.

cs.CR

Antiferromagnetism-altered plasmon dynamics

The interaction between plasmons and magnons is a long-sought phenomenon with implications for fundamental physics and spintronics applications. In three-dimensional systems, this coupling is suppressed by the large mismatch in energy scales, but two-dimensional (2D) plasmons with gapless dispersion can overlap with magnons over a broad spectral range. Despite numerous theoretical predictions, experimental observation of magnon-plasmon interaction has remained elusive. In this work, we study a first-of-its-kind hybrid plasmon-magnon platform based on 2D materials. By deploying scattering-type scanning near-field optical microscopy (s-SNOM) with terahertz radiation, we image propagating plasmon wavepackets at a graphene/NiPS$_3$ interface and track their dynamics across the antiferromagnetic transition of NiPS$_3$. We observe a clear renormalization of the plasmon-polariton dispersion concurrent with the onset of antiferromagnetic order. With complementary Raman scattering and nano-terahertz spectroscopy, we unveil spectral weight redistribution and dielectric screening changes, potentially associated with the multi-magnon continuum, as the underlying mechanism. These results provide solid evidence of coupling between plasmon and antiferromagnetic order, marking a cornerstone for a potential platform for hybrid magnon-plasmon interactions in 2D materials, opening avenues for coherent spin-plasmon devices and tunable terahertz spintronic components.

cond-mat.str-el

Observation of Coherent Ferron Emission and Propagation

Excitation of ordered quantum phases gives rise to collective modes and quasiparticles, as exemplified by spin waves and magnons emerging from magnetic order. Extending this paradigm to ferroelectric materials suggests the existence of polarization waves and their fundamental quanta, ferrons. Here, we report the generation and transport of polarization waves, i.e., coherent ferrons, in the van der Waals ferroelectric material NbOI2. Upon excitation by a short laser pulse, the polarization wave emits intense and narrow-band terahertz (THz) radiation at the ferroelectric transverse optical phonon frequency, modulates the ferroelectric order parameter, and propagates uniaxially along the polar axis at hypersonic velocities of ~105 m/s. These long-lived, uniaxial, and dipole-carrying polarization waves may find applications in narrow-band THz emission, ferronic information processing, and coherent electric control.

cond-mat.mtrl-sci

BADTV: Unveiling Backdoor Threats in Third-Party Task Vectors

Task arithmetic in large-scale pre-trained models enables agile adaptation to diverse downstream tasks without extensive retraining. By leveraging task vectors (TVs), users can perform modular updates through simple arithmetic operations like addition and subtraction. Yet, this flexibility presents new security challenges. In this paper, we investigate how TVs are vulnerable to backdoor attacks, revealing how malicious actors can exploit them to compromise model integrity. By creating composite backdoors that are designed asymmetrically, we introduce BadTV, a backdoor attack specifically crafted to remain effective simultaneously under task learning, forgetting, and analogy operations. Extensive experiments show that BadTV achieves near-perfect attack success rates across diverse scenarios, posing a serious threat to models relying on task arithmetic. We also evaluate current defenses, finding they fail to detect or mitigate BadTV. Our results highlight the urgent need for robust countermeasures to secure TVs in real-world deployments.

cs.LG

Giant optical spin-orbit interactions in ferroelectric van der Waals waveguides

Optical spin-orbit interactions (SOI) link photonic spin to momentum, offering a route toward on-chip polarization control and beam steering. Nevertheless, achieving sufficient optical SOI and nonlinearities on sub-micrometer scales - a prerequisite for dense photonic integration - remains an outstanding challenge. Here, we show that highly birefringent van der Waals (vdW) waveguides provide an ideal, chip-compatible platform to address this limitation. We focus on the ferroelectric semiconductor NbOI2, which exhibits record optical nonlinearities and dielectric anisotropy. Using femtosecond optical microscopy, we image light propagation and harmonic conversion beyond the total internal reflection barrier over tens of micrometers in NbOI2 slab waveguides. We report giant optical spin-splitting through the optical spin Hall effect, which facilitates spatial separation of optical spin currents on sub-micrometer scales, in quantitative agreement with a microscopic light-matter interaction model. We further leverage optical spin-momentum locking to realize polarization-controlled waveguide steering. We generalize these observations across various vdW waveguides and empirically confirm a scaling law linking dielectric anisotropy to geometric spin-splitting. Our results establish highly anisotropic vdW waveguides as an ideal platform for densely integrated opto-spintronic technologies.

cond-mat.mtrl-sci

Trust Me, Import This: Dependency Steering Attacks via Malicious Agent Skills

LLM-powered coding agents increasingly make software supply chain decisions. They generate imports, recommend packages, and write installation commands. Prior work showed that these systems can hallucinate non-existent package names, which attackers may register as malicious packages. In this paper, we show that this risk is not only a passive model failure. It can be actively induced through the persistent Skill artifact. We introduce Dependency Steering, an attack paradigm in which a malicious Skill biases a coding agent toward an attacker-controlled package during benign coding tasks. The attack does not require modifying model weights, training data, or user prompts. To construct realistic attacks, we design a Skill-level optimization method that searches for localized semantic edits that preserve the apparent purpose of the original Skill while increasing targeted package generation. Across multiple coding-oriented LLMs and programming benchmarks, Dependency Steering achieves high targeted hallucination rates, transfers across models and task domains, and remains difficult for evaluated Skill scanners and LLM-based auditors to detect. Our results show that persistent agent instructions form an underexplored software supply chain attack surface.

cs.CR

Tunable Narrowband Terahertz Radiation from van der Waals Ferroelectrics

The terahertz (THz) spectral range is central to high-speed communication, precision metrology, sensing technologies, and a range of fundamental scientific investigations. Achieving these capabilities in practical systems increasingly demands chip-scale integration of THz photonic components that are typically bulky. In this context, van der Waals (vdW) materials provide a unique platform for integrated nonlinear photonics in the visible and near-infrared regimes, and extending this framework into the THz domain would constitute a significant advance. Here, we report tunable, intense, and narrowband THz radiation from ferroelectric niobium oxyhalides. Through halogen substitution and alloying, we achieve continuous and precise control over the emission frequency from 3.1 to 5.8 THz. We show that the narrowband THz radiation is driven by phonons associated with the ferroelectric polarization. We further demonstrate dynamic and nonvolatile control of the polarity of the coherent THz wave with external electric field. This work demonstrates efficient narrowband THz emission from vdW ferroeletrics and provides microscopic insight into its origin, paving the way for on-chip THz technology for a broad range of applications.

physics.optics

Charge Density Wave and Ferromagnetism in Intercalated CrSBr

In materials with one-dimensional electronic bands, electron-electron interactions can produce intriguing quantum phenomena, including spin-charge separation and charge density waves (CDW). Most of these systems, however, are non-magnetic, motivating a search for anisotropic materials where the coupling of charge and spin may affect emergent quantum states. Here, chemical intercalation of the van der Waals magnetic semiconductor CrSBr yields $Li_{0.17(2)} (tetrahydrofuran)_{0.26(3)} CrSBr$, which possess an electronically driven quasi-1D CDW with an onset temperature above room temperature. Concurrently, electron doping increases the magnetic ordering temperature from 132 K to 200 K and switches its interlayer magnetic coupling from antiferromagnetic to ferromagnetic. The spin-polarized nature of the anisotropic bands that give rise to this CDW enforces an intrinsic coupling of charge and spin. The coexistence and interplay of ferromagnetism and charge modulation in this exfoliatable material provides a promising platform for studying tunable quantum phenomena across a range of temperatures and thicknesses.

cond-mat.mtrl-sci

VP-NTK: Exploring the Benefits of Visual Prompting in Differentially Private Data Synthesis

Differentially private (DP) synthetic data has become the de facto standard for releasing sensitive data. However, many DP generative models suffer from the low utility of synthetic data, especially for high-resolution images. On the other hand, one of the emerging techniques in parameter efficient fine-tuning (PEFT) is visual prompting (VP), which allows well-trained existing models to be reused for the purpose of adapting to subsequent downstream tasks. In this work, we explore such a phenomenon in constructing captivating generative models with DP constraints. We show that VP in conjunction with DP-NTK, a DP generator that exploits the power of the neural tangent kernel (NTK) in training DP generative models, achieves a significant performance boost, particularly for high-resolution image datasets, with accuracy improving from 0.644$\pm$0.044 to 0.769. Lastly, we perform ablation studies on the effect of different parameters that influence the overall performance of VP-NTK. Our work demonstrates a promising step forward in improving the utility of DP synthetic data, particularly for high-resolution images.

cs.CV

Data Poisoning Attacks to Locally Differentially Private Range Query Protocols

Local Differential Privacy (LDP) has been widely adopted to protect user privacy in decentralized data collection. However, recent studies have revealed that LDP protocols are vulnerable to data poisoning attacks, where malicious users manipulate their reported data to distort aggregated results. In this work, we present the first study on data poisoning attacks targeting LDP range query protocols, focusing on both tree-based and grid-based approaches. We identify three key challenges in executing such attacks, including crafting consistent and effective fake data, maintaining data consistency across levels or grids, and preventing server detection. To address the first two challenges, we propose novel attack methods that are provably optimal, including a tree-based attack and a grid-based attack, designed to manipulate range query results with high effectiveness. \textbf{Our key finding is that the common post-processing procedure, Norm-Sub, in LDP range query protocols can help the attacker massively amplify their attack effectiveness.} In addition, we study a potential countermeasure, but also propose an adaptive attack capable of evading this defense to address the third challenge. We evaluate our methods through theoretical analysis and extensive experiments on synthetic and real-world datasets. Our results show that the proposed attacks can significantly amplify estimations for arbitrary range queries by manipulating a small fraction of users, providing 5-10x more influence than a normal user to the estimation.

cs.CR

Poisoning Attacks to Local Differential Privacy Protocols for Trajectory Data

Trajectory data, which tracks movements through geographic locations, is crucial for improving real-world applications. However, collecting such sensitive data raises considerable privacy concerns. Local differential privacy (LDP) offers a solution by allowing individuals to locally perturb their trajectory data before sharing it. Despite its privacy benefits, LDP protocols are vulnerable to data poisoning attacks, where attackers inject fake data to manipulate aggregated results. In this work, we make the first attempt to analyze vulnerabilities in several representative LDP trajectory protocols. We propose \textsc{TraP}, a heuristic algorithm for data \underline{P}oisoning attacks using a prefix-suffix method to optimize fake \underline{Tra}jectory selection, significantly reducing computational complexity. Our experimental results demonstrate that our attack can substantially increase target pattern occurrences in the perturbed trajectory dataset with few fake users. This study underscores the urgent need for robust defenses and better protocol designs to safeguard LDP trajectory data against malicious manipulation.

cs.CR

Layer-Aware Task Arithmetic: Disentangling Task-Specific and Instruction-Following Knowledge

Large language models (LLMs) demonstrate strong task-specific capabilities through fine-tuning, but merging multiple fine-tuned models often leads to degraded performance due to overlapping instruction-following components. Task Arithmetic (TA), which combines task vectors derived from fine-tuning, enables multi-task learning and task forgetting but struggles to isolate task-specific knowledge from general instruction-following behavior. To address this, we propose Layer-Aware Task Arithmetic (LATA), a novel approach that assigns layer-specific weights to task vectors based on their alignment with instruction-following or task-specific components. By amplifying task-relevant layers and attenuating instruction-following layers, LATA improves task learning and forgetting performance while preserving overall model utility. Experiments on multiple benchmarks, including WikiText-2, GSM8K, and HumanEval, demonstrate that LATA outperforms existing methods in both multi-task learning and selective task forgetting, achieving higher task accuracy and alignment with minimal degradation in output quality. Our findings highlight the importance of layer-wise analysis in disentangling task-specific and general-purpose knowledge, offering a robust framework for efficient model merging and editing.

cs.CL

Safe LoRA: the Silver Lining of Reducing Safety Risks when Fine-tuning Large Language Models

While large language models (LLMs) such as Llama-2 or GPT-4 have shown impressive zero-shot performance, fine-tuning is still necessary to enhance their performance for customized datasets, domain-specific tasks, or other private needs. However, fine-tuning all parameters of LLMs requires significant hardware resources, which can be impractical for typical users. Therefore, parameter-efficient fine-tuning such as LoRA have emerged, allowing users to fine-tune LLMs without the need for considerable computing resources, with little performance degradation compared to fine-tuning all parameters. Unfortunately, recent studies indicate that fine-tuning can increase the risk to the safety of LLMs, even when data does not contain malicious content. To address this challenge, we propose Safe LoRA, a simple one-liner patch to the original LoRA implementation by introducing the projection of LoRA weights from selected layers to the safety-aligned subspace, effectively reducing the safety risks in LLM fine-tuning while maintaining utility. It is worth noting that Safe LoRA is a training-free and data-free approach, as it only requires the knowledge of the weights from the base and aligned LLMs. Our extensive experiments demonstrate that when fine-tuning on purely malicious data, Safe LoRA retains similar safety performance as the original aligned model. Moreover, when the fine-tuning dataset contains a mixture of both benign and malicious data, Safe LoRA mitigates the negative effect made by malicious data while preserving performance on downstream tasks. Our codes are available at \url{https://github.com/IBM/SafeLoRA}.

cs.LG

A 2D van der Waals Material for Terahertz Emission with Giant Optical Rectification

Exfoliation and stacking of two-dimensional (2D) van der Waals (vdW) crystals have created unprecedented opportunities in the discovery of quantum phases. A major obstacle to the advancement of this field is the limited spectroscopic access due to a mismatch in sample sizes (1 - 10 micrometer) and wavelengths (0.1 - 1 millimeter) of electromagnetic radiation relevant to their low-energy excitations. Here, we introduce a new member of the 2D vdW material family: a terahertz (THz) emitter. We show intense and broadband THz generation from the vdW ferroelectric semiconductor NbOI2 with optical rectification efficiency over one-order-of-magnitude higher than that of the current standard THz emitter, ZnTe. The NbOI2 THz emitter can be easily integrated into vdW heterostructures for on-chip near-field THz spectroscopy of a target vdW material/device. Our approach provides a general spectroscopic tool for the rapidly expanding field of 2D vdW materials and quantum matter.

cond-mat.mtrl-sci

CmdCaliper: A Semantic-Aware Command-Line Embedding Model and Dataset for Security Research

This research addresses command-line embedding in cybersecurity, a field obstructed by the lack of comprehensive datasets due to privacy and regulation concerns. We propose the first dataset of similar command lines, named CyPHER, for training and unbiased evaluation. The training set is generated using a set of large language models (LLMs) comprising 28,520 similar command-line pairs. Our testing dataset consists of 2,807 similar command-line pairs sourced from authentic command-line data. In addition, we propose a command-line embedding model named CmdCaliper, enabling the computation of semantic similarity with command lines. Performance evaluations demonstrate that the smallest version of CmdCaliper (30 million parameters) suppresses state-of-the-art (SOTA) sentence embedding models with ten times more parameters across various tasks (e.g., malicious command-line detection and similar command-line retrieval). Our study explores the feasibility of data generation using LLMs in the cybersecurity domain. Furthermore, we release our proposed command-line dataset, embedding models' weights and all program codes to the public. This advancement paves the way for more effective command-line embedding for future researchers.

cs.CL

Coupling of Electronic Transitions to Ferroelectric Order in a 2D Semiconductor

A ferroelectric material often exhibits a soft transvers optical (TO) phonon mode which governs it phase transition. Charge coupling to this ferroelectric soft mode may further mediate emergent physical properties, including superconductivity and defect tolerance. However, direct experimental evidence for such coupling is scarce. Here we show that a photo-launched coherent phonon couples strongly to electronic transitions across the bandgap in the van der Waals (vdW) two-dimensional (2D) ferroelectric semiconductor NbOI2. Using terahertz time-domain spectroscopy and first-principles calculations, we identify this mode as the TO phonon responsible for ferroelectric order. This exclusive coupling occurs only with above-gap electronic transition and is absent in the valence band as revealed by resonant inelastic X-ray scattering. Our findings suggest a new role of the soft TO phonon mode in electronic and optical properties of ferroelectric semiconductors.

cond-mat.mtrl-sci

Ring-A-Bell! How Reliable are Concept Removal Methods for Diffusion Models?

Diffusion models for text-to-image (T2I) synthesis, such as Stable Diffusion (SD), have recently demonstrated exceptional capabilities for generating high-quality content. However, this progress has raised several concerns of potential misuse, particularly in creating copyrighted, prohibited, and restricted content, or NSFW (not safe for work) images. While efforts have been made to mitigate such problems, either by implementing a safety filter at the evaluation stage or by fine-tuning models to eliminate undesirable concepts or styles, the effectiveness of these safety measures in dealing with a wide range of prompts remains largely unexplored. In this work, we aim to investigate these safety mechanisms by proposing one novel concept retrieval algorithm for evaluation. We introduce Ring-A-Bell, a model-agnostic red-teaming tool for T2I diffusion models, where the whole evaluation can be prepared in advance without prior knowledge of the target model. Specifically, Ring-A-Bell first performs concept extraction to obtain holistic representations for sensitive and inappropriate concepts. Subsequently, by leveraging the extracted concept, Ring-A-Bell automatically identifies problematic prompts for diffusion models with the corresponding generation of inappropriate content, allowing the user to assess the reliability of deployed safety mechanisms. Finally, we empirically validate our method by testing online services such as Midjourney and various methods of concept removal. Our results show that Ring-A-Bell, by manipulating safe prompting benchmarks, can transform prompts that were originally regarded as safe to evade existing safety mechanisms, thus revealing the defects of the so-called safety mechanisms which could practically lead to the generation of harmful contents. Our codes are available at https://github.com/chiayi-hsu/Ring-A-Bell.

cs.LG

Visualizing moiré ferroelectricity via plasmons and nano-photocurrent in graphene/twisted-WSe2 structures

Ferroelectricity, a spontaneous and reversible electric polarization, is found in certain classes of van der Waals (vdW) material heterostructures. The discovery of ferroelectricity in twisted vdW layers provides new opportunities to engineer spatially dependent electric and optical properties associated with the configuration of moiré superlattice domains and the network of domain walls. Here, we employ near-field infrared nano-imaging and nano-photocurrent measurements to study ferroelectricity in minimally twisted WSe2. The ferroelectric domains are visualized through the imaging of the plasmonic response in a graphene monolayer adjacent to the moiré WSe2 bilayers. Specifically, we find that the ferroelectric polarization in moiré domains is imprinted on the plasmonic response of the graphene. Complementary nano-photocurrent measurements demonstrate that the optoelectronic properties of graphene are also modulated by the proximal ferroelectric domains. Our approach represents an alternative strategy for studying moiré ferroelectricity at native length scales and opens promising prospects for (opto)electronic devices.

cond-mat.mes-hall