SearcharxivSearch

arXiv subjects

Huili Wang

Publications and source records attributed to Huili Wang.

16 recordsLinked to original sources

Black-box Membership Inference Attacks on the Pre-training Data of Image-generation Models

The rapid advancement of diffusion-based image generation models has raised serious concerns regarding potential copyright and privacy infringements involving human-created data. Membership inference attacks (MIAs) have emerged as a promising tool for identifying unauthorized data usage during model training. Existing methods typically assess the ability of model to denoise perturbed suspect images as an indicator of membership status. However, the discriminative power of such features is highly dependent on the degree of model memorization and deteriorates significantly when applied to less exposed data (e.g., pre-training data). Although several methods attempt to enhance detection by leveraging internal model features, these features are generally inaccessible in mainstream closed-source image generation platforms, limiting their practicality. In this paper, we demonstrate that analyzing how a black-box diffusion model denoises a target image and corresponding perturbed textual instructions can reveal more distinctive membership cues. Based on this insight, we propose a black-box membership inference attack framework (named SD-MIA) that leverages a cross-modal data perturbation mechanism to detect pre-training data in diffusion models. We conduct extensive experiments on both a public benchmark dataset and a newly constructed dataset, each comprising pre-training membership and non-membership samples with identical distributions. Experimental results demonstrate that SD-MIA achieves superior performance compared to existing baselines, including those with the unfair advantage of accessing internal model features.

cs.CV

Black-Box Membership Inference Attack for LVLMs via Prior Knowledge-Calibrated Memory Probing

Large vision-language models (LVLMs) derive their capabilities from extensive training on vast corpora of visual and textual data. Empowered by large-scale parameters, these models often exhibit strong memorization of their training data, rendering them susceptible to membership inference attacks (MIAs). Existing MIA methods for LVLMs typically operate under white- or gray-box assumptions, by extracting likelihood-based features for the suspected data samples based on the target LVLMs. However, mainstream LVLMs generally only expose generated outputs while concealing internal computational features during inference, limiting the applicability of these methods. In this work, we propose the first black-box MIA framework for LVLMs, based on a prior knowledge-calibrated memory probing mechanism. The core idea is to assess the model memorization of the private semantic information embedded within the suspected image data, which is unlikely to be inferred from general world knowledge alone. We conducted extensive experiments across four LVLMs and three datasets. Empirical results demonstrate that our method effectively identifies training data of LVLMs in a purely black-box setting and even achieves performance comparable to gray-box and white-box methods. Further analysis reveals the robustness of our method against potential adversarial manipulations, and the effectiveness of the methodology designs. Our code and data are available at https://github.com/spmede/KCMP.

cs.CR

MrM: Black-Box Membership Inference Attacks against Multimodal RAG Systems

Multimodal retrieval-augmented generation (RAG) systems enhance large vision-language models by integrating cross-modal knowledge, enabling their increasing adoption across real-world multimodal tasks. These knowledge databases may contain sensitive information that requires privacy protection. However, multimodal RAG systems inherently grant external users indirect access to such data, making them potentially vulnerable to privacy attacks, particularly membership inference attacks (MIAs). % Existing MIA methods targeting RAG systems predominantly focus on the textual modality, while the visual modality remains relatively underexplored. To bridge this gap, we propose MrM, the first black-box MIA framework targeted at multimodal RAG systems. It utilizes a multi-object data perturbation framework constrained by counterfactual attacks, which can concurrently induce the RAG systems to retrieve the target data and generate information that leaks the membership information. Our method first employs an object-aware data perturbation method to constrain the perturbation to key semantics and ensure successful retrieval. Building on this, we design a counterfact-informed mask selection strategy to prioritize the most informative masked regions, aiming to eliminate the interference of model self-knowledge and amplify attack efficacy. Finally, we perform statistical membership inference by modeling query trials to extract features that reflect the reconstruction of masked semantics from response patterns. Experiments on two visual datasets and eight mainstream commercial visual-language models (e.g., GPT-4o, Gemini-2) demonstrate that MrM achieves consistently strong performance across both sample-level and set-level evaluations, and remains robust under adaptive defenses.

cs.CV

Enhancing Watermarking Quality for LLMs via Contextual Generation States Awareness

Recent advancements in watermarking techniques have enabled the embedding of secret messages into AI-generated text (AIGT), serving as an important mechanism for AIGT detection. Existing methods typically interfere with the generation processes of large language models (LLMs) to embed signals within the generated text. However, these methods often rely on heuristic rules, which can result in suboptimal token selection and a subsequent decline in the quality of the generated content. In this paper, we introduce a plug-and-play contextual generation states-aware watermarking framework (CAW) that dynamically adjusts the embedding process. It can be seamlessly integrated with various existing watermarking methods to enhance generation quality. First, CAW incorporates a watermarking capacity evaluator, which can assess the impact of embedding messages at different token positions by analyzing the contextual generation states. Furthermore, we introduce a multi-branch pre-generation mechanism to avoid the latency caused by the proposed watermarking strategy. Building on this, CAW can dynamically adjust the watermarking process based on the evaluated watermark capacity of each token, thereby minimizing potential degradation in content quality. Extensive experiments conducted on datasets across multiple domains have verified the effectiveness of our method, demonstrating superior performance compared to various baselines in terms of both detection rate and generation quality.

cs.CR

HeteRAG: A Heterogeneous Retrieval-augmented Generation Framework with Decoupled Knowledge Representations

Retrieval-augmented generation (RAG) methods can enhance the performance of LLMs by incorporating retrieved knowledge chunks into the generation process. In general, the retrieval and generation steps usually have different requirements for these knowledge chunks. The retrieval step benefits from comprehensive information to improve retrieval accuracy, whereas excessively long chunks may introduce redundant contextual information, thereby diminishing both the effectiveness and efficiency of the generation process. However, existing RAG methods typically employ identical representations of knowledge chunks for both retrieval and generation, resulting in suboptimal performance. In this paper, we propose a heterogeneous RAG framework (\myname) that decouples the representations of knowledge chunks for retrieval and generation, thereby enhancing the LLMs in both effectiveness and efficiency. Specifically, we utilize short chunks to represent knowledge to adapt the generation step and utilize the corresponding chunk with its contextual information from multi-granular views to enhance retrieval accuracy. We further introduce an adaptive prompt tuning method for the retrieval model to adapt the heterogeneous retrieval augmented generation process. Extensive experiments demonstrate that \myname achieves significant improvements compared to baselines.

cs.IR

Towards Next-Generation Steganalysis: LLMs Unleash the Power of Detecting Steganography

Linguistic steganography provides convenient implementation to hide messages, particularly with the emergence of AI generation technology. The potential abuse of this technology raises security concerns within societies, calling for powerful linguistic steganalysis to detect carrier containing steganographic messages. Existing methods are limited to finding distribution differences between steganographic texts and normal texts from the aspect of symbolic statistics. However, the distribution differences of both kinds of texts are hard to build precisely, which heavily hurts the detection ability of the existing methods in realistic scenarios. To seek a feasible way to construct practical steganalysis in real world, this paper propose to employ human-like text processing abilities of large language models (LLMs) to realize the difference from the aspect of human perception, addition to traditional statistic aspect. Specifically, we systematically investigate the performance of LLMs in this task by modeling it as a generative paradigm, instead of traditional classification paradigm. Extensive experiment results reveal that generative LLMs exhibit significant advantages in linguistic steganalysis and demonstrate performance trends distinct from traditional approaches. Results also reveal that LLMs outperform existing baselines by a wide margin, and the domain-agnostic ability of LLMs makes it possible to train a generic steganalysis model (Both codes and trained models are openly available in https://github.com/ba0z1/Linguistic-Steganalysis-with-LLMs).

cs.CR

Phase-field based lattice Boltzmann model for simulating thermocapillary flows

This paper proposes a simple and accurate lattice Boltzmann model for simulating thermocapillary flows, which is able to deal with thermophysical parameters contrasts. In this model, two lattice Boltzmann equations are utilized to solve the conservative Allen-Cahn equation and the incompressible Navier-Stokes equations, while another lattice Boltzmann equation is used for solving the temperature field, where the collision term is delicately designed such that the influence of the thermophysical parameters contrasts is incorporated. In contrast to previous lattice Boltzmann model for thermocapillary flows, the most distinct feature of the current model is that the forcing term used in the present thermal lattice Boltzmann equation is not needed to calculate space derivatives of the heat capacitance or the order parameter, making the scheme much simpler and also possible to retain the main merits of the lattice Boltzmann method. The developed model is firstly validated by considering the thermocapillary flows in a heated microchannel with two superimposed planar fluids. It is then used to simulate thermocapillary migration of a two-dimensional deformable droplet, and its accuracy is once again consistent with the theoretical prediction when the Marangoni number approaches zero. Finally, we numerically study the motion of two recalcitrant bubbles in a two-dimensional channel where the relationship between surface tension and temperature is assumed to be a parabolic function. It is found that owing to the competing between the inertia and thermal effects, the bubbles are able to move against the liquid's bulk motion and towards areas with low surface tension.

physics.flu-dyn

A finite-difference lattice Boltzmann model with second-order accuracy of time and space for incompressible flow

In this paper, a kind of finite-difference lattice Boltzmann method with the second-order accuracy of time and space (T2S2-FDLBM) is proposed. In this method, a new simplified two-stage fourth order time-accurate discretization approach is applied to construct time marching scheme, and the spatial gradient operator is discretized by a mixed difference scheme to maintain a second-order accuracy both in time and space. It is shown that the previous finite-difference lattice Boltzmann method (FDLBM) proposed by Guo [1] is a special case of the T2S2-FDLBM. Through the von Neumann analysis, the stability of the method is analyzed and two specific T2S2-FDLBMs are discussed. The two T2S2-FDLBMs are applied to simulate some incompressible flows with the non-uniform grids. Compared with the previous FDLBM and SLBM, the T2S2-FDLBM is more accurate and more stable. The value of the Courant-Friedrichs-Lewy condition number in our method can be up to 0.9, which also significantly improves the computational efficiency.

physics.comp-ph

Switching the Optical Chirality in Magneto-plasmonic Metasurfaces Using Applied Magnetic Fields

Chiral nanophotonic devices are promising candidates for chiral molecules sensing, polarization diverse nanophotonics and display technologies. Active chiral nanophotonic devices, where the optical chirality can be controlled by an external stimulus has triggered great research interest. However, efficient modulation of the optical chirality has been challenging. Here, we demonstrate switching of the extrinsic chirality by applied magnetic fields in a magneto-plasmonic metasurface device based on a magneto-optical oxide material, Ce1Y2Fe5O12 (Ce:YIG). Thanks to the low optical loss and strong magneto-optical effect of Ce:YIG, we experimentally demonstrated a giant and continuous far-field circular dichroism (CD) modulation by applied magnetic fields from -0.65° to +1.9° at 950 nm wavelength under glancing incident conditions. The far field CD modulation is due to both magneto-optical circular dichroism and near-field modulation of the superchiral fields by applied magnetic fields. Finally, we demonstrate magnetic field tunable chiral imaging in millimeter-scale magneto-plasmonic metasurfaces fabricated using self-assembly. Our results provide a new way for achieving planar integrated, large-scale and active chiral metasurfaces for polarization diverse nanophotonics.

physics.optics

Discrete unified gas kinetic scheme for nonlinear convection-diffusion equations

In this paper, we develop a discrete unified gas kinetic scheme (DUGKS) for general nonlinear convection-diffusion equation (NCDE), and show that the NCDE can be recovered correctly from the present model through the Chapman-Enskog analysis. We then test the present DUGKS through some classic convection-diffusion equations, and find that the numerical results are in good agreement with analytical solutions and the DUGKS model has a second-order convergence rate. Finally, as a finite-volume method, DUGKS can also adopt the non-uniform mesh. Besides, we performed some comparisons among the DUGKS, finite-volume lattice Boltzmann model (FV-LBM), single-relaxation-time lattice Boltzmann model (SLBM) and multiple-relaxation-time lattice Boltzmann model (MRT-LBM). The results show that the DUGKS model is more accurate than FV-LBM, more stable than SLBM, and almost has the same accuracy as the MRT-LBM. Besides, the using of non-uniform mesh may make DUGKS model more flexible.

physics.comp-ph

A generalized lattice Boltzmann model for fluid flow system and its application in two-phase flows

In this paper, a generalized lattice Boltzmann (LB) model with a mass source is proposed to solve both incompressible and nearly incompressible Navier-Stokes (N-S) equations. This model can be used to deal with single-phase and two-phase flows problems with a mass source term. From this generalized model, we can not only get some existing models, but also derive new models. Moreover, for the incompressible model derived, a modified pressure scheme is introduced to calculate the pressure, and then to ensure the accuracy of the model. In this work, we will focus on a two-phase flow system, and in the frame work of our generalized LB model, a new phase-field-based LB model is developed for incompressible and quasi-incompressible two-phase flows. A series of numerical simulations of some classic physical problems, including a spinodal decomposition, a static droplet, a layered Poiseuille flow, and a bubble rising flow under buoyancy, are performed to validate the developed model. Besides, some comparisons with previous quasi-incompressible and incompressible LB models are also carried out, and the results show that the present model is accurate in the study of two-phase flows. Finally, we also conduct a comparison between quasi-incompressible and incompressible LB models for two-phase flow problems, and find that in some cases, the proposed quasi-incompressible LB model performs better than incompressible LB models.

physics.comp-ph

Computational study on the half-metallicity in transition metal-oxide-incorporated 2D g-C3N4 nanosheets

In this study, based on the first-principles calculations, we systematically investigated the electronic and magnetic properties of the transition metal-oxide-incorporated 2D g-C3N4 nanosheet (labeled C3N4-TM-O, TM = Sc-Mn). The results suggest that the TM-O binds to g-C3N4 nanosheets strongly for all systems. We found that the 2D C3N4-TM-O framework is ferromagnetic for TM = Sc, Ti, V, Cr, while it is antiferromagnetic for TM = Mn. All the ferromagnetic systems exhibit the half-metallic property. Furthermore, Monte Carlo simulations based on the Heisenberg model suggest that the Curie temperatures (T_c) of the C3N4-TM-O (TM = Sc, Ti, V, Cr) framework are 169 K, 68 K, 203 K, and 190 K, respectively. Based on Bader charge analysis, we found that the origin of the half-metallicity at Fermi energy can be partially attributed to the transfer of electrons from TM atoms to the g-C3N4 nanosheet. In addition, we found that not only electrons but also holes can induce half-metallicity for 2D g-C3N4 nanosheets, which may help to understand the origin of half-metallicity for graphitic carbon nitride.

cond-mat.mtrl-sci

Dissociation of Liquid Water on Defective Rutile TiO2 (110) Surfaces Using Ab-Initio Molecular Dynamics Simulations

In order to obtain a comprehensive understanding of both thermodynamics and kinetics of water dissociation on TiO2, the reactions between liquid water and perfect and defective rutile TiO2 (110) surfaces were investigated using ab initio molecular dynamics simulations. The results showed that the free-energy barrier (~ 4.4 kcal/mol) is too high for a spontaneous dissociation of water on the perfect rutile (110) surface at a low temperature. The most stable oxygen vacancy (Vo1) on the rutile (110) surface cannot promote the dissociation of water, while other unstable oxygen vacancies can significantly enhance the water dissociation rate. This is opposite to the general understanding that Vo1 defects are active sites for water dissociation. Furthermore, we reveal that water dissociation is an exothermic reaction, which demonstrates that the dissociated state of the adsorbed water is thermodynamically favorable for both perfect and defective rutile (110) surfaces. The dissociation adsorption of water can also increase the hydrophilicity of TiO2.

physics.chem-ph

Phase-field-based lattice Boltzmann modeling of large-density-ratio two-phase flows

In this paper, we present a simple and accurate lattice Boltzmann (LB) model for immiscible two-phase flows, which is able to deal with large density contrasts. This model utilizes two LB equations, one of which is used to solve the conservative Allen-Cahn equation, and the other is adopted to solve the incompressible Navier-Stokes equations. A novel forcing distribution function is elaborately designed in the LB equation for the Navier-Stokes equations, which make it much simpler than the existing LB models. In addition, the proposed model can achieve superior numerical accuracy compared with previous Allen-Cahn type of LB models. Several benchmark two-phase problems, including static droplet, layered Poiseuille flow, and Spinodal decomposition are simulated to validate the present LB model. It is found that the present model can achieve relatively small spurious velocities in the LB community, and the obtained numerical results also show good agreement with the analytical solutions or some available results. At last, we use the present model to investigate the droplet impact on a thin liquid film with a large density ratio of 1000 and the Reynolds number ranging from 20 to 500. The fascinating phenomenon of droplet splashing is successfully reproduced by the present model and the numerically predicted spreading radius exhibits to obey the power law reported in the literature.

physics.comp-ph