SearcharxivSearch

arXiv subjects

Jonathan Steinberg

Publications and source records attributed to Jonathan Steinberg.

13 recordsLinked to original sources

MOSAIC-Bench: Measuring Compositional Vulnerability Induction in Coding Agents

Coding agents often pass per-prompt safety review yet ship exploitable code when their tasks are decomposed into routine engineering tickets. The challenge is structural: existing safety alignment evaluates overt requests in isolation, leaving models blind to malicious end-states that emerge from sequenced compliance with innocuous-looking requests. We introduce MOSAIC-Bench (Malicious Objectives Sequenced As Innocuous Compliance), a benchmark of 199 three-stage attack chains paired with deterministic exploit oracles on deployed software substrates (10 web-application substrates, 31 CWE classes, 5 programming languages) that treats both exploit ground truth and downstream reviewer protocol as first-class evaluation axes. On this benchmark, nine production coding agents from Anthropic, OpenAI, Google, Moonshot, Zhipu, and Minimax compose innocuous tickets at 53-86% end-to-end ASR with only two refusals across all staged runs. In a matched direct-prompt experiment over four frontier Claude/Codex agents, vulnerable-output rates fall to 0-20.4%: Claude primarily refuses, while Codex primarily hardens rather than emitting the vulnerable implementation - ticket staging silences both defense modes simultaneously. Downstream, code reviewer agents approve 25.8% of these confirmed-vulnerable cumulative diffs as routine PRs, and a full-context implementation protocol closes only 50% of the staged/direct gap, ruling out context fragmentation as the sole explanation. As a deployable but non-adaptive mitigation, reframing the reviewer as an adversarial pentester reduces evasion across the evaluated reviewer subset; pentester framed evasion ranges from 3.0% to 17.6%, and an open-weight Gemma-4-E4B-it reviewer under this framing detects 88.4% of attacks on the dataset with a 4.6% false-positive rate measured on 608 real-world GitHub PRs.

cs.CR

Semantic Denial of Service in LLM-controlled robots

Safety-oriented instruction-following is supposed to keep LLM-controlled robots safe. We show it also creates an availability attack surface. By injecting short safety-plausible phrases (1-5 tokens) into a robots audio channel, an adversary can trigger the models safety reasoning to halt or disrupt execution without jailbreaking the model or overriding its policy. In the embodied setting, this is a semantic denial-of-service attack: the agent stops because the injected signal looks like a legitimate alert. Across four vision-language models, seven prompt-level defenses, three deployment modes, and single- and multi-injection settings, we find that prompt-only defenses trade off attack suppression against genuine hazard response. The strongest defenses reduce hard-stop attack success on some models, but defenses change the form of disruption, not its fact: suppressed hard stops re-emerge as acknowledge loops and false alerts, which we measure with Disruption Success Rate (DSR). We further find that injection variety is consistently more effective than repeating the same phrase, suggesting that models treat diverse safety cues as corroborating evidence. The practical implication is architectural rather than prompt-level: systems that route unauthenticated audio text directly into the LLM create an avoidable security dependency between safety monitoring and action selection.

cs.CR

Where Vision Becomes Text: Locating the OCR Routing Bottleneck in Vision-Language Models

Vision-language models (VLMs) can read text from images, but where does this optical character recognition (OCR) information enter the language processing stream? We investigate the OCR routing mechanism across three architecture families (Qwen3-VL, Phi-4, InternVL3.5) using causal interventions. By computing activation differences between original images and text-inpainted versions, we identify architecture-specific OCR bottlenecks whose dominant location depends on the vision-language integration strategy: DeepStack models (Qwen) show peak sensitivity at mid-depth (about 50%) for scene text, while single-stage projection models (Phi-4, InternVL) peak at early layers (6-25%), though the exact layer of maximum effect varies across datasets. The OCR signal is remarkably low-dimensional: PC1 captures up to 72.9% of variance. Crucially, principal component analysis (PCA) directions learned on one dataset transfer to others, demonstrating shared text-processing pathways. Surprisingly, in models with modular OCR circuits (notably Qwen3-VL-4B), OCR removal can improve counting performance (up to +6.9 percentage points), suggesting OCR interferes with other visual processing in sufficiently modular architectures.

cs.CL

Quantum Error Mitigated Classical Shadows

Classical shadows enable us to learn many properties of a quantum state $ρ$ with very few measurements. However, near-term and early fault-tolerant quantum computers will only be able to prepare noisy quantum states $ρ$ and it is thus a considerable challenge to efficiently learn properties of an ideal, noise free state $ρ_{id}$. We consider error mitigation techniques, such as Probabilistic Error Cancellation (PEC), Zero Noise Extrapolation (ZNE) and Symmetry Verification (SV) which have been developed for mitigating errors in single expected value measurements and generalise them for mitigating errors in classical shadows. We find that PEC is the most natural candidate and thus develop a thorough theoretical framework for PEC shadows with the following rigorous theoretical guarantees: PEC shadows are an unbiased estimator for the ideal quantum state $ρ_{id}$; the sample complexity for simultaneously predicting many linear properties of $ρ_{id}$ is identical to that of the conventional shadows approach up to a multiplicative factor which is the sample overhead due to error mitigation. Due to efficient post-processing of shadows, this overhead does not depend directly on the number of qubits but rather grows exponentially with the number of noisy gates. The broad set of tools introduced in this work may be instrumental in exploiting near-term and early fault-tolerant quantum computers: We demonstrate in detailed numerical simulations a range of practical applications of quantum computers that will significantly benefit from our techniques.

quant-ph

Hierarchies for Semidefinite Optimization in $\mathcal{C}^\star$-Algebras

Semidefinite Optimization has become a standard technique in the landscape of Mathematical Programming that has many applications in finite dimensional Quantum Information Theory. This paper presents a way for finite-dimensional relaxations of general cone programs on $\mathcal{C}^\star$-algebras which have structurally similar properties to ordinary cone programs, only putting the notion of positivity at the core of optimization. We show that well-known hierarchies for generalized problems like NPA but also Lasserre's hierarchy and to some extend symmetry reductions of generic SDPs by de-Klerk et al. can be considered from a general point of view of $\mathcal{C}^\star$-algebras in combination to optimization problems.

math.OC

Certifying the activation of Bell nonlocality with finite data

The activation of Bell nonlocality is a protocol that enables the violation of a Bell inequality from a system that initially did not allow for any such violation because the state of the system was Bell-local. This activation of hidden Bell nonlocality has been demonstrated in experiments; however, while the certification of Bell nonlocality is conceptional straightforward, a statistically rigorous verification that the initial state is Bell-local has not yet been achieved. This is due to two key obstacles: The lack of a method to establish a suitable confidence region from the measured data and the need for an efficient technique to verify Bell locality of all states within the confidence region. In this work, we address both challenges. We introduce a confidence polytope in the form of a hyperoctahedron and provide a computationally efficient method to verify whether a quantum state admits a local hidden state model, thus being unsteerable and, consequently, Bell-local. Using these methods, we find that a statistically rigorous certification of hidden Bell nonlocality needs of the order of $10^9$ samples.

quant-ph

No-go theorem based on incomplete information of Wigner about his friend

The notion of measurements is central for many debates in quantum mechanics. One critical point is whether a measurement can be regarded as an absolute event, giving the same result for any observer in an irreversible manner. Using ideas from the gedankenexperiment of Wigner's friend it has been argued that, when combined with the assumptions of locality and no-superdeterminism, regarding a measurement as an absolute event is incompatible with the universal validity of quantum mechanics. We consider a weaker assumption: is the measurement event realised relatively to the observer when he only partially observed the outcome. We proposed a protocol to show that this assumption putting in conjunction with the natural assumptions of no-superdeterminism and locality is also not compatible with the universal validity of quantum mechanics.

quant-ph

Graph-theoretic approach to Bell experiments with low detection efficiency

Bell inequality tests where the detection efficiency is below a certain threshold $η_{\rm{crit}}$ can be simulated with local hidden-variable models. Here, we introduce a method to identify Bell tests requiring low $η_{\rm{crit}}$ and relatively low dimension $d$ of the local quantum systems. The method has two steps. First, we show a family of bipartite Bell inequalities for which, for correlations produced by maximally entangled states, $η_{\rm{crit}}$ can be upper bounded by a function of some invariants of graphs, and use it to identify correlations that require small $η_{\rm{crit}}$. We present examples in which, for maximally entangled states, $η_{\rm{crit}} \le 0.516$ for $d=16$, $η_{\rm{crit}} \le 0.407$ for $d=28$, and $η_{\rm{crit}} \le 0.326$ for $d=32$. We also show evidence that the upper bound for $η_{\rm{crit}}$ can be lowered down to $0.415$ for $d=16$ and present a method to make the upper bound of $η_{\rm{crit}}$ arbitrarily small by increasing the dimension and the number of settings. All these upper bounds for $η_{\rm{crit}}$ are valid (as it is the case in the literature) assuming no noise. The second step is based on the observation that, using the initial state and measurement settings identified in the first step, we can construct Bell inequalities with smaller $η_{\rm{crit}}$ and better noise robustness. For that, we use a modified version of Gilbert's algorithm that takes advantage of the automorphisms of the graphs used in the first step. We illustrate its power by explicitly developing an example in which $η_{\rm{crit}}$ is $12.38\%$ lower and the required visibility is $14.62\%$ lower than the upper bounds obtained in the first step. The tools presented here may allow for developing high-dimensional loophole-free Bell tests and loophole-free Bell nonlocality over long distances.

quant-ph

Optimising shadow tomography with generalised measurements

Advances in quantum technology require scalable techniques to efficiently extract information from a quantum system, such as expectation values of observables or its entropy. Traditional tomography is limited to a handful of qubits and shadow tomography has been suggested as a scalable replacement for larger systems. Shadow tomography is conventionally analysed based on outcomes of ideal projective measurements on the system upon application of randomised unitaries. Here, we suggest that shadow tomography can be much more straightforwardly formulated for generalised measurements, or positive operator valued measures. Based on the idea of the least-square estimator, shadow tomography with generalised measurements is both more general and simpler than the traditional formulation with randomisation of unitaries. In particular, this formulation allows us to analyse theoretical aspects of shadow tomography in detail. For example, we provide a detailed study of the implication of symmetries in shadow tomography. Shadow tomography with generalised measurements is also indispensable in realistic implementation of quantum mechanical measurements, when noise is unavoidable. Moreover, we also demonstrate how the optimisation of measurements for shadow tomography tailored toward a particular set of observables can be carried out.

quant-ph

Finding maximal quantum resources

For many applications the presence of a quantum advantage crucially depends on the availability of resourceful states. Although the resource typically depends on the particular task, in the context of multipartite systems entangled quantum states are often regarded as resourceful. We propose an algorithmic method to find maximally resourceful states of several particles for various applications and quantifiers. We discuss in detail the case of the geometric measure, identifying physically interesting states and delivering insights to the problem of absolutely maximally entangled states. Moreover, we demonstrate the universality of our approach by applying it to maximally entangled subspaces, the Schmidt-rank, the stabilizer rank as well as the preparability in triangle networks.

quant-ph

Real eigenstructure of regular simplex tensors

We are concerned with the eigenstructure of supersymmetric tensors. Like in the matrix case, normalized tensor eigenvectors are fixed points of the tensor power iteration map. However, unless the given tensor is orthogonally decomposable, some of these fixed points may be repelling and therefore be undetectable by any numerical scheme. In this paper, we consider the case of regular simplex tensors whose symmetric decomposition is induced by an overcomplete, equiangular set of $n+1$ vectors from $\mathbb R^n$. We discuss the full real eigenstructure of such tensors, including the robustness analysis of all normalized eigenvectors. As it turns out, regular simplex tensors exhibit robust as well as non-robust eigenvectors which, moreover, only partly coincide with the generators from the symmetric tensor decomposition.

math.NA

Minimal scheme for certifying three-outcome qubit measurements in the prepare-and-measure scenario

The number of outcomes is a defining property of a quantum measurement, in particular, if the measurement cannot be decomposed into simpler measurements with fewer outcomes. Importantly, the number of outcomes of a quantum measurement can be irreducibly higher than the dimension of the system. The certification of this property is possible in a semi-device-independent way either based on a Bell-like scenario or by utilizing the simpler prepare-and-measure scenario. Here we show that in the latter scenario the minimal scheme for a certifying an irreducible three-outcome qubit measurement requires three state preparations and only two measurements and we provide experimentally feasible examples for this minimal certification scheme. We also discuss the dimension assumption characteristic to the semi-device-independent approach and to which extend it can be mitigated.

quant-ph

Quaternionic quantum theory admits universal dynamics only for two-level systems

We revisit the formulation of quantum mechanics over the quaternions and investigate the dynamical structure within this framework. Similar to standard complex quantum mechanics, time evolution is then mediated by a unitary operator which can be written as the exponential of the generator of time shifts. By imposing physical assumptions on the correspondence between the energy observable and the generator of time shifts, we prove that quaternionic quantum theory admits a time evolution only for systems with a quaternionic dimension of at most two. Applying the same strategy to standard complex quantum theory, we reproduce that the correspondence dictated by the Schrödinger equation is the only possible choice, up to a shift of the global phase.

quant-ph