Searcharxiv⌕ Search

arXiv subjects

Jun Yan

Publications and source records attributed to Jun Yan.

At least 109 records · Page 6Linked to original sources

Test-time Backdoor Mitigation for Black-Box Large Language Models with Defensive Demonstrations

Existing studies in backdoor defense have predominantly focused on the training phase, overlooking the critical aspect of testing time defense. This gap becomes pronounced in the context of LLMs deployed as Web Services, which typically offer only black-box access, rendering training-time defenses impractical. To bridge this gap, this study critically examines the use of demonstrations as a defense mechanism against backdoor attacks in black-box LLMs. We retrieve task-relevant demonstrations from a clean data pool and integrate them with user queries during testing. This approach does not necessitate modifications or tuning of the model, nor does it require insight into the model's internal architecture. The alignment properties inherent in in-context learning play a pivotal role in mitigating the impact of backdoor triggers, effectively recalibrating the behavior of compromised models. Our experimental analysis demonstrates that this method robustly defends against both instance-level and instruction-level backdoor attacks, outperforming existing defense baselines across most evaluation scenarios.

cs.CL↗

CALF-SBM: A Covariate-Assisted Latent Factor Stochastic Block Model

We propose a novel network generative model extended from the standard stochastic block model by concurrently utilizing observed node-level information and accounting for network-enabled nodal heterogeneity. The proposed model is so so-called covariate-assisted latent factor stochastic block model (CALF-SBM). The inference for the proposed model is done in a fully Bayesian framework. The primary application of CALF-SBM in the present research is focused on community detection, where a model-selection-based approach is employed to estimate the number of communities which is practically assumed unknown. To assess the performance of CALF-SBM, an extensive simulation study is carried out, including comparisons with multiple classical and modern network clustering algorithms. Lastly, the paper presents two real data applications, respectively based on an extremely new network data demonstrating collaborative relationships of otolaryngologists in the United States and a traditional aviation network data containing information about direct flights between airports in the United States and Canada.

stat.ME↗

Lyapunov stability and uniqueness problems for Hamilton-Jacobi equations without monotonicity

We consider the evolutionary Hamilton-Jacobi equation \begin{align*} w_t(x,t)+H(x,Dw(x,t),w(x,t))=0, \quad(x,t)\in M\times [0,+\infty), \end{align*} where $M$ is a compact manifold, $H:T^*M\times R\to R$, $H=H(x,p,u)$ satisfies Tonelli conditions in $p$ and the Lipschitz condition in $u$. This work mainly concerns with the Lyapunov stability (including asymptotic stability, and instability) and uniqueness of stationary viscosity solutions of the equation. A criterion for stability and a criterion for instability are given. We do not utilize auxiliary functions and thus our method is different from the classical Lyapunov's direct method. We also prove several uniqueness results for stationary viscosity solutions. The Hamiltonian $H$ has no concrete form and it may be non-monotonic in the argument $u$, where the situation is more complicated than the monotonic case. Several simple but nontrivial examples are provided, including the following equation on the unit circle \[ w_t(x,t)+\frac{1}{2}w^2_x(x,t)-a\cdot w_x(x,t)+(\sin x+b)\cdot w(x,t)=0,\quad x\in \mathbf{S}, \] where $a$, $b\in R$ are parameters. We analyze the stability, and instability of the stationary solution $w=0$ when parameters vary, and show that $w=0$ is the unique stationary solution when $a=0$, $b>1$ and $a\neq0$, $b\geqslant 1$. The sign of the integral of $\frac{\partial H}{\partial u}$ with respect to the Mather measure of the contact Hamiltonian system generated by $H$ plays an essential role in the proofs of aforementioned results. For this reason, we first develop the Mather and weak KAM theories for contact Hamiltonian systems in this non-monotonic setting. A decomposition theorem of the Mañé set is the main result of this part.

math.AP↗

On GEE for Mean-Variance-Correlation Models: Variance Estimation and Model Selection

Generalized estimating equations (GEE) are of great importance in analyzing clustered data without full specification of multivariate distributions. A recent approach jointly models the mean, variance, and correlation coefficients of clustered data through three sets of regressions (Luo and Pan, 2022). We observe that these estimating equations, however, are a special case of those of Yan and Fine (2004) which further allows the variance to depend on the mean through a variance function. The proposed variance estimators may be incorrect for the variance and correlation parameters because of a subtle dependence induced by the nested structure of the estimating equations. We characterize model settings where their variance estimation is invalid and show the variance estimators in Yan and Fine (2004) correctly account for such dependence. In addition, we introduce a novel model selection criterion that enables the simultaneous selection of the mean-scale-correlation model. The sandwich variance estimator and the proposed model selection criterion are tested by several simulation studies and real data analysis, which validate its effectiveness in variance estimation and model selection. Our work also extends the R package geepack with the flexibility to apply different working covariance matrices for the variance and correlation structures.

stat.ME↗

A note on improved bounds for hypergraph rainbow matching problems

A natural question, inspired by the famous Ryser-Brualdi-Stein Conjecture, is to determine the largest positive integer $g(r,n)$ such that every collection of $n$ matchings, each of size $n$, in an $r$-partite $r$-uniform hypergraph contains a rainbow matching of size $g(r,n)$. The parameter $g'(r,n)$ is defined identically with the exception that the host hypergraph is not required to be $r$-partite. In this note, we improve the best known lower bounds on $g'(r,n)$ for all $r \geq 4$ and the upper bounds on $g(r,n)$ for all $r \geq 3$, provided $n$ is sufficiently large. More precisely, we show that if $r\ge3$ then $$\frac{2n}{r+1}-Θ_r(1)\le g'(r,n)\le g(r,n)\le n-Θ_r(n^{1-\frac{1}{r}}).$$ Interestingly, while it has been conjectured that $g(2,n)=g'(2,n)=n-1$, our results show that if $r\ge3$ then $g(r,n)$ and $g'(r,n)$ are bounded away from $n$ by a function which grows in $n$. We also prove analogous bounds for the related problem where we are interested in the smallest size $s$ for which any collection of $n$ matchings of size $s$ in an ($r$-partite) $r$-uniform hypergraph contains a rainbow matching of size $n$.

math.CO↗

On the dynamics of contact Hamiltonian systems II: Variational construction of asymptotic orbits

This paper is a continuation of our study of the dynamics of contact Hamiltonian systems in \cite{JY}, but without monotonicity assumption. Due to the complexity of general cases, we focus on the behavior of action minimizing orbits. We pick out certain action minimizing invariant sets $\{\widetilde{\mathcal{N}}_u\}$ in the phase space naturally stratified by solutions $u$ to the corresponding Hamilton-Jacobi equation. Using an extension of characteristic method, we establish the existence of semi-infinite orbits that is asymptotic to some $\widetilde{\mathcal{N}}_u$ and heteroclinic orbits between $\widetilde{\mathcal{N}}_u$ and $\widetilde{\mathcal{N}}_v$ for two different solutions $u$ and $v$.

math.DS↗

Medical Multimodal Foundation Models in Clinical Diagnosis and Treatment: Applications, Challenges, and Future Directions

Recent advancements in deep learning have significantly revolutionized the field of clinical diagnosis and treatment, offering novel approaches to improve diagnostic precision and treatment efficacy across diverse clinical domains, thus driving the pursuit of precision medicine. The growing availability of multi-organ and multimodal datasets has accelerated the development of large-scale Medical Multimodal Foundation Models (MMFMs). These models, known for their strong generalization capabilities and rich representational power, are increasingly being adapted to address a wide range of clinical tasks, from early diagnosis to personalized treatment strategies. This review offers a comprehensive analysis of recent developments in MMFMs, focusing on three key aspects: datasets, model architectures, and clinical applications. We also explore the challenges and opportunities in optimizing multimodal representations and discuss how these advancements are shaping the future of healthcare by enabling improved patient outcomes and more efficient clinical workflows.

cs.AI↗

Convergence/divergence phenomena in the vanishing discount limit of Hamilton-Jacobi equations

We study the asymptotic behavior of solutions of an equation of the form \begin{equation}\label{abs}\tag{*} G\big(x, D_x u,λu(x)\big) = c_0\qquad\hbox{in $M$} \end{equation} on a closed Riemannian manifold $M$, where $G\in C(T^*M\times\mathbb{R})$ is convex and superlinear in the gradient variable, is globally Lipschitz but not monotone in the last argument, and $c_0$ is the critical constant associated with the Hamiltonian $H:=G(\cdot,\cdot,0)$. By assuming that $\partial_u G(\cdot,\cdot,0)$ satisfies a positivity condition of integral type on the Mather set of $H$, we prove that any equi-bounded family of solutions of \eqref{abs} uniformly converges to a distinguished critical solution $u_0$ as $λ\to 0^+$. We furthermore show that any other possible family of solutions uniformly diverges to $+\infty$ or $-\infty$. We then look into the linear case $G(x,p,u):=a(x)u + H(x,p)$ and prove that the family $(u_λ)_{λ\in (0,λ_0)}$ of maximal solutions to \eqref{abs} is well defined and equi-bounded for $λ_0>0$ small enough. When $a$ changes sign and enjoys a stronger localized positivity assumption, we show that equation \eqref{abs} does admit other solutions too, and that they all uniformly diverge to $-\infty$ as $λ\to 0^+$. This is the first time that converging and diverging families of solutions are shown to coexist in such a generality.

math.AP↗

Fix the Tests: Augmenting LLMs to Repair Test Cases with Static Collector and Neural Reranker

During software evolution, it is advocated that test code should co-evolve with production code. In real development scenarios, test updating may lag behind production code changing, which may cause compilation failure or bring other troubles. Existing techniques based on pre-trained language models can be directly adopted to repair obsolete tests caused by such unsynchronized code changes, especially syntactic-related ones. However, the lack of task-oriented contextual information affects the repair accuracy on large-scale projects. Starting from an obsolete test, the key challenging task is precisely identifying and constructing Test-Repair-Oriented Contexts (TROCtxs) from the whole repository within a limited token size. In this paper, we propose SYNTER (SYNtactic-breaking-changes-induced TEst Repair), a novel approach based on LLMs to automatically repair obsolete test cases via precise and concise TROCtxs construction. Inspired by developers' programming practices, we design three types of TROCtx: class context, usage context, and environment context. Given an obsolete test case to repair, SYNTER firstly collects the related code information for each type of TROCtx through static analysis techniques automatically. Then, it generates reranking queries to identify the most relevant TROCtxs, which will be taken as the repair-required key contexts and be input to the large language model for the final test repair. To evaluate the effectiveness of SYNTER, we construct a benchmark dataset that contains a set of obsolete tests caused by syntactic breaking changes. The experimental results show that SYNTER outperforms baseline approaches both on textual- and intent-matching metrics. With the augmentation of constructed TROCtxs, hallucinations are reduced by 57.1%.

cs.SE↗

Exponential odd-distance sets under the Manhattan metric

We construct a set of $2^n$ points in $\mathbb{R}^n$ such that all pairwise Manhattan distances are odd integers, which improves the recent linear lower bound of Golovanov, Kupavskii and Sagdeev. In contrast to the Euclidean and maximum metrics, this shows that the odd-distance set problem behaves very differently to the equilateral set problem under the Manhattan metric. Moreover, all coordinates of the points in our construction are integers or half-integers, and we show that our construction is optimal under this additional restriction.

math.CO↗

Segment-Anything Models Achieve Zero-shot Robustness in Autonomous Driving

Semantic segmentation is a significant perception task in autonomous driving. It suffers from the risks of adversarial examples. In the past few years, deep learning has gradually transitioned from convolutional neural network (CNN) models with a relatively small number of parameters to foundation models with a huge number of parameters. The segment-anything model (SAM) is a generalized image segmentation framework that is capable of handling various types of images and is able to recognize and segment arbitrary objects in an image without the need to train on a specific object. It is a unified model that can handle diverse downstream tasks, including semantic segmentation, object detection, and tracking. In the task of semantic segmentation for autonomous driving, it is significant to study the zero-shot adversarial robustness of SAM. Therefore, we deliver a systematic empirical study on the robustness of SAM without additional training. Based on the experimental results, the zero-shot adversarial robustness of the SAM under the black-box corruptions and white-box adversarial attacks is acceptable, even without the need for additional training. The finding of this study is insightful in that the gigantic model parameters and huge amounts of training data lead to the phenomenon of emergence, which builds a guarantee of adversarial robustness. SAM is a vision foundation model that can be regarded as an early prototype of an artificial general intelligence (AGI) pipeline. In such a pipeline, a unified model can handle diverse tasks. Therefore, this research not only inspects the impact of vision foundation models on safe autonomous driving but also provides a perspective on developing trustworthy AGI. The code is available at: https://github.com/momo1986/robust_sam_iv.

cs.CV↗

Results on pattern avoidance in parking functions

In this paper, we mainly study two notions of pattern avoidance in parking functions. First, for any collection of length 3 patterns, we compute the number of parking functions of size $n$ that avoid them under the first notion. This is motivated by the recent work of Adeniran and Pudwell, who obtained analogous results using a second notion of pattern avoidance. Then, we provide new purely bijective proofs for two of their results, and improve the formula of another one. Finally, we apply similar enumeration techniques to the work of Novelli and Thibon on certain Hopf algebras of generalised parking functions, and compute their graded dimensions.

math.CO↗

VQ-DeepVSC: A Dual-Stage Vector Quantization Framework for Video Semantic Communication

In response to the rapid growth of global videomtraffic and the limitations of traditional wireless transmission systems, we propose a novel dual-stage vector quantization framework, VQ-DeepVSC, tailored to enhance video transmission over wireless channels. In the first stage, we design the adaptive keyframe extractor and interpolator, deployed respectively at the transmitter and receiver, which intelligently select key frames to minimize inter-frame redundancy and mitigate the cliff-effect under challenging channel conditions. In the second stage, we propose the semantic vector quantization encoder and decoder, placed respectively at the transmitter and receiver, which efficiently compress key frames using advanced indexing and spatial normalization modules to reduce redundancy. Additionally, we propose adjustable index selection and recovery modules, enhancing compression efficiency and enabling flexible compression ratio adjustment. Compared to the joint source-channel coding (JSCC) framework, the proposed framework exhibits superior compatibility with current digital communication systems. Experimental results demonstrate that VQ-DeepVSC achieves substantial improvements in both Multi-Scale Structural Similarity (MS-SSIM) and Learned Perceptual Image Patch Similarity (LPIPS) metrics than the H.265 standard, particularly under low channel signal-to-noise ratio (SNR) or multi-path channels, highlighting the significantly enhanced transmission capabilities of our approach.

cs.NI↗

Descents and inversions in powers of permutations

In this paper, we generalise several recent results by Archer and Geary on descents in powers of permutations, and confirm all their conjectures. Specifically, for all $k\in\mathbb{Z}^+$, we prove explicit formulas for the expected numbers of descents and inversions in the $k$-th powers of permutations in $\mathcal{S}_n$ for all $n\geq2k+1$. We also compute the number of Grassmanian permutations in $\mathcal{S}_n$ whose $k$-th powers remain Grassmanian, and the number of permutations in $\mathcal{S}_n$ whose $k$-th powers have the maximum number of descents.

math.CO↗

Better Debugging: Combining Static Analysis and LLMs for Explainable Crashing Fault Localization

Nowadays, many applications do not exist independently but rely on various frameworks or libraries. The frequent evolution and the complex implementation of framework APIs induce many unexpected post-release crashes. Starting from the crash stack traces, existing approaches either perform direct call graph (CG) tracing or construct datasets with similar crash-fixing records to locate buggy methods. However, these approaches are limited by the completeness of CG or dependent on historical fixing records. Moreover, they fail to explain the buggy candidates by revealing their relationship with the crashing point. To fill the gap, we propose an explainable crashing fault localization approach by combining static analysis and LLM techniques. Our primary insight is that understanding the semantics of exception-throwing statements in the framework code can help find and apprehend the buggy methods in the app code. Based on this idea, first, we design the exception-thrown summary (ETS) that describes the key elements related to each framework-specific exception and extract ETSs by performing static analysis. Then we make data-tracking of its key elements to identify and sort buggy candidates for the given crash. After that, we introduce LLMs to improve the explainability of the localization results. To construct effective LLM prompts, we design the candidate information summary (CIS) that describes multiple types of explanation-related contexts and then extract CISs via static analysis. We apply our approach to one typical scenario, i.e., locating Android framework-specific crashing faults, and implement a tool CrashTracker. For fault localization, it exhibited an overall MRR value of 0.91 in precision. For fault explanation, compared to the naive one produced by static analysis only, the LLM-powered explanation achieved a 67.04% improvement in users' satisfaction score.

cs.SE↗

How Susceptible are Large Language Models to Ideological Manipulation?

Large Language Models (LLMs) possess the potential to exert substantial influence on public perceptions and interactions with information. This raises concerns about the societal impact that could arise if the ideologies within these models can be easily manipulated. In this work, we investigate how effectively LLMs can learn and generalize ideological biases from their instruction-tuning data. Our findings reveal a concerning vulnerability: exposure to only a small amount of ideologically driven samples significantly alters the ideology of LLMs. Notably, LLMs demonstrate a startling ability to absorb ideology from one topic and generalize it to even unrelated ones. The ease with which LLMs' ideologies can be skewed underscores the risks associated with intentionally poisoned training data by malicious actors or inadvertently introduced biases by data annotators. It also emphasizes the imperative for robust safeguards to mitigate the influence of ideological manipulations on LLMs.

cs.CL↗

Knowledge-Informed Auto-Penetration Testing Based on Reinforcement Learning with Reward Machine

Automated penetration testing (AutoPT) based on reinforcement learning (RL) has proven its ability to improve the efficiency of vulnerability identification in information systems. However, RL-based PT encounters several challenges, including poor sampling efficiency, intricate reward specification, and limited interpretability. To address these issues, we propose a knowledge-informed AutoPT framework called DRLRM-PT, which leverages reward machines (RMs) to encode domain knowledge as guidelines for training a PT policy. In our study, we specifically focus on lateral movement as a PT case study and formulate it as a partially observable Markov decision process (POMDP) guided by RMs. We design two RMs based on the MITRE ATT\&CK knowledge base for lateral movement. To solve the POMDP and optimize the PT policy, we employ the deep Q-learning algorithm with RM (DQRM). The experimental results demonstrate that the DQRM agent exhibits higher training efficiency in PT compared to agents without knowledge embedding. Moreover, RMs encoding more detailed domain knowledge demonstrated better PT performance compared to RMs with simpler knowledge.

cs.AI↗