SearcharxivSearch

arXiv subjects

Kun Zhai

Publications and source records attributed to Kun Zhai.

15 recordsLinked to original sources

SkillTrojan: Backdoor Attacks on Skill-Based Agent Systems

Skill-based agent systems tackle complex tasks by composing reusable skills, improving modularity and scalability while introducing a largely unexamined security attack surface. We propose SkillTrojan, a backdoor attack that targets skill implementations rather than model parameters or training data. SkillTrojan embeds malicious logic inside otherwise plausible skills and leverages standard skill composition to reconstruct and execute an attacker-specified payload. The attack partitions an encrypted payload across multiple benign-looking skill invocations and activates only under a predefined trigger. SkillTrojan also supports automated synthesis of backdoored skills from arbitrary skill templates, enabling scalable propagation across skill-based agent ecosystems. To enable systematic evaluation, we release a dataset of 3,000+ curated backdoored skills spanning diverse skill patterns and trigger-payload configurations. We instantiate SkillTrojan in a representative code-based agent setting and evaluate both clean-task utility and attack success rate. Our results show that skill-level backdoors can be highly effective with minimal degradation of benign behavior, exposing a critical blind spot in current skill-based agent architectures and motivating defenses that explicitly reason about skill composition and execution. Concretely, on EHR SQL, SkillTrojan attains up to 97.2% ASR while maintaining 89.3% clean ACC on GPT-5.2-1211-Global.

cs.CR

AgentHazard: A Benchmark for Evaluating Harmful Behavior in Computer-Use Agents

Computer-use agents extend language models from text generation to persistent action over tools, files, and execution environments. Unlike chat systems, they maintain state across interactions and translate intermediate outputs into concrete actions. This creates a distinct safety challenge in that harmful behavior may emerge through sequences of individually plausible steps, including intermediate actions that appear locally acceptable but collectively lead to unauthorized actions. We present \textbf{AgentHazard}, a benchmark for evaluating harmful behavior in computer-use agents. AgentHazard contains \textbf{2,653} instances spanning diverse risk categories and attack strategies. Each instance pairs a harmful objective with a sequence of operational steps that are locally legitimate but jointly induce unsafe behavior. The benchmark evaluates whether agents can recognize and interrupt harm arising from accumulated context, repeated tool use, intermediate actions, and dependencies across steps. We evaluate AgentHazard on Claude Code, OpenClaw, and IFlow using mostly open or openly deployable models from the Qwen3, Kimi, GLM, and DeepSeek families. Our experimental results indicate that current systems remain highly vulnerable. In particular, when powered by Qwen3-Coder, Claude Code exhibits an attack success rate of \textbf{73.63\%}, suggesting that model alignment alone does not reliably guarantee the safety of autonomous agents.

cs.AI

BackdoorAgent: A Unified Framework for Backdoor Attacks on LLM-based Agents

Large language model (LLM) agents execute tasks through multi-step workflows that combine planning, memory, and tool use. While this design enables autonomy, it also expands the attack surface for backdoor threats. Backdoor triggers injected into specific stages of an agent workflow can persist through multiple intermediate states and adversely influence downstream outputs. However, existing studies remain fragmented and typically analyze individual attack vectors in isolation, leaving the cross-stage interaction and propagation of backdoor triggers poorly understood from an agent-centric perspective. To fill this gap, we propose \textbf{BackdoorAgent}, a modular and stage-aware framework that provides a unified, agent-centric view of backdoor threats in LLM agents. BackdoorAgent structures the attack surface into three functional stages of agentic workflows, including \textbf{planning attacks}, \textbf{memory attacks}, and \textbf{tool-use attacks}, and instruments agent execution to enable systematic analysis of trigger activation and propagation across different stages. Building on this framework, we construct a standardized benchmark spanning four representative agent applications: \textbf{Agent QA}, \textbf{Agent Code}, \textbf{Agent Web}, and \textbf{Agent Drive}, covering both language-only and multimodal settings. Our empirical analysis shows that \textit{triggers implanted at a single stage can persist across multiple steps and propagate through intermediate states.} For instance, when using a GPT-based backbone, we observe trigger persistence in 43.58\% of planning attacks, 77.97\% of memory attacks, and 60.28\% of tool-stage attacks, highlighting the vulnerabilities of the agentic workflow itself to backdoor threats. To facilitate reproducibility and future research, our code and benchmark are publicly available at GitHub.

cs.AI

FedAPT: Federated Adversarial Prompt Tuning for Vision-Language Models

Federated Prompt Tuning (FPT) is an efficient method for cross-client collaborative fine-tuning of large Vision-Language Models (VLMs). However, models tuned using FPT are vulnerable to adversarial attacks, leading to misclassification in downstream tasks. In this work, we introduce Federated Adversarial Prompt Tuning (\textbf{FedAPT}), a novel method designed to enhance the adversarial robustness of FPT. We identify a key issue in FedAPT under non-independent and identically distributed (non-IID) settings: a \textit{class information gap} between clients and the global model. Clients rely solely on limited local label information to generate adversarial samples for training, while the global model must defend against adversarial attacks from global labels. To address this issue, we propose a \textbf{class-aware prompt generator} that generates visual prompts from text prompts. This generator is guided by a \emph{Global Label Embedding} (serving as a ``beacon") which encodes cross-client label information to create more globally-aligned visual prompts. Additionally, we propose a \textbf{cross-layer generator sharing} strategy to enhance prompt coupling across different layers of the model, further boosting adversarial robustness. Extensive experiments on multiple image classification datasets demonstrate the superiority of FedAPT in improving adversarial robustness, outperforming existing methods by a large margin. FedAPT also exhibits exceptional generalization in cross-domain and cross-dataset scenarios, indicating its effectiveness in real-world applications.

cs.CV

FedEGG: Federated Learning with Explicit Global Guidance

Federated Learning (FL) holds great potential for diverse applications owing to its privacy-preserving nature. However, its convergence is often challenged by non-IID data distributions, limiting its effectiveness in real-world deployments. Existing methods help address these challenges via optimization-based client constraints, adaptive client selection, or the use of pre-trained models or synthetic data. In this work, we reinterpret these approaches as all introducing an \emph{implicit guiding task} to regularize and steer client learning. Following this insight, we propose to introduce an \emph{explicit global guiding task} into the current FL framework to improve convergence and performance. To this end, we present \textbf{FedEGG}, a new FL algorithm that constructs a global guiding task using a well-defined, easy-to-converge learning task based on a public dataset and Large Language Models (LLMs). This approach effectively combines the strengths of federated (the original FL task) and centralized (the global guiding task) learning. We provide a theoretical analysis of FedEGG's convergence, examining the impact of data heterogeneity between the guiding and FL tasks and the guiding strength. Our analysis derives an upper bound for the optimal guiding strength, offering practical insights for implementation. Empirically, FedEGG demonstrates superior performance over state-of-the-art FL methods under both IID and non-IID settings, and further improves their performances when combined.

cs.LG

Orbital torque switching of room temperature two-dimensional van der Waals ferromagnet Fe3GaTe2

Efficiently manipulating the magnetization of van der Waals ferromagnets has attracted considerable interest in developing room-temperature two-dimensional material-based memory and logic devices. Here, taking advantage of the unique properties of the van der Waals ferromagnet as well as promising characteristics of the orbital Hall effect, we demonstrate the room-temperature magnetization switching of van der Waals ferromagnet Fe3GaTe2 through the orbital torque generated by the orbital Hall material, Titanium (Ti). The switching current density is estimated to be around 1.6 x 10^6 A/cm^2, comparable to that achieved in Fe3GaTe2 using spin-orbit torque from spin Hall materials. The efficient magnetization switching arises from the combined effects of the large orbital Hall conductivity of Ti and the strong spin-orbit correlation of the Fe3GaTe2, as confirmed through theoretical calculations. Our findings advance the understanding of orbital torque switching and pave the way for exploring material-based orbitronic devices.

cond-mat.mtrl-sci

FedCAda: Adaptive Client-Side Optimization for Accelerated and Stable Federated Learning

Federated learning (FL) has emerged as a prominent approach for collaborative training of machine learning models across distributed clients while preserving data privacy. However, the quest to balance acceleration and stability becomes a significant challenge in FL, especially on the client-side. In this paper, we introduce FedCAda, an innovative federated client adaptive algorithm designed to tackle this challenge. FedCAda leverages the Adam algorithm to adjust the correction process of the first moment estimate $m$ and the second moment estimate $v$ on the client-side and aggregate adaptive algorithm parameters on the server-side, aiming to accelerate convergence speed and communication efficiency while ensuring stability and performance. Additionally, we investigate several algorithms incorporating different adjustment functions. This comparative analysis revealed that due to the limited information contained within client models from other clients during the initial stages of federated learning, more substantial constraints need to be imposed on the parameters of the adaptive algorithm. As federated learning progresses and clients gather more global information, FedCAda gradually diminishes the impact on adaptive parameters. These findings provide insights for enhancing the robustness and efficiency of algorithmic improvements. Through extensive experiments on computer vision (CV) and natural language processing (NLP) datasets, we demonstrate that FedCAda outperforms the state-of-the-art methods in terms of adaptability, convergence, stability, and overall performance. This work contributes to adaptive algorithms for federated learning, encouraging further exploration.

cs.LG

Continuous Electrical Manipulation of Magnetic Anisotropy and Spin Flopping in van der Waals Ferromagnetic Devices

Controlling the magnetic anisotropy of ferromagnetic materials plays a key role in magnetic switching devices and spintronic applications. Examples of spin-orbit torque devices with different magnetic anisotropy geometries (in-plane or out-of-plane directions) have been demonstrated with novel magnetization switching mechanisms for extended device functionalities. Normally, the intrinsic magnetic anisotropy in ferromagnetic materials is unchanged within a fixed direction, and thus, it is difficult to realize multifunctionality devices. Therefore, continuous modulation of magnetic anisotropy in ferromagnetic materials is highly desired but remains challenging. Here, we demonstrate a gate-tunable magnetic anisotropy transition from out-of-plane to canted and finally to in-plane in layered Fe$_5$GeTe$_2$ by combining the measurements of the angle-dependent anomalous Hall effect and magneto-optical Kerr effect with quantitative Stoner-Wohlfarth analysis. The magnetic easy axis continuously rotates in a spin-flop pathway by gating or temperature modulation. Such observations offer a new avenue for exploring magnetization switching mechanisms and realizing new spintronic functionalities.

cond-mat.mtrl-sci

Probe Skyrmion phases and dynamics in MnSi via the magnetoelectric effect in a composite configuration

We have developed a sensitive technique to probe the magnetic skyrmion phases and dynamics by employing the interfacial coupling effect in a magnetoelectric composite configuration. The study on a MnSi single crystal sample using this technique provides clear evidences for the skyrmion lattice phase and coexistence of skyrmion and conical phase. Above the Curie temperature TC, a region with strong spin fluctuation is revealed as well. By tuning the density of Skyrmion or disorder, a transition from the skyrmion lattice to skyrmion-conical coexisting phase is observed. The observation is in good agreement with a theoretical model which predicts the dissipation behavior in the coexistence phase.

cond-mat.mtrl-sci

Byzantine-Robust Federated Learning via Credibility Assessment on Non-IID Data

Federated learning is a novel framework that enables resource-constrained edge devices to jointly learn a model, which solves the problem of data protection and data islands. However, standard federated learning is vulnerable to Byzantine attacks, which will cause the global model to be manipulated by the attacker or fail to converge. On non-iid data, the current methods are not effective in defensing against Byzantine attacks. In this paper, we propose a Byzantine-robust framework for federated learning via credibility assessment on non-iid data (BRCA). Credibility assessment is designed to detect Byzantine attacks by combing adaptive anomaly detection model and data verification. Specially, an adaptive mechanism is incorporated into the anomaly detection model for the training and prediction of the model. Simultaneously, a unified update algorithm is given to guarantee that the global model has a consistent direction. On non-iid data, our experiments demonstrate that the BRCA is more robust to Byzantine attacks compared with conventional methods

cs.LG

Reentrance of spin-driven ferroelectricity through rotational tunneling of ammonium

Quantum effects fundamentally engender exotic physical phenomena in macroscopic systems, which advance next-generation technological applications. Rotational tunneling that represents the quantum phenomenon of the librational motion of molecules is ubiquitous in hydrogen-contained materials. However, its direct manifestation in realizing macroscopic physical properties is elusive. Here we report an observation of reentrant ferroelectricity under low pressure that is mediated by the rotational tunneling of ammonium ions in molecule-based (NH$_4$)$_2$FeCl$_5 \cdot$H$_2$O. Applying a small pressure leads to a transition from spin-driven ferroelectricity to paraelectricity coinciding with the stabilization of a collinear magnetic phase. Such a transition is attributed to the hydrogen bond fluctuations via the rotational tunneling of ammonium groups as supported by theoretical calculations. Higher pressure lifts the quantum fluctuations and leads to a reentrant ferroelectric phase concomitant with another incommensurate magnetic phase. These results demonstrate that the rotational tunneling emerges as a new route to control magnetic-related properties in soft magnets, opening avenues for designing multi-functional materials and realizing potential quantum control.

cond-mat.mtrl-sci

Electromagnon in Y-type hexaferrite BaSrCoZnFe$_{11}$AlO$_{22}$

We investigated static and dynamic magnetoelectric properties of single crystalline BaSrCoZnFe$_{11}$AlO$_{22}$ which is a room-temperature multiferroic with Y-type hexaferrite crystal structure. Below $300\,\rm K$, a purely electric-dipole-active electromagnon at $\approx 1.2\,\rm THz$ with the electric polarization oscillating along the hexagonal axis was observed by THz and Raman spectroscopies. We investigated the behavior of the electromagnon with applied DC magnetic field and linked its properties to static measurements of the magnetic structure. Our analytical calculations determined selection rules for electromagnons activated by the magnetostriction mechanism in various magnetic structures of Y-type hexaferrite. Comparison with our experiment supports that the electromagnon is indeed activated by the magnetostriction mechanism involving spin vibrations along the hexagonal axis.

cond-mat.mtrl-sci

Electromagnon in the Z-type hexaferrite $({\rm Ba}_{x}{\rm Sr}_{1-x})_3\rm Co_2Fe_{24}O_{41}$

We studied experimentally the high-temperature magnetoelectric $({\rm Ba}_{x}{\rm Sr}_{1-x})_3\rm Co_2Fe_{24}O_{41}$ prepared as ceramics (x = 0, 0.2) and a single crystal (x = 0.5) using inelastic neutron scattering, THz time-domain, Raman and far-infrared spectroscopies. The spectra, measured with varying temperature and magnetic field, reveal rich information about the collective spin and lattice excitations. In the ceramics, we observed an infrared-active magnon which is absent in $E^ω\perp z$ polarized THz spectra of the crystal, and we assume that it is an electromagnon active in $E^ω \| z$ polarized spectra. On heating from 7 to 250 K, the frequency of this electromagnon drops from 36 to 25 cm$^{-1}$ and its damping gradually increases, so it becomes overdamped at room temperature. Applying external magnetic field has a similar effect on the damping and frequency of the electromagnon, and the mode is no more observable in the THz spectra above 2 T, as the transverse-conical magnetic structure transforms into a collinear one. Raman spectra reveal another spin excitation with a slightly different frequency and much higher damping. Upon applying magnetic field higher than 3 T, in the low-frequency part of the THz spectra, a narrow excitation appears whose frequency linearly increases with magnetic field. We interpret this feature as the ferromagnetic resonance.

cond-mat.mtrl-sci

A multilevel nonvolatile magnetoelectric memory based on memtranstor

The coexistence and coupling between magnetization and electric polarization in multiferroic materials provide extra degrees of freedom for creating next-generation memory devices. A variety of concepts of multiferroic or magnetoelectric memories have been proposed and explored in the past decade. Here we propose a new principle to realize a multilevel nonvolatile memory based on the multiple states of the magnetoelectric coefficient (α) of multiferroics. Because the states of α depends on the relative orientation between magnetization and polarization, one can reach different levels of α by controlling the ratio of up and down ferroelectric domains with external electric fields. Our experiments in a device made of the PMN-PT/Terfenol-D multiferroic heterostructure confirm that the states of α can be well controlled between positive and negative by applying selective electric fields. Consequently, two-level, four-level, and eight-level nonvolatile memory devices are demonstrated at room temperature. This kind of multilevel magnetoelectric memory retains all the advantages of ferroelectric random access memory but overcomes the drawback of destructive reading of polarization. In contrast, the reading of α is nondestructive and highly efficient in a parallel way, with an independent reading coil shared by all the memory cells.

cond-mat.mtrl-sci

A non-volatile memory based on nonlinear magnetoelectric effects

The magnetoelectric effects in multiferroics have a great potential in creating next-generation memory devices. We conceive a new concept of non-volatile memories based on a type of nonlinear magnetoelectric effects showing a butterfly-shaped hysteresis loop. The principle is to utilize the states of the magnetoelectric coefficient, instead of magnetization, electric polarization or resistance, to store binary information. Our experiments in a device made of the PMN-PT/Terfenol-D multiferroic heterostructure clearly demonstrate that the sign of the magnetoelectric coefficient can be repeatedly switched between positive and negative by applying electric fields, confirming the feasibility of this principle. This kind of non-volatile memory has outstanding practical virtues such as simple structure, easy operations in writing and reading, low power, fast speed, and diverse materials available.

cond-mat.mtrl-sci