Searcharxiv⌕ Search

arXiv subjects

Omanshu Thapliyal

Publications and source records attributed to Omanshu Thapliyal.

8 recordsLinked to original sources

Bounded Reachability & Jailbreak Detection via Contraction-Constrained State Space Models

Safety heads are lightweight classifiers attached to pretrained language models for flagging harmful inputs before generation. Their empirical detection performance has been studied, but their formal robustness properties remain largely unexplored. We ask when a State Space Model (SSM)-based safety head can be certified to produce the same prediction for all inputs within a bounded embedding-space perturbation. We prove that the answer turns on a single condition: the $l_\infty$ norm of the state transition matrix must satisfy $\norm{A}_\infty<1$ (the \emph{contraction condition}), which enables exact interval bound propagation (IBP) certification for linear time-invariant classifiers. When the contraction condition holds, the reachable output interval has bounded steady-state width and examples can be certified as robustly classified. When it fails, the interval grows exponentially with sequence length and certification is impossible at any practical perturbation radius. We enforce contraction with a hinge penalty and show on toxic comment data that certified fraction improves from 41\% to 59\%, with a sharp empirical phase transition at $\norm{A}_\infty=1$ matching the theory. Applying a contraction-regularized S4 head to jailbreak detection on JailbreakBench, we achieve a zero-shot transfer to AdvBench (DR=0.994) and HarmBench (DR=0.988). A logistic regression on mean-pooled Mamba-130M embeddings matches or exceeds the S4 head on every detection metric, confirming that harmful intent is already linearly separable in the embedding space. The S4 safety head's contribution is not superior discrimination but the formal certification that no probe-based approach provides.

cs.AI↗

SSM Adapters via Hankel Reduced-order Modeling: Injection Site Determines Task Suitability in Long-Context Fine-Tuning

While parameter-efficient fine-tuning (PEFT) typically targets attention projectors, its efficacy for tasks requiring sequential state accumulation remains under-explored. We examine if PEFT for such tasks can benefit from state space model (SSMs) adapters, and if MLP blocks are better injection sites. We introduce Hankel Reduced order Model (HRM) adapter, an SSM-based residual module initialized via Balanced Truncation of empirical Hankel Grammians. By leveraging the time-invariance of the system matrix $\bar{A}$, HRM enables an exact FFT-based parallel scan, achieving computational parity with LoRA across all context lengths. In iso-parametric evaluations on Mistral-7B (8.4M trainable parameters), HRM outperforms LoRA variants on LongBench tasks, including QuALITY (+34.8\% relative accuracy) and QMSum (+71.6\% relative ROUGE-1). HRM further demonstrates consistent superiority across 18 configurations of synthetic state-tracking (DFA, Parity) and character-level language modeling (enwik8). Gate analysis reveals that HRM adapters effectively learn to modulate recurrence, providing a robust architectural alternative to low-rank adaptation for long-context sequence modeling.

cs.LG↗

A Multi-Head Attention Approach for SLA Compliance Monitoring in Data Centers

Service level agreements (SLAs) in data center colocation contracts define precise thresholds for power, temperature, and humidity, with tiered violation penalties expressed as credits against monthly recurring charges. Traditional reactive monitoring detects breaches only after they occur, limiting remediation opportunities. We present a framework that encodes SLA rules as structured JSON objects to generate training data without manual annotation. We train a per-customer multi-head transformer model in which each attention head specializes in one SLA rule, learning temporal dependencies that precede violations by 30 minutes. Post-training, the inference service emits structured prediction events transformed into three role-specific views: finance schemas exposing credit liability, operations schemas surfacing risk scores and recommended interventions, and compliance schemas bundling predictions with immutable telemetry signatures for audit. By aligning model architecture directly with contractual obligations, this framework enables operators to anticipate SLA breaches, prioritize corrective actions, and minimize financial penalties.

cs.LG↗

Safe Navigation using Neural Radiance Fields via Reachable Sets

Safe navigation in cluttered environments is an important challenge for autonomous systems. Robots navigating through obstacle ridden scenarios need to be able to navigate safely in the presence of obstacles, goals, and ego objects of varying geometries. In this work, reachable set representations of the robot's real-time capabilities in the state space can be utilized to capture safe navigation requirements. While neural radiance fields (NeRFs) are utilized to compute, store, and manipulate the volumetric representations of the obstacles, or ego vehicle, as needed. Constrained optimal control is employed to represent the resulting path planning problem, involving linear matrix inequality constraints. We present simulation results for path planning in the presence of numerous obstacles in two different scenarios. Safe navigation is demonstrated through using reachable sets in the corresponding constrained optimal control problems.

eess.SY↗

An Algorithm for Distributed Computation of Reachable Sets for Multi-Agent Systems

In this paper, we consider the problem of distributed reachable set computation for multi-agent systems (MASs) interacting over an undirected, stationary graph. A full state-feedback control input for such MASs depends no only on the current agent's state, but also of its neighbors. However, in most MAS applications, the dynamics are obscured by individual agents. This makes reachable set computation, in a fully distributed manner, a challenging problem. We utilize the ideas of polytopic reachable set approximation and generalize it to a MAS setup. We formulate the resulting sub-problems in a fully distributed manner and provide convergence guarantees for the associated computations. The proposed algorithm's convergence is proved for two cases: static MAS graphs, and time-varying graphs under certain restrictions.

eess.SY↗

Direct Data-Driven Discrete-time Bilinear Biquadratic Regulator

We present a novel direct data-driven algorithm that learns an optimal control policy for the Bilinear Biquadratic Regulator (BBR) for an unknown bilinear system. The BBR is difficult to solve owing to the presence of the nonlinear biquadratic performance index and the bilinear cross-term in the dynamics. To address these difficulties, we apply several transformations on the state decision variables to obtain a nonlinear optimization problem with a linear performance index and affine (in the parameterized control) state-dependent equality. The adroit use of the Hamiltonian and Pontryagin's Minimum Principle allows us to derive a pair of first-order necessary conditions that, at each point in time, are easily solvable linear matrix equalities (LMEs) which give the optimal state-dependent control law. We then use the marginal sample autocorrelation of the collected data to obtain a direct data-driven equivalent of these LMEs. We demonstrate the performance of the proposed algorithm via illustrative numerical examples.

eess.SY↗

Data-driven Cyberattack Synthesis against Network Control Systems

Network Control Systems (NCSs) pose unique vulnerabilities to cyberattacks due to a heavy reliance on communication channels. These channels can be susceptible to eavesdropping, false data injection (FDI), and denial of service (DoS). As a result, smarter cyberattacks can employ a combination of techniques to cause degradation of the considered NCS performance. We consider a white-box cyberattack synthesis technique in which the attacker initially eavesdrops to gather system data, and constructs equivalent system model. We utilize the equivalent model to synthesize hybrid cyberattacks -- a combination of FDI and DoS attacks against the NCS. Reachable sets for the equivalent NCS model provide rapid, real-time directives towards selecting NCS agents to be attacked. The devised method provides a significantly more realistic approach toward cyberattack synthesis against NCSs with unknown parameters. We demonstrate the proposed method using a multi-aerial vehicle formation control scenario.

eess.SY↗

Approximating Reachable Sets for Neural Network based Models in Real-Time via Optimal Control

In this paper, we present a data-driven framework for real-time estimation of reachable sets for control systems where the plant is modeled using neural networks (NNs). We utilize a running example of a quadrotor model that is learned using trajectory data via NNs. The NN learned offline, can be excited online to obtain linear approximations for reachability analysis. We use a dynamic mode decomposition based approach to obtain linear liftings of the NN model. The linear models thus obtained can utilize optimal control theory to obtain polytopic approximations to the reachable sets in real-time. The polytopic approximations can be tuned to arbitrary degrees of accuracy. The proposed framework can be extended to other nonlinear models that utilize NNs to estimate plant dynamics. We demonstrate the effectiveness of the proposed framework using an illustrative simulation of quadrotor dynamics.

eess.SY↗