SearcharxivSearch

arXiv subjects

Ping He

Publications and source records attributed to Ping He.

At least 19 recordsLinked to original sources

From Pre-triangulation to Triangulation: Obstructions and Exact Lifting

We give a new equivalent formulation of Verdier's octahedral axiom. An initial square in a pre-triangulated category determines an obstruction in a quotient of ordinary Hom groups. Its vanishing is equivalent to the existence of a good completion, and $\mathrm{TR4}$ is equivalent to this vanishing for the squares associated with composable morphisms. As a consequence, if two pre-triangulations have the same underlying additive category and one is triangulated, then the other satisfies $\mathrm{TR4}$ precisely when their relative inverse Heller comparison admits an exact lift along every short exact sequence in the Freyd category. As applications, we prove that the exotic pre-triangulated category of D\'iaz Cabrera--Muro is in fact a triangulated category over every algebraically closed field. We construct scalar families for type-$A_{3a-1}$ preprojective algebras over arbitrary fields and for a range of Dynkin preprojective algebras in characteristic two; in each family the zero parameter is the unique triangulated member. The local equations also yield separable descent, including canonical triangulations for non-modular equivariantizations and for the Markman--Mehrotra K3 deformation categories.

math.RT

Beyond the Payload: How User Invocation Shapes Coding Agent Vulnerability to Repository Poisoning

Coding agents are increasingly used for software engineering tasks, including bootstrapping projects from third-party repositories whose integrity cannot be assumed. Prior work on repository poisoning largely focuses on attacker-controlled injection and disguise, but developers also shape risk through everyday invocation choices: what task to delegate, how to phrase the request, and which skills or rules to supply. We term these user-side choices Prompt-Level Configurations (PLCs) and introduce CIPR (Coding In Poisoned Repos), the first benchmark that systematically varies PLCs in poisoned real-world repositories. CIPR comprises 1,920 instances across 20 repositories, four task types, three social-media-grounded prompt styles, and three skill/rule conditions, and measures attack success rate (ASR) and agent alert rate (AR) using automated runtime and trace-based oracles. Our evaluation reveals two key insights: (1) Vulnerability is highly context-dependent, with task type creating up to a 4.5-fold difference in ASR, with test-execution task forming a silent attack surface (high ASR, low AR). (2) Prompt expression shifts risk indirectly: underspecified prompts reduce ASR by truncating execution depth; noisy prompts exhibit a directional trend toward suppressing alerts by making malicious content less conspicuous. These findings highlight that coding agent vulnerability is not a static property, but a dynamic outcome shaped by everyday user configurations.

cs.CR

Efficient three-dimensional variational data assimilation of multi-plane PIV data

We perform three-dimensional variational data assimilation (3DVar) using a discrete adjoint approach to optimise the time-averaged momentum equations. The experimental data consist of sparse stereoscopic particle image velocimetry (PIV) measurements collected along $12$ cross-stream planes in the wake of a vehicle-like bluff body at a Reynolds number $Re_L = 5.64 \times 10^5$ based on the streamwise body length. Adjoint localisation is proposed and implemented to reduce the memory footprint of the discrete adjoint method for spatially-varying control variables in 3DVar by confining the control variable space to a user-defined subdomain. Restricting the control variable to $12$ % of the full control space yields a maximum reduction in peak memory of $64$ %, while producing assimilated fields of comparable fidelity with respect to mean velocity and the optimised momentum forcing field. The localised adjoint case improves upon the baseline Spalart--Allmaras turbulence model and recovers the correct asymmetric topology of the complex three-dimensional (3D) recirculation bubble. The assimilated Reynolds shear stress agrees well with the experiment, and the assimilated mean pressure is shown to be physically consistent when correlated with the in-plane vorticity fields. A data efficiency study is also performed, in which the number of planes provided for assimilation is progressively reduced, demonstrating that the data coverage must extend at least to the end of the primary recirculation bubble to adequately constrain the near-wake dynamics. The efficiency that adjoint localisation affords is crucial for assimilating sparse, experimental data for 3D separated flows on fine meshes that can tackle industrial problems of interest.

physics.flu-dyn

Visko Orbis 1.0: A Live Model for Real-Time Interactive Long Video Generation

We present Visko Orbis 1.0, a Live Model for real-time, interactive long video generation. Users can change the prompt at any moment during generation, and the update becomes visible in real time. Visko Orbis 1.0 supports long-form text-to-video, image-to-video, and video continuation, with multilingual prompts and prompt switching while generation is in progress. A bounded multi-scale memory preserves subjects, scenes, and style across chunks, sustaining hour-scale rollouts without evident quality or color drift. The generator is factorized causally in time, matching the causal structure of physical dynamics, and is aligned with a latent world-model reward for predictive consistency. Built on a distilled chunk-wise streaming generator and a streaming video upscaler, Visko Orbis 1.0 delivers 4K video generation at 24 FPS in real time, using an optimized GPU serving engine. In quantitative evaluations, Visko Orbis 1.0 achieves the best DOVER aesthetic and technical scores and the best VideoAlign visual and motion quality, and leads three physical-plausibility protocols (VideoPhy-2, Physics-IQ, and VBench-2.0 Physics); in long-form Arena comparisons, it obtains the highest overall-preference and temporal-stability ratings among all the state-of-the-art real-time interactive video generation systems.

cs.CV

SE(3)-MeanFlow: Few-Step Protein Backbone Generation on Lie Groups

Generative modeling of protein backbones promises the de novo design of proteins with prescribed structural and functional properties. Existing diffusion and flow-matching models produce high-quality backbones on SE(3)^N, but inference requires numerically integrating an ODE over hundreds of network evaluations, each involving a Lie group exponential map - a bottleneck for high-throughput design campaigns. We introduce SE(3)-MeanFlow, a few-step generative framework that extends MeanFlow from Euclidean space to the Lie group geometry of protein frames. Working natively in the Lie algebra so(3) and in R^3, we derive closed-form average-velocity identities for rotations and translations, giving simulation-free training targets. We further introduce an SE(3) alpha-Flow objective that removes the Jacobian-vector product from the rotation branch and serves as a warm-up stage, after which training switches to a small-t stabilized MeanFlow loss that is used for the remainder of pretraining and for rectification-based post-training. In protein backbone generation, SE(3)-MeanFlow matches or exceeds flow-matching baselines that use several times more sampling steps, and its advantage widens in the few-step regime, where rectification lets it lead at every matched budget - at a modest cost in diversity.

cs.LG

Hybrid Analysis for Secure MCP Tool Use in LLM Agents

The rapid development of large language model (LLM) agents has enabled their broad adoption across diverse real-world tasks. To standardize interactions between LLM agents and external environments, Model Context Protocol (MCP) tools have emerged as a de facto standard and have been widely integrated into these systems. However, the use of MCP tools also introduces new safety risks, as LLM agents can be induced to perform malicious or unauthorized actions. Although prior work has proposed defenses for securing tool use in LLM agents, most methods rely on static analysis, i.e., inspecting prompts and generated outputs, which limits the defense effectiveness and robustness. To address these limitations, we propose MTGuard, a hybrid analysis-based defense framework designed to safeguard the use of MCP tools in LLM agents by leveraging lifecycle-aware static-dynamic co-analysis. Extensive evaluation demonstrates that MTGuard effectively mitigates multiple categories of harmful tool use across different LLM agents while maintaining performance on benign user tasks.

cs.CR

Weak Equilibrium Measures and Capacity--Hitting Identities for the Hypoelliptic Third-Order Langevin Diffusion

We construct weak equilibrium measures and weak capacities for the hypoelliptic third-order Langevin diffusion motivated by an accelerated sampling algorithm (Mou et al. (2021) \textit{J. Mach. Learn. Res.}, \textbf{22}(42), 1--41). In this process, the Brownian noise acts only in the highest-order auxiliary variable and reaches the physical variables through a step-three H\"ormander chain, so the standard uniformly elliptic boundary-flux theory is not directly applicable at characteristic points of phase-space balls. We prove an elliptic-regularization stability theorem for the corresponding hitting laws and then define the weak equilibrium measure and weak capacity. The proof combines the boundary-hitting stability strategy of Lee--Ramil--Seo (2026, \textit{arXiv:2503.12610v2}) with localized hypoelliptic heat-kernel estimates (Pigato (2022) \textit{Stoch. Process. Appl.}, \textbf{145}, 117--142) adapted to the third-order chain. We obtain the bounded-domain weak capacity--hitting identity and a Lyapunov drift argument in the spirit of Lee--Ramil--Seo that yields positive Harris recurrence and extends the construction to a whole-space weak equilibrium measure, and whole-space capacity--hitting identity.

math.PR

Learning from Synthetic Data without Model Collapse in Iterative Instruction Tuning

Model collapse is a central challenge in learning from synthetic data: as later-generation large language models (LLMs) are trained on an increasing proportion of model-generated data, performance can degrade due to narrowed coverage and accumulated bias. Existing work mainly studies how to bound this degradation. In iterative model evolution, however, the more meaningful objective is to ensure that each successive model improves over its predecessor, which requires diagnosing collapse at a granularity that is actionable for data curation. We study this problem in synthetic data self-improving for instruction tuning. We show that collapse in this setting is not simply uniform performance degradation, but can appear as a polarization of competence, where synthetic training reinforces already strong skills while further degrading weak ones. Motivated by this observation, we propose KITE (Knowledge-boundary Instruction Tuning via Exploration), a two-stage framework that combines failure-guided data generation with boundary-aware uncertainty curation. Experiments across several datasets and multiple open-source LLMs show that KITE yields more stable improvement than strong synthetic-data baselines.

cs.CL

FlashDiff: Efficient Regional Execution and Scheduling for Diffusion Model Serving

Diffusion models have become the central backbone for modern image, video, and audio generation, but their efficient service remains a challenge. Unlike autoregressive decoding, diffusion inference repeatedly updates high-dimensional spatial or temporal latents over many denoising steps. This all-region execution pattern makes generation latency high and limits serving throughput. Existing multi-GPU parallelization methods can reduce per-step computation, but often introduce substantial activation exchange overhead, causing communication to offset or even outweigh the benefits of parallel execution. This paper presents FlashDiff, a diffusion serving system that improves inference efficiency through adaptive regional execution and scheduling. FlashDiff is based on the observation that diffusion refinement is not uniform across latent regions or denoising steps: different regions often stabilize at different rates, while neighboring steps exhibit strong temporal correlation. FlashDiff leverages these properties to selectively execute only regions that require further refinement and to reallocate the resulting compute slack across concurrent serving requests. FlashDiff consists of three mechanisms. First, it decomposes the latent representation into coherent execution regions using early-stage attention signals, preserving semantic structure while exposing fine-grained parallelism. Second, it uses a lightweight runtime controller to estimate region activity and bypass low-impact updates when further refinement is unlikely to affect output quality. Third, it applies an affinity-aware online scheduler that co-locates dependent regions, balances residual load across GPUs, and reuses reclaimed compute capacity to improve serving efficiency. Across real-world image, video, and audio workloads, FlashDiff reduces end-to-end serving latency by 30-97% and improves throughput by 1.2-2.2x.

cs.DC

PhysMiner: An Agentic AI Framework for Discovering Turbulence Physics

Uncovering the physical mechanisms of turbulent flows remains a fundamental challenge in fluid mechanics. In particular, conventional velocity-gradient analysis methods suffer from shear contamination, which hinders accurate identification of the dominant physical mechanisms. This study presents PhysMiner, an automated framework integrating the triple decomposition method of the velocity gradient tensor with large language model-driven reasoning for turbulence-physics discovery. The triple decomposition module automatically decomposes flow fields into rigid rotation, pure shearing, and normal straining components, enabling statistical analysis, contour visualization, vortex-line extraction, and threshold-insensitive vortex identification while eliminating shear contamination. These automated capabilities are validated across five benchmarks, ranging from canonical configurations to complex engineering flows. A discover-physics agent combines flow statistics, spatial structures, and literature-derived knowledge to perform pattern recognition and physical inference, while a review Agent iteratively validates physical consistency to ensure reliable conclusions. A continuously evolving Triple Decomposition Library accumulates statistical knowledge from successfully analyzed flows, enabling cross-case comparison and progressive enhancement of inductive capability. The complete PhysMiner pipeline is validated end-to-end on the periodic hill flow, where the framework autonomously generates turbulence modeling recommendations and derives an improved subgrid-scale model with superior Reynolds-stress predictions. PhysMiner is open to the public and establishes a foundation for long-term collaborative advancement in automated turbulence-physics discovery.

physics.flu-dyn

Splitting Rules from Kinematic Flow: Local Evolution and Emergent Time

The differential equations satisfied by the wavefunction coefficients of conformally coupled scalars in a power-law cosmology can be recast as an iterative differential system of basis functions. These functions can be encoded within graph tubings and are governed by a set of rules describing how they flow in kinematic space. In this paper, we formulate a set of splitting rules equivalent to the kinematic flow at tree level by reversing the flow direction of graph tubings. Specifically, for any basis function, these rules identify all other basis functions whose total differentials contain it. From the splitting perspective, we uncover deeper physical information captured by graph tubings, such as the formation of singularity structures and the realization of local evolution. In an alternative basis based on time ordering, the splitting processes correspond to the emergence of time integrals. These rules can also be generalized naturally to the $\mathrm{tr}\,\phi^3$ theory beyond individual graphs, providing a physical interpretation of the structure of the associahedron. This suggests that graph tubings and the kinematic flow may be more fundamental objects than the differential equations, and may have a life of their own.

hep-th

Min Generalized Sliced Gromov Wasserstein: A Scalable Path to Gromov Wasserstein

We propose min Generalized Sliced Gromov--Wasserstein (min-GSGW), a sliced formulation for the Gromov--Wasserstein (GW) problem using expressive generalized slicers. The key idea is to learn coupled nonlinear slicers that assign compatible push-forward values to both input measures, so that monotone coupling in the projected domain lifts to a transport plan evaluated against the GW objective in the original spaces. The resulting plan induces a GW objective value, and min-GSGW minimizes this cost directly in the original spaces. We further show that min-GSGW is rigid-motion invariant, a crucial property for geometric matching and shape analysis tasks. Our contributions are threefold: 1) we introduce generalized slicers into the sliced GW framework, 2) we construct a slicing-based efficient GW transport plan; and 3) we develop an amortized variant that replaces per-instance optimization with a learned slicer for unseen input pairs. We perform experiments on animal mesh matching, horse mesh interpolation, and ShapeNet part transfer. Results show that min-GSGW produces meaningful geometric correspondences and GW objective values at substantially lower computational cost than existing GW solvers.

cs.LG

Compiling Activation Steering into Weights via Null-Space Constraints for Stealthy Backdoors

Safety-aligned large language models (LLMs) are increasingly deployed in real-world pipelines, yet this deployment also enlarges the supply-chain attack surface: adversaries can distribute backdoored checkpoints that behave normally under standard evaluation but jailbreak when a hidden trigger is present. Recent post-hoc weight-editing methods offer an efficient approach to injecting such backdoors by directly modifying model weights to map a trigger to an attacker-specified response. However, existing methods typically optimize a token-level mapping that forces an affirmative prefix (e.g., ``Sure''), which does not guarantee sustained harmful output -- the model may begin with apparent agreement yet revert to safety-aligned refusal within a few decoding steps. We address this reliability gap by shifting the backdoor objective from surface tokens to internal representations. We extract a steering vector that captures the difference between compliant and refusal behaviors, and compile it into a persistent weight modification that activates only when the trigger is present. To preserve stealthiness and benign utility, we impose a null-space constraint so that the injected edit remains dormant on clean inputs. The method is efficient, requiring only a small set of examples and admitting a closed-form solution. Across multiple safety-aligned LLMs and jailbreak benchmarks, our method achieves high triggered attack success while maintaining non-triggered safety and general utility.

cs.CR

Sinkhorn-Drifting Generative Models

We establish a theoretical link between the recently proposed "drifting" generative dynamics and gradient flows induced by the Sinkhorn divergence. In a particle discretization, the drift field admits a cross-minus-self decomposition: an attractive term toward the target distribution and a repulsive/self-correction term toward the current model, both expressed via one-sided normalized Gibbs kernels. We show that Sinkhorn divergence yields an analogous cross-minus-self structure, but with each term defined by entropic optimal-transport couplings obtained through two-sided Sinkhorn scaling (i.e., enforcing both marginals). This provides a precise sense in which drifting acts as a surrogate for a Sinkhorn-divergence gradient flow, interpolating between one-sided normalization and full two-sided Sinkhorn scaling. Crucially, this connection resolves an identifiability gap in prior drifting formulations: leveraging the definiteness of the Sinkhorn divergence, we show that zero drift (equilibrium of the dynamics) implies that the model and target measures match. Experiments show that Sinkhorn drifting reduces sensitivity to kernel temperature and improves one-step generative quality, trading off additional training time for a more stable optimization, without altering the inference procedure used by drift methods. These theoretical gains translate to strong low-temperature improvements in practice: on FFHQ-ALAE at the lowest temperature setting we evaluate, Sinkhorn drifting reduces mean FID from 187.7 to 37.1 and mean latent EMD from 453.3 to 144.4, while on MNIST it preserves full class coverage across the temperature sweep. Project page: https://mint-vu.github.io/SinkhornDrifting/

cs.LG

FraudShield: Knowledge Graph Empowered Defense for LLMs against Fraud Attacks

Large language models (LLMs) have been widely integrated into critical automated workflows, including contract review and job application processes. However, LLMs are susceptible to manipulation by fraudulent information, which can lead to harmful outcomes. Although advanced defense methods have been developed to address this issue, they often exhibit limitations in effectiveness, interpretability, and generalizability, particularly when applied to LLM-based applications. To address these challenges, we introduce FraudShield, a novel framework designed to protect LLMs from fraudulent content by leveraging a comprehensive analysis of fraud tactics. Specifically, FraudShield constructs and refines a fraud tactic-keyword knowledge graph to capture high-confidence associations between suspicious text and fraud techniques. The structured knowledge graph augments the original input by highlighting keywords and providing supporting evidence, guiding the LLM toward more secure responses. Extensive experiments show that FraudShield consistently outperforms state-of-the-art defenses across four mainstream LLMs and five representative fraud types, while also offering interpretable clues for the model's generations.

cs.CR

Assimilating rough features: A data-driven framework to infer rough wall properties from sparse experimental data

Surface roughness influences turbulent boundary layers (TBLs) primarily through the roughness function $\Delta U^+$ and the equivalent sand-grain roughness height \(k_s\). Direct determination of \(k_s\) typically requires detailed velocity and wall-shear stress measurements, which are often impractical. As an alternative, this study presents a data assimilation framework that modifies a smooth-wall Reynolds-Averaged Navier-Stokes (RANS) baseline to match sparse rough-wall particle image velocimetry (PIV) data in the fully rough regime. Through this approach, secondary variables such as the friction velocity, \(u_\tau\), and \(k_s\) can be inferred from the assimilated flow fields. The assimilated TBL reproduces experimental velocity profiles within 1\% and predicts friction velocity within 1-6\% of the experimental measurements. Furthermore, the \(k_s\) values inferred from the assimilation also match the experimental data up to 1\%. These results demonstrate the potential of data assimilation as a cost-effective alternative to high-fidelity methods and support the generalisation of the framework to model streamwise-varying roughness by treating \(k_s\) as a function of fetch length.

physics.flu-dyn

HogVul: Black-box Adversarial Code Generation Framework Against LM-based Vulnerability Detectors

Recent advances in software vulnerability detection have been driven by Language Model (LM)-based approaches. However, these models remain vulnerable to adversarial attacks that exploit lexical and syntax perturbations, allowing critical flaws to evade detection. Existing black-box attacks on LM-based vulnerability detectors primarily rely on isolated perturbation strategies, limiting their ability to efficiently explore the adversarial code space for optimal perturbations. To bridge this gap, we propose HogVul, a black-box adversarial code generation framework that integrates both lexical and syntax perturbations under a unified dual-channel optimization strategy driven by Particle Swarm Optimization (PSO). By systematically coordinating two-level perturbations, HogVul effectively expands the search space for adversarial examples, enhancing the attack efficacy. Extensive experiments on four benchmark datasets demonstrate that HogVul achieves an average attack success rate improvement of 26.05\% over state-of-the-art baseline methods. These findings highlight the potential of hybrid optimization strategies in exposing model vulnerabilities.

cs.CR

Symmetric Dicke States as Optimal Probes for Wave-Like Dark Matter

We identify symmetric Dicke states as the optimal quantum probes for distributed sensing of wave-like dark-matter fields. Within an ensemble-averaged quantum-metrological framework that incorporates the field's random phases and finite coherence, they maximize the Fisher information for short-baseline arrays with $N_d$ sensors and realize a robust $N_d^2$ enhancement. They also retain this collective advantage under amplitude-damping noise, whereas GHZ-type probes are highly fragile and rapidly lose their sensitivity once such noise is included. For two sensors at separations comparable to the dark-matter coherence length, the optimal entangled state acquires an additional spatial-correlation phase and outperforms both Dicke and independent probes. Our framework applies broadly to stochastic bosonic fields, including gravitational waves, and can be implemented with superconducting qubits, atomic ensembles, and NV centers.

hep-ph