SearcharxivSearch

arXiv subjects

Qinfeng Li

Publications and source records attributed to Qinfeng Li.

At least 19 recordsLinked to original sources

SkillAligner: Treating Retrieved Skills as Adaptable Drafts at Execution Time

General-purpose skills promise reusable procedural knowledge for language agents, yet semantic relevance does not guarantee execution utility: a retrieved skill may encode assumptions that conflict with the current task, execution environment, or other retrieved skills. We formalize this problem as the skill--execution misfit. To address it, we propose SkillAligner, a training-free execution-time skill adaptation framework that treats retrieved skills as adaptable drafts rather than fixed instructions. Before execution, SkillAligner performs a one-time joint adaptation that specializes useful skill fragments to task requirements, aligns their procedural assumptions with the available execution interface, and composes the resulting guidance by resolving dependencies, conflicts, and redundancy across skills. The adapted content is consolidated into a compact execution guide and reused throughout the subsequent trajectory. Extensive experiments across diverse agent benchmarks and model backbones show that SkillAligner substantially improves task performance over existing skill-use baselines, reduces skill-induced regressions at the instance level, and lowers total inference cost.

cs.LG

A Quantitative P\'olya--Szeg\H{o} Theorem for Tangential Polygons

For a bounded Lipschitz domain $\Omega\subset\mathbb R^2$, let $T(\Omega)=\int_\Omega u_\Omega\, dx$ denote its torsional rigidity, where $-\Delta u_\Omega=1$ in $\Omega$ and $u_\Omega=0$ on $\partial\Omega$. We prove a quantitative P\'olya--Szeg\H{o} inequality for tangential polygons. Let $N\ge3$, let $P$ be a tangential $N$-gon, set $A=|P|$, and let $R_N$ be the regular $N$-gon of area $A$. Writing $L(\cdot)$ for perimeter, we obtain the explicit deficit estimate \[ T(R_N)-T(P)\ge \frac{A^2}{8N\tan(\pi/N)} \left(1-\frac{L(R_N)^2}{L(P)^2}\right)^2.\]Thus, at fixed area, the torsional deficit is controlled from below purely by the perimeter ratio. In particular, the regular $N$-gon is the unique maximizer of torsional rigidity among tangential $N$-gons of prescribed area; for $N=3$ this gives the classical triangular P\'olya--Szeg\H{o} theorem with a quantitative estimate. The same perimeter estimate yields an explicit positive lower bound for $T(R_{N+1})-T(R_N)$ for equal-area regular polygons, and hence a rather short alternative proof of the strict monotonicity of torsional rigidity in $N$. Combined with the Kohler--Jobin inequality, it also gives an explicit sufficient condition for the polygonal Faber--Krahn inequality within the tangential class. Our full quantitative inequality is stronger: it contains, in addition, a nonnegative angular Jensen deficit, which yields quantitative angular stability away from degenerate configurations.

math.AP

AttriMem: Attribution-Guided Process Feedback for Agent Memory Construction

Effective memory is crucial for LLM agents, yet constructing it effectively remains challenging. A memory-construction policy decides what information to extract, store, update, compress, or discard as interactions accumulate. Heuristic memory methods rely on subjective, task-specific rules, which can misalign with downstream objectives and limit cross-task adaptability. RL-based methods, by contrast, learn from task feedback but mainly use outcome- or module-level rewards. These coarse signals indicate task success but cannot identify which intermediate memory contents support the final answer, creating a fine-grained credit-assignment bottleneck. However, constructing such process feedback is prohibitively difficult because intermediate memory decisions lack unique ground-truth targets, while the appropriate credit varies with the agent's uncertain reasoning trajectory and therefore cannot be specified in advance. We propose AttriMem, an attribution-guided process-feedback framework for learning memory-construction policies with RL. AttriMem augments the global outcome reward with local rewards derived from token-level contributions to the final answer. Experiments on long-horizon dialogue question answering show that AttriMem outperforms retrieval-based, heuristic, and RL-based baselines, generalizes across benchmarks and answer models, stabilizes RL optimization.

cs.AI

Serrin's Problem under Dirichlet Perturbations: Geometric Compactness and Sharp Planar Stability

In earlier work [21], we posed a stability question for Serrin's overdetermined problem under Dirichlet perturbations and proved that the answer is negative in dimensions $n\ge3$. Here we resolve the question in the planar convex class and obtain a sharp quantitative theory without any a priori geometric nondegeneracy. Let $u_\Omega$ solve \[ -\Delta u_\Omega=1\ \text{in }\Omega,\qquad \partial_\nu u_\Omega=-\frac{|\Omega|}{P(\Omega)}\ \text{on }\partial\Omega, \qquad \int_{\partial\Omega}u_\Omega\,d\sigma=0, \] and set $O(\Omega):=\text{osc}_{\partial \Omega}u_\Omega$. We construct fixed-area annuli with $O(\Omega_k)\to0$ that remain far from every disk, showing that convexity is essential in dimension two. By contrast, if $\Omega_k\subset\mathbb R^2$ are convex, $|\Omega_k|=\pi$, and $O(\Omega_k)\to0$, then, up to translations, $\Omega_k$ converges in Hausdorff distance to the unit disk. Moreover, \[ R_\Omega-r_\Omega+\inf_{z\in\mathbb R^2}d_H(\Omega,B_1(z)) \le C\,O(\Omega) \] for all planar convex $\Omega$ with $|\Omega|=\pi$ and sufficiently small $O(\Omega)$, and the linear order is optimal. The proof combines a new mechanism excluding long-thin degeneration, the rough-domain Serrin rigidity theorem of Figalli--Zhang, new tangential-gradient and linear boundary-growth estimates, a boundary $P$-function estimate, and the reverse-Serrin identity of Magnanini--Molinarolo--Poggesi. We also study the weaker deficit \[ A(\Omega):=\frac1{P(\Omega)}\int_{\partial\Omega}u_\Omega,d\sigma-\min_{\partial\Omega}u_\Omega. \] In the planar convex class, $A(\Omega_k)\to0$ still forces convergence to a disk, and \[ R_\Omega-r_\Omega+\inf_z d_H(\Omega,B_1(z)) \le C A(\Omega)^{2/3} \] for $|\Omega|=\pi$ and sufficiently small $A(\Omega)$.

math.AP

Mixed Torsion on Right Triangles and the P\'olya--Szeg\H{o} Monotonicity Problem for Regular Polygons

Motivated by the polygonal P\'olya--Szeg\H{o} conjecture for torsional rigidity, we study two monotonicity problems for torsional rigidity. The first concerns a mixed torsion problem on fixed-area right triangles, with a Dirichlet condition on one leg and Neumann conditions on the other leg and on the hypotenuse. We prove that the mixed torsional rigidity strictly increases as the ratio of the Neumann leg to the Dirichlet leg increases. The proof uses a Hadamard shape derivative, a Pohozaev-type identity, and a monotonicity result for the mixed torsion function. We also prove a similar result for the mixed ground state of Laplacian. The second concerns regular polygons. If \(P_N\) denotes the regular \(N\)-gon of area \(\pi\), we prove, by a purely analytic Schwarz--Christoffel/Bergman analytic-content argument, that \[ T^D(P_{N+1})>T^D(P_N),\qquad N\ge3, \] where \(T^D\) is the Dirichlet torsional rigidity. We also obtain the asymptotic expansion \[ T^D(P_N)=\frac{\pi}{8}-\frac{\pi\zeta(3)}{N^3} +\frac{\pi^5}{45N^4}+O(N^{-5}). \]

math.AP

PragLocker: Protecting Agent Intellectual Property in Untrusted Deployments via Non-Portable Prompts

LLM agents rely on prompts to implement task-specific capabilities based on foundation LLMs, making agent prompts valuable intellectual property. However, in untrusted deployments, adversaries can copy and reuse these prompts with other proprietary LLMs, causing economic losses. To protect these prompts, we identify four key challenges: proactivity, runtime protection, usability, and non-portability that existing approaches fail to address. We present PragLocker, a prompt protection scheme that satisfies these requirements. PragLocker constructs function-preserving obfuscated prompts by anchoring semantics with code symbols and then using target-model feedback to inject noise, yielding prompts that only work on the target LLM. Experiments across multiple agent systems, datasets, and foundation LLMs show that PragLocker substantially reduces cross-LLM portability, maintains target performance, and remains robust against adaptive attackers.

cs.CR

Towards Steering without Sacrifice: Principled Training of Steering Vectors for Prompt-only Interventions

Recently, steering vectors (SVs) have emerged as an effective and lightweight approach to steer behaviors of large language models (LLMs), among which fine-tuned SVs are more effective than optimization-free ones. However, current approaches to fine-tuned SVs suffer from two limitations. First, they require careful selection of steering factors on a per-SV basis to balance steering effectiveness and generation quality at inference time. Second, they operate as full-sequence SVs (FSSVs), which can sacrifice generation quality regardless of factor selection due to excessive intervention on the model generation process. To address the first limitation, we propose joint training of steering factors and directions, such that post-hoc factor selection is no longer required. Using neural network scaling theory, we find that moderately large initialization sizes and learning rates for steering factors are essential for stability and efficiency of joint training. To tackle the second limitation, we draw inspiration from representation fine-tuning and introduce Prompt-only SV (PrOSV), an SV that intervenes only on a few prompt tokens. Our empirical results show that PrOSV outperforms traditional FSSVs on AxBench when using our joint training scheme. We also find that PrOSV achieves a better tradeoff between general model utility and adversarial robustness than FSSV.

cs.LG

Monotonicity of the first nonzero Steklov eigenvalue of regular $N$-gon with fixed perimeter

We study the first nontrivial Steklov eigenvalue of perimeter-normalized regular \(N\)-gons and show that it is strictly increasing in \(N\). The proof mainly relies on an analytic framework that establishes a refined asymptotic expansion in three steps: first, identifying the Steklov eigenvalue as the maximal eigenvalue of a Toeplitz-type operator; second, deriving the eigenvalue and its associated eigenfunctions simultaneously via Schur reduction; and finally, obtaining the exact coefficients in the Schur moment expansion by evaluating Euler-type sums. The monotonicity is proved to be eventual, holding for \(N\ge 20\). For the remaining cases \(3\le N\le 20\), we provide complementary computer-assisted verification, confirming monotonicity across the full range of \(N\).

math.AP

CryptoTensors: A Light-Weight Large Language Model File Format for Highly-Secure Model Distribution

To enhance the performance of large language models (LLMs) in various domain-specific applications, sensitive data such as healthcare, law, and finance are being used to privately customize or fine-tune these models. Such privately adapted LLMs are regarded as either personal privacy assets or corporate intellectual property. Therefore, protecting model weights and maintaining strict confidentiality during deployment and distribution have become critically important. However, existing model formats and deployment frameworks provide little to no built-in support for confidentiality, access control, or secure integration with trusted hardware. Current methods for securing model deployment either rely on computationally expensive cryptographic techniques or tightly controlled private infrastructure. Although these approaches can be effective in specific scenarios, they are difficult and costly for widespread deployment. In this paper, we introduce CryptoTensors, a secure and format-compatible file structure for confidential LLM distribution. Built as an extension to the widely adopted Safetensors format, CryptoTensors incorporates tensor-level encryption and embedded access control policies, while preserving critical features such as lazy loading and partial deserialization. It enables transparent decryption and automated key management, supporting flexible licensing and secure model execution with minimal overhead. We implement a proof-of-concept library, benchmark its performance across serialization and runtime scenarios, and validate its compatibility with existing inference frameworks, including Hugging Face Transformers and vLLM. Our results highlight CryptoTensors as a light-weight, efficient, and developer-friendly solution for safeguarding LLM weights in real-world and widespread deployments.

cs.CR

RAGFort: Dual-Path Defense Against Proprietary Knowledge Base Extraction in Retrieval-Augmented Generation

Retrieval-Augmented Generation (RAG) systems deployed over proprietary knowledge bases face growing threats from reconstruction attacks that aggregate model responses to replicate knowledge bases. Such attacks exploit both intra-class and inter-class paths, progressively extracting fine-grained knowledge within topics and diffusing it across semantically related ones, thereby enabling comprehensive extraction of the original knowledge base. However, existing defenses target only one path, leaving the other unprotected. We conduct a systematic exploration to assess the impact of protecting each path independently and find that joint protection is essential for effective defense. Based on this, we propose RAGFort, a structure-aware dual-module defense combining "contrastive reindexing" for inter-class isolation and "constrained cascade generation" for intra-class protection. Experiments across security, performance, and robustness confirm that RAGFort significantly reduces reconstruction success while preserving answer quality, offering comprehensive defense against knowledge base extraction attacks.

cs.AI

Do Not Merge My Model! Safeguarding Open-Source LLMs Against Unauthorized Model Merging

Model merging has emerged as an efficient technique for expanding large language models (LLMs) by integrating specialized expert models. However, it also introduces a new threat: model merging stealing, where free-riders exploit models through unauthorized model merging. Unfortunately, existing defense mechanisms fail to provide effective protection. Specifically, we identify three critical protection properties that existing methods fail to simultaneously satisfy: (1) proactively preventing unauthorized merging; (2) ensuring compatibility with general open-source settings; (3) achieving high security with negligible performance loss. To address the above issues, we propose MergeBarrier, a plug-and-play defense that proactively prevents unauthorized merging. The core design of MergeBarrier is to disrupt the Linear Mode Connectivity (LMC) between the protected model and its homologous counterparts, thereby eliminating the low-loss path required for effective model merging. Extensive experiments show that MergeBarrier effectively prevents model merging stealing with negligible accuracy loss.

cs.CR

Monotonicity properties of the Robin torsion function in a class of symmetric planar domains

We prove the monotonicity property of the Robin torsion function in a smooth planar domain $\Omega$ with a line of symmetry, provided that the Robin coefficient $\beta$ is greater than or equal to the negative of the boundary curvature $\kappa$ (i.e., $\beta \geq -\kappa$ on $\partial\Omega$). We also show that this condition is, in a certain sense, sharp by constructing a counterexample.

math.AP

Flow approach on Riesz type nonlocal energies

Via continuous deformations based on natural flow evolutions, we prove several novel monotonicity results for Riesz-type nonlocal energies on triangles and quadrilaterals. Some of these results imply new and simpler proofs for known theorems without relying on any symmetrization arguments.

math.AP

A flow approach to the monotonicity of shape functionals

We develop a geometric flow framework to investigate two classical shape functionals: the torsional rigidity and the first Dirichlet eigenvalue of the Laplacian. First, by constructing novel deformation paths governed by height-stretching flows, leg-stretching flows, and angle-bisector flows, we prove new monotonicity properties for these functionals under deformations of triangles and rhombuses. These results also lead to new and simpler proofs of some known results, without using the Steiner symmetrization argument. Second, we introduce a mean curvature flow approach to the Saint-Venant inequality, providing a new geometric proof for smooth convex domains. We establish a weak monotonicity property along the flow and characterize the equality case, which leads to the discovery of an intriguing new functional whose extremal properties suggest a further conjecture. Third, by discovering a gradient norm inequality for the sides of rectangles, we prove monotonicity and rigidity results of the torsional rigidity on rectangles.

math.AP

HijackRAG: Hijacking Attacks against Retrieval-Augmented Large Language Models

Retrieval-Augmented Generation (RAG) systems enhance large language models (LLMs) by integrating external knowledge, making them adaptable and cost-effective for various applications. However, the growing reliance on these systems also introduces potential security risks. In this work, we reveal a novel vulnerability, the retrieval prompt hijack attack (HijackRAG), which enables attackers to manipulate the retrieval mechanisms of RAG systems by injecting malicious texts into the knowledge database. When the RAG system encounters target questions, it generates the attacker's pre-determined answers instead of the correct ones, undermining the integrity and trustworthiness of the system. We formalize HijackRAG as an optimization problem and propose both black-box and white-box attack strategies tailored to different levels of the attacker's knowledge. Extensive experiments on multiple benchmark datasets show that HijackRAG consistently achieves high attack success rates, outperforming existing baseline attacks. Furthermore, we demonstrate that the attack is transferable across different retriever models, underscoring the widespread risk it poses to RAG systems. Lastly, our exploration of various defense mechanisms reveals that they are insufficient to counter HijackRAG, emphasizing the urgent need for more robust security measures to protect RAG systems in real-world deployments.

cs.CR

CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment

Proprietary large language models (LLMs) exhibit strong generalization capabilities across diverse tasks and are increasingly deployed on edge devices for efficiency and privacy reasons. However, deploying proprietary LLMs at the edge without adequate protection introduces critical security threats. Attackers can extract model weights and architectures, enabling unauthorized copying and misuse. Even when protective measures prevent full extraction of model weights, attackers may still perform advanced attacks, such as fine-tuning, to further exploit the model. Existing defenses against these threats typically incur significant computational and communication overhead, making them impractical for edge deployment. To safeguard the edge-deployed LLMs, we introduce CoreGuard, a computation- and communication-efficient protection method. CoreGuard employs an efficient protection protocol to reduce computational overhead and minimize communication overhead via a propagation protocol. Extensive experiments show that CoreGuard achieves upper-bound security protection with negligible overhead.

cs.CR

On the location of the maximal gradient of the torsion function over some non-symmetric planar domains

We investigate the location of the maximal gradient of the torsion function on certain non-symmetric planar domains. First, by establishing uniform estimates for convex narrow domains, we show that as a planar domain bounded by two graphs becomes increasingly narrow, the location of the maximal gradient of its torsion function converges to the endpoints of the longest vertical segment, with smaller curvature among them. This result confirms that Saint-Venant's conjecture on the location of fail points holds for asymptotically narrow domains. Second, for triangles, we prove that the maximal gradient of the torsion function always occurs on the longest side, lying between the foot of the altitude and the midpoint of that side. Moreover, via nodal line analysis, we show that, restricted to each side, the critical point of the gradient is unique and non-degenerate. Additionally, by perturbation and barrier arguments, we establish that for a class of nearly equilateral triangles, this critical point is closer to the midpoint than to the foot of the altitude, and the maximal gradient at the midpoint exceeds that at the foot of the altitude. Third, employing the reflection method, we demonstrate that for a non-concentric annulus, the maximal gradient of the torsion function is always attained at the point on the inner boundary closest to the center of the outer boundary.

math.AP

On Laplacian eigenvalue equation with constant Neumann boundary data

Let $Ω$ be a bounded Lipshcitz domain in $\mathbb{R}^n$ and we study boundary behaviors of solutions to the Laplacian eigenvalue equation with constant Neumann data. \begin{align} \label{cequation0} \begin{cases} -Δu=cu\quad &\mbox{in $Ω$}\\ \frac{\partial u}{\partial ν}=-1\quad &\mbox{on $\partial Ω$}. \end{cases} \end{align}First, by using properties of Bessel functions and proving new inequalities on elementary symmetric polynomials, we obtain the following inequality for rectangular boxes, balls and equilateral triangles: \begin{align} \label{bbb} \lim_{c\rightarrow μ_2^-}c\int_{\partial Ω}u_c\, dσ\ge \frac{n-1}{n}\frac{P^2(Ω)}{|Ω|}, \end{align}with equality achieved only at cubes and balls. In the above, $u_c$ is the solution to the eigenvalue equation and $μ_2$ is the second Neumann Laplacian eigenvalue. Second, let $κ_1$ be the best constant for the Poincaré inequality with mean zero on $\partial Ω$, and we prove that $κ_1\le μ_2$, with equality holds if and only if $\int_{\partial Ω}u_c\, dσ>0$ for any $c\in (0,μ_2)$. As a consequence, $κ_1=μ_2$ on balls, rectangular boxes and equilateral triangles, and balls maximize $κ_1$ over all Lipschitz domains with fixed volume. As an application, we extend the symmetry breaking results from ball domains obtained in Bucur-Buttazzo-Nitsch[J. Math. Pures Appl., 2017], to wider class of domains, and give quantitative estimates for the precise breaking threshold at balls and rectangular boxes. It is a direct consequence that for domains with $κ_1<μ_2$, the above boundary limit inequality is never true, while whether it is valid for domains on which $κ_1=μ_2$ remains open.

math.AP