SearcharxivSearch

arXiv subjects

Xiaoping Zhang

Publications and source records attributed to Xiaoping Zhang.

At least 19 recordsLinked to original sources

INTENT-AS-A-TOOL Makes it Easy to Track Agentic Misalignment

As large language models (LLMs) are deployed as autonomous agents, safety failures increasingly involve consequential actions. We study agentic misalignment, where agents take harmful actions under goal conflicts and pressures. Using chain-of-thought (CoT) monitoring, we find that harmful execution is often preceded by intent signals in reasoning. However, post-hoc CoT labels are too coarse to show how intent changes during generation. We introduce INTENT-AS-A-TOOL, an approach that adds intent-targeted tools to give the model a dedicated channel for expressing commitment to a target behavior. The probability of calling an intent tool provides a judge-free, fine-grained signal of the model's tendency to pursue that behavior. Our results show that INTENT-AS-A-TOOL complements CoT monitoring, expands post-hoc CoT labels into dense trajectories, and identifies critical steps for online intervention. These findings suggest that action preferences are useful for tracking agentic misalignment during reasoning. Our code and data are accessible: https://github.com/RebeccaZhang22/intent-as-a-tool.

cs.CL

The Model's Tell: Measuring Context-Leakage Attack Signals with Behavior Gauges

LLMs increasingly rely on external contexts, such as pre-defined system prompts or retrieved documents, to improve generation quality. However, processing these contexts alongside user queries creates an attack surface: adversarial inputs can induce models to disclose them. Prior probing studies suggest that leakage-related signals emerge in hidden states, yet the need to extract these states poses additional deployment challenges. In this paper, we explore whether this internal signal leaves a more accessible ``tell'' before decoding. We propose LeakGauge, which probes this response by appending a suffix that gauges leakage behavior and mapping its prefill token probabilities to an attack-risk score. While a direct gauge uses the initial tokens of confidential content, we find that a content-agnostic one that verbalizes leakage behavior yields more robust signals. Across 11 LLMs, including GLM-5.2 (753B) and Kimi-K3 (2.8T), LeakGauge reaches an AUROC range of 0.944--0.996 on unseen attacks. The signal remains stable when the content changes language or the attack shifts from verbatim to semantic disclosure. By activation-steering interventions, we further show that the risk score is sensitive to an internal leakage-related direction, relating the observable signal to the model's internal representation. In addition, LeakGauge enables an input detector with fewer than 0.5K extra parameters and added latency of 10.34 ms. Code: \href{https://github.com/yeasen-z/LeakGauge}.

cs.CR

Your Agentic LLMs Secretly Encode Indirect Prompt-Injection Exposure in Hidden States

Agentic LLMs are vulnerable to indirect prompt injection (IPI) attacks, e.g., malicious side-tasks hidden in external tool results. While many efforts have sought to address this threat, little is known about the internals of agentic LLMs when they are exposed to IPI attacks. For simplicity, we refer to this condition as IPI exposure. In this paper, we study IPI exposure from three perspectives. (1) Probing: Across eight models, including the 753B-parameter GLM-5.2 and the 2.8T-parameter Kimi-K3, simple linear probes trained on pre-generation hidden states can predict LLMs' IPI exposure. These probes achieve 0.90+ AUROC on unseen attacks, agent instructions, and task suites; they remain robustly predictive under adaptive attacks and in cross-lingual settings. (2) Defense: We reveal and diagnose a knowledge-action gap: post-trained LLMs encode signals predictive of IPI exposure, yet do not reliably bind these signals to safe agentic actions. We therefore introduce a probe-gated reasoning-based defense to bridge this gap at test time. On difficult AgentDojo settings, it substantially reduces attack success rate, e.g., from 34.6% to 0% on Qwen3.5-27B, and better preserves clean-task utility than the baselines. (3) Explanation: We introduce an analysis framework that identifies natural-language explanations strongly correlated with probe-captured signals. The resulting profiles differ across models: latent signals can align with either direct IPI-exposure sensing or indirect operational cues. Code is available at https://github.com/jianshuod/IPI-exposure-signal.

cs.CR

ICME 2026 Grand Challenge on Cross-Scenario Defect Detection and Fine-Grained Severity Grading for High-Precision Manufacturing

This paper presents the IEEE International Conference on Multimedia and Expo (ICME) 2026 Grand Challenge on Cross-Scenario Defect Detection and Fine-Grained Severity Grading for High-Precision Manufacturing. The challenge is motivated by two key limitations of existing industrial defect inspection systems: (1) current deep learning-based methods often suffer significant performance degradation when deployed in unseen production scenarios, and (2) most benchmarks neglect severity-aware assessment, which is critical for risk control and yield optimization. To address these limitations, we design two complementary tracks: Track 1 (Cross-Scenario Defect Detection) targets accurate defect detection, localization, and classification across diverse unseen production environments; Track 2 (Fine-Grained Severity Grading) requires assigning each detected defect an industry-standard severity level, including Acceptable, Marginal NG, NG, and Gross NG. We construct a large-scale industrial dataset of high-resolution microscopic images spanning seven representative defect categories, comprising over 3,800 images with pixel-level instance annotations for Track 1 and over 2,600 images with severity-grade labels for Track 2. The challenge attracted 86 registered participants with 130 submissions; during the final testing phase, 21 teams submitted results and 12 teams provided models with technical reports. The resulting benchmark, together with the diverse and effective solutions contributed by participating teams, sets a new standard for industrial defect analysis research.

cs.CV

Numerical estimation of the capture ability of Neptunian mean motion resonances

Resonant populations of trans-Neptunian objects serve as crucial dynamical archives for unraveling the early migratory history of the Solar System. A quantitative assessment of the capture efficiency into various mean motion resonances (MMRs) during migration is essential for understanding the origins of these populations, constraining migration parameters, and reconstructing of the primordial planetesimal disk. Using numerical simulations, this study systematically investigates the capture capability of exterior MMRs during Neptune's outward migration in a planar model. For a specific p:q MMR, the small bodies can be captured only when their eccentricities surpass a certain threshold, which increases with faster migration rates, greater distances of MMRs, and higher resonance orders. On the other hand, as long as a particle's eccentricity is suitable, its capture efficiency shows little dependence on the migration rate; instead, it mainly depends on the p value and heliocentric distance, decaying exponentially as either parameter increases. Based on our simulation results, we derive for the first time a simple empirical expression to calculate eccentricity threshold and the capture efficiency. This research provides a systematic quantitative framework for understanding capture into Neptunian MMRs during migration. Future integrations of more comprehensive observational data will facilitate a more precise reconstruction of the Solar System's early dynamical evolution.

astro-ph.EP

Lunar ejecta as the missing piece to resolve the lunar cratering asymmetry

The leading-trailing asymmetry in lunar crater distribution provides a critical record of inner solar system dynamics, yet the long-standing discrepancy between the observed higher asymmetry and lower theoretical predictions indicates a gap in our understanding of the impactor population. This paper hypothesizes that lunar impact ejecta, which can enter Earth-like orbits and return, constitute a previously unaccounted-for component. Through numerical simulations, we find that ~25% of escaped ejecta will re-impact the Earth-Moon system within 3 Myr, with about 1.2% striking the Moon. Crucially, these lunar impacts exhibit an extreme leading-trailing asymmetry with a ratio of 5.9. Our results indicate that lunar ejecta, if comprising ~15% of total impactors, can fully explain the observed asymmetry, leading to their recognition as active agents shaping the lunar impact record. This work provides new constraints for understanding the impact environment of the Earth-Moon system, with direct relevance to the interpretation of lunar geology, the transport of lunar material to Earth, and ongoing space exploration missions.

astro-ph.EP

LeakDojo: Decoding the Leakage Threats of RAG Systems

Retrieval-Augmented Generation (RAG) enables large language models (LLMs) to leverage external knowledge, but also exposes valuable RAG databases to leakage attacks. As RAG systems grow more complex and LLMs exhibit stronger instruction-following capabilities, existing studies fall short of systematically assessing RAG leakage risks. We present LeakDojo, a configurable framework for controlled evaluation of RAG leakage. Using LeakDojo, we benchmark six existing attacks across fourteen LLMs, four datasets, and diverse RAG systems. Our study reveals that (1) query generation and adversarial instructions contribute independently to leakage, with overall leakage well approximated by their product; (2) stronger instruction-following capability correlates with higher leakage risk; and (3) improvements in RAG faithfulness can introduce increased leakage risk. These findings provide actionable insights for understanding and mitigating RAG leakage in practice. Our codebase is available at https://github.com/yeasen-z/LeakDojo.

cs.CR

Generalized Transferable Neural Networks for Steady-State Partial Differential Equations

Deep learning has emerged as a compelling framework for scientific and engineering computing, motivating growing interest in neural network-based solvers for partial differential equations (PDEs). Within this landscape, network architectures with deterministic feature construction have become an appealing approach, offering both high accuracy and computational efficiency in practice. Among them, the transferable neural network (TransNet) is a special class of shallow neural networks (i.e., single-hidden-layer architectures), whose hidden-layer parameters are predetermined according to the principle of uniformly distributed partition hyperplanes. Although TransNet has demonstrated strong performance in solving PDEs with relatively smooth solutions, its accuracy and stability may deteriorate in the presence of highly oscillatory solution structures, where activation saturation and system conditioning issues become limiting factors. In this paper, we propose a generalized transferable neural network (GTransNet) for solving steady-state PDEs, which augments the original TransNet design with additional hidden layers while preserving its interpretable feature-generation mechanism. In particular, the first hidden layer of GTransNet retains TransNet's parameter sampling strategy but incorporates an additional symmetry constraint on the neuron biases, while the subsequent hidden layers omit bias terms and employ a variance-controlled sampling strategy for selecting neuron weights.

math.NA

Developing and characterizing a new-generation regolith simulant "IGCAS-AST01" for the Tianwen-2 target asteroid (469219) Kamo'oalewa

China plans to return samples from the near-Earth asteroid (469219) Kamo'oalewa, which we previously identified as an LL-chondrite-compositional, highly space-weathered object with fine-grained regolith. In this study, we developed 10 mL of Kamo'oalewa regolith simulant, designated "IGCAS-AST01", by irradiating LL5/6 chondrite (Kheneg Ljou^ad) powder with a high-energy pulsed laser. We then analyzed the composition, grain size distribution, density, porosity, visible to near-infrared reflectance spectrum, thermal emission spectrum, thermal diffusivity, specific heat capacity, and microstructural features of both the fresh (unirradiated) powder and IGCAS-AST01. IGCAS-AST01 is composed of 57.8 vol.% olivine, 19.9 vol.% orthopyroxene, 5.6 vol.% diopside, 12.2 vol.% plagioclase, 2.6 vol.% troilite, and minor amounts of other phases. It has a mean size of 26.99 um, a median size of 23.19 um, a density of 700 kg m^-3, and a porosity of 79.1%. Additionally, IGCAS-AST01 exhibits a low reflectance of 0.1 at 0.55 um and an extremely steep spectral slope. In the temperature range of 253.15-473.15 K, its thermal diffusivity and specific heat capacity range from 3.6-4.7 x 10^-6 m^2 s^-1 and 718.43-890.20 J kg^-1 K^-1, respectively. Furthermore, thick amorphous rims and abundant nanophase metallic iron particles are observed in olivine and pyroxene grains of IGCAS-AST01. These results could support the Tianwen-2 mission's payload calibration, sampling operations, on-orbit scientific data interpretation, and future sample analysis.

astro-ph.EP

Tianwen-2 target asteroid (469219) Kamo'oalewa probably develops an Itokawa-compositional but ultra-highly space-weathered surface

China's Tianwen-2 mission plans to return samples from a small, rapidly spinning Earth quasi-satellite (469219) Kamo'oalewa. Previous studies linked Kamo'oalewa to lunar composition and origin. Here, we propose another scenario. We reanalyzed the reflectance spectrum of Kamo'oalewa and obtained an absorption band center at 1.001+-0.028 um (error is 1sigma), consistent with LL chondrites. We then conducted space weathering (SW) experiments on meteorites and found that highly space-weathered LL chondrite powder (but not slab) successfully reproduced the reflectance spectrum of Kamo'oalewa. We further traced the dynamical origin of Kamo'oalewa and found that it probably originated from the v6 secular resonance, and more specifically, the Flora family. Kamo'oalewa exhibits a similar composition to Itokawa and 7 objects in the Flora family, but with a higher degree of space weathering. We, therefore, proposed that Kamo'oalewa probably originated from the Flora family and developed an Itokawa-compositional, highly space-weathered, fine-regolith-dominated surface.

astro-ph.EP

Shape, regolith size and thickness, SMFe^0 content, and spectral type of Tianwen-2 target asteroid (469219) Kamo'oalewa

China's Tianwen-2 spacecraft will return samples from the near-Earth asteroid (469219) Kamo'oalewa. We previously reported that Kamo'oalewa develops an LL-chondrite-compositional, highly space-weathered surface. This study aims to estimate Kamo'oalewa's shape, regolith grain size and thickness, sub-micrometer iron (SMFe0) content, and spectral type. Using the lightcurve data and the Cellinoid model, we modeled Kamo'oalewa's shape, rotation period, and pole orientation. We then estimated its global distribution of regolith critical size using the balance method of gravity, cohesive force, and centrifugal force. Furthermore, in the temperature range of 253.15 to 473.15 K, we measured the thermal parameters of laser-irradiated LL chondrite powder that best matches Kamo'oalewa's spectrum, estimating Kamo'oalewa's thermal inertia and skin depth (lower limit of regolith thickness). Using the radiative transfer mixing model, we also estimated the content of SMFe0 in Kamo'oalewa's regolith. Finally, using the MIT online spectral classification tool for the laser-irradiated LL chondrite powder, we obtained a virtual spectral type of Kamo'oalewa. Our model gives a size of 68 m x 46 m x 39 m, a rotation period of 27.66 minutes, and a pole orientation of 134.7 degrees longitude and -11.4 degrees latitude for Kamo'oalewa. Regolith grains with a size <2 cm can remain stable over 93.8% of the global surface area of Kamo'oalewa. Laser-irradiated LL chondrite powder shows a low thermal inertia (95.5 to 135.1 J m^-2 K^-1 s^-1/2), corresponding to a thermal skin depth of 3 to 3.5 mm on Kamo'oalewa. An SMFe0 content of 0.29 +- 0.05 wt.% is required to match Kamo'oalewa's spectrum. The virtual spectral type of Kamo'oalewa is given as "Sqw".

astro-ph.EP

Anomalously Strong Localized First Ionization Potential Effect Associated with a Solar Subflare

Plasma composition in the solar corona commonly differs from that of the photosphere, with the enhancement of low--first-ionization-potential (FIP) elements referred to as the FIP effect. This phenomenon provides important diagnostics of energy and mass transport between different layers of the solar atmosphere. In this work, we analyze an anomalously strong, localized FIP effect observed in active region 13486 associated with a subflaring episode on 2023 November 17, using multiwavelength observations combining high energy-resolution soft X-ray disk-integrated spectra obtained by the Macao Science Satellite-1B with spatially resolved EUV/UV and H$\alpha$ imaging from Hinode/EIS, SDO/AIA and HMI, and CHASE/HIS. By investigating the temporal evolution of plasma composition in response to changes in magnetic field orientation, we provide new insight into the physical processes linking magnetic reconnection, ponderomotive force fractionation, and coronal abundance anomalies. This work reveals that the anomalously strong enhancement of low-FIP elements is localized in regions with strongly inclined magnetic fields despite a subflare. We interpret these observations within the framework of the ponderomotive force fractionation model and propose that the inclined magnetic geometry enhances the transmission of upward-propagating magnetohydrodynamic waves by reducing reflection near the plasma-$\beta$$\simeq$1 layer, enhancing FIP fractionation associated with a consequential upward-directed ponderomotive force. In addition, sustained chromospheric heating associated with chromospheric reconnection and flux cancellation appears to maintain the enhanced FIP effect for tens of minutes following the event.

astro-ph.SR

Acceleration of planetary migration: Resonance crossing and planetesimal ring

Planetary migration is a crucial stage in the early solar system, explaining many observational phenomena and providing constraints on details related to the solar system's origins. This paper aims to investigate the acceleration during planetary migration in detail using numerical simulations, delving deeper into the early solar system's preserved information. We confirm that planetary migration is a positive feedback process: the faster the migration, the more efficient the consumption of planetesimals; once the migration slows down, Neptune clears the surrounding space, making further migration more difficult to sustain. Quantitatively, a tenfold increase in migration rate corresponds to an approximately 30% reduction in the mass of planetesimals consumed to increase per unit angular momentum of Neptune. We also find that Neptune's final position is correlated with the initial surface density of planetesimals at that location, suggesting that the disk density at 30au was approximately 0.009$M_{\oplus}/au^2$ in the early solar system. Two mechanisms that can accelerate planetary migration are identified: the first is MMR between Uranus and Neptune. Migration acceleration will be triggered whenever these two giant planets cross their major MMR. The second mechanism is the ring structure within the planetesimal disk, as the higher planetesimal density in this region can provide the material support necessary for migration acceleration. Our research indicates that Neptune in the current solar system occupies a relatively delicate position. In case Neptune crossed the 1:2 MMR with Uranus, it could have migrated to a much more distant location. Therefore, under the influence of the positive feedback mechanism, the evolution of the solar system to its current configuration might be a stochastic outcome rather than an inevitable consequence.

astro-ph.EP

A Unified Probabilistic Framework for Dictionary Learning with Parsimonious Activation

Dictionary learning is traditionally formulated as an $L_1$-regularized signal reconstruction problem. While recent developments have incorporated discriminative, hierarchical, or generative structures, most approaches rely on encouraging representation sparsity over individual samples that overlook how atoms are shared across samples, resulting in redundant and sub-optimal dictionaries. We introduce a parsimony promoting regularizer based on the row-wise $L_\infty$ norm of the coefficient matrix. This additional penalty encourages entire rows of the coefficient matrix to vanish, thereby reducing the number of dictionary atoms activated across the dataset. We derive the formulation from a probabilistic model with Beta-Bernoulli priors, which provides a Bayesian interpretation linking the regularization parameters to prior distributions. We further establish theoretical calculation for optimal hyperparameter selection and connect our formulation to both Minimum Description Length, Bayesian model selection and pathlet learning. Extensive experiments on benchmark datasets demonstrate that our method achieves substantially improved reconstruction quality (with a 20\% reduction in RMSE) and enhanced representation sparsity, utilizing fewer than one-tenth of the available dictionary atoms, while empirically validating our theoretical analysis.

cs.LG

DSAT-HD: Dual-Stream Adaptive Transformer with Hybrid Decomposition for Multivariate Time Series Forecasting

Time series forecasting is crucial for various applications, such as weather, traffic, electricity, and energy predictions. Currently, common time series forecasting methods are based on Transformers. However, existing approaches primarily model limited time series or fixed scales, making it more challenging to capture diverse features cross different ranges. Additionally, traditional methods like STL for complex seasonality-trend decomposition require pre-specified seasonal periods and typically handle only single, fixed seasonality. We propose the Hybrid Decomposition Dual-Stream Adaptive Transformer (DSAT-HD), which integrates three key innovations to address the limitations of existing methods: 1) A hybrid decomposition mechanism combining EMA and Fourier decomposition with RevIN normalization, dynamically balancing seasonal and trend components through noise Top-k gating; 2) A multi-scale adaptive pathway leveraging a sparse allocator to route features to four parallel Transformer layers, followed by feature merging via a sparse combiner, enhanced by hybrid attention combining local CNNs and global interactions; 3) A dual-stream residual learning framework where CNN and MLP branches separately process seasonal and trend components, coordinated by a balanced loss function minimizing expert collaboration variance. Extensive experiments on nine datasets demonstrate that DSAT-HD outperforms existing methods overall and achieves state-of-the-art performance on some datasets. Notably, it also exhibits stronger generalization capabilities across various transfer scenarios.

cs.LG

VideoGuard: Protecting Video Content from Unauthorized Editing

With the rapid development of generative technology, current generative models can generate high-fidelity digital content and edit it in a controlled manner. However, there is a risk that malicious individuals might misuse these capabilities for misleading activities. Although existing research has attempted to shield photographic images from being manipulated by generative models, there remains a significant disparity in the protection offered to video content editing. To bridge the gap, we propose a protection method named VideoGuard, which can effectively protect videos from unauthorized malicious editing. This protection is achieved through the subtle introduction of nearly unnoticeable perturbations that interfere with the functioning of the intended generative diffusion models. Due to the redundancy between video frames, and inter-frame attention mechanism in video diffusion models, simply applying image-based protection methods separately to every video frame can not shield video from unauthorized editing. To tackle the above challenge, we adopt joint frame optimization, treating all video frames as an optimization entity. Furthermore, we extract video motion information and fuse it into optimization objectives. Thus, these alterations can effectively force the models to produce outputs that are implausible and inconsistent. We provide a pipeline to optimize this perturbation. Finally, we use both objective metrics and subjective metrics to demonstrate the efficacy of our method, and the results show that the protection performance of VideoGuard is superior to all the baseline methods.

cs.CV

AlignFreeNet: Is Cross-Modal Pre-Alignment Necessary? An End-to-End Alignment-Free Lightweight Network for Visible-Infrared Object Detection

Cross-modal misalignments, such as spatial offsets, resolution discrepancies, and semantic deficiencies, frequently occur in visible-infrared object detection (VI-OD). To mitigate this, existing methods are typically adapted into an alignment-based fusion paradigm, in which an explicit pixel- or feature-level alignment module is inserted before cross-modal fusion. However, pixel-level alignment struggles to cope with severe or mixed misalignments, whereas feature-level alignment often introduces undesirable noise into fused representations under such conditions, ultimately limiting detection performance. In this paper, we propose a novel alignment-free network (AlignFreeNet) for VI-OD. Differing from prior methods, AlignFreeNet abandons any explicit alignment and instead adopts an alignment-free fusion paradigm. Specifically, AlignFreeNet comprises two core modules: variation-guided cross-modal compensation (VCC) and frequency-guided cross-modal fusion (FCF). VCC adaptively feeds the compensated information derived from cross-modal discrepancies back into each modality, enhancing visible and infrared representations without the noise caused by explicit alignment. FCF achieves robust cross-modal fusion by suppressing task-irrelevant redundancy via frequency-domain gating, effectively mitigating noise introduced in the process. Moreover, VCC and FCF jointly exploit low- and high-frequency cues to preserve foreground contours in fused representations, effectively mitigating cross-modal blending caused by severe mixed misalignments. Extensive evaluations on DVTOD, M3FD, and DroneVehicle demonstrate that our AlignFreeNet achieves state-of-the-art performance under severe mixed misalignment conditions, highlighting its robustness and generalization.

cs.CV

TMT: Cross-domain Semantic Segmentation with Region-adaptive Transferability Estimation

Recent advances in Vision Transformers (ViTs) have significantly advanced semantic segmentation performance. However, their adaptation to new target domains remains challenged by distribution shifts, which often disrupt global attention mechanisms. While existing global and patch-level adaptation methods offer some improvements, they overlook the spatially varying transferability inherent in different image regions. To address this, we propose the Transferable Mask Transformer (TMT), a region-adaptive framework designed to enhance cross-domain representation learning through transferability guidance. First, we dynamically partition the image into coherent regions, grouped by structural and semantic similarity, and estimates their domain transferability at a localized level. Then, we incorporate region-level transferability maps directly into the self-attention mechanism of ViTs, allowing the model to adaptively focus attention on areas with lower transferability and higher semantic uncertainty. Extensive experiments across 20 diverse cross-domain settings demonstrate that TMT not only mitigates the performance degradation typically associated with domain shift but also consistently outperforms existing approaches.

cs.CV