SearcharxivSearch

arXiv subjects

Xiaoxue Yang

Publications and source records attributed to Xiaoxue Yang.

8 recordsLinked to original sources

Checkpoint-GCG: Auditing and Attacking Fine-Tuning-Based Prompt Injection Defenses

Large language models (LLMs) are increasingly deployed in real-world applications ranging from chatbots to agentic systems, where they are expected to process untrusted data and follow trusted instructions. Failure to distinguish between the two poses significant security risks, exploited by prompt injection attacks, which inject malicious instructions into the data to control model outputs. Model-level defenses have been proposed to mitigate prompt injection attacks. These defenses fine-tune LLMs to ignore injected instructions in untrusted data. We introduce Checkpoint-GCG, a white-box attack against fine-tuning-based defenses. Checkpoint-GCG enhances the Greedy Coordinate Gradient (GCG) attack by leveraging intermediate model checkpoints produced during fine-tuning to initialize GCG, with each checkpoint acting as a stepping stone for the next one to continuously improve attacks. First, we instantiate Checkpoint-GCG to evaluate the robustness of the state-of-the-art defenses in an auditing setup, assuming both (a) full knowledge of the model input and (b) access to intermediate model checkpoints. We show Checkpoint-GCG to achieve up to $96\%$ attack success rate (ASR) against the strongest defense. Second, we relax the first assumption by searching for a universal suffix that would work on unseen inputs, and obtain up to $89.9\%$ ASR against the strongest defense. Finally, we relax both assumptions by searching for a universal suffix that would transfer to similar black-box models and defenses, achieving an ASR of $63.9\%$ against a newly released defended model from Meta.

cs.CR

Multi-Turn Jailbreaks Are Simpler Than They Seem

While defenses against single-turn jailbreak attacks on Large Language Models (LLMs) have improved significantly, multi-turn jailbreaks remain a persistent vulnerability, often achieving success rates exceeding 70% against models optimized for single-turn protection. This work presents an empirical analysis of automated multi-turn jailbreak attacks across state-of-the-art models including GPT-4, Claude, and Gemini variants, using the StrongREJECT benchmark. Our findings challenge the perceived sophistication of multi-turn attacks: when accounting for the attacker's ability to learn from how models refuse harmful requests, multi-turn jailbreaking approaches are approximately equivalent to simply resampling single-turn attacks multiple times. Moreover, attack success is correlated among similar models, making it easier to jailbreak newly released ones. Additionally, for reasoning models, we find surprisingly that higher reasoning effort often leads to higher attack success rates. Our results have important implications for AI safety evaluation and the design of jailbreak-resistant systems. We release the source code at https://github.com/diogo-cruz/multi_turn_simpler

cs.LG

Balanced Mixed-Type Tabular Data Synthesis with Diffusion Models

Diffusion models have emerged as a robust framework for various generative tasks, including tabular data synthesis. However, current tabular diffusion models tend to inherit bias in the training dataset and generate biased synthetic data, which may influence discriminatory actions. In this research, we introduce a novel tabular diffusion model that incorporates sensitive guidance to generate fair synthetic data with balanced joint distributions of the target label and sensitive attributes, such as sex and race. The empirical results demonstrate that our method effectively mitigates bias in training data while maintaining the quality of the generated samples. Furthermore, we provide evidence that our approach outperforms existing methods for synthesizing tabular data on fairness metrics such as demographic parity ratio and equalized odds ratio, achieving improvements of over $10\%$. Our implementation is available at https://github.com/comp-well-org/fair-tab-diffusion.

cs.LG

Analog of photon-assisted tunneling originated from dark Floquet state in periodically modulated waveguide arrays

We theoretically report an analog of photon-assisted tunneling (PAT) in a periodically driven lattice array without a static biased potential by studying a three-channel waveguide system. This analog of PAT can be achieved by only periodically modulating the top waveguide and adjusting the distance between the bottom and its adjacent waveguide. It is numerically shown that the PAT resonances also exist in the five-channel waveguide system and probably exist in the waveguide arrays with other odd numbers of waveguides, but they will become weak as the number of waveguides increases. With origin different from traditional PAT, this type of PAT found in our work is closely linked to the existence of the zero-energy (dark) Floquet states. It is readily observable under currently accessible experimental conditions and may be useful for controlling light propagation in waveguide arrays.

quant-ph

Coherent destruction of tunneling in a lattice array with controllable boundary

We have investigated how the dynamics of a quantum particle initially localized in the left boundary site under periodic driving can be manipulated via control of the right boundary site of a lattice array. Because of the adjustable coupling between the right boundary site and its nearest-neighbor, we can realize either coherent destruction of tunneling to coherent tunneling (CDT-CT) transition or coherent tunneling to coherent destruction of tunneling (CT-CDT) transition, by driving or moving the right boundary site while keeping the left boundary site driven by a periodically oscillating field with a fixed driving parameter. In particular, the transition direction shows odd-even sensitivity to the number of lattice sites. We have also revealed that our proposed CDT-CT transition is robust against the second order coupling (SOC) between next-nearest-neighbor sites in odd-$N$-site systems, whereas localization can be significantly enhanced by SOC in even-$N$-site systems. More interestingly, it is found destruction and revival of CDT observable in non-high-frequency regimes. Our results can be readily verified within the capacity of current experiments.

quant-ph

Correlation and entanglement of two-component Bose-Einstein condensates in a double well

We consider a novel system of two-component atomic Bose-Einstein condensate in a double-well potential. Based on the well-known two-mode approximation, we demonstrate that there are obvious avoided level-crossings when both interspecies and intraspecies interactions of two species are increased. The quantum dynamics of the system exhibits revised oscillating behaviors compared with a single component condensate. We also examine the entanglement of two species. Our numerical calculations show the onset of entanglement can be signed as a violation of Cauchy-Schwarz inequality of second-order cross correlation function. Consequently, we use Von Neumann entropy to quantity the degree of entanglement.

cond-mat.other

Deformed Two-Mode Quadrature Operators in Noncommutative Space

Starting from noncommutative quantum mechanics algebra, we investigate the variances of the deformed two-mode quadrature operators under the evolution of three types of two-mode squeezed states in noncommutative space. A novel conclusion can be found and it may associate the checking of the variances in noncommutative space with homodyne detecting technology. Moreover, we analyze the influence of the scaling parameter on the degree of squeezing for the deformed level and the corresponding consequences.

hep-th

Many-body dynamics of a Bose system with attractive interactions on a ring

We investigate the many-body dynamics of an effectively attractive one-dimensional Bose system confined in a toroidal trap. The mean-field theory predicts that a bright-soliton state will be formed when increasing the interparticle interaction over a critical point. The study of quantum many-body dynamics in this paper reveals that there is a modulation instability in a finite Bose system correspondingly. We show that Shannon entropy becomes irregular near and above the critical point due to quantum correlations. We also study the dynamical behavior of the instability by exploring the momentum distribution and the fringe visibility, which can be verified experimentally by releasing the trap

cond-mat.other