SearcharxivSearch

arXiv subjects

Xiaoyu Sun

Publications and source records attributed to Xiaoyu Sun.

At least 19 recordsLinked to original sources

The Non-Principal-Axis Rotation and Convex Shape Model of Earth Quasi-Satellite and the Target of China's Tianwen-2 Mission (469219) Kamo`oalewa

(469219) Kamo`oalewa is the most stable Earth quasi-satellite and the target of China's Tianwen-2 asteroid sample return mission. Due to its small size, fast rotation, and the limited observing geometry accessible from the ground, many physical properties of Kamo`oalewa remain poorly constrained, including the rotational state and shape. We obtained three epochs of high-cadence, high signal-to-noise photometric lightcurves of Kamo`oalewa with the Gemini North Telescope from 2026 April to May, supplemented by one lightcurve from the Lowell Discovery Telescope in 2026 May. Our analysis suggests that Kamo`oalewa is in a non-principal-axis rotation with an elongated shape. Four possible solutions exist, including a long-axis mode (LAM) solution and a short-axis mode (SAM) solution, as well as their corresponding mirrored angular momentum directions. The most preferable solution has a LAM model with a precession period $P_ϕ=27.65\pm0.03~\text{min}$ and a rotational period $P_ψ=50.49\pm0.08~\text{min}$, and the angular momentum points to ecliptic coordinates $(λ, β) = (226^\mathrm{o}\pm20^\mathrm{o}, -39^\mathrm{o}\pm20\mathrm{o})$, although we cannot rule out other solutions or other close-by periods due to aliasing. We also derived a convex shape inversion for the LAM models with consistent rotational parameters but could not find a satisfactory inversion for the SAM models. The corresponding angular momentum points to $(λ, β)=(225^\mathrm{o}, -43^\mathrm{o})$, and the periods are $P_ϕ=27.90~\text{min}$ and $P_ψ=49.66~\text{min}$. The non-principal-axis rotation provides additional constraints on the dynamic history or the internal structure of Kamo`oalewa.

astro-ph.EP

Direct experimental measurement of femtonewton-scale momentum transfer force from electron beams

Electron beams (e-beams) are ubiquitous in imaging, patterning, and propulsion. This prevalence is rooted in the profound mastery of their wave-particle duality and energy-transfer pathways. Yet, a fundamental dimension remains largely unexplored: while the mechanical effect (i.e., the momentum transfer to a target) is theoretically known, quantification of its femtonewton-range force has remained elusive. This discrepancy represents a missing piece of the puzzle toward a comprehensive understanding of e-beam-matter interactions, and ultimately limits the multi-dimensional exploitation of e-beams. A force sensor combining femtonewton sensitivity, immunity to electromagnetic noise, compatibility with vacuum, and absolute calibration is critical to bridge the gap between theory and experiment. Here the FINEST (Femtonewton Interferometric Nanomechanical Electron-beam Sensing Technology) sensor is proposed and successfully tested to measure the force of an e-beam. FINEST is an optical-pressure-calibrated 3D spring-type optical sensor that operates reliably under e-beam conditions. Femtonewton-scale forces from 2-30 keV e-beams are directly measured, ranging from 505 fN to 13 pN. Both linear scaling with beam current and a non-monotonic energy dependence (peaking near 10 keV) are observed. Based on this calibrated force, the mechanical contribution to e-beam ice etching was quantitatively confirmed; its effect is orders of magnitude lower than the total etch depth and lacks noticeable energy dependence. By achieving the first direct experimental measurement of e-beam momentum transfer, this work adds a long-missing dimension to the physical landscape of e-beam processes. These findings provide a quantitative basis for furthering the multi-dimensional exploitation of e-beams, potentially transforming our approach to precision nanofabrication, sensing, and fundamental electron physics research.

physics.optics

Monolithic Multifocal Diamond Metalens for High-Power Laser Systems

High-power laser systems increasingly rely on multi-beam processing to enhance manufacturing throughput. However, conventional multifocal systems remain constrained by bulky architectures, stringent alignment requirements, and susceptibility to laser-induced degradation under intense irradiation. Here, we demonstrate a monolithic multifocal diamond metalens with a 7.2 mm aperture that maintains exceptional thermal stability and power tolerance. The device employs high-aspect-ratio truncated-cone diamond nanopillars to generate two focal spots separated by 200 μm at a focal length of 4 mm. Under sustained 25 W pulsed-laser irradiation for 1 h, the diamond metalens exhibits a focal shift of only 25.5 μm, resulting in a maximum processing-depth variation of 33.2 μm during 4H silicon carbide (SiC) laser scribing, far below the 319.1 μm deviation observed for a commercial objective lens combined with a beam-splitting diffractive optical element (DOE). Even under extreme optical loading, the metalens withstands continuous-wave laser irradiation up to 8.25 kW for 30 s without structural degradation, while complementary pulsed testing yields a laser-induced damage threshold (LIDT) of 2.45 J/(cm^2) for diamond. This work broadens the operating envelope of transmissive meta-optics to extreme optical loads, opening new opportunities across high-power photonic systems.

physics.optics

SkillGuard: A Permission-Centric Framework for Agent Skill Security

Skills extend LLM agents with reusable instructions, scripts, data, and tool bindings. This shift makes skills a new security principal in agent systems: a skill can alter the agent's reasoning before any tool is called, and it can also steer the agent toward actions with concrete side effects. However, current skill ecosystems lack a permission model that captures this dual role. Existing defenses either inspect skill files before use or constrain individual tool calls during execution, leaving the connection between skill-level intent, contextual influence, and runtime behavior weakly governed. In this paper, we present SkillGuard, a skill-centric permission framework that treats skills as permission-bearing executable artifacts. SkillGuard introduces a dual-plane governance model that jointly regulates context influence and action side effects through skill manifests, runtime permission control, user interaction, and policy enforcement. We evaluate the permission taxonomy expressiveness on 1,260 real-world skills, and 99.93% of observed protected objects are covered. In adversarial evaluations on SkillInject dataset, SkillGuard reduces attack success rate from 35.3% to 20.7% for contextual injections and from 36.7% to 18.0% for obvious injections, while decently maintaining benign task completion. These results suggest that SkillGuard, as a skill-centric permission framework, can provide a practical foundation for improving the security of agent skill ecosystems.

cs.CR

The Creation and Analysis of Government AI Transparency Statements in Australia

Governments increasingly deploy AI in public services, making transparency essential for accountability and public trust. Australia's Standard for AI Transparency Statements (AITS) requires government bodies to disclose how AI is used in practice, yet little empirical evidence exists on how these requirements are realised in documents. This paper presents a government AITS dataset, dubbed AITS-101, and provides one of the first systematic analysis of their content. Using stylometric, quantitative, and qualitative document analyses, we examine disclosure coverage, structure, and recurring patterns. Our findings reveal substantial variation in AI-related practice disclosure, highlight gaps between policy intent and implementation, and inform the design of more effective public-sector AI transparency standards.

cs.CY

On Quantum Perceptron Learning via Quantum Search

With the growing interest in quantum machine learning, the perceptron, a fundamental building block in traditional machine learning, has emerged as a valuable model for exploring the potential of quantum algorithms. In this work, we make two principal contributions. First, we revisit the \emph{quantum version space perceptron} algorithm proposed by Kapoor et al. (2016), by identifying and correcting a flawed complexity assumption. We show that the query complexity of the algorithm is dimension-dependent, which has significant implications for its behaviour in high-dimensional regimes under worst-case scenarios. Second, we propose and analyse two \emph{quantum-enhanced} cutting-plane algorithms for perceptron learning. Specifically, we leverage established quantum subroutines such as \emph{Grover's search} and \emph{quantum walk search}, and provide detailed algorithmic constructions together with query and arithmetic complexity analyses. Our results establish improved complexity bounds under an idealised implementation framework and noise-free quantum computational models, offering insights into the trade-offs between margin dependence, dimensional dependence, and quantum resources. These findings provide a refined understanding of quantum perceptron models and their theoretical computational complexity properties.

quant-ph

Manifold partitioning induced sequential optical reasoning and decision framework for photonic computing

Real-world data are intrinsically embedded in highly entangled manifolds, making the extraction of separable representations a central challenge for artificial intelligent (AI) systems. While optical neural networks (ONNs) offer ultrafast and energy-efficient data processing, their capacity is constrained by limited physical depth. Here, we introduce a sequential optical reasoning and decision (SORD) framework, an architecture that performs time-sequenced hierarchical inference by decomposing global tasks into coarse-to-fine steps via geometry-guided data partitioning. At each step, SORD executes small reasoning via dynamic operator selection, effectively reducing the overall task complexity without scaling up physical architecture. Experimentally, SORD enables a single-layer diffractive ONN to achieve otherwise intractable 100-class optical fiber speckle classification with 94% accuracy and a system energy efficiency of 23.3 TOPS/W. This high-fidelity recognition is further examined in a human-machine interface, featuring real-time interactive all-optical sensing. Overall, our work establishes a scalable and hardware-efficient approach to expanding the effective expressivity of compact photonic AI systems, and may advance their deployment in applications requiring real-time sensing, inference, and control.

physics.optics

Many a Little Makes a Mickle: A Code-Centric Empirical Study of Data Minimization Principle in Android App Development

Modern mobile applications consume large amounts of data to function, raising significant privacy concerns and regulatory challenges. While prior work has primarily focused on detecting compliance gaps through policy analysis, there remains a lack of actionable guidance for developers to implement privacy principles at the code level. In this paper, we focus on data minimization as a developer-operationalizable principle and investigate its realization in Android applications. We conduct a formative study on 1,114 open-source Android apps to identify ten recurring data minimization scenarios across five data-handling stages. Building on this, we perform a large-scale analysis of 9,875 real-world APKs and distill 31 actionable coding guidelines to support privacy-compliant development. We further examine LLM-based code generation in Android development and find that state-of-the-art models consistently reproduce data minimization-risky practices, indicating that they inherit and amplify patterns from real-world code. Encouragingly, incorporating our guidelines eliminates these issues across all evaluated models. Our work advocates a shift toward responding to privacy regulatory requirements at their code-level root causes, enabling better compliance in both human and AI-assisted programming.

cs.SE

VPD-100K: Towards Generalizable and Fine-grained Visual Privacy Protection

Privacy protection has become a critical requirement in the era of ubiquitous visual data sharing, imposing higher demands on efficient and robust privacy detection algorithms. However, current robust detection models are severely hindered by the lack of comprehensive datasets. Existing privacy-oriented datasets often suffer from limited scale, coarse-grained annotations, and narrow domain coverage, failing to capture the intricate details of sensitive information in realworld environments. To bridge this gap, we present a large-scale, fine-grained Visual Privacy Dataset (VPD-100K), designed to facilitate generalized privacy detection. We establish a holistic taxonomy comprising four primary domains: Human Presence, On-Screen Personally Identifiable Information (PII), Physical Identifiers, and Location Indicators, containing 100,000 images annotated with 33 fine-grained classes and over 190,000 object instances. Statistical analysis reveals that our dataset features long-tailed distributions, small object scales, and high visual complexity. These characteristics make the dataset particularly valuable for demanding, unconstrained applications such as live streaming, where actors frequently face unintentional, realtime information leakage. Furthermore, we design an effective frequency-enhanced lightweight module consisting of frequency-domain attention fusion and adaptive spectral gating mechanism that breaks the limitations of spatial pixel intensity to better capture the subtle details of sensitive information. Extensive experiments conducted on both diverse image and streaming videos benchmarks consistently demonstrate the effectiveness of our VPD-100K dataset and the wellcurated frequency mechanism. The code and dataset are available at https://vpd-100k.github.io/.

cs.CV

Putting on the Thinking Hats: A Survey on Chain of Thought Fine-tuning from the Perspective of Human Reasoning Mechanism

Chain of thought (CoT) fine-tuning aims to endow large language models (LLMs) with reasoning capabilities by training them on curated reasoning traces. It leverages both supervised and reinforced fine-tuning to cultivate human-like reasoning skills in LLMs, including detailed planning, divergent thinking, intuitive judgment, timely reflection, internal thinking, and fact perception, etc. As CoT fine-tuning has advanced, LLMs have demonstrated substantial improvements in tasks such as mathematical reasoning and code generation. However, existing surveys about CoT fine-tuning primarily focus on technical aspects and overlook a systematic analysis from the perspective of human reasoning mechanisms. Given that the ultimate goal of CoT fine-tuning is to enable LLMs to reason like humans, it is crucial to investigate this technique through the lens of human cognition. To fill this gap, we present the first comprehensive survey of CoT fine-tuning grounded in human reasoning theory. Specifically, inspired by the well-known Six Thinking Hats framework, which systematically characterizes common human thinking modes using six metaphorical hats, we classify and examine CoT fine-tuning methods through this lens. Furthermore, building upon this theory, we outline potential directions for future research in CoT fine-tuning. In addition, we compile a comprehensive overview of existing datasets and model performances, and a real-time GitHub repository \footnote{https://github.com/AI-Chen/Awesome-CoT-Finetuning} that continuously tracks recent advances in this area is maintained. We hope this survey will serve as a valuable resource to inspire innovation and foster progress in this rapidly evolving field.

cs.CL

Context-Free Grammar Inference for Complex Programming Languages in Black Box Settings

Grammar inference for complex programming languages remains a significant challenge, as existing approaches fail to scale to real world datasets within practical time constraints. In our experiments, none of the state-of-the-art tools, including Arvada, Treevada and Kedavra were able to infer grammars for complex languages such as C, C++, and Java within 48 hours. Arvada and Treevada perform grammar inference directly on full-length input examples, which proves inefficient for large files commonly found in such languages. While Kedavra introduces data decomposition to create shorter examples for grammar inference, its lexical analysis still relies on the original inputs. Additionally, its strict no-overgeneralization constraint limits the construction of complex grammars. To overcome these limitations, we propose Crucio, which builds a decomposition forest to extract short examples for lexical and grammar inference via a distributional matrix. Experimental results show that Crucio is the only method capable of successfully inferring grammars for complex programming languages (where the number of nonterminals is up to 23x greater than in prior benchmarks) within reasonable time limits. On the prior simple benchmark, Crucio achieves an average recall improvement of 1.37x and 1.19x over Treevada and Kedavra, respectively, and improves F1 scores by 1.21x and 1.13x.

cs.PL

Deployability-Centric Infrastructure-as-Code Generation: Fail, Learn, Refine, and Succeed through LLM-Empowered DevOps Simulation

Infrastructure-as-Code (IaC) generation holds significant promise for automating cloud infrastructure provisioning. Recent advances in Large Language Models (LLMs) present a promising opportunity to democratize IaC development by generating deployable infrastructure templates from natural language descriptions. However, current evaluation focuses on syntactic correctness while ignoring deployability, the critical measure of the utility of IaC configuration files. Six state-of-the-art LLMs performed poorly on deployability, achieving only 20.8$\sim$30.2% deployment success rate on the first attempt. In this paper, we construct DPIaC-Eval, the first deployability-centric IaC template benchmark consisting of 153 real-world scenarios cross 58 unique services. Also, we propose an LLM-based deployability-centric framework, dubbed IaCGen, that uses iterative feedback mechanism encompassing format verification, syntax checking, and live deployment stages, thereby closely mirroring the real DevOps workflows. Results show that IaCGen can make 54.6$\sim$91.6% generated IaC templates from all evaluated models deployable in the first 10 iterations. Additionally, human-in-the-loop feedback that provide direct guidance for the deployability errors, can further boost the performance to over 90% passItr@25 on all evaluated LLMs. Furthermore, we explore the trustworthiness of the generated IaC templates on user intent alignment and security compliance. The poor performance (25.2% user requirement coverage and 8.4% security compliance rate) indicates a critical need for continued research in this domain.

cs.SE

A Comparative Study of Android Performance Issues in Real-world Applications and Literature

Performance issues in Android applications significantly undermine users' experience, engagement, and retention, which is a long-lasting research topic in academia. Unlike functionality issues, performance issues are more difficult to diagnose and resolve due to their complex root causes, which often emerge only under specific conditions or payloads. Although many efforts haven attempt to mitigate the impact of performance issues by developing methods to automatically identify and resolve them, it remains unclear if this objective has been fulfilled, and the existing approaches indeed targeted on the most critical performance issues encountered in real-world settings. To this end, we conducted a large-scale comparative study of Android performance issues in real-world applications and literature. Specifically, we started by investigating real-world performance issues, their underlying root causes (i.e., contributing factors), and common code patterns. We then took an additional step to empirically summarize existing approaches and datasets through a literature review, assessing how well academic research reflects the real-world challenges faced by developers and users. Our comparison results show a substantial divergence exists in the primary performance concerns of researchers, developers, and users. Among all the identified factors, 57.14% have not been examined in academic research, while a substantial 76.39% remain unaddressed by existing tools, and 66.67% lack corresponding datasets. This stark contrast underscores a substantial gap in our understanding and management of performance issues. Consequently, it is crucial for our community to intensify efforts to bridge these gaps and achieve comprehensive detection and resolution of performance issues.

cs.SE

Navigating the Labyrinth: Path-Sensitive Unit Test Generation with Large Language Models

Unit testing is essential for software quality assurance, yet writing and maintaining tests remains time-consuming and error-prone. To address this challenge, researchers have proposed various techniques for automating unit test generation, including traditional heuristic-based methods and more recent approaches that leverage large language models (LLMs). However, these existing approaches are inherently path-insensitive because they rely on fixed heuristics or limited contextual information and fail to reason about deep control-flow structures. As a result, they often struggle to achieve adequate coverage, particularly for deep or complex execution paths. In this work, we present a path-sensitive framework, JUnitGenie, to fill this gap by combining code knowledge with the semantic capabilities of LLMs in guiding context-aware unit test generation. After extracting code knowledge from Java projects, JUnitGenie distills this knowledge into structured prompts to guide the generation of high-coverage unit tests. We evaluate JUnitGenie on 2,258 complex focal methods from ten real-world Java projects. The results show that JUnitGenie generates valid tests and improves branch and line coverage by 29.60% and 31.00% on average over both heuristic and LLM-based baselines. We further demonstrate that the generated test cases can uncover real-world bugs, which were later confirmed and fixed by developers.

cs.SE

A First Look at Privacy Risks of Android Task-executable Voice Assistant Applications

With the development of foundation AI technologies, task-executable voice assistants (VAs) have become more popular, enhancing user convenience and expanding device functionality. Android task-executable VAs are applications that are capable of understanding complex tasks and performing corresponding operations. Given their prevalence and great autonomy, there is no existing work examine the privacy risks within the voice assistants from the task-execution pattern in a holistic manner. To fill this research gap, this paper presents a user-centric comprehensive empirical study on privacy risks in Android task-executable VA applications. We collect ten mainstream VAs as our research target and analyze their operational characteristics. We then cross-check their privacy declarations across six sources, including privacy labels, policies, and manifest files, and our findings reveal widespread inconsistencies. Moreover, we uncover three significant privacy threat models: (1) privacy misdisclosure in mega apps, where integrated mini apps such as Alexa skills are inadequately represented; (2) privilege escalation via inter-application interactions, which exploit Android's communication mechanisms to bypass user consent; and (3) abuse of Google system applications, enabling apps to evade the declaration of dangerous permissions. Our study contributes actionable recommendations for practitioners and underscores broader relevance of these privacy risks to emerging autonomous AI agents.

cs.CR

Towards Context-aware Mobile Privacy Notice: Implementation of A Deployable Contextual Privacy Policies Generator

Lengthy and legally phrased privacy policies impede users' understanding of how mobile applications collect and process personal data. Prior work proposed Contextual Privacy Policies (CPPs) for mobile apps to display shorter policy snippets only in the corresponding user interface contexts, but the pipeline could not be deployable in real-world mobile environments. In this paper, we present PrivScan, the first deployable CPP Software Development Kit (SDK) for Android. It captures live app screenshots to identify GUI elements associated with types of personal data and displays CPPs in a concise, user-facing format. We provide a lightweight floating button that offers low-friction, on-demand control. The architecture leverages remote deployment to decouple the multimodal backend pipeline from a mobile client comprising five modular components, thereby reducing on-device resource demands and easing cross-platform portability. A feasibility-oriented evaluation shows an average execution time of 9.15\,s, demonstrating the practicality of our approach. The source code of PrivScan is available at https://github.com/buyanghc/PrivScan and the demo video can be found at https://www.youtube.com/watch?v=ck-25otfyHc.

cs.CR

Pressure-Driven Moiré Potential Enhancement and Tertiary Gap Opening in Graphene/h-BN Heterostructure

Moiré superlattices enable engineering of correlated quantum states through tunable periodic potentials, where twist angle controls periodicity but dynamic potential strength modulation remains challenging. Here, we develop a high-pressure quantum transport technique for van der Waals heterostructures, achieving the ultimate pressure limit (~9 GPa) in encapsulated moiré devices. In aligned graphene/h-BN, we demonstrate that pressure induces a substantial enhancement of the moiré potential strength, evidenced by the suppression of the first valence bandwidth and the near-doubling of the primary band gap. Moreover, we report the first observation of a tertiary gap emerging above 6.4 GPa, verifying theoretical predictions. Our results establish hydrostatic pressure as a universal parameter to reshape moiré band structures. By enabling quantum transport studies at previously inaccessible pressure regimes, this Letter expands the accessible parameter space for exploring correlated phases in moiré systems.

cond-mat.str-el

Securing the Sky: Integrated Satellite-UAV Physical Layer Security for Low-Altitude Wireless Networks

Low-altitude wireless networks (LAWNs) have garnered significant attention in the forthcoming 6G networks. In LAWNs, satellites with wide coverage and unmanned aerial vehicles (UAVs) with flexible mobility can complement each other to form integrated satellite-UAV networks, providing ubiquitous and high-speed connectivity for low-altitude operations. However, the higher line-of-sight probability in low-altitude airspace increases transmission security concerns. In this work, we present a collaborative beamforming-based physical layer security scheme for LAWNs. We introduce the fundamental aspects of integrated satellite-UAV networks, physical layer security, UAV swarms, and collaborative beamforming for LAWN applications. Following this, we highlight several opportunities for collaborative UAV swarm secure applications enabled by satellite networks, including achieving physical layer security in scenarios involving data dissemination, data relay, eavesdropper collusion, and imperfect eavesdropper information. Next, we detail two case studies: a secure relay system and a two-way aerial secure communication framework specifically designed for LAWN environments. Simulation results demonstrate that these physical layer security schemes are effective and beneficial for secure low-altitude wireless communications. A short practicality analysis shows that the proposed method is applicable to LAWN scenarios. Finally, we discuss current challenges and future research directions for enhancing security in LAWNs.

cs.NI