SearcharxivSearch

arXiv subjects

Xuesong Bai

Publications and source records attributed to Xuesong Bai.

12 recordsLinked to original sources

Detectors Learn the Wrong Thing: Shortcut-Resistant Adversarial Training Against Physically Realizable Attacks

AI-enabled visual perception systems are increasingly deployed in intelligent transportation infrastructure and autonomous vehicle related applications. However, physically realizable adversarial appearances pose a significant reliability challenge for these safety-critical systems. Adversarial training is effective, but repeated co-occurrence between adversarial texture and positive person instances can cause detectors to treat the texture itself as evidence of object presence, forming a patch texture shortcut. The detector may then treat texture as evidence for the target, causing false detections on texture-only inputs and weakening cross attack generalisation. We propose InsCAT, an instance-level contrastive adversarial training framework that prevents detectors from using adversarial texture as an independent decision cue. SICA aligns adversarial person features with matched clean features and separates them from texture-only negatives, while ROPO and Guard maintain online attack pressure and coordinate training. We evaluate eight independently generated attack textures on rendered nuScenes, INRIAPerson, printed garments, and three detector families. InsCAT achieves an average attack AP of 82.3% on rendered nuScenes, exceeding the strongest baseline by 11.1 points.Relative to AT-Mix, texture FPR decreases from 46.9% to 7.3%. Physical tests yield an F1 score of 96.6% and an FPR of 1.8%. Consistent gains across separately trained detectors demonstrate applicability across architectures with direct inference. The findings show that robust physical detection depends on preserving target related evidence while preventing adversarial texture from becoming an independent decision cu

cs.CV

AdvSerial: Physical Adversarial Attacks on Infrastructure-mounted Pedestrian Detectors via Semantic Feature Suppression

AI-based visual perception systems are increasingly deployed in infrastructure surveillance, including roadside monitoring units, highway cameras, and smart-city pedestrian management systems. The security vulnerability of these systems to physical adversarial attacks poses a direct threat to the reliable operation of transportation infrastructure. We propose AdvSerial, a dynamic 2D--3D joint optimization framework for generating continuous high-angle physical adversarial patches against pedestrian detectors in infrastructure-based scenarios. We UV-map a boundary-aware quilted texture onto 3D garments, combine 2D digital attacks with 3D sparse- and continuous-frame rendering, and explicitly suppress person-specific semantic features while enforcing temporal continuity. A Feature Smooth Quilting strategy reduces visible patch boundaries and bounds cross-seam feature discontinuities. A serial-frame loss encourages long uninterrupted sequences of detection failures. In physical world experiments, AdvSerial achieves a 74.8% attack success rate on YOLO-v5 and degrades mean detection confidence from 84.30% to 39.38%. Experiments spanning eight detectors with different architectures demonstrate strong transferability. Notably, it achieves an $89.71%$ attack success rate on YOLO-v2 and resists both patch-detection defenses (NapGuard) and 3D-temporal perception (Sparse4D-v3). The results reveal persistent, temporally consistent failure modes under high-angle surveillance, and motivate the design of motion-aware and 3D-aware defenses for security-critical infrastructure deployments.

cs.CV

Dynamics and stochastic resonance in a mathematical model of bistable phosphorylation and nuclear size control

Robust oscillations play crucial roles in a wide variety of biological processes and are often generated by deterministic mechanisms. However, stochastic fluctuations often generate complex perturbations of these deterministic oscillations, potentially strengthening or weakening their robustness. In this paper, we study bistable phosphorylation as a mechanism for robust oscillation. We present a simple nucleocytoplasmic transport and cell growth model where cargo proteins undergo bistable phosphorylation prior to nuclear import. We perform a detailed bifurcation analysis to examine the system's dynamical behavior. We then introduce additive noise into the model and study the stochastic resonance behavior and robustness of oscillations under noise. Our results show that, depending on the phosphorylation threshold, time-scale parameters, and nucleocytoplasmic transport rate, bistable phosphorylation may generate oscillations via Hopf bifurcations; moreover, stochastic resonance and Bautin bifurcations enhance the robustness of the oscillations.

math.DS

Demonstration of quantum error detection in a silicon quantum processor

Quantum error detection is essential in realizing large-scale universal quantum computation, especially for quantum error correction (QEC). However, key elements for FTQC have yet to be realized in silicon qubits. Here, we demonstrate quantum error detection on a donor-based silicon quantum processor comprising four-nuclear spin qubits and one electron spin as an auxiliary qubit. The entanglement capability of this system is validated through the establishment of two-qubit Bell state entanglement between the nuclear spins and the generation of a four-qubit Greenberger-Horne-Zeilinger (GHZ) state, achieving a GHZ state fidelity of 88.5(2.3)%. Furthermore, by executing a four-qubit error detection circuit with the stabilizers, we successfully detect arbitrary single-qubit errors. The encoded Bell state entanglement information is recovered by performing the Pauli-frame update (PFU) via postprocessing. Based on the detected errors, we identify strongly biased noise in our system. Our results mark a significant advance toward FTQC in silicon spin qubits.

quant-ph

AdvReal: Physical Adversarial Patch Generation Framework for Security Evaluation of Object Detection Systems

Autonomous vehicles are typical complex intelligent systems with artificial intelligence at their core. However, perception methods based on deep learning are extremely vulnerable to adversarial samples, resulting in security accidents. How to generate effective adversarial examples in the physical world and evaluate object detection systems is a huge challenge. In this study, we propose a unified joint adversarial training framework for both 2D and 3D domains, which simultaneously optimizes texture maps in 2D image and 3D mesh spaces to better address intra-class diversity and real-world environmental variations. The framework includes a novel realistic enhanced adversarial module, with time-space and relighting mapping pipeline that adjusts illumination consistency between adversarial patches and target garments under varied viewpoints. Building upon this, we develop a realism enhancement mechanism that incorporates non-rigid deformation modeling and texture remapping to ensure alignment with the human body's non-rigid surfaces in 3D scenes. Extensive experiment results in digital and physical environments demonstrate that the adversarial textures generated by our method can effectively mislead the target detection model. Specifically, our method achieves an average attack success rate (ASR) of 70.13% on YOLOv12 in physical scenarios, significantly outperforming existing methods such as T-SEA (21.65%) and AdvTexture (19.70%). Moreover, the proposed method maintains stable ASR across multiple viewpoints and distances, with an average attack success rate exceeding 90% under both frontal and oblique views at a distance of 4 meters. This confirms the method's strong robustness and transferability under multi-angle attacks, varying lighting conditions, and real-world distances. The demo video and code can be obtained at https://github.com/Huangyh98/AdvReal.git.

cs.CV

Mathematical model of Nucleocytoplasmic Transport and Nuclear-to-Cell Ratio in a growing cell

It has been observed that the growth of the nucleus and the cytoplasm is coordinated during cell growth, resulting in a nearly constant nuclear-to-cell volume ratio (N/C) throughout the cell cycle. Previous studies have shown that the N/C ratio is determined by the ratio between the number of proteins in the nucleus and the total number of proteins in the cell. These observations suggest the importance of the nucleocytoplasmic transport process in nuclear size by regulating protein concentrations in the nucleus and cytoplasm. This paper combines a biophysical model of Ran-mediated nucleocytoplasmic transport and a simple cell growth model to provide insights into several key aspects of the N/C ratio homeostasis in growing cells. Our model shows that the permeability of the nuclear envelope needs to grow in line with the cell to maintain a nearly constant N/C ratio, that several parameters involved in the nucleocytoplasmic transport mechanism and gene translation significantly affect the N/C ratio, and that Ran may potentially compensate for the lack of NTF2 in the nucleocytoplasmic transport mechanism to maintain a viable N/C ratio. However, this compensation is possible only if RanGDP is allowed to translocate through the nuclear envelope independently of NTF2.

q-bio.CB

Text2Scenario: Text-Driven Scenario Generation for Autonomous Driving Test

Autonomous driving (AD) testing constitutes a critical methodology for assessing performance benchmarks prior to product deployment. The creation of segmented scenarios within a simulated environment is acknowledged as a robust and effective strategy; however, the process of tailoring these scenarios often necessitates laborious and time-consuming manual efforts, thereby hindering the development and implementation of AD technologies. In response to this challenge, we introduce Text2Scenario, a framework that leverages a Large Language Model (LLM) to autonomously generate simulation test scenarios that closely align with user specifications, derived from their natural language inputs. Specifically, an LLM, equipped with a meticulously engineered input prompt scheme functions as a text parser for test scenario descriptions, extracting from a hierarchically organized scenario repository the components that most accurately reflect the user's preferences. Subsequently, by exploiting the precedence of scenario components, the process involves sequentially matching and linking scenario representations within a Domain Specific Language corpus, ultimately fabricating executable test scenarios. The experimental results demonstrate that such prompt engineering can meticulously extract the nuanced details of scenario elements embedded within various descriptive formats, with the majority of generated scenarios aligning closely with the user's initial expectations, allowing for the efficient and precise evaluation of diverse AD stacks void of the labor-intensive need for manual scenario configuration. Project page: https://caixxuan.github.io/Text2Scenario.GitHub.io.

cs.SE

Stochastic Gene Expression Model of Nuclear-to-Cell Ratio Homeostasis

Cell size varies between different cell types, and between different growth and osmotic conditions. However, the nuclear-to-cell volume ratio (N/C ratio) remains nearly constant. In this paper, we build on existing deterministic models of N/C ratio homeostasis and develop a simplified gene translation model to study the effect of stochasticity on the N/C ratio homeostasis. We solve the corresponding chemical master equation and obtain the mean and variance of the N/C ratio. We also use a Taylor expansion approximation to study the effects of the system size on the fluctuations of the N/C ratio. We then combine the translation model with a cell division model to study the effects of extrinsic noises from cell division on the N/C ratio. Our model demonstrates that the N/C ratio homeostasis is maintained when the stochasticity in cell growth is taken into account, that the N/C ratio is largely determined by the gene fraction of nuclear proteins, and that the fluctuations in the N/C ratio diminish as the system size increases.

q-bio.CB

VCAT: Vulnerability-aware and Curiosity-driven Adversarial Training for Enhancing Autonomous Vehicle Robustness

Autonomous vehicles (AVs) face significant threats to their safe operation in complex traffic environments. Adversarial training has emerged as an effective method of enabling AVs to preemptively fortify their robustness against malicious attacks. Train an attacker using an adversarial policy, allowing the AV to learn robust driving through interaction with this attacker. However, adversarial policies in existing methodologies often get stuck in a loop of overexploiting established vulnerabilities, resulting in poor improvement for AVs. To overcome the limitations, we introduce a pioneering framework termed Vulnerability-aware and Curiosity-driven Adversarial Training (VCAT). Specifically, during the traffic vehicle attacker training phase, a surrogate network is employed to fit the value function of the AV victim, providing dense information about the victim's inherent vulnerabilities. Subsequently, random network distillation is used to characterize the novelty of the environment, constructing an intrinsic reward to guide the attacker in exploring unexplored territories. In the victim defense training phase, the AV is trained in critical scenarios in which the pretrained attacker is positioned around the victim to generate attack behaviors. Experimental results revealed that the training methodology provided by VCAT significantly improved the robust control capabilities of learning-based AVs, outperforming both conventional training modalities and alternative reinforcement learning counterparts, with a marked reduction in crash rates. The code is available at https://github.com/caixxuan/VCAT.

cs.LG

AutoAttacker: A Large Language Model Guided System to Implement Automatic Cyber-attacks

Large language models (LLMs) have demonstrated impressive results on natural language tasks, and security researchers are beginning to employ them in both offensive and defensive systems. In cyber-security, there have been multiple research efforts that utilize LLMs focusing on the pre-breach stage of attacks like phishing and malware generation. However, so far there lacks a comprehensive study regarding whether LLM-based systems can be leveraged to simulate the post-breach stage of attacks that are typically human-operated, or "hands-on-keyboard" attacks, under various attack techniques and environments. As LLMs inevitably advance, they may be able to automate both the pre- and post-breach attack stages. This shift may transform organizational attacks from rare, expert-led events to frequent, automated operations requiring no expertise and executed at automation speed and scale. This risks fundamentally changing global computer security and correspondingly causing substantial economic impacts, and a goal of this work is to better understand these risks now so we can better prepare for these inevitable ever-more-capable LLMs on the horizon. On the immediate impact side, this research serves three purposes. First, an automated LLM-based, post-breach exploitation framework can help analysts quickly test and continually improve their organization's network security posture against previously unseen attacks. Second, an LLM-based penetration test system can extend the effectiveness of red teams with a limited number of human analysts. Finally, this research can help defensive systems and teams learn to detect novel attack behaviors preemptively before their use in the wild....

cs.CR

ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing

Domain Name System (DNS) is a critical component of the Internet. DNS resolvers, which act as the cache between DNS clients and DNS nameservers, are the central piece of the DNS infrastructure, essential to the scalability of DNS. However, finding the resolver vulnerabilities is non-trivial, and this problem is not well addressed by the existing tools. To list a few reasons, first, most of the known resolver vulnerabilities are non-crash bugs that cannot be directly detected by the existing oracles (or sanitizers). Second, there lacks rigorous specifications to be used as references to classify a test case as a resolver bug. Third, DNS resolvers are stateful, and stateful fuzzing is still challenging due to the large input space. In this paper, we present a new fuzzing system termed ResolverFuzz to address the aforementioned challenges related to DNS resolvers, with a suite of new techniques being developed. First, ResolverFuzz performs constrained stateful fuzzing by focusing on the short query-response sequence, which has been demonstrated as the most effective way to find resolver bugs, based on our study of the published DNS CVEs. Second, to generate test cases that are more likely to trigger resolver bugs, we combine probabilistic context-free grammar (PCFG) based input generation with byte-level mutation for both queries and responses. Third, we leverage differential testing and clustering to identify non-crash bugs like cache poisoning bugs. We evaluated ResolverFuzz against 6 mainstream DNS software under 4 resolver modes. Overall, we identify 23 vulnerabilities that can result in cache poisoning, resource consumption, and crash attacks. After responsible disclosure, 19 of them have been confirmed or fixed, and 15 CVE numbers have been assigned.

cs.CR

A two-stage method for reconstruction of parameters in diffusion equations

Parameter reconstruction for diffusion equations has a wide range of applications. In this paper, we proposed a two-stage scheme to efficiently solve conductivity reconstruction problems for steady-state diffusion equations with solution data measured inside the domain. The first stage is based on total variation regularization of the log diffusivity and the split Bregman iteration method. In the second stage, we apply the K-means clustering for the reconstruction of ``blocky'' conductivity functions. The convergence of the scheme is theoretically proved and extensive numerical examples are shown to demonstrate the performance of the scheme.

math.NA