Searcharxiv⌕ Search

arXiv subjects

Yanting Wang

Publications and source records attributed to Yanting Wang.

At least 37 records · Page 2Linked to original sources

PISanitizer: Preventing Prompt Injection to Long-Context LLMs via Prompt Sanitization

Long context LLMs are vulnerable to prompt injection, where an attacker can inject an instruction in a long context to induce an LLM to generate an attacker-desired output. Existing prompt injection defenses are designed for short contexts. When extended to long-context scenarios, they have limited effectiveness. The reason is that an injected instruction constitutes only a very small portion of a long context, making the defense very challenging. In this work, we propose PISanitizer, which first pinpoints and sanitizes potential injected tokens (if any) in a context before letting a backend LLM generate a response, thereby eliminating the influence of the injected instruction. To sanitize injected tokens, PISanitizer builds on two observations: (1) prompt injection attacks essentially craft an instruction that compels an LLM to follow it, and (2) LLMs intrinsically leverage the attention mechanism to focus on crucial input tokens for output generation. Guided by these two observations, we first intentionally let an LLM follow arbitrary instructions in a context and then sanitize tokens receiving high attention that drive the instruction-following behavior of the LLM. By design, PISanitizer presents a dilemma for an attacker: the more effectively an injected instruction compels an LLM to follow it, the more likely it is to be sanitized by PISanitizer. Our extensive evaluation shows that PISanitizer can successfully prevent prompt injection, maintain utility, outperform existing defenses, is efficient, and is robust to optimization-based and strong adaptive attacks. The code is available at https://github.com/sleeepeer/PISanitizer.

cs.CR↗

Expectation-Realization Interpretation of Quantum Superposition

By comparing Schrödinger's cat with its classical counterpart, I show that a quantum superposition should be understood as an expectation over possible eigenstates weighted by wave-like probabilities. Upon the occurrence of a certain event, the quantum system is randomly realized into one of the possible eigenstates due to its intrinsic stochasticity. While the randomness of a single realization cannot be controlled or predicted, the overall distribution can be regulated via experimental setup and converges as the number of events increases. A measurement is indeed an activity employing a certain event to convert a quantum effect into a macroscopic outcome. Consequently, the puzzling concepts of wavefunction collapse, many worlds, and decoherence become unnecessary for understanding quantum superposition. This expectation-realization interpretation, which integrates probability theory with wave mechanics, can also be extended to quantum pathways. Moreover, it reframes tests of Bell's inequalities as validating the wave-like probability nature of quantum mechanics, with no need to invoke the mysterious notions of quantum non-locality and "spooky action at a distance".

quant-ph↗

Shape-Determined Kinetic Pathways in 2D Solid-Solid Phase Transitions

Solid-solid phase transitions are ubiquitous in nature, but the kinetic pathway of anisotropic particle systems remains elusive, where the coupling between translational and rotational motions plays a critical role in various kinetic processes. Here we investigate this problem by molecular dynamics simulation for two-dimensional ball-stick polygon systems, where pentagon, hexagon, and octagon systems all undergo an isostructural solid-solid phase transition. During heating, the translational motion exhibits merely a homogeneous expansion, whereas the time evolution of body-orientation is shape-determined. The local defects of body-orientation self-organize into a vague stripe for pentagon, a random pattern for hexagon, while a distinct stripe for octagon. The underlying kinetic pathway of octagon adheres to the quasi-equilibrium assumption, whereas the pathways of hexagon and pentagon are governed by translational and rotational motion, respectively. This diversity is originated from different kinetic coupling modes determined by the anisotropy of molecules, and can affect the phase transition rates. The reverse process in terms of cooling follows the same mechanism, with more diverse kinetic pathways attributed to the possible kinetic traps. Our findings promote the theoretical understanding of microscopic kinetics of solid-solid phase transitions as well as provide direct guidance for the rational design of materials utilizing desired kinetic features.

cond-mat.soft↗

UniC-RAG: Universal Knowledge Corruption Attacks to Retrieval-Augmented Generation

Retrieval-augmented generation (RAG) systems are widely deployed in real-world applications in diverse domains such as finance, healthcare, and cybersecurity. However, many studies showed that they are vulnerable to knowledge corruption attacks, where an attacker can inject adversarial texts into the knowledge database of a RAG system to induce the LLM to generate attacker-desired outputs. Existing studies mainly focus on attacking specific queries or queries with similar topics (or keywords). In this work, we propose UniC-RAG, a universal knowledge corruption attack against RAG systems. Unlike prior work, UniC-RAG jointly optimizes a small number of adversarial texts that can simultaneously attack a large number of user queries with diverse topics and domains, enabling an attacker to achieve various malicious objectives, such as directing users to malicious websites, triggering harmful command execution, or launching denial-of-service attacks. We formulate UniC-RAG as an optimization problem and further design an effective solution to solve it, including a balanced similarity-based clustering method to enhance the attack's effectiveness. Our extensive evaluations demonstrate that UniC-RAG is highly effective and significantly outperforms baselines. For instance, UniC-RAG could achieve over 90% attack success rate by injecting 100 adversarial texts into a knowledge database with millions of texts to simultaneously attack a large set of user queries (e.g., 2,000). Additionally, we evaluate existing defenses and show that they are insufficient to defend against UniC-RAG, highlighting the need for new defense mechanisms in RAG systems.

cs.CR↗

Phase transitions in voting simulated by an intelligent Ising model

Voting is an important social activity for expressing public opinions. By conceptually considering a group of voting agents to be intelligent matter, the impact of real-time information on voting results is quantitatively studied by an intelligent Ising model, which is formed by adding nonlinear instantaneous feedback of the overall magnetization to the conventional Ising model. In the new model, the interaction strength becomes a variable depending on the total magnetization rather than a constant, which mimics the scenario that the decision of an individual during vote influenced by the dynamically changing polling result during the election process. Our analytical derivations along with Mote Carlo simulations reveal that, with a positive feedback, the intelligent Ising model exhibits phase transitions at any finite temperatures, a feature lacked in the conventional one-dimensional Ising model. In all dimensions, by varying the feedback strength, the system changes from going through a second-order phase transition to going through a first-order phase transition with increasing temperature, and the two types of phase transitions are connected by a tricritical point. This study on the one hand demonstrates that the intelligent matter with a nonlinear adaptive interaction can exhibit qualitatively different phase behaviors from conventional matter, and on the other hand shows that, during voting, even unbiased feedback may possibly induce spontaneous symmetry breaking, leading to a biased outcome where one side of the vote becomes favored.

cond-mat.stat-mech↗

TracLLM: A Generic Framework for Attributing Long Context LLMs

Long context large language models (LLMs) are deployed in many real-world applications such as RAG, agent, and broad LLM-integrated applications. Given an instruction and a long context (e.g., documents, PDF files, webpages), a long context LLM can generate an output grounded in the provided context, aiming to provide more accurate, up-to-date, and verifiable outputs while reducing hallucinations and unsupported claims. This raises a research question: how to pinpoint the texts (e.g., sentences, passages, or paragraphs) in the context that contribute most to or are responsible for the generated output by an LLM? This process, which we call context traceback, has various real-world applications, such as 1) debugging LLM-based systems, 2) conducting post-attack forensic analysis for attacks (e.g., prompt injection attack, knowledge corruption attacks) to an LLM, and 3) highlighting knowledge sources to enhance the trust of users towards outputs generated by LLMs. When applied to context traceback for long context LLMs, existing feature attribution methods such as Shapley have sub-optimal performance and/or incur a large computational cost. In this work, we develop TracLLM, the first generic context traceback framework tailored to long context LLMs. Our framework can improve the effectiveness and efficiency of existing feature attribution methods. To improve the efficiency, we develop an informed search based algorithm in TracLLM. We also develop contribution score ensemble/denoising techniques to improve the accuracy of TracLLM. Our evaluation results show TracLLM can effectively identify texts in a long context that lead to the output of an LLM. Our code and data are at: https://github.com/Wang-Yanting/TracLLM.

cs.CR↗

TrojanDec: Data-free Detection of Trojan Inputs in Self-supervised Learning

An image encoder pre-trained by self-supervised learning can be used as a general-purpose feature extractor to build downstream classifiers for various downstream tasks. However, many studies showed that an attacker can embed a trojan into an encoder such that multiple downstream classifiers built based on the trojaned encoder simultaneously inherit the trojan behavior. In this work, we propose TrojanDec, the first data-free method to identify and recover a test input embedded with a trigger. Given a (trojaned or clean) encoder and a test input, TrojanDec first predicts whether the test input is trojaned. If not, the test input is processed in a normal way to maintain the utility. Otherwise, the test input will be further restored to remove the trigger. Our extensive evaluation shows that TrojanDec can effectively identify the trojan (if any) from a given test input and recover it under state-of-the-art trojan attacks. We further demonstrate by experiments that our TrojanDec outperforms the state-of-the-art defenses.

cs.CR↗

A Critical Edge Number Revealed for Phase Stabilities of Two-Dimensional Ball-Stick Polygons

Phase behaviors of two-dimensional (2D) systems constitute a fundamental topic in condensed matter and statistical physics. Although hard polygons and interactive point-like particles are well studied, the phase behaviors of more realistic molecular systems considering intermolecular interaction and molecular shape remain elusive. Here we investigate by molecular dynamics simulation thermal stabilities of 2D ball-stick polygons, serving as simplified models for molecular systems. Below the melting temperature $T_{m}$, we identify a critical edge number $n_{c}$, at which a waving superlattice structure emerges; when n < $n_{c}$,the triangular system stabilizes at a spin-ice-like glassy state; when n > $n_{c}$,the polygons stabilize at crystalline states, and $T_{m}$ is higher for polygons with more edges at higher pressures but exhibits a crossover for hexagon and octagon at low pressures. A theoretical framework taking into account the competition between entropy and enthalpy is proposed to provide a comprehensive understanding of our results, which is anticipated to facilitate the design of 2D materials.

cond-mat.soft↗

FCert: Certifiably Robust Few-Shot Classification in the Era of Foundation Models

Few-shot classification with foundation models (e.g., CLIP, DINOv2, PaLM-2) enables users to build an accurate classifier with a few labeled training samples (called support samples) for a classification task. However, an attacker could perform data poisoning attacks by manipulating some support samples such that the classifier makes the attacker-desired, arbitrary prediction for a testing input. Empirical defenses cannot provide formal robustness guarantees, leading to a cat-and-mouse game between the attacker and defender. Existing certified defenses are designed for traditional supervised learning, resulting in sub-optimal performance when extended to few-shot classification. In our work, we propose FCert, the first certified defense against data poisoning attacks to few-shot classification. We show our FCert provably predicts the same label for a testing input under arbitrary data poisoning attacks when the total number of poisoned support samples is bounded. We perform extensive experiments on benchmark few-shot classification datasets with foundation models released by OpenAI, Meta, and Google in both vision and text domains. Our experimental results show our FCert: 1) maintains classification accuracy without attacks, 2) outperforms existing state-of-the-art certified defenses for data poisoning attacks, and 3) is efficient and general.

cs.CR↗

MMCert: Provable Defense against Adversarial Attacks to Multi-modal Models

Different from a unimodal model whose input is from a single modality, the input (called multi-modal input) of a multi-modal model is from multiple modalities such as image, 3D points, audio, text, etc. Similar to unimodal models, many existing studies show that a multi-modal model is also vulnerable to adversarial perturbation, where an attacker could add small perturbation to all modalities of a multi-modal input such that the multi-modal model makes incorrect predictions for it. Existing certified defenses are mostly designed for unimodal models, which achieve sub-optimal certified robustness guarantees when extended to multi-modal models as shown in our experimental results. In our work, we propose MMCert, the first certified defense against adversarial attacks to a multi-modal model. We derive a lower bound on the performance of our MMCert under arbitrary adversarial attacks with bounded perturbations to both modalities (e.g., in the context of auto-driving, we bound the number of changed pixels in both RGB image and depth image). We evaluate our MMCert using two benchmark datasets: one for the multi-modal road segmentation task and the other for the multi-modal emotion recognition task. Moreover, we compare our MMCert with a state-of-the-art certified defense extended from unimodal models. Our experimental results show that our MMCert outperforms the baseline.

cs.CV↗

Molecular Dynamics Simulations of Microscopic Structural Transition and Macroscopic Mechanical Properties of Magnetic Gels

Magnetic gels with embedded micro/nano-sized magnetic particles in crosslinked polymer networks can be actuated by external magnetic fields, with changes in their internal microscopic structures and macroscopic mechanical properties. We investigate the responses of such magnetic gels to an external magnetic field, by means of coarse-grained molecular dynamics simulations. We find that the dynamics of magnetic particles are determined by the interplay of between magnetic dipole-dipole interactions, polymer elasticity and thermal fluctuations. The corresponding microscopic structures formed by the magnetic particles such as elongated chains can be controlled by the external magnetic field. Furthermore, the magnetic gels can exhibit reinforced macroscopic mechanical properties, where the elastic modulus increases algebraically with the magnetic moments of the particles in the form of $\propto(m-m_{\mathrm{c}})^{2}$ when magnetic chains are formed. This simulation work can not only serve as a tool for studying the microscopic and the macroscopic responses of the magnetic gels, but also facilitate future fabrications and practical controls of magnetic composites with desired physical properties.

cond-mat.soft↗

Asymmetric Nucleation Processes in Spontaneous Mode Switch of Active Matter

Flocking and vortical are two typical motion modes in active matter. Although it is known that the two modes can spontaneously switch between each other in a finite-size system, the switching dynamics remain elusive. In this work, by computer simulation of a two-dimensional Vicsek-like system with 1000 particles, we find from the perspective of classical nucleation theory that the forward and backward switching dynamics are asymmetric: from flocking to vortical is a one-step nucleation process, while the opposite is a two-step nucleation process with the system staying in a metastable state before reaching the final flocking state.

cond-mat.soft↗

SFC Deployment in Space-Air-Ground Integrated Networks Based on Matching Game

The space-air-ground integrated network (SAGIN) is dynamic and flexible, which can support transmitting data in environments lacking ground communication facilities. However, the nodes of SAGIN are heterogeneous and it is intractable to share the resources to provide multiple services. Therefore, in this paper, we consider using network function virtualization technology to handle the problem of agile resource allocation. In particular, the service function chains (SFCs) are constructed to deploy multiple virtual network functions of different tasks. To depict the dynamic model of SAGIN, we propose the reconfigurable time extension graph. Then, an optimization problem is formulated to maximize the number of completed tasks, i.e., the successful deployed SFC. It is a mixed integer linear programming problem, which is hard to solve in limited time complexity. Hence, we transform it as a many-to-one two-sided matching game problem. Then, we design a Gale-Shapley based algorithm. Finally, via abundant simulations, it is verified that the designed algorithm can effectively deploy SFCs with efficient resource utilization.

cs.NI↗

Phase Behaviors of Ionic Liquids Attributed to the Dual Ionic and Organic Nature

Ionic liquids (ILs), also known as room-temperature molten salts, are composed of pure ions with melting points usually below 100 degrees centigrade. Because of their low volatility and vast amounts of species, ILs can serve as "green solvents" and "designer solvents" to meet the requirements of various applications by fine tuning their molecular structures. A good understanding of the phase behaviors of ILs is certainly fundamentally important in terms of their wide applications. This review intends to summarize the major conclusions so far drawn on phase behaviors of ILs by computational, theoretical, and experimental studies, illustrating the intrinsic relationship between their dual ionic and organic nature and the crystalline phases, nanoscale segregation liquid phase, ionic liquid crystal phases, as well as phase behaviors of their mixture with small organic molecules.

cond-mat.soft↗

Conservation of the Stokes-Einstein Relation in Supercooled Water

The Stokes-Einstein (SE) relation is commonly regarded as being breakdown in supercooled water. However, this conclusion is drawn upon testing the validities of some variants of the SE relation rather than its original form, and it appears conflicting with the fact that supercooled water is in its local equilibrium. In this work, we show by molecular dynamics simulation that both the Einstein and Stokes relations are indeed conserved in supercooled water. The inconsistency between the original SE relation and its variants comes from two facts: (1) the substitutes of the shear viscosity in the SE variants are wavevector-dependent, so it is only a cursory approximation; (2) the effective hydrodynamic radius actually decreases with decreasing temperature, instead of being a constant as assumed in the SE variants. Besides supercooled water, this inconsistency may also exist in other supercooled liquids.

cond-mat.soft↗

Modelling Elastically-Mediated Liquid-Liquid Phase Separation

We propose a continuum theory of the liquid-liquid phase separation in an elastic network where phase-separated microscopic droplets rich in one fluid component can form as an interplay of fluids mixing, droplet nucleation, network deformation, thermodynamic fluctuation, \emph{etc}. We find that the size of the phase separated droplets decreases with the shear modulus of the elastic network in the form of $\sim[\mathrm{modulus}]^{-1/3}$ and the number density of the droplet increases almost linearly with the shear modulus $\sim[\mathrm{modulus}]$, which are verified by the experimental observations. Phase diagrams in the space of (fluid constitution, mixture interaction, network modulus) are provided, which can help to understand similar phase separations in biological cells and also to guide fabrications of synthetic cells with desired phase properties.

cond-mat.soft↗

Statistical mechanics of a nonequilibrium steady-state classical particle system driven by a constant external force

A classical particle system coupled with a thermostat driven by an external constant force reaches its steady state when the ensemble-averaged drift velocity does not vary with time. The statistical mechanics of such a system is derived merely based on the equal probability and ergodicity principles, free from any conclusions drawn on equilibrium statistical mechanics or local equilibrium hypothesis. The momentum space distribution is determined by a random walk argument, and the position space distribution is determined by employing the equal probability and ergodicity principles. The expressions for energy, entropy, free energy, and pressures are then deduced, and the relation among external force, drift velocity, and temperature is also established. Moreover, the relaxation towards its equilibrium is found to be an exponentially decaying process obeying the minimum entropy production theorem.

cond-mat.stat-mech↗

A Brief Review of Continuous Models for Ionic Solutions: the Poisson-Boltzmann and Related Theories

The Poisson-Boltzmann (PB) theory is one of the most important theoretical models describing charged systems continuously. However, it suffers from neglecting ion correlations, which hinders its applicability to more general charged systems other than extremely dilute ones. Therefore, some modified versions of the PB theory are developed to effectively include ion correlations. Focused on their applications to ionic solutions, the original PB theory and its variances, including the field-theoretic approach, the correlation-enhanced PB model, the Outhwaite-Bhuiyan modified PB theory and the mean field theories, are briefly reviewed in this paper with the diagnosis of their advantages and limitations.

cond-mat.stat-mech↗