SearcharxivSearch

arXiv subjects

Yixin He

Publications and source records attributed to Yixin He.

18 recordsLinked to original sources

A counterexample to Nevanlinna's century-old half-plane problem

Let $\mathbb{H}=\{z\in\mathbb{C}:\operatorname{Im}z>0\}$, and let $N(\mathbb{H})$ denote the Nevanlinna class in $\mathbb{H}$, consisting of meromorphic functions representable as quotients of two bounded analytic functions in $\mathbb{H}$. We construct a nonconstant meromorphic function $F$ on $\mathbb{C}$ such that $F^{-1}(\{0,1,\infty\})\subset\mathbb{R}$ and $F|_{\mathbb{H}}\notin N(\mathbb{H})$. Thus, omitting three distinct values of the Riemann sphere in a half-plane does not force a meromorphic function on $\mathbb{C}$ to be of bounded type there. This provides a counterexample to Nevanlinna's century-old half-plane problem.

math.CV

The nonseparable case of Kadison's problem on orthonormal bases of unitaries for type $\mathrm{II}_1$ factors

In 1967, Kadison asked ``does every type $\mathrm{II}_1$ factor have an orthonormal (with respect to the trace) basis consisting of unitaries?''In a previous paper \cite{HTZ26}, He, Tang, and Zhang resolved Kadison's problem in the separable case. We prove the complementary nonseparable case and thereby resolve Kadison's problem in full. In fact, the basis may be chosen to consist of self-adjoint unitaries. The proof combines a relative norming lemma under small-density constraints, a finite-layer certification scheme ensuring that the relevant Hilbert-space projections are represented by bounded elements of the ambient factor, and a transfinite extension along the density character of $L^2(M,\tau)$.

math.OA

Beurling--Carleson Endpoint Counterexamples: Singular Inner Functions and a Semilinear Equation

We settle two endpoint problems for Beurling--Carleson support conditions. For $0 3$ and $\alpha=\frac{m-3}{m-1}$, we construct a nonatomic probability measure supported on a single $\alpha$-Beurling--Carleson set that is not the deficiency measure of any nearly maximal solution of $\Delta u=(u_+)^m$. Thus hereditary failure persists at the first endpoint, while the critical support condition in the second problem is necessary but not sufficient. The proofs combine endpoint Cantor--Moran constructions with kernel divergence and a nonlinear energy obstruction.

math.CV

Variable-Radius Disk Transforms and an Area-Integral Problem of Zalcman

For $0<\alpha\leq1$, define $(\mathcal T_\alpha f)(z) :=\int_{B(z,\alpha(1-|z|))}f(\zeta)\,dA(\zeta)$ for $z\in\mathbb D$, where $dA$ is planar Lebesgue measure. We prove that $\mathcal T_\alpha$ is injective on $C(\mathbb D)\cap L^\infty(\mathbb D)$ for $0<\alpha<1$, and that $\mathcal T_1$ is injective on $L^1(\mathbb D)$. In contrast, for each $0<\alpha<1$ there is an injective linear map from $C_c^\infty((0,\alpha))$ into the kernel of $\mathcal T_\alpha$ on $C^\infty(\mathbb D)$; every nonzero function in its image is necessarily unbounded near $\partial\mathbb D$. Under the area-measure interpretation, these results give a complete answer to Hayman--Lingham Problem~7.29, attributed there to L.~Zalcman. The proof combines generalized Abel equations, an Euler--Poisson--Darboux energy argument, and Volterra continuation.

math.FA

The separable case of Kadison's problem on orthonormal bases of unitaries for type $\mathrm{II}_1$ factors

In 1967, Kadison asked ``does every type $\mathrm{II}_1$ factor have an orthonormal (with respect to the trace) basis consisting of unitaries?'' Using a noncommutative Lyapunov theorem of Akemann and Weaver, we prove that if $M$ is a separable diffuse finite von Neumann algebra with a normal faithful trace $\tau$, then $L^2(M,\tau)$ admits an orthonormal basis consisting of self-adjoint unitaries in $M$. Consequently, we affirm the separable case of the Kadison problem.

math.OA

A Solution to a Problem of Rubel on Two-Parameter Normal Families of Entire Functions

We construct an entire function $ F(z,a,b)\in \mathcal{O}(\mathbb{C}^3) $ such that the family $$ \{F(\,\cdot\,,a,b):a,b\in\mathbb{C}\} $$ of entire functions of \(z\) is normal on \(\mathbb{C}\), while \(F\) does not factor through a single entire parameter. This solves a problem of L.~A.~Rubel concerning Liouville-type rigidity. In fact, our example satisfies the stronger condition $$ F_bF_{a,z}-F_aF_{b,z}\neq 0 \qquad\text{on }\mathbb{C}^3. $$ The geometric core of the construction is a Fatou--Bieberbach domain contained in the thin region $$ \{(u,v)\in\mathbb{C}^2:|u-v^2|<1+|v|\}. $$ We obtain this domain from the basin of attraction of an explicit polynomial automorphism of \(\mathbb{C}^2\), together with the theorem of Rosay and Rudin on attracting basins.

math.CV

On Fuchs's additive intersection problem for the hyperbolic metric

For hyperbolic domains $D_1,D_2\subset \{z\in\mathbb C:|z|<R\}$ and $z\in D_1\cap D_2$, we consider the ratio $$ \frac{\lambda_{D_1\cap D_2}(z)} {\lambda_{D_1}(z)+\lambda_{D_2}(z)}. $$ We solve a problem of W. H. J. Fuchs by proving that the supremum of this ratio is $+\infty$ when $D_1$ and $D_2$ range over all hyperbolic domains. If $D_1$ and $D_2$ are further assumed to be simply connected, then the supremum is $1$. We also show that the infimum of this ratio is $\frac12$ in both settings, and that the value $\frac12$ is attained if and only if $D_1=D_2$.

math.CV

Generalizing the Clunie--Hayman construction in an Erd\H{o}s maximum-term problem

Let $f(z)=\sum_{n\ge0}a_n z^n$ be a transcendental entire function and write $M(r,f):=\max_{|z|=r}|f(z)|$ and $\mu(r,f):=\max_{n\ge0}|a_n|\,r^n$. A problem of Erd\H{o}s asks for the value of $$ B:=\sup_f \liminf_{r\to\infty}\frac{\mu(r,f)}{M(r,f)}. $$ In 1964, Clunie and Hayman proved that $\frac{4}{7} 0.58507, $$ improving the classical constant $\frac{4}{7}$.

math.CV

An Erd\H{o}s--Trotter problem on antichains with multiplicity $r$ on each occurring level

Fix an integer $r\ge2$. For each $n$ we consider families $\mathcal F\subseteq 2^{[n]}$ that form an antichain and have the property that, for every $t$, if there exists $A\in\mathcal F$ with $|A|=t$ then there exist at least $r$ members of $\mathcal F$ of size $t$. A problem of Erd\H{o}s and Trotter asserts that, for each fixed $r$, there exists a threshold $n_0(r)$ such that whenever $n>n_0(r)$ one can achieve $n-3$ distinct set sizes in such a family, and asks for estimates on $n_0(r)$. We compute that $n_0(2)=3$ and $n_0(3)=8$. For all $r\ge4$ we prove matching linear bounds up to lower-order terms, namely $$ 2r+2 \le n_0(r) \le 2r+2\log_2 r + O(\log_2\log_2 r). $$ In particular, $n_0(r) = 2r + o(r)$.

math.CO

PINA: Prompt Injection Attack against Navigation Agents

Navigation agents powered by large language models (LLMs) convert natural language instructions into executable plans and actions. Compared to text-based applications, their security is far more critical: a successful prompt injection attack does not just alter outputs but can directly misguide physical navigation, leading to unsafe routes, mission failure, or real-world harm. Despite this high-stakes setting, the vulnerability of navigation agents to prompt injection remains largely unexplored. In this paper, we propose PINA, an adaptive prompt optimization framework tailored to navigation agents under black-box, long-context, and action-executable constraints. Experiments on indoor and outdoor navigation agents show that PINA achieves high attack success rates with an average ASR of 87.5%, surpasses all baselines, and remains robust under ablation and adaptive-attack conditions. This work provides the first systematic investigation of prompt injection attacks in navigation and highlights their urgent security implications for embodied LLM agents.

cs.CR

Red Teaming Program Repair Agents: When Correct Patches can Hide Vulnerabilities

LLM-based agents are increasingly deployed for software maintenance tasks such as automated program repair (APR). APR agents automatically fetch GitHub issues and use backend LLMs to generate patches that fix the reported bugs. However, existing work primarily focuses on the functional correctness of APR-generated patches, whether they pass hidden or regression tests, while largely ignoring potential security risks. Given the openness of platforms like GitHub, where any user can raise issues and participate in discussions, an important question arises: Can an adversarial user submit a valid issue on GitHub that misleads an LLM-based agent into generating a functionally correct but vulnerable patch? To answer this question, we propose SWExploit, which generates adversarial issue statements designed to make APR agents produce patches that are functionally correct yet vulnerable. SWExploit operates in three main steps: (1) program analysis to identify potential injection points for vulnerable payloads; (2) adversarial issue generation to provide misleading reproduction and error information while preserving the original issue semantics; and (3) iterative refinement of the adversarial issue statements based on the outputs of the APR agents. Empirical evaluation on three agent pipelines and five backend LLMs shows that SWExploit can produce patches that are both functionally correct and vulnerable (the attack success rate on the correct patch could reach 0.91, whereas the baseline ASRs are all below 0.20). Based on our evaluation, we are the first to challenge the traditional assumption that a patch passing all tests is inherently reliable and secure, highlighting critical limitations in the current evaluation paradigm for APR agents.

cs.SE

Learning to Ponder: Adaptive Reasoning in Latent Space

Test-time compute has emerged as a key paradigm for enhancing LLM reasoning, yet prevailing approaches like Best-of-N and majority voting apply uniform depth across inputs, wasting computation on simple queries while potentially under-thinking complex ones. We present FR-Ponder, a single-graph, backbone-training-free framework that allocates instance-adaptive reasoning compute via latent steering. A less than 1M-param controller observes hidden states and decides to halt or apply a small ponder step by adding a pre-computed steering vector to frozen representations. Our method extracts the latent steering vector associated with deeper reasoning outputs and direct IO from LLM and re-applies it through a tunable scaling factor, allowing the model to adapt its reasoning depth to the complexity of each input. To balance performance and computational cost, we employ Group Relative Policy Optimization (GRPO) as a reward signal to adaptively regulate reasoning depth, achieving task accuracy while mitigating overreasoning. Through curriculum learning and careful reward engineering, FR-Ponder learns calibrated compute allocation correlated with problem difficulty. On GSM8K and MATH500, FR-Ponder improves the compute-accuracy frontier, delivering lower FLOPs with better matched accuracy and comparing favorably to early-exit baselines, without modifying backbone weights. Analyses visualize interpretable steering directions and show learned compute allocation correlates with problem difficulty.

cs.AI

Your Compiler is Backdooring Your Model: Understanding and Exploiting Compilation Inconsistency Vulnerabilities in Deep Learning Compilers

Deep learning (DL) compilers are core infrastructure in modern DL systems, offering flexibility and scalability beyond vendor-specific libraries. This work uncovers a fundamental vulnerability in their design: can an official, unmodified compiler alter a model's semantics during compilation and introduce hidden backdoors? We study both adversarial and natural settings. In the adversarial case, we craft benign models where triggers have no effect pre-compilation but become effective backdoors after compilation. Tested on six models, three commercial compilers, and two hardware platforms, our attack yields 100% success on triggered inputs while preserving normal accuracy and remaining undetected by state-of-the-art detectors. The attack generalizes across compilers, hardware, and floating-point settings. In the natural setting, we analyze the top 100 HuggingFace models (including one with 220M+ downloads) and find natural triggers in 31 models. This shows that compilers can introduce risks even without adversarial manipulation. Our results reveal an overlooked threat: unmodified DL compilers can silently alter model semantics. To our knowledge, this is the first work to expose inherent security risks in DL compiler design, opening a new direction for secure and trustworthy ML.

cs.CR

Diagnosing Memorization in Chain-of-Thought Reasoning, One Token at a Time

Large Language Models (LLMs) perform well on reasoning benchmarks but often fail when inputs alter slightly, raising concerns about the extent to which their success relies on memorization. This issue is especially acute in Chain-of-Thought (CoT) reasoning, where spurious memorized patterns can trigger intermediate errors that cascade into incorrect final answers. We introduce STIM, a novel framework for Source-aware Token-level Identification of Memorization, which attributes each token in a reasoning chain to one of multiple memorization sources - local, mid-range, or long-range - based on their statistical co-occurrence with the token in the pretraining corpus. Our token-level analysis across tasks and distributional settings reveals that models rely more on memorization in complex or long-tail cases, and that local memorization is often the dominant driver of errors, leading to up to 67% of wrong tokens. We also show that memorization scores from STIM can be effective in predicting the wrong tokens in the wrong reasoning step. STIM offers a powerful tool for diagnosing and improving model reasoning and can generalize to other structured step-wise generation tasks.

cs.CL

Recent Advances in Large Langauge Model Benchmarks against Data Contamination: From Static to Dynamic Evaluation

Data contamination has received increasing attention in the era of large language models (LLMs) due to their reliance on vast Internet-derived training corpora. To mitigate the risk of potential data contamination, LLM benchmarking has undergone a transformation from static to dynamic benchmarking. In this work, we conduct an in-depth analysis of existing static to dynamic benchmarking methods aimed at reducing data contamination risks. We first examine methods that enhance static benchmarks and identify their inherent limitations. We then highlight a critical gap-the lack of standardized criteria for evaluating dynamic benchmarks. Based on this observation, we propose a series of optimal design principles for dynamic benchmarking and analyze the limitations of existing dynamic benchmarks. This survey provides a concise yet comprehensive overview of recent advancements in data contamination research, offering valuable insights and a clear guide for future research efforts. We maintain a GitHub repository to continuously collect both static and dynamic benchmarking methods for LLMs. The repository can be found at this link.

cs.LG