SearcharxivSearch

arXiv subjects

Zelin Zhang

Publications and source records attributed to Zelin Zhang.

At least 19 recordsLinked to original sources

Thermodynamics of Kerr-Newman-Bertotti-Robinson black holes

In this work, we extend the thermodynamic analyses of the neutral and specially charged Kerr-Bertotti-Robinson black holes to the general Kerr-Newman-Bertotti-Robinson family, in which the electric and external-field parameters are independent. Using covariant surface charges and canonical integrability methods, we determine the total angular momentum and the canonical mass. The angular momentum follows analytically from the combined gravitational and electromagnetic surface charges. However, the infinitesimal charge associated with coordinate time translations is not integrable in solution space, so the mass must be associated with a more general symmetry generator. Imposing the canonical integrability conditions on this generator, together with the Kerr-Newman mass as the zero-field boundary condition, selects the Christodoulou-Ruffini mass and determines the associated thermodynamic potentials. The first law and Smarr formula take the same form as the ones in usual Kerr-Newman case, and the two previously studied Kerr-Bertotti-Robinson cases are recovered as special limits.

gr-qc

Shadows and Thin-Disk Images of Kerr-Newman Black Holes in a Bertotti-Robinson Magnetic Field

In this paper, we investigate the optical properties of Kerr-Newman-Bertotti-Robinson (KN-BR) black holes. We use the separability of null geodesics to analyze unstable spherical photon orbits and determine the radial extent of the photon shell. Because the spacetime is not asymptotically flat, we construct the critical curve on the screen of a finite-distance zero-angular-momentum observer. We then perform backward ray tracing for a geometrically thin and optically thin disk that extends from the outer region to the event horizon, and examine the resulting images, intensity profiles, critical-curve areas, and inner-shadow areas. We find that the genuine neutral Kerr-BR$_0$ and specially charged Kerr-BR$_s$ configurations have nearly identical optical appearances. It is remarkable that for the KN-BR black holes increasing the electric charge reduces the characteristic image size in the Kerr-Newman limit but enlarges it in the magnetized configurations considered here. We also find that the external magnetic field strongly increases the apparent image scale, while the observer inclination affects the inner-shadow area more significantly than the critical-curve area. These results may provide useful theoretical insight for future observations aimed at identifying such exotic magnetized black holes.

gr-qc

MarkNull: Model-Agnostic Watermark Removal in AI-Generated Images via On-Manifold Latent Manipulation

Digital watermarking has emerged as a critical technique for provenance and copyright attribution in AI-generated imagery, yet its robustness against realistic, model-agnostic removal attacks remains poorly explored. Existing attacks either succeed only against specific generative models or achieve removal at the cost of severe visual degradation. In this paper, we propose MarkNull, a model-agnostic watermark removal attack via on-manifold latent manipulation. MarkNull is grounded in a key observation: watermarked images exhibit a strong statistical dependency between the generated latent representation and the embedded initial noise. To quantify this dependency, we introduce the Noise-Latent Alignment Score (NLAS) and formulate an optimization objective that selectively decorrelates the latent representation from the embedded watermark while preserving semantic fidelity. Extensive evaluations across different categories of watermarking paradigms, including post-hoc, fine-tuning-based, and initial-noise-based schemes, demonstrate that MarkNull reduces average bit accuracy to 53.14%, approaching random-guessing (50%), without perceptible image degradation. To further improve scalability, we propose MarkNull-A, an amortized, optimization-free variant that distills the attack into a single forward pass, achieving 0.50 s/image with modest computational overhead. Notably, our attacks successfully compromise Google's SynthID-Image system while preserving high visual quality and transfer effectively to video watermarking. Finally, we present an attack detection mechanism as a defensive counterpart to MarkNull and MarkNull-A, highlighting the necessity of developing watermark designs resilient to model-agnostic latent-space attacks.

cs.CR

LoginTrap: Uncovering Task-Agnostic Phishing-Style Indirect Prompt Injection Attacks against LLM-based Web Agents

LLM-based web agents automate user tasks by observing webpages and executing browser actions on behalf of users. As these agents operate on real web services, login becomes a sensitive authentication boundary because it involves credentials and sensitive information. Existing work shows that malicious webpage content can manipulate web agent actions, but it has not fully examined whether such content can induce login and cause end-to-end private data leakage. We study this attack surface and present LoginTrap, a task-agnostic login-inducing attack against LLM-based web agents. LoginTrap assumes a black box attacker that controls the webpage context and the induced login flow without knowing the user task or web agent internals. Under this threat model, LoginTrap uses webpage context to generate page-specific indirect injections through a fuzzing-inspired process, making login appear as a plausible prerequisite for continuing the task and guiding the agent to a controlled login page. We conduct a comprehensive analysis of LoginTrap across realistic web agent executions. The results show that LoginTrap reaches 86\% average end-to-end attack success across LLM backbones and remains effective across agent architectures and defenses. These findings identify login inducement as a systematic authentication boundary risk and motivate further research on authentication-aware defenses for web agents.

cs.CR

Images of Braneworld black holes with radiatively inefficient accretion flows

Horizon-scale imaging acts as a transformative tool for probing spacetime geometry, enabling stringent tests of gravitational theories in the strong-field regime. The Casadio-Fabbri-Mazzacurati(CFM) black hole in braneworld contains an extra parameter that characterizes the tidal effects from the bulk geometry, making it highly valuable for this task. We perform general relativistic radiative transfer (GRRT) simulations and generate synthetic images consistent with Event Horizon Telescope observations of M87*. We find that the tidal parameter imprints nonmonotonic changes on the image morphology, underscoring the intricate coupling between spacetime geometry and the observable radiation from the accreting plasma. We also analyze the image-comparison metric using normalized cross-correlation coefficients and the DSSIM index and find that the magnitudes of these mismatches are on the order of 10^3, which implies that identifying braneworld black holes through black hole images remains challenging even with future ngEHT and BHEX observations.

gr-qc

Security, Privacy, and Ethical Risks in OpenClaw

This paper systematically investigates the security, privacy, and ethical risks, as well as the traceability challenges of OpenClaw, a locally executable AI agent system for natural language interaction and real-world task completion. While OpenClaw shows strong potential for personal assistance, office automation, cross-platform task management, and information integration, it also raises serious security, privacy, and ethical concerns. By analyzing its system architecture, core functionalities, deployment model, and representative application scenarios, this paper aims to reveal the risks that may arise when such a highly privileged agent is integrated into personal and organizational digital environments. We focus in particular on the challenges associated with persistent local storage, tool invocation, cross-context information aggregation, multi-user interaction, and the integration of plugins and external services. We argue that these issues constitute major barriers to the trustworthy deployment and widespread adoption of this technology. Finally, we summarize the open challenges in security defenses, privacy protection, ethical governance, and traceability in agent use, and call for joint efforts from researchers, developers, deployers, and regulators to build AI agent systems that are safer, more reliable, and more trustworthy.

cs.CR

Are Watermarked Images Editable? SafeMark for Watermark-Preserving Text-Guided Image Editing

This paper investigates a fundamental yet underexplored question: can watermarked images remain editable without compromising watermark integrity? We propose SafeMark, a framework for watermark-preserving text-guided image manipulation that explicitly integrates watermark integrity into the editing process. Specifically, SafeMark adds a thresholded watermark-decoding loss directly to the diffusion editor's training objective, fine-tuning the editor so that semantically valid edits also preserve the embedded watermark at the final output. This design admits a clean information-theoretic justification: maintaining high bit-accuracy on the edited image lower-bounds the mutual information that the editor channel preserves between watermark and edited output, the quantity that fundamentally controls watermark recoverability. SafeMark is compatible with differentiable diffusion-based editors, and requires no architectural modification. Extensive evaluations across multiple datasets, text-guided editing methods, and post-edit distortion settings demonstrate that SafeMark achieves high watermark bit accuracy across diverse editing settings while maintaining high-quality semantic edits, without sacrificing robustness to common post-edit distortions. These results demonstrate that semantic editability and watermark integrity are fundamentally compatible, enabling trustworthy image provenance in generative editing pipelines.

cs.CV

From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI

Generative AI systems are increasingly used not only to produce content but also to retrieve data, invoke tools, and execute actions. This work examines the security and safety implications of that shift across content-level, model-level, and agentic threats. We analyze how attacker access requirements, system autonomy, and the scope of potential harm change as models move from generating artifacts to executing operations through tool chains and external APIs. We then assess technical countermeasures including detection, watermarking, alignment, and emerging agentic safeguards, and show that several depend on forms of institutional coordination that current governance arrangements do not yet provide. Across the cases examined, capability deployment and attack-surface expansion repeatedly outpace defensive responses as systems move from generating content to executing real-world actions.

cs.CR

CrossWeaver: Cross-modal Weaving for Arbitrary-Modality Semantic Segmentation

Multimodal semantic segmentation has shown great potential in leveraging complementary information across diverse sensing modalities. However, existing approaches often rely on carefully designed fusion strategies that either use modality-specific adaptations or rely on loosely coupled interactions, thereby limiting flexibility and resulting in less effective cross-modal coordination. Moreover, these methods often struggle to balance efficient information exchange with preserving the unique characteristics of each modality across different modality combinations. To address these challenges, we propose CrossWeaver, a simple yet effective multimodal fusion framework for arbitrary-modality semantic segmentation. Its core is a Modality Interaction Block (MIB), which enables selective and reliability-aware cross-modal interaction within the encoder, while a lightweight Seam-Aligned Fusion (SAF) module further aggregates the enhanced features. Extensive experiments on multiple multimodal semantic segmentation benchmarks demonstrate that our framework achieves state-of-the-art performance with minimal additional parameters and strong generalization to unseen modality combinations.

cs.CV

When and Why Does Unsupervised RL Succeed in Mathematical Reasoning? A Manifold Envelopment Perspective

Although outcome-based reinforcement learning (RL) significantly advances the mathematical reasoning capabilities of Large Language Models (LLMs), its reliance on computationally expensive ground-truth annotations imposes a severe scalability bottleneck. Unsupervised RL guided by intrinsic rewards offers a scalable alternative, yet it suffers from opaque training dynamics and catastrophic instability, such as policy collapse and reward hacking. In this paper, we first design and evaluate a suite of intrinsic rewards that explicitly enforce concise and certain generation. Second, to discover the boundaries of this approach, we test base models across a spectrum of intrinsic reasoning capabilities, revealing how a model's foundational logical prior dictates its success or failure. Finally, to demystify why certain configurations stabilize while others collapse, we introduce a novel geometric diagnostic lens, showing that successful cases are enveloped by manifolds. Ultimately, our work goes beyond merely demonstrating that enforcing concise and certain responses successfully boosts mathematical reasoning; we reveal when this unsupervised approach breaks down and geometrically diagnose why.

cs.LG

Secure and Robust Watermarking for AI-generated Images: A Comprehensive Survey

The rapid progress of Generative Artificial Intelligence (GenAI) has enabled the effortless synthesis of high-quality visual content, while simultaneously raising pressing concerns about intellectual property protection, authenticity, and accountability. Among various countermeasures, watermarking has emerged as a fundamental mechanism for tracing provenance, distinguishing AI-generated images from natural content, and supporting trustworthy digital ecosystems. This paper presents a comprehensive survey of AI-generated image watermarking, systematically reviewing the field from five perspectives: (1) the formalization and fundamental components of image watermarking systems; (2) existing watermarking methodologies and their comparative characteristics; (3) evaluation metrics in terms of visual fidelity, embedding capacity, and detectability; (4) known vulnerabilities under malicious attacks and recent advances in secure and robust watermarking designs; and (5) open challenges, emerging trends, and future research directions. The survey seeks to offer researchers a holistic understanding of watermarking technologies for AI-generated images and to facilitate their continued advancement toward secure and responsible AI-generated content practices.

cs.CR

MarkSweep: A No-box Removal Attack on AI-Generated Image Watermarking via Noise Intensification and Frequency-aware Denoising

AI watermarking embeds invisible signals within images to provide provenance information and identify content as AI-generated. In this paper, we introduce MarkSweep, a novel watermark removal attack that effectively erases the embedded watermarks from AI-generated images without degrading visual quality. MarkSweep first amplifies watermark noise in high-frequency regions via edge-aware Gaussian perturbations and injects it into clean images for training a denoising network. This network then integrates two modules, the learnable frequency decomposition module and the frequency-aware fusion module, to suppress amplified noise and eliminate watermark traces. Theoretical analysis and extensive experiments demonstrate that invisible watermarks are highly vulnerable to MarkSweep, which effectively removes embedded watermarks, reducing the bit accuracy of HiDDeN and Stable Signature watermarking schemes to below 67%, while preserving perceptual quality of AI-generated images.

cs.CR

Mean-Field Game for Gene Expression of Beetles

In this paper, we investigate the probability of the expression of genes that control the size of beetles under competitive relationships. We use the mean field game (MFG) theory in multiple populations to characterize the different competitive pressures of large and small beetles in the population, and simulate the probability of gene expression in finite time $[0, T]$. Therefore, we prove the existence and uniqueness of the solution of the equation under some assumptions.

math.OC

EGFormer: Towards Efficient and Generalizable Multimodal Semantic Segmentation

Recent efforts have explored multimodal semantic segmentation using various backbone architectures. However, while most methods aim to improve accuracy, their computational efficiency remains underexplored. To address this, we propose EGFormer, an efficient multimodal semantic segmentation framework that flexibly integrates an arbitrary number of modalities while significantly reducing model parameters and inference time without sacrificing performance. Our framework introduces two novel modules. First, the Any-modal Scoring Module (ASM) assigns importance scores to each modality independently, enabling dynamic ranking based on their feature maps. Second, the Modal Dropping Module (MDM) filters out less informative modalities at each stage, selectively preserving and aggregating only the most valuable features. This design allows the model to leverage useful information from all available modalities while discarding redundancy, thus ensuring high segmentation quality. In addition to efficiency, we evaluate EGFormer on a synthetic-to-real transfer task to demonstrate its generalizability. Extensive experiments show that EGFormer achieves competitive performance with up to 88 percent reduction in parameters and 50 percent fewer GFLOPs. Under unsupervised domain adaptation settings, it further achieves state-of-the-art transfer performance compared to existing methods.

cs.CV

BCDDM: Branch-Corrected Denoising Diffusion Model for Black Hole Image Generation

The properties of black holes and accretion flows can be inferred by fitting Event Horizon Telescope (EHT) data to simulated images generated through general relativistic ray tracing (GRRT). However, due to the computationally intensive nature of GRRT, the efficiency of generating specific radiation flux images needs to be improved. This paper introduces the Branch Correction Denoising Diffusion Model (BCDDM), a deep learning framework that synthesizes black hole images directly from physical parameters. The model incorporates a branch correction mechanism and a weighted mixed loss function to enhance accuracy and stability. We have constructed a dataset of 2,157 GRRT-simulated images for training the BCDDM, which spans seven key physical parameters of the radiatively inefficient accretion flow (RIAF) model. Our experiments show a strong correlation between the generated images and their physical parameters. By enhancing the GRRT dataset with BCDDM-generated images and using ResNet50 for parameter regression, we achieve significant improvements in parameter prediction performance. BCDDM offers a novel approach to reducing the computational costs of black hole image generation, providing a faster and more efficient pathway for dataset augmentation, parameter estimation, and model fitting.

astro-ph.GA

Images of Kerr-MOG black holes surrounded by geometrically thick magnetized equilibrium tori

We adopt general relativistic ray-tracing (GRRT) schemes to study images of Kerr-MOG black holes surrounded by geometrically thick magnetized equilibrium tori, which belong to steady-state solutions of thick accretion disks within the framework of general relativistic magnetohydrodynamics (GRMHD). The black hole possesses an extra dimensionless MOG parameter described its deviation from usual Kerr one. Our results show that the presence of the MOG parameter leads to smaller disks in size, but enhances the total flux density and peak brightness in their images. Combining with observation data of black hole M87* from the Event Horizon Telescope (EHT), we make a constraint on parameters of the Kerr-MOG black hole and find that the presence of the MOG parameter broadens the allowable range of black hole spin.

gr-qc

Constraining a disformal Schwarzschild black hole in DHOST theories with the orbit of the S2 star

With the observed data of the S2 orbit around the black hole Sgr A$^*$ and the Markov Chain Monte Carlo method, we make a constraint on parameters of a disformal Schwarzschild black hole in quadratic degenerate higher-order scalar-tensor (DHOST) theories. This black hole belongs to a class of non-stealth solutions and owns an extra disformal parameter described the deviation from general relativity. Our results show that the best fit value of the disformal parameter is positive. However, in the range of $1σ$, we also find that general relativity remains to be consistent with the observation of the S2 orbit.

gr-qc

Polarized image of a rotating black hole surrounded by a cold dark matter halo

We have studied the polarized image of an equatorial emitting ring around a rotating black hole surrounded by a cold dark matter (CDM) halo. Results show that the CDM halo density has the similar effects of the halo's characteristic radius on the polarized image for the black hole. The effects of the CDM halo on the polarized image depend on the magnetic field configuration, the fluid velocity and the observed inclination. With the increase of the CDM halo parameters, the observed polarization intensity decreases when the magnetic field lies in equatorial plane, but in the case where the magnetic field is perpendicular to the equatorial plane, the change of the observed polarization intensity with CDM halo also depends on the position of the emitting point in the ring. The change of the electric vector position angle (EVPA) with the CDM halo becomes more complicated. Our results also show that the influence of the CDM halo on the polarized image is generally small, which are consistent with the effects of dark matter halo on black hole shadows. These results could help to further understand dark matter from black hole images.

gr-qc