Searcharxiv⌕ Search

arXiv subjects

Zhiqiang Hao

Publications and source records attributed to Zhiqiang Hao.

2 recordsLinked to original sources

APEX: Active Protection at Execution Boundaries for LLM Agents

Indirect prompt injection (IPI) hides adversarial instructions in content that large language model (LLM) agents read at runtime. As agents compose heterogeneous capability units, including Tools, MCP servers, and Skills, the carriers of injection multiply, and defenses built to recognize attack patterns fall behind them. We instead shift defense from covering attack patterns to one stable point: whatever the carrier and however the injection propagates, harm materializes only at the \emph{execution boundary}, where the agent turns internal state into an external action or released output. Safety there turns on two conditions, both settled by the trusted task rather than by the run: whether the proposed effect is authorized, and whether the runtime information reaching it is endorsed by that task. We present APEX, an active defense that enforces both at this boundary from a single authorization contract compiled before untrusted execution: \emph{evidence-gated prevention} admits an effect only when the contract justifies it, while \emph{deception-based exposure} makes unendorsed use reveal itself before the effect commits. Protection therefore follows from what the task permits rather than from how an attack is built, and applies uniformly across capability units without attack-specific policies or taint tracking. Against 13 baselines, APEX attains 0\% attack success on five of six benchmarks and 0.56\% on the sixth, holds 0\% under adaptive attacks on all three capability-unit types, and remains effective across defender backbones. Code is available at https://github.com/ZhengXR930/APEX_official/tree/official.

cs.CR↗

Two-party quantum private comparison based on eight-qubit entangled state

The purpose of quantum private comparison (QPC) is to solve "Tierce problem" using quantum mechanics laws, where the "Tierce problem" is to judge whether the secret data of two participants are equal under the condition of protecting data privacy. Here we consider for the first time the usefulness of eight-qubit entangled states for QPC by proposing a new protocol. The proposed protocol only adopts necessary quantum technologies such as preparing quantum states and quantum measurements without using any other quantum technologies (e.g. unitary operations and entanglement swapping), thus the protocol has advantages in quantum device consumption. The measurements adopted only include single-particle measurements, which is easier to implement than entangled-state measurements under the existing technical conditions. The proposed protocol takes advantage of the entanglement characteristics of the eight-qubit entangled state, and uses joint computation, decoy photon technology, the keys generated by a quantum key distribution protocol to ensure data privacy. We show that when all singleparticle measurements in the proposed protocol are replaced by Bell measurements, the purpose of the protocol can also be achieved. We also show that the proposed protocol can be changed into a semi-quantum protocol with a few small changes.

quant-ph↗