SearcharxivSearch

arXiv subjects

Ziyang You

Publications and source records attributed to Ziyang You.

9 recordsLinked to original sources

Invisible Manipulation Channels in AI-Assisted Financial Advisory: Implications for Market Integrity and Regulatory Design

AI systems are increasingly deployed for credit assessment and investment advisory in global financial markets, yet the integrity of their inference pipelines remains insufficiently addressed by existing regulatory frameworks. This paper identifies and empirically validates an invisible manipulation channel operating at the sampling layer of LLM inference--a vulnerability that allows adversaries to systematically bias AI-generated financial opinions while preserving full compliance with output-based audit mechanisms, including statistical watermarking. We show that this inference-stage manipulation is statistically hard to detect: the Kullback-Leibler divergence between manipulated and normal output distributions can be made arbitrarily small, so that any output-based detection scheme requires impractically large sample sizes to achieve reliable detection power. Empirical experiments across credit rating and investment advisory scenarios show that directional bias keywords can be amplified by 1.8-1.9x under stealth-preserving (aware) manipulation while triggering zero of six black-box detectors and preserving watermark integrity. The vulnerability generalizes across three mainstream watermarking schemes and three heterogeneous model architectures, establishing it as a systemic financial infrastructure risk. Software-based defenses including cryptographically secure pseudorandom number generators are entirely ineffective, while QRNG combined with TEE hardware isolation achieves 100% attack blocking--reducing the target rate to the natural baseline--by replacing the predictable hash key with quantum-derived entropy that renders all pre-computed manipulation targets invalid. We propose four regulatory amendments centered on mandatory QRNG certification for high-risk financial AI systems under NIST SP 800-90B, inference-layer supply chain audits, and output provenance mechanisms.

cs.CR

Blind PRNG Hijacking: An Undetectable Integrity-Preserving Attack Against LLM Watermarking

Cryptographic watermarking is a leading defense for attributing text generated by large language models (LLMs). Existing schemes, including KGW, Unigram, and DipMark, derive their security guarantees from the assumption that the underlying pseudo-random number generator (PRNG) is trustworthy. This work introduces SeedHijack, the first supply-chain attack on LLM watermarking that is simultaneously (i) blind -- requiring no knowledge of the watermark key, detector, or model logits, (ii) integrity-preserving -- amplifying rather than erasing the watermark signal, and (iii) orthogonal to detection -- the attack-induced bias is statistically independent of all content-side detector statistics, ensuring that amplification and evasion coexist without trade-off. Rather than perturbing generated text, SeedHijack replaces the PRNG at the supply-chain layer, biasing green-list selection without altering output tokens or degrading text quality. Across three watermarking schemes and three open-source LLMs, the attack triggers 0/6 state-of-the-art content-side statistical detectors while inflating the watermark z-score up to 2.42x (system-level defenses such as entropy-source attestation remain orthogonal and complementary). A quantum random number generator (QRNG) countermeasure is shown to fully neutralize the attack while preserving benign watermarking utility. These findings establish PRNG integrity as a first-class security requirement for cryptographic content-provenance systems.

cs.CR

DiffusionHijack: Supply-Chain PRNG Backdoor Attack on Diffusion Models and Quantum Random Number Defense

Diffusion models depend on pseudo-random number generators (PRNGs) for latent noise sampling. We present DiffusionHijack, a supply-chain backdoor attack that hijacks the PRNG to deterministically control generated images. A malicious PRNG, injected via compromised packages, forces pixel-perfect reproduction of attacker-chosen content (SSIM = 1.00, N = 100 trials) on Stable Diffusion v1.4, v1.5, and SDXL -- without modifying model weights. The attack is inherently undetectable by existing model auditing and content moderation mechanisms, as it operates entirely outside the neural network computation graph. The attack remains effective under stochastic sampling (eta > 0), bypasses CLIP-based safety checkers (98-100% success), and operates independently of the user's prompt. As a countermeasure, we replace the PRNG with a quantum random number generator (QRNG), which provides information-theoretic unpredictability. Across N = 100 prompt-model combinations, QRNG defense completely neutralizes the attack, reducing output similarity to random baseline levels (SSIM < 0.20 for SD 1.x models, < 0.45 for SDXL). This work exposes a previously overlooked supply-chain vulnerability and offers a hardware-level fundamental mitigation for generative AI systems.

cs.CR

Seed Hijacking of LLM Sampling and Quantum Random Number Defense

Large language models (LLMs) rely on deterministic pseudorandom number generators (PRNGs) for autoregressive sampling, creating a critical supply-chain attack surface overlooked by existing defenses. We present SeedHijack, a backdoor attack that manipulates PRNG outputs to force attacker-specified token selection without altering model logits. In a 540-trial benchmark on GPT-2 (124M), the attack achieves 99.6% exact token injection across 9 sampling configurations; it reaches 100% success on four aligned models (1.5B-7B, RLHF/SFT/reasoning distillation) and bypasses all alignment methods tested in this work. We further propose a defense based on a hardware quantum random number generator (QRNG), which neutralizes the attack in our evaluated threat model with negligible median overhead (+0.6% latency, +7.7 MB memory). Our work identifies a critical sampling-layer vulnerability and provides a practical, deployable QRNG-based defense.

cs.CR

Thermalizing channel states for rapid qubit heating

Although known for negatively impacting the operation of superconducting qubits, thermal baths are shown to exert qubit control in a positive way, provided they are properly engineered. We demonstrate an experimental method to engineer the transduction of microwave driving into heat flow through a leaky resonator. Given the precise conversion, a qubit receiving the heat flow obtains a quasi-thermal equilibrium with arbitrary target temperature in hundreds of nanoseconds. We show that the dynamics of the quantum transducing process is described by thermalizing channel states, generated from the double dressings of the resonator by the semi-classical driving and the qubit-resonator coupling. Their spectrum, coupling, and driving strength determine the channel rate of energy flow, along with the relaxation rates of photon leakage into the bath. The analytical prediction is shown to match well with the experimental measurements on an Xmon qubit circuit.

quant-ph

Dynamic phases induced by two-level system defects on driven qubits

Recent experimental evidences point to two-level defects, located in the oxides and on the interfaces of the Josephson junctions, as the major constituents of decoherence in superconducting qubits. How these defects affect the qubit evolution with the presence of external driving is less well understood since the semiclassical qubit-field coupling renders the Jaynes-Cummings model for qubit-defect coupling undiagonalizable. We analyze the decoherence dynamics in the continuous coherent state space induced by the driving and solve the master equation endowed with an extra decay-cladded driving term via a Fokker-Planck equation. The solutions for diffusion propagators as Gaussian distributions show four distinct dynamic phases: four types of convergence paths to limit cycles of varying radius by the distribution mean, which are determined by the competing external driving and the defect decays. The qubit trajectory resulted from these solutions is a super-Poissonian over displac ed Fock states, which reduces to a Gibbs state of effective temperature decided by the defect at zero driving limit. Further, the Poincare map shows the dependence of the rate of convergence on the initial state. In other words, the qubit evolution can serve as an indicator of the defect coupling strength through the variation of the driving strength as a parameter.

quant-ph

Neural network based time-resolved state tomography of superconducting qubits

Superconducting qubits have emerged as a premier platform for large-scale quantum computation, yet the fidelity of state readout is often hindered by random noise and crosstalk, especially in multi-qubit systems. While neural networks trained on labeled data have shown promise in reducing crosstalk effects during readout, their current capabilities are limited to binary discrimination of joint-qubit states due to architectural constraints. Here we introduce a time-resolved modulated neural network capable of full-state tomography for individual qubits, enabling detailed time-resolved measurements like Rabi oscillations. This scalable approach, with a dedicated module per qubit, mitigated readout error by an order of magnitude under low signal-to-noise ratios and substantially reduced variance in Rabi oscillation measurements. This advancement bolsters quantum state discrimination with neural networks, and propels the development of next-generation quantum processors with enhanced performance and scalability.

quant-ph

Computing Shor's algorithmic steps with classical light beams

When considered as orthogonal bases in distinct vector spaces, the unit vectors of polarization directions and the Laguerre-Gaussian modes of polarization amplitude are inseparable, constituting a so-called classical entangled light beam. Equating this classical entanglement to quantum entanglement necessary for computing purpose, we show that the parallelism featured in Shor's factoring algorithm is equivalent to the concurrent light-path propagation of an entangled beam or pulse train. A gedanken experiment is proposed for executing the key algorithmic steps of modular exponentiation and Fourier transform on a target integer $N$ using only classical manipulations on the amplitudes and polarization directions. The multiplicative order associated with the sought-after integer factors is identified through a four-hole diffraction interference from sources obtained from the entangled beam profile. The unique mapping from the fringe patterns to the computed order is demonstrated through simulations for the case $N=15$.

quant-ph

Measurement of classical entanglement using interference fringes

Classical entanglement refers to non-separable correlations between the polarization direction and the polarization amplitude of a light field. The degree of entanglement is quantified by the Schmidt number, taking the value of unity for a separable state and two for a maximally entangled state. We propose two detection methods to determine this number based on the distinguishable patterns of interference between four light sources derived from the unknown laser beam to be detected. The second method being a modification of the first one has the interference fringes form discernable angles uniquely related to the entangled state. The maximally entangled state corresponds to fringes symmetric about the diagonal axis at either 45° or 135° direction while the separable state corresponds to fringes symmetric either about the X- or Y-axis or both simultaneously. States with Schmidt number between unity and two have fringes of symmetric angles between these two extremes. The detection methods would be beneficial to constructing transmission channels of information contained in the classically entangled states.

quant-ph