Searcharxiv⌕ Search

SEARCH · Searcharxiv

Search Searcharxiv

Search indexed arXiv papers on artificial intelligence, large language models, computer vision and robotics. Read source abstracts and follow links to arXiv.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 361 records · Page 20Linked to original sources

A Counting and Sampling Lovász Local Lemma

We establish counting and sampling analogues of the Lovász Local Lemma: we give efficient algorithms for approximately counting and exactly sampling satisfying assignments of general constraint satisfaction problems (CSPs) in the local lemma regime $$4 \mathrm{e} p (D+1)^2\leq 1, $$ where $p$ is the maximum constraint violation probability and $D$ is the maximum dependency degree. This condition is tight up to constant factors under $\mathbf{NP}\neq\mathbf{RP}$, matching known hardness bounds for counting and sampling in natural subclasses of CSPs. Our key ingredient is a novel $2$-tree expansion for constraint marginal probabilities that exhibits exponential decay of correlations throughout this regime. This expansion yields deterministic polynomial-time approximate counting for fixed local parameters, randomized approximate counting with quadratic cost, and exact sampling in expected near-linear time when the local parameters are fixed.

cs.DS↗

0%, 45%, or 99%: A Guardrail's Own Share of the Refusals It Is Credited With

A defended pipeline's refusals have two producers: the guardrail bolted in front of the model, and the model's own alignment. Recovering the split costs nothing, because a guard block replaces the model's response and the two counts are therefore disjoint. Holding the defense, the targets, the corpus and the judge fixed, the guardrail's own share of the refusals credited to it is 0%, 41-45%, or 99% across three settings that a results table would describe identically. Two choices move it, and neither belongs to the deployer who bought the guardrail. The attacker drives the share to zero by choosing which channel carries the payload: a plainly written request rendered as pixels, with nothing obfuscated, leaves a text guard's read covering none of it. The evaluator drives the share to 99% by choosing what text fills a defense's internal slots: fill them with the unencoded request behind an encoded attack, a read no deployed defender possesses, and the same guard blocks almost everything. The two consequences differ, and only the attacker's can happen to a running system. The evaluator's choice is an artifact carried by the literature, and its size is set by where the granted text lands: substantial at a guard gate, smaller in a caption-mediated re-check, absent in a majority-vote smoother, an ordering reproduced in an independent replicate. Isolating the grant inside the caption-mediated defense refutes the prediction we registered, since the harm-verdict stage contributes nothing while the stage that regenerates the answer carries the whole effect. The reference implementation builds every stage from a single prompt field that cannot represent the difference between what the attacker sent and what the benchmark records, and an audit of four further released harnesses and of the benchmark itself finds the same structural gap, so faithful porting supplies the grant silently.

cs.CR↗

Sharp homogeneous Gagliardo--Nirenberg inequalities and normalized solutions for generalized stationary MMT equations

We prove the existence of optimizers for a class of homogeneous Gagliardo-Nirenberg inequalities of the form $$ \|D^{s}ϕ\|_{L^q} \leq C \|D^{s_1}ϕ\|_{L^p}^{1-θ} \|D^{s_2}ϕ\|_{L^2}^θ, \quad s_1 s_1$, the problem reduces, after shifting the derivative orders, to the result of Bellazzini, Frank and Visciglia, whereas the case $s\leq s_1$ follows from the present paper. As an application, we study normalized solutions of the associated Euler-Lagrange equations under the constraint $$ \|D^{s_1}ψ\|_{L^p}^p=λ>0. $$ In particular, the case $p=2$ includes the stationary equation arising from the Majda-McLaughlin-Tabak (MMT) model.

math.AP↗

Stable $q$-Hermitian coordinate calculus: Capelli--PBW transport, mixed polarization algebra, and localization obstructions

We extend a finite-support $q$-Hermitian radial calculus to Clifford-valued coordinate polynomials. For $N$ bosonic Hermitian vector labels and finite fermionic support, the stable range $m\ge 2N$ admits a canonical Gram--harmonic normal form by Howe separation. A label--Capelli inverse normalizes the Clifford contractions, while a finite Wick--Chevalley conjugation lifts the divided-power scalar gauge to the full Clifford PBW module. Coupling the normalized contractions to contractible fermionic seed complexes gives two conjugate polynomial-preserving $q$-Hermitian coordinate families. They are square-zero, anticommute within each polarization, restrict exactly to the radial PBW calculus, have scalar boundary trace $[2m-2n]_q$, and recover the classical Hermitian super Dirac pair as $q\to1$. For the mixed polarizations we introduce a relative triangular transport. The Grassmann relations for the normalized Capelli contractions hold on the full coordinate module and yield a labelwise factorization. Hence all higher-filtration mixed terms are finite subset products of explicit local defects, and the mixed polarization algebra closes for arbitrary finite label sets and finite fermionic support. The classical complex structure is common to both polarizations, whereas the two full transported Clifford--Weyl products are distinct for $0<q<1$. We also show that the fermionic Cartan denominator is forced in the natural polynomial first-order Berezin--Weyl class and determine the minimal factorwise Ore localization needed for the conjugate all-charge homotopies. The $q$-dependent Cartan orbit is nonresonant for $m\ge\max\{2N,n\}$. Finally, fixed finite-order differential and finite nonzero-shift realizations on the undeformed coordinate algebra are ruled out.

math.CV↗

A Proof of the Imbalance Conjecture

For an edge $uv$ of a finite simple graph $G$, its imbalance is $|d_G(u)-d_G(v)|$, and the imbalance multiset $M_G$ consists of the imbalances of all edges of $G$. Kozerenko and Skochko conjectured that $M_G$ is graphic whenever every edge has positive imbalance. We prove this conjecture. The main ingredient is the following capacity bound: for every set $A$ of $k$ edges, \[ \sum_{e\in E(G)\setminus A}\min\{k,\operatorname{imb}_G(e)\} \ge k\max\{Δ-k,0\}, \] where $Δ$ is the maximum degree of $G$. This bound yields all Erdős--Gallai inequalities directly; a parity computation completes the proof.

math.CO↗

Trajectory-Induced Self-Calibration for Hidden-Target Localization Through an Unknown-Pose Range-Bearing Relay

This paper studies hidden-target localization from range-bearing packets reported by a relay beacon whose global position and yaw are unknown. The vehicle knows its own trajectory but never directly senses the target; the relay packet contains only local-frame range and bearing to the vehicle and to the hidden target. Unlike bearing-only network localization, relative-frame localization, and target-enclosing control, the target is neither directly observed in the vehicle frame nor treated as a node in a relative-sensing graph. The main result characterizes the minimal motion that removes the resulting calibration ambiguity: one vehicle pose leaves a continuous yaw/translation/target gauge, whereas two distinct vehicle-relative observations from one unknown-pose relay constructively determine relay yaw (modulo 2 pi), relay position, and the anchored target in the noiseless case. A local rank corollary, a shared-target multi-beacon extension, and a trajectory-spread conditioning lemma connect relay self-calibration to finite-window excitation and native range-bearing estimation. In Monte Carlo evaluation the estimator recovers the hidden target with 5.5 mm RMSE, five times below the 30 mm per-packet range noise and thirteen times more accurate than a naive EKF baseline; it converges to the same accuracy from 2 m target offsets and 2.4 rad yaw errors, and Huber weighting preserves millimeter accuracy under 10% outlier corruption that drops the unprotected estimator to a 0.10 success rate. Trajectory spread predicts estimator quality: the two weakly excited trajectories carry condition numbers above 100 with success rates of 0.82 and 0.70, while every well-excited trajectory attains full success.

eess.SY↗

Win-Ratio Regression for Prioritized Composite Outcomes in Observational Studies: Doubly Robust and Efficient Estimation with Future-Score Correction

Prioritized pairwise outcomes are useful when clinical events follow a natural hierarchy, but censoring before pair resolution complicates estimation. We develop a win-ratio regression framework for this setting by defining a complete-data target over follow-up and deriving an estimating equation for the observed data. The central idea is future-score correction (FC): when censoring prevents later pairwise comparisons from being observed, the method replaces the remaining score with its conditional expectation given the observed history. This correction recovers pairwise information beyond that provided by inverse censoring weights alone. Additionally, we incorporate treatment weighting and baseline outcome augmentation to address baseline confounding. Together, these components yield double robustness for treatment assignment and censoring. Inference is obtained from U-statistic theory. Under standard regularity conditions, the AIPW-FC estimator is asymptotically normal and efficient when all nuisance functions are correctly specified. Simulations with 30%, 50%, and 65% censoring show that efficiency gains from future-score correction increase with the censoring rate, with relative efficiency reaching 1.50 under 65% censoring and near-nominal coverage for AIPW-FC. An application to OneFlorida electronic health record data illustrates the method for a composite outcome that prioritizes death over hospitalization.

stat.ME↗

Wind-confined jet collimation revealed by the acceleration-phase photosphere of GRB 220426A

We analyze the prompt emission of the exceptionally bright GRB 220426A observed by {\it Fermi}/GBM, whose time-resolved spectra are among the narrowest measured in any GRB. Here we show that observations during the first $\sim 5$~s are consistent with the signal being emitted while the jet was still in the initial radiation-dominated acceleration phase. The time-resolved spectra allow the effective launch radius, $r_0$, to be inferred with unusual precision. We find $r_0 \sim \mathrm{few} \times 10^{10}\,\mathrm{cm}$, increasing linearly with time. These findings match the theoretical expectation for the recollimation shock, implying that this GRB shows the first clear evidence for the existence and evolution of a recollimation shock. Using this interpretation, the linear increase observed is sustained over a period longer than expected from a pure jet breakout. Therefore, the jet collimation must have persisted even after breakout. We suggest that the collimation was maintained by a finite, dense, wind-like circumburst medium, which would reproduce the observed behavior of the prompt emission. We conclude that late-stage progenitor mass-loss can shape the earliest prompt emission and that the photospheric emission provides a way to probe both the jet collimation and the innermost region of the circumburst medium (CBM) surrounding the progenitor, independently of the constraints from interacting supernovae.

astro-ph.HE↗

A Chain- and Diagram-Level Semantics for Morphological Calculus Refinement, monodromy, and bivector orbit decompositions

Morphological calculus represents decompositions of geometric objects by polynomial-like expressions in a symbol for the real line, but scalar operations suppress the incidence and attachment maps needed to reconstruct the space. We formulate a finite semantics using script chain complexes. The cell-count polynomial satisfies $$ \mathcal M_S(t)=\mathcal P_{S,\mathbb K}(t)+(1+t)\mathcal B_{S,\mathbb K}(t), $$ where $\mathcal P$ is the Poincar'e polynomial and $\mathcal B$ records boundary ranks. Over $\mathbb Z$, Smith labels separate unit pairs, representing refinement overhead, from non-unit pairs carrying torsion. We distinguish Cartesian products from bundles, derive the monodromy defect for mapping tori, and replace scalar gluing by a finite bar construction. Mapping cones, joins, and double mapping cylinders arise as reduced models. We apply the construction to bivector discrepancies in Sommen's calculations. In dimension four, Hodge decomposition identifies the unit bivector sphere with $S^2*S^2$; the angular excess is a contractible relative complex from inserting the rank-two midpoint. In dimension five, the $SO(5)$-action on $S(Λ^2\mathbb R^5)=S^9$ has principal orbit $SO(5)/T^2$ and singular orbits $\widetilde G_2(\mathbb R^5)$ and $\mathbb{CP}^3$. For standard Bruhat cell structures, the reduced double-mapping-cylinder inventory differs from sphere homology by seven unit-labelled pairs. We also treat Borel--Moore realizations of selected noncompact symbols, define division as an action-certified partial operation, and describe the orbit-type face diagram for unit bivectors in dimension six. There the correction polynomial has nonnegative coefficients, while compatibility of the face attachments remains open. These examples separate subdivision and attachment data from quotient actions and support conditions suppressed by scalar notation.

math.AG↗

Excitation-Supervised Closed-Loop Self-Calibration and Target Seeking for an Unknown-Pose Range-Bearing Relay

A vehicle seeking a hidden target through a range-bearing relay of unknown position and yaw must decide, online, whether its own motion has already made the relay calibration trustworthy, and what to do when it has not. Two distinct vehicle-relative observations are known to remove the calibration gauge and make the target's relay-local packet globally actionable (arXiv:2608.09464), but that statement is static: it classifies a stored window only after the fact. This paper supplies the closed-loop layer: we show that the trajectory-spread margin $S_v$ that governs identifiability is simultaneously a finite-noise seed-accuracy bound, a local-vector variance decomposition, and a circle-geometry excitation budget, and we use it to supervise an excitation-reset controller. An excitation-supervised algorithm retriggers exploratory motion whenever the spread certificate is insufficient, projecting the target-seeking input away from the excitation's push, and otherwise proceeds to unrestricted target seeking. Under explicit sampling assumptions the supervision rule provably acquires any required excitation in finite time; in the noiseless local regime with positive excitation decay, estimator convergence yields target-seeking convergence after certification; and the threshold is selected from a desired calibration-accuracy level rather than chosen heuristically. Closed-loop simulation, paired Monte Carlo comparisons, a spread-threshold ablation, and a ROS 2/Gazebo software-in-the-loop experiment with sensing delay validate the approach. A decay-rate sweep shows that supervision matters when a fixed schedule's decay outruns the unknown time-to-adequate-excitation: over 100 paired trials the fixed baseline's yaw RMSE rises from 0.010 to 0.065 rad and success falls to 56%, while target-tracking error remains insensitive; supervision keeps yaw RMSE between 0.0095 and 0.0191 rad with 100% success.

eess.SY↗

Evolve Vision-Language-Action Model into an Agent with On-the-fly Tool-use

This paper integrates end-to-end Visual-Language-Action (VLA) models with agentic tool-use to propose Agentic Robot with Tool-use (ART). ART is a tool-injection framework that tunes any VLA model to leverage off-the-shelf tool modules for low-level vision, high-level affordance, and embodiment enhancement. Compared to vanilla VLA models with a whole continuous action solution space, ART reduces the complexity of the action solution space through tool-use, which not only improves generalizability across different tasks but also reduces data dependency. To demonstrate the advantages (high generalizability and low data dependency) of this framework, we first built a dataset of 30K tool-use trajectories and action demonstrations, which is much smaller than those used by baseline methods. We then designed a training regimen for long-trajectory tool-use reasoning in challenging environments. Experiments show that ART achieves a 20% higher success rate than mainstream baselines on simulation and real-world tasks, such as pick-and-place in the dark at novel viewpoints. Empirical results highlight the benefits of an agent-based approach: modular tool utilization enables more efficient training, lightweight deployment, and scalable integration of new tools. This design fosters robustness, adaptability, and extensibility, paving the way for the practical deployment of VLA systems in complex real-world scenarios.

cs.RO↗

TRACE: Trajectory Aware Reasoning for Multi-Turn Adversarial Conversation Evaluation

Multi-turn jailbreak attacks have emerged as a critical safety threat to LLMs, as harmful objectives are decomposed across a sequence of apparently benign turns to bypass guardrails. Existing defenses lack the reasoning capacity to identify evolving manipulation patterns, often trading helpfulness for safety by over-refusing benign requests related to sensitive topics. We introduce Trace, a multi-turn defense with trajectory-aware structured reasoning. Before generating each response, the model identifies manipulation cues from the trajectory, evaluates both the benign and adversarial interpretations of user intent, assigns a jailbreak score, and commits to an action: Allow, Caution, or Decline. We curate 4k multi-turn adversarial conversations from five attack frameworks, pair them with 2.4k benign dialogs, and 600 sensitive-but-benign conversations. We train Llama-3.1-8B-Instruct with SFT and GRPO under a multi-component reward that jointly optimizes helpfulness on benign prompts and robustness against jailbreak attempts. Across seven multi-turn attack benchmarks, Trace attains an average attack success rate (ASR) of 14.5% against 31.4% for the strongest baseline and 74.9% for the undefended target, while significantly raising the attacker effort required per successful jailbreak. Trace also balances usability and safety, achieving a 93.3% average compliance on over-refusal benchmarks.

cs.AI↗

Quasianalyticity and geometric rigidity in anisotropic Calderón's problem

The anisotropic Calderón problem of determining a smooth Riemannian metric from boundary measurements, up to a boundary-fixing diffeomorphism, remains open in dimensions $n\ge3$~\cite{uhlmann2009electrical}. We establish unique identifiability results in two complementary regimes. In the first, the identity principle for quasianalytic functions propagates boundary information and yields unique identifiability on compact manifolds without a prescribed product structure, including a partial-data consequence; under a prescribed normal geometry, quasianalyticity is needed only in the distinguished direction. In the second, suitable symmetry or one-sided ordering assumptions lead to unique identifiability at $C^\infty$ regularity with full or restricted boundary access. Taken together, the results exhibit a tradeoff among regularity, geometric structure, and boundary access: quasianalyticity supplies continuation when no global product structure is prescribed, while symmetry or one-sided order replaces that continuation at $C^\infty$ regularity.

math.AP↗

The Critical Semilinear Elliptic Equation with Isolated Boundary Singularities II

Continuing the work of the second author (2017), we study the Sobolev critical semilinear elliptic equation in the half-space with an isolated boundary singularity and zero Dirichlet boundary condition. This paper addresses two open questions in this setting: the existence of Delaunay type log-periodic solutions posed by del Pino--Musso--Pacard (2007), and the asymptotic classification of singular solutions posed by Bidaut-Véron--Ponce--Véron (2007). We construct a global continuum of positive log-periodic solutions containing the local bifurcation branch and prove that blow-up along this continuum occurs at a uniquely determined period. We also construct the corresponding concentrating family and prove its local uniqueness. Consequently, the expected stationary asymptotic classification fails, and no universal critical scaling-invariant upper bound can hold throughout the half-space. This behavior contrasts sharply with the classical interior singularity theory of Caffarelli--Gidas--Spruck (1989).

math.AP↗

Convex Networks Remain Hard to Certify: Dimension-Accuracy Barriers for Lipschitz Constants

Input-convex neural networks permit globally tractable minimization over their inputs, so one might expect their global regularity to be tractable in low input dimension. We prove exact and accuracy-sensitive barriers to this expectation. Given a bias-free one-hidden-layer ReLU network $f(x)=\sum_{r=1}^n \mathrm{ReLU}(a_r^\top x)$ with unit positive output weights, deciding whether its global Euclidean Lipschitz constant is at least a rational threshold is NP-complete and W[1]-hard when parameterized by the input dimension $d$. The same holds on the unit ball and with integral first-layer weights having at most nine nonzeros. More sharply, no deterministic multiplicative approximation scheme runs in $g(d)\mathrm{poly}(\mathcal B,1/\varepsilon)$ time unless FPT equals W[1]. Under the Exponential Time Hypothesis, no such algorithm runs in $g(d)(\mathcal B+1/\varepsilon)^{o(d/\log d)}$ time. Thus accuracy cannot have a polynomial dependence separated from dimension. The exact result resolves the Euclidean case of an open problem posed at COLT 2025 and left open by the ICLR 2026 parameterized hardness theory for general two-layer networks. The approximation barrier is specific to generator-presented zonotopes, complementing known $(1/\varepsilon)^{O(d)}$-time schemes and an analogous barrier for halfspace-presented polytopes. Our lifted-selector reduction has an inverse-polynomial radial gap, proved through a quantitative theorem for rational cyclic zonogons. Equivalently, the results apply to Euclidean zonotope radius and positive-semidefinite binary quadratic maximization parameterized by rank. Convexity makes minimization easy, but it does not make global sensitivity fixed-parameter tractable or permit a dimension-separated fully polynomial accuracy guarantee.

cs.CC↗

Simplicity of reduced crossed products

We characterize the simplicity of reduced crossed product C*-algebras in terms of stabilizer subgroups. Specifically, we prove that if $G$ is a countable group and $X$ is a minimal $G$-flow, then the reduced crossed product C*-algebra $\mathrm{C}(X) \times_λG$ is simple if and only if there is a point in $X$ with a C*-simple stabilizer subgroup. Further, these conditions are equivalent to a generic point in $X$ having a C*-simple stabilizer subgroup. We also provide an example demonstrating that this result does not extend to uncountable groups. This completely resolves a question of Ozawa.

math.OA↗

Self-Bounding Regret Matching+ in Potential Games and Product-Simplex Optimization

Regret matching+ (RM+) is parameter free, scale invariant, and central to large game solving, but its only general individual-regret guarantee grows as $\sqrt{T}$. A recent ICLR result used this envelope to prove that RM+ reaches an $ε$-stationary point of a smooth objective over a product of simplices in $O(ε^{-4})$ iterations, or $O(ε^{-8})$ from the standard zero initialization. We give an exact one-step conservation law for RM+. It states that forward utility gain pays for both squared state motion and growth of the regret-state norm. Norm growth is at most $\sqrt{m-1}$ times forward gain for $m$ actions, and the coefficient is sharp. This yields four results for unmodified RM+. Its regret on any utility path is controlled by centered temporal variation. Its regret is uniformly bounded under alternating play in every finite exact potential game, resolving an open question and making squared activation gaps summable. Both certified lazy and ordinary cyclic play attain an $ε^{-2}$ exponent. On any smooth, possibly nonconcave simplex objective, RM+ finds an $ε$-KKT point in $O(ε^{-2})$ iterations. Most broadly, for a smooth objective over an arbitrary product of simplices, cyclic block RM+ attains the same $O(ε^{-2})$ exponent from arbitrary initialization, with an explicit trajectory-dependent constant. The proof controls the finite objective loss caused by low-state blocks and then self-bounds every block state and the total squared path length. Complete proofs cover zero states, sharpness, common-profile stationarity, and robust gain dominance. Oracle-normalized diagnostics compare RM+ with predictive and smooth extra-gradient variants on graphical potential games and dense nonconvex objectives.

cs.GT↗

Reflex-Guard: A Low-Latency Guardrail for LLM Prompt Safety Using Dense Semantic Embeddings

Large Language Models (LLMs) in real-world applications often face the risks of specially crafted prompts designed to bypass the safety controls. Existing guardrail methods, such as LLM-as-a-judge and cloud-based safety APIs are able to detect unsafe content. However, they often add a delay of about 250-900 ms to each request. This delay is too high for real-time applications, when the system usually needs to respond in less than 100 ms. Furthermore, routing user prompts through external moderation endpoints raises significant data privacy concerns. This paper introduces Reflex-Guard, a lightweight guardrail that runs locally. It uses jailbreak-aware preprocessing, compact sentence-transformer embeddings, and seven fast binary classifiers. Together, these components enable high-accuracy prompt safety filtering with much lower latency than existing solutions. Through systematic evaluation on a strategically balanced dataset of 30,568 samples drawn from five complementary sources, we demonstrate that Reflex-Guard achieves 95.9% recall on harmful prompts at 37.6 ms end-to-end latency. It is faster than existing baselines, including Llama Guard 2 at 255 ms and SafeDecoding at 723 ms. It can detect 100% of GCG suffix attacks and Base64-encoded prompts using the default threshold. However, DrAttack structured prompts required lowering the threshold to 0.03 for optimal detection, as they produced a distinct probability distribution. Reflex-Guard achieves Reflex Efficiency Score (RES) scores up to 16.79, significantly outperforming Llama Guard 2 (11.90) and SafeDecoding (9.80). This analysis offers practical deployment advice and shows that different attack types occupy distinct regions in the embedding probability space.

cs.CR↗