14 papers
Tracing Provenance and Detecting Tampering with Complementary LLM Watermarks
Xiaoyan Feng, Yanjun Zhang, He Zhang +2
Watermarking LLM-generated text is an important task for tracing its provenance. Existing LLM watermarks preserve provenance under editing, but this same robustness allows an adver…
Rethinking Federated Unlearning via the Lens of Memorization
Jiaheng Wei, Yanjun Zhang, He Zhang +5
Federated learning (FL) increasingly needs machine unlearning to comply with privacy regulations. However, existing federated unlearning approaches may overlook the overlapping inf…
Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks
Yubin Qu, Ying Zhang, Yanjun Zhang +4
Coding agents now run autonomously with shell, file, and network privileges. When a user issues a benign request, the agent sometimes does more than asked: it deletes unrelated fil…
ARES: Scalable and Practical Gradient Inversion Attack in Federated Learning through Activation Recovery
Zirui Gong, Leo Yu Zhang, Yanjun Zhang +4
Federated Learning (FL) enables collaborative model training by sharing model updates instead of raw data, aiming to protect user privacy. However, recent studies reveal that these…
Transferable Backdoor Attacks for Code Models via Sharpness-Aware Adversarial Perturbation
Shuyu Chang, Haiping Huang, Yanjun Zhang +3
Code models are increasingly adopted in software development but remain vulnerable to backdoor attacks via poisoned training data. Existing backdoor attacks on code models face a f…
Less Is More -- Until It Breaks: Security Pitfalls of Vision Token Compression in Large Vision-Language Models
Xiaomei Zhang, Zhaoxi Zhang, Leo Yu Zhang +3
Visual token compression is widely adopted to improve the inference efficiency of Large Vision-Language Models (LVLMs), enabling their deployment in latency-sensitive and resource-…