collaborators

7 papers

cs.CR2026

The Missing Boundary: How Autonomous Agents Lose Control

Zonghao Ying, Xiangfan Wu, Bo Yang +5

Autonomous agents increasingly perform long-horizon tasks involving tool use, persistent state, and consequential actions, raising a fundamental question: \emph{under what conditio…

cs.CR2026

Security Assessment of DeepSeek Harness with A.I.G: Evaluating Resistance to Indirect Prompt Injection

Zonghao Ying, Xiangfan Wu, Huiyu Wu +4

We assess indirect prompt injection in DeepSeek Harness (DSH), using AI-Infra-Guard (A.I.G) to construct tests, deliver controlled taint, execute DSH, collect traces, and judge out…

cs.CR2026

Ventor-QTest: Threat-Model-Driven Verification of Vendor-Hosted LLM APIs

Xiangfan Wu, Zonghao Ying, Huiyu Wu +4

As large language models become increasingly widespread, third-party providers that deploy open-weight models have become an important part of the ecosystem. Auditing the quality o…

cs.CR2026

SkillJack: Persistent Skill Backdoors in Self-Evolving Agents

Zonghao Ying, Xiangfan Wu, Huiyu Wu +4

Self-evolving agents increasingly convert interaction histories into reusable skills that persist beyond individual tasks. While prior work studies memory and retrieval poisoning,…

cs.CR2026

SkillSentry: Adaptive Honey Worlds for Dynamic Safety Testing of Agent Skills

Nizhang Li, Zonghao Ying, Xiangfan Wu +7

External skills extend the capabilities of large language model agents, but also introduce an execution-time attack surface: a skill that appears benign under inspection may reveal…

cs.MA2026

SafeFlow: Semantic Information-Flow Control for Blocking Malicious Propagation in Multi-Agent Systems

Haowen Dai, Zonghao Ying, Wenfeng Li +10

Multi-agent systems improve capability through task decomposition and role specialization, but these same mechanisms introduce an important safety blind spot: a harmful objective c…