most citedDemystifying LLM Supply Chain Vulnerabilities in the Wild: Distribution, Root Cause, and Real-World Impact

1 citations · 1 across the 8 of their papers we have counts for

collaborators

10 papers

cs.CR2026

SkillSentry: Adaptive Honey Worlds for Dynamic Safety Testing of Agent Skills

Nizhang Li, Zonghao Ying, Xiangfan Wu +7

External skills extend the capabilities of large language model agents, but also introduce an execution-time attack surface: a skill that appears benign under inspection may reveal…

cs.MA2026

SafeFlow: Semantic Information-Flow Control for Blocking Malicious Propagation in Multi-Agent Systems

Haowen Dai, Zonghao Ying, Wenfeng Li +10

Multi-agent systems improve capability through task decomposition and role specialization, but these same mechanisms introduce an important safety blind spot: a harmful objective c…

cs.AI2026

Dynamic Defense Profiling Enables Cognitive Jailbreak of Text-to-Image Models

Dongdong Yang, Deyue Zhang, Zhao Liu +5

Text-to-Image (T2I) generative models have achieved remarkable progress in synthesizing high-quality visual content, yet they remain vulnerable to adversarial misuse, particularly…

cs.CR20261 cited

Demystifying LLM Supply Chain Vulnerabilities in the Wild: Distribution, Root Cause, and Real-World Impact

Shenao Wang, Yanjie Zhao, Zhao Liu +2

LLMs are rapidly transitioning from research prototypes to core components in production systems across industries such as finance and healthcare. These deployments rely on a growi…

cs.AI2026

ElephantAgent: Contextual State Continuity in Agentic Systems

Jiankai Jin, Xiangzheng Zhang, Zhao Liu +4

Agentic systems enhance their capabilities by invoking external tools and maintaining persistent memory. However, these external dependencies introduce novel attack surfaces. Recen…

cs.LG2026

Robust Privacy: Inference-Stage Privacy through Certified Robustness

Jiankai Jin, Xiangzheng Zhang, Zhao Liu +4

An adversary observing a model's released prediction can infer sensitive attributes of the queried input, or even reconstruct representatives of the model's training data. The infe…