Tianwei Zhang lists you as their PhD student. Claim this profile to confirm it and keep the rest of your record right.

Claim this profile

Academic lineage

View as a tree

Advisors

Works79 from public data

TitleCited by
  • Prompt Injection attack against LLM-integrated Applications

    Yi Liu, Ge-Lei Deng, Yuekang Li, Kailong Wang, Tian-Wei Zhang, Yepang Liu, Hao-Yu Wang, Yanhong Zheng, +1 more

    arXiv · 2023

    This study deconstructs the complexities and implications of prompt injection attacks on actual LLM-integrated applications and forms HouYi, a novel black-box prompt injection attack technique, which draws inspiration from traditional web injection attacks.

    926
  • Jailbreaking ChatGPT via Prompt Engineering: An Empirical Study

    Yi Liu, Ge-Lei Deng, Zheng-Zi Xu, Yuekang Li, Yao-Wen Zheng, Ying Zhang, Li-Da Zhao, Tian-Wei Zhang, +2 more

    arXiv · 2023

    The study underscores the importance of prompt structures in jailbreaking LLMs and discusses the challenges of robust jailbreak prompt generation and prevention.

    738
  • MASTERKEY: Automated Jailbreaking of Large Language Model Chatbots

    Ge-Lei Deng, Yi Liu, Yuekang Li, Kailong Wang, Ying Zhang, Zefeng Li, Hao-Yu Wang, Tian-Wei Zhang, +1 more

    Network and Distributed System Security Symposium · 2024

    Jailbreaker is presented, a comprehensive framework that offers an in-depth understanding of jailbreak attacks and countermeasures, and an automatic generation method for jailbreak prompts is introduced, leveraging a fine-tuned LLM to validate the potential of automated jailbreak generation across various commercial LLM chatbots.

    275
  • MasterKey: Automated Jailbreak Across Multiple Large Language Model Chatbots

    Ge-Lei Deng, Yi Liu, Yuekang Li, Kai-Long Wang, Ying Zhang, Zefeng Li, Hao-Yu Wang, Tian-Wei Zhang, +1 more

    arXiv · 2023

    A novel method that utilizes time-based characteristics intrinsic to the generation process to deconstruct the defense mechanisms employed by popular LLM chatbot services, and an innovative method for the automatic generation of jailbreak prompts that target robustly defended LLM chatbots.

    206
  • PentestGPT: An LLM-empowered Automatic Penetration Testing Tool

    Ge-Lei Deng, Yi Liu, V'ictor Mayoral-Vilches, Peng Liu, Yuekang Li, Yuan Xu, Tian-Wei Zhang, Yang Liu, +2 more

    arXiv · 2023

    PentestGPT is an LLM-empowered automatic penetration testing tool that leverages the abundant domain knowledge inherent in LLMs and proves effective in tackling real-world penetration testing challenges.

    204
  • A Comprehensive Study of Jailbreak Attack versus Defense for Large Language Models

    Zihao Xu, Yi Liu, Gelei Deng, Yuekang Li, Stjepan Picek

    Findings of the Association for Computational Linguistics ACL 2024 · 2024

    It is revealed that existing white-box attacks underperform compared to universal techniques and that including special tokens in the input significantly affects the likelihood of successful attacks.

    155
  • The Threat of Offensive AI to Organizations

    Yisroel Mirsky, Ambra Demontis, J. Kotak, R. Shankar, Ge-Lei Deng, Liu Yang, X. Zhang, Maura Pintor, +3 more

    Computers & Security · 2022

    The threat of offensive AI on organizations is explored through a literature review and a user study, which identifies 33 offensive AI capabilities which adversaries can use to enhance their attacks.

    131
  • Automatic Code Summarization via ChatGPT: How Far Are We?

    Wei-Song Sun, C. Fang, Yudu You, Yun Miao, Yi Liu, Yuekang Li, Ge-Lei Deng, Shenghan Huang, +5 more

    arXiv · 2023

    Evaluating ChatGPT on a widely-used Python dataset called CSN-Python and comparing it with several state-of-the-art (SOTA) code summarization models shows that in terms of BLEU and ROUGE-L,ChatGPT's code summarizing performance is significantly worse than all three SOTA models.

    120
  • Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale

    Yi Liu, Wei-Zhe Wang, Rui Feng, Yao Zhang, Guang-Quan Xu, Ge-Lei Deng, Yue-Kang Li, L. Zhang

    arXiv · 2026

    The first large-scale empirical security analysis of this emerging ecosystem, collecting 42,447 skills from two major marketplaces and systematically analyzing 31,132 using SkillScan, a multi-stage detection framework integrating static analysis with LLM-based semantic classification reveals pervasive security risks.

    114
  • A Hitchhiker’s Guide to Jailbreaking ChatGPT via Prompt Engineering

    Yi Liu, Gelei Deng, Zhengzi Xu, Yuekang Li, Yaowen Zheng, Ying Zhang, Lida Zhao, Tianwei Zhang, +1 more

    Proceedings of the 4th International Workshop on Software Engineering and AI for Data Quality in Cyber-Physical Systems/Internet of Things · 2024

    It was discovered that GPT-3.5 and GPT-4 could still generate inappropriate content in response to malicious prompts without the need for jailbreaking, underscores the critical need for effective prompt management within LLM systems and provides valuable insights and data to spur further research in LLM testing and jailbreak prevention.

    103
  • Morest

    Yi Liu, Yuekang Li, Ge-Lei Deng, Yang Liu, Rui-Yuan Wan, Runchao Wu, Dandan Ji, Shiheng Xu, +1 more

    Proceedings/Proceedings - International Conference on Software Engineering · 2022

    This paper proposes Morest, a model-based RESTful API testing technique that builds and maintains a dynamically updating RESTful-service Property Graph (RPG) to model the behaviors of REST-services and guide the call sequence generation.

    103
  • 101
  • PonziGuard: Detecting Ponzi Schemes on Ethereum with Contract Runtime Behavior Graph (CRBG)

    Rui-Chao Liang, Jing Chen, Kun He, Yue-Ming Wu, Ge-Lei Deng, Ruiying Du, Cong Wu

    IEEE/ACM International Conference on Software Engineering (ICSE) · 2024

    73
  • Source Code Summarization in the Era of Large Language Models

    IEEE/ACM International Conference on Software Engineering (ICSE) · 2025

    53
  • SoK: Rethinking Sensor Spoofing Attacks against Robotic Vehicles from a Systematic View

    Yuan Xu, Xing-Shuo Han, Ge-Lei Deng, Ji-Wei Li, Yang Liu, Tian-Wei Zhang

    IEEE European Symposium on Security and Privacy · 2023

    A novel action flow model is proposed to systematically describe robotic function executions and unexplored sensor spoofing threats and two novel attack methodologies are designed to verify the feasibility of newly discovered spoofing attack vectors.

    51
  • On the (In)Security of Secure ROS2

    Ge-Lei Deng, Guowen Xu, Yuan Zhou, Tian-Wei Zhang, Yang Liu

    ACM SIGSAC Conference on Computer and Communications Security (CCS) · 2022

    This paper successfully identifies four security vulnerabilities in ROS2's native security module: Secure ROS2 (SROS2), and proposes a general defense solution based on the private broadcast encryption scheme to enhance the security of ROS2.

    51
  • Novel denial-of-service attacks against cloud-based multi-robot systems

    Yuan Xu, Ge-Lei Deng, Tian-Wei Zhang, Han Qiu, Yungang Bao

    Information Sciences · 2021

    By analyzing different attack vectors in cloud-robotic platforms, this paper proposes three new DoS attacks, which manipulate the network resources, micro-architecture resources, and function parameters respectively, and alerts the robotics community to these catastrophic attacks.

    46
  • Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems

    Yubin Qu, Yi Liu, Tong-Cheng Geng, Ge-Lei Deng, Yue-Kang Li, L. Zhang, Ying Zhang, Lei Ma

    arXiv · 2026

    This work introduces Document-Driven Implicit Payload Execution (DDIPE), which embeds malicious logic in code examples and configuration templates within skill documentation within skill documentation, and generates 1,070 adversarial skills from 81 seeds across 15 MITRE ATTACK categories.

    45
  • Glitch Tokens in Large Language Models: Categorization Taxonomy and Effective Detection

    Yu-Xi Li, Yi Liu, Ge-Lei Deng, Ying Zhang, Wenjia Song, Ling Shi, Kai-Long Wang, Yuekang Li, +2 more

    Proceedings of the ACM on software engineering. · 2024

    This study introduces and systematically explore the phenomenon of “glitch tokens”, which are anomalous tokens produced by established tokenizers and could potentially compromise the models’ quality of response, and proposes GlitchHunter, a novel iterative clustering-based technique for efficient glitch token detection.

    42
  • An Investigation of Byzantine Threats in Multi-Robot Systems

    Ge-Lei Deng, Yuan Zhou, Yuan Xu, Tian-Wei Zhang, Yang Liu

    International Symposium on Research in Attacks, Intrusions and Defenses (RAID) · 2021

    An in-depth investigation about the Byzantine threats in MRSs, where some robot is untrusted is presented, and a practical methodology to identify potential Byzantine risks in a given MRS workload built from the Robot Operating System (ROS) is designed.

    41
  • "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild

    Yi Liu, Zhi-Hao Chen, Yan-Jun Zhang, Ge-Lei Deng, Yue-Kang Li, Jian-Ting Ning, L. Zhang

    arXiv · 2026

    This work constructs the first labeled dataset of malicious agent skills by behaviorally verifying 98,380 skills from two community registries, confirming 157 malicious skills with 632 vulnerabilities.

    34
  • Oedipus: LLM-enchanced Reasoning CAPTCHA Solver

    Ge-Lei Deng, Hao-Ran Ou, Yi Liu, Jie Zhang, Tian-Wei Zhang, Yang Liu

    ACM SIGSAC Conference on Computer and Communications Security (CCS) · 2025

    Oedipus, an innovative end-to-end framework for automated reasoning CAPTCHA solving, is introduced with a novel strategy that dissects the complex and human-easy-AI-hard tasks into a sequence of simpler and AI-easy steps.

    34
  • Digger: Detecting Copyright Content Mis-usage in Large Language Model Training

    Hao-Dong Li, Ge-Lei Deng, Yi Liu, Kai-Long Wang, Yuekang Li, Tian-Wei Zhang, Yang Liu, Guo-Ai Xu, +2 more

    arXiv · 2024

    This paper introduces a detailed framework designed to detect and assess the presence of content from potentially copyrighted books within the training datasets of LLMs, and investigates the presence of recognizable quotes from famous literary works within these datasets.

    34
  • IllusionCAPTCHA: A CAPTCHA based on Visual Illusion

    Ziqi Ding, Gelei Deng, Yi Liu, Junchen Ding, Jieshan Chen, Yulei Sui, Yuekang Li

    Proceedings of the ACM on Web Conference 2025 · 2025

    In IllusionCAPTCHA, a novel security mechanism employing the "Human-Easy but AI-Hard" paradigm, a structured, step-by-step method that generates misleading options, which particularly guide LLMs towards making incorrect choices and reduce their chances of successfully solving CAPTCHAs.

    27
  • Efficient Detection of Toxic Prompts in Large Language Models

    Yi Liu, Junzhe Yu, Huijia Sun, Ling Shi, Ge-Lei Deng, Yuqi Chen, Yang Liu

    IEEE/ACM International Conference on Automated Software Engineering (ASE) · 2024

    ToxicDetector is proposed, a lightweight greybox method designed to efficiently detect toxic prompts in LLMs that achieves high accuracy, efficiency, and scalability, making it a practical method for toxic prompt detection in LLMs.

    25
  • GenderCARE: A Comprehensive Framework for Assessing and Reducing Gender Bias in Large Language Models

    Kunsheng Tang, Wenbo Zhou, Jie Zhang, Aishan Liu, Gelei Deng, Shuai Li, Peigui Qi, Weiming Zhang, +2 more

    Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security · 2024

    This work constructs GenderPair, a novel pair-based benchmark designed to assess gender bias in LLMs comprehensively, and establishes pioneering criteria for gender equality benchmarks, spanning dimensions such as inclusivity, diversity, explainability, objectivity, robustness, and realisticity.

    23
  • IRCopilot: Automated Incident Response with Large Language Models

    Xihuan Lin, Jie Zhang, Ge-Lei Deng, Tianzhe Liu, Xiao-Long Liu, Chang-Cai Yang, Tian-Wei Zhang, Qing Guo, +1 more

    arXiv · 2025

    An incremental benchmark based on real-world incident response tasks is constructed based on Large Language Models to thoroughly evaluate the performance of LLMs in this domain and proposes IRCopilot, a novel framework for automated incident response powered by LLMs.

    22
  • Uncovering Logit Suppression Vulnerabilities in LLM Safety Alignment

    Yu-Xi Li, Yi Liu, Yuekang Li, Ling Shi, Ge-Lei Deng, Sheng Chen, Kai-Long Wang

    Lecture notes in computer science · 2026

    This work introduces Semantic-sensitive Alignment and Generation (SSAG), a method designed to systematically manipulate output-layer logits without altering model parameters that exposes harmful responses with a 95% success rate while reducing response time by 86%.

    20
  • Fine-Grained Verifiers: Preference Modeling as Next-token Prediction in Vision-Language Alignment

    Chenhang Cui, An Zhang, Yi-Yang Zhou, Zhaorun Chen, Ge-Lei Deng, Huaxiu Yao, Tat-Seng Chua

    arXiv · 2024

    FiSAO (Fine-Grained Self-Alignment Optimization), a novel self-alignment method that utilizes the model's own visual encoder as a fine-grained verifier to improve vision-language alignment without the need for additional data, is proposed.

    20
  • MeTMaP: Metamorphic Testing for Detecting False Vector Matching Problems in LLM Augmented Generation

    Guanyu Wang, Yuekang Li, Yi Liu, Gelei Deng, Tianlin Li, Guosheng Xu, Yang Liu, Haoyu Wang, +1 more

    Proceedings of the 2024 IEEE/ACM First International Conference on AI Foundation Models and Software Engineering · 2024

    MeTMaP is presented, a metamorphic testing framework developed to identify false vector matching in LLM -augmented generation systems, and the results em-phasize the widespread issue of false matches in vector matching methods and the critical need for effective detection and mitigation in LLM -augmented applications.

    18
  • PANDORA: Jailbreak GPTs by Retrieval Augmented Generation Poisoning

    Gelei Deng, Yi Liu, Kailong Wang, Yuekang Li, Tianwei Zhang, Yang Liu

    Proceedings 2024 Workshop on AI Systems with Confidential COmputing · 2024

    16
  • PhyScout: Detecting Sensor Spoofing Attacks via Spatio-temporal Consistency

    Yuan Xu, Gelei Deng, Xingshuo Han, Guanlin Li, Han Qiu, Tianwei Zhang

    Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security · 2024

    Compared to existing defense solutions, PhyScout offers rapid identification of sensor attacks (within 100ms) with low performance overhead (CPU-based), and conflict visualization, and presents new avenues for future research in robust and efficient defense mechanisms against sensor spoofing attacks.

    16
  • Groot: Adversarial Testing for Generative Text-to-Image Models with Tree-based Semantic Transformation

    Yi Liu, Guowei Yang, Ge-Lei Deng, Feiyu Chen, Yuqi Chen, Ling Shi, Tian-Wei Zhang, Yang Liu

    arXiv · 2024

    Groot is introduced, the first automated framework leveraging tree-based semantic transformation for adversarial testing of text-to-image models and achieves a remarkable success rate on leading text-to-image models such as DALL-E 3 and Midjourney.

    16
  • How Your Credentials Are Leaked by LLM Agent Skills: An Empirical Study

    Zhi-Hao Chen, Ying Zhang, Yi Liu, Ge-Lei Deng, Yue-Kang Li, Yan-Jun Zhang, Jian-Ting Ning, L. Zhang, +2 more

    IEEE/ACM International Conference on Automated Software Engineering (ASE) · 2026

    The first large-scale empirical study on credential leakage in agent skills is presented, identifying 520 affected skills containing 1,708 security issues, and yields a taxonomy of 10 leakage patterns.

    15
  • PentestEval: Benchmarking LLM-based Penetration Testing with Modular and Stage-Level Design

    Ruo-Zhao Yang, Ming-Fei Cheng, Ge-Lei Deng, Tian-Wei Zhang, Jun-Jie Wang, Xiao-Fei Xie

    arXiv · 2025

    PentestEval is introduced, the first comprehensive benchmark for evaluating LLMs across six decomposed penetration testing stages: Information Collection, Weakness Gathering and Filtering, Attack Decision-Making, Exploit Generation and Revision, and Revision.

    15
  • Image-Based Geolocation Using Large Vision-Language Models

    Yi Liu, Junchen Ding, Ge-Lei Deng, Yuekang Li, Tian-Wei Zhang, Weisong Sun, Yaowen Zheng, Jing-Quan Ge, +1 more

    arXiv · 2024

    It is revealed that LVLMs can accurately determine geolocations from images, even without explicit geographic training, and an innovative framework that significantly enhances image-based geolocation accuracy is introduced, called tool{}, an innovative framework that significantly enhances image-based geolocation accuracy.

    15
  • What Makes a Good LLM Agent for Real-world Penetration Testing?

    Ge-Lei Deng, Yi Liu, Yue-Kang Li, Ruo-Zhao Yang, Xiao-Fei Xie, Jie M. Zhang, Han Qiu, Tian-Wei Zhang

    arXiv · 2026

    Excalibur is presented, a penetration testing agent that couples strong tooling with difficulty-aware planning and addresses a limitation that model scaling alone does not eliminate, showing that difficulty-aware planning yields consistent end-to-end gains across models.

    14
  • Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks

    Yu-Bin Qu, Ying Zhang, Yan-Jun Zhang, Ge-Lei Deng, Yue-Kang Li, L. Zhang, Yi Liu

    arXiv · 2026

    OverEager-Gen is presented, a benchmark dedicated to overeager behavior on benign tasks, and OverEager-Bench contains 500 validated scenarios and ~7,500 runs across four agent products and six base models, indicating that model-layer alignment does not fully propagate through permissive permission gating.

    13
  • Enhancing Model Defense Against Jailbreaks with Proactive Safety Reasoning

    Xiang-Lin Yang, Ge-Lei Deng, Jieming Shi, Tian-Wei Zhang, Jin-Song Dong

    arXiv · 2025

    A novel defense strategy, Safety Chain-of-Thought (SCoT), is proposed, which harnesses the enhanced reasoning capabilities of LLMs for proactive assessment of harmful inputs, rather than simply blocking them.

    11
  • VisionGuard: Secure and Robust Visual Perception of Autonomous Vehicles in Practice

    Xingshuo Han, Haozhao Wang, Kangqiao Zhao, Gelei Deng, Yuan Xu, Hangcheng Liu, Han Qiu, Tianwei Zhang

    Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security · 2024

    The key of VisionGuard is to leverage the spatiotemporal inconsistency property of PAEs to detect anomalies and it predicts the motion states from historical ones and compares them with the current driving states to identify any motion inconsistency caused by physical attacks.

    10
  • GeneRAG: Enhancing Large Language Models with Gene-Related Task by Retrieval-Augmented Generation

    Xinyi Lin, Ge-Lei Deng, Yuekang Li, Jing-Quan Ge, Joshua W. K. Ho, Yi Liu

    bioRxiv (Cold Spring Harbor Laboratory) · 2024

    GeneRAG is introduced, a frame-work that enhances LLMs’ gene-related capabilities using RAG and the Maximal Marginal Relevance (MMR) algorithm, and its potential to bridge a critical gap in LLM capabilities for more effective applications in genetics is highlighted.

    10
  • Distributed Motion Control for Multiple Mobile Robots Using Discrete-Event Systems and Model Predictive Control

    Yuan Zhou, Hesuan Hu, Ge-Lei Deng, Kun Cheng, Shang-Wei Lin, Yang Liu, Zuohua Ding

    IEEE Transactions on Systems Man and Cybernetics Systems · 2023

    9
  • Risky-Bench: Probing Agentic Safety Risks under Real-World Deployment

    Jing-Nan Zheng, Yanzhen Luo, D. Xu, Bing Liu, Yuxin Chen, Chen-Hang Cui, Ge-Lei Deng, Chao-Chao Lu, +3 more

    arXiv · 2026

    Risky-Bench organizes evaluation around domain-agnostic safety principles to derive context-aware safety rubrics that delineate safety space, and systematically evaluates safety risks across this space through realistic task execution under varying threat assumptions.

    8
  • 8
  • ASTER: Automatic Speech Recognition System Accessibility Testing for Stutterers

    Yi Liu, Yuekang Li, Ge-Lei Deng, Felix Juefei-Xu, Yao Du, Cen Zhang, Cheng-Wei Liu, Yeting Li, +2 more

    IEEE/ACM International Conference on Automated Software Engineering (ASE) · 2023

    Aster, a technique for automatically testing the accessibility of ASR systems, is implemented as a framework and evaluated, finding that it significantly increases the word error rate, match error rates, and word information loss in the evaluated AsR systems.

    6
  • VerifyML: Obliviously Checking Model Fairness Resilient to Malicious Model Holder

    Guowen Xu, Xing-Shuo Han, Ge-Lei Deng, Tian-Wei Zhang, Sheng-Min Xu, Jian-Ting Ning, Anjia Yang, Hong-Wei Li

    IEEE Transactions on Dependable and Secure Computing · 2023

    The first secure inference framework to check the fairness degree of a given Machine learning (ML) model is presented, which allows the vast majority of overhead to be performed offline, thus meeting the low latency requirements for online inference.

    5
  • ExploitFlow, cyber security exploitation routes for Game Theory and AI research in robotics

    V. Vilches, Ge-Lei Deng, Yi Liu, M. Pinzger, S. Rass

    arXiv · 2023

    Results indicate that EF is effective for exploring machine learning in robot cybersecurity, and several limitations in EF-driven agents are identified, including a propensity to overfit, the scarcity and production cost of datasets for generalization, and challenges in interpreting networking states across varied security settings.

    5
  • Mind Your HEARTBEAT! Claw Background Execution Inherently Enables Silent Memory Pollution

    Ye-Chao Zhang, Shi-Qian Zhao, Jie Zhang, Ge-Lei Deng, Jia-Wen Zhang, Xiaogeng Liu, Chaowei Xiao, Tian-Wei Zhang

    arXiv · 2026

    It is found that social credibility cues are the dominant driver of short-term behavioral influence, with misleading rates up to 61%, and routine memory-saving behavior can promote short-term pollution into durable long-term memory at rates up to 91%, with cross-session behavioral influence reaching 76%.

    4
  • A Survey of LLM-Driven Penetration Testing: Taxonomy, Co-Evolution, and Open Challenges

    Zhe-Yuan He, Jia-Qi Dong, Zihao Li, Ting Chen, Ge-Lei Deng, Feng Luo, Jinkun Ji, Yuanlong Cao, +1 more

    arXiv · 2026

    A systematic analysis of 81 papers between 2023 and 2026 addresses gaps in a unified taxonomy, a systematic understanding of how agent architectures and evaluation benchmarks have co-evolved, and a clear characterization of remaining capability and reliability gaps.

    3
  • DECEIVE-AFC: Adversarial Claim Attacks against Search-Enabled LLM-based Fact-Checking Systems

    Hao-Ran Ou, Kangjie Chen, Ge-Lei Deng, Hang-Cheng Liu, Jie Zhang, Tian-Wei Zhang, Kwok-Yan Lam

    arXiv · 2026

    DECEIVE-AFC is proposed, an agent-based adversarial attack framework that integrates novel claim-level attack strategies and adversarial claim validity evaluation principles that systematically explores adversarial attack trajectories that disrupt search behavior, evidence retrieval, and LLM-based reasoning without relying on access to evidence sources or model internals.

    3
  • Turning Bias into Bugs: Bandit-Guided Style Manipulation Attacks on LLM Judges

    Xiang-Lin Yang, Bryan Hooi, Ge-Lei Deng, Tian-Wei Zhang, Jin-Song Dong

    arXiv · 2026

    BITE is introduced, a black-box adversarial framework that learns semantics-preserving edits to mislead an LLM judge and artificially inflate the scores it assigns and exposes a fundamental weakness in the LLM-as-a-judge paradigm and motivates robust, attack-aware evaluation.

    3
  • When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents

    Ye-Chao Zhang, Shi-Qian Zhao, Jia-Wen Zhang, Jie Zhang, Ge-Lei Deng, Xiaogeng Liu, Chao-Wei Xiao, Tian-Wei Zhang

    arXiv · 2026

    Results suggest that persistent memory can turn ordinary external processing into a practical pathway for long-term agent compromise.

    3
  • A Rusty Link in the AI Supply Chain: Detecting Evil Configurations in Model Repositories

    Zi-Qi Ding, Qian Fu, Junchen Ding, Ge-Lei Deng, Yi Liu, Yue-Kang Li

    IEEE Security and Privacy Workshops (SPW) · 2025

    This work presents the first comprehensive study of malicious configurations on Hugging Face, identifying three attack scenarios (file, website, and repository operations) that expose inherent risks and introduces Configscan, an LLM-based tool that analyzes configuration files in the context of their associated runtime code and critical libraries, effectively detecting suspicious elements with low false positive rates and high accuracy.

    3
  • Do LLMs and VLMs Share Neurons for Inference? Evidence and Mechanisms of Cross-Modal Transfer

    Chen-Hang Cui, An Zhang, Yuxin Chen, Ge-Lei Deng, Jing-Nan Zheng, Zhenkai Liang, Xiang Wang, Tat-Seng Chua

    arXiv · 2026

    It is demonstrated that shared neurons form an interpretable bridge between LLMs and LVLMs, enabling low-cost transfer of inference ability into multimodal models, and across diverse mathematics and perception benchmarks, SNRF consistently enhances LVLM inference performance while preserving perceptual capabilities.

    2
  • Detecting Perception-Based Attacks using Visual Odometry: Inconsistency Modeling and Checking on Robotic States

    Yuan Xu, Ge-Lei Deng, Tian-Wei Zhang

    Proceedings - IEEE International Conference on Robotics and Automation/Proceedings · 2025

    2
  • Mission: Impossible – Image-Based Geolocation with Large Vision Language Models

    Yi Liu, Ge-Lei Deng, Junchen Ding, Yuekang Li, Tian-Wei Zhang, Weisong Sun, Yaowen Zheng, Jing-Quan Ge

    Proceedings on Privacy Enhancing Technologies · 2025

    This study investigates the geolocation capabilities of state-of-the-art LVLMs, and introduces ETHAN, a framework integrating chain-of-thought (CoT) reasoning that highlights the potential trajectory of such technologies rather than their current widespread, high-accuracy applicability.

    2
  • When Audio and Text Disagree: Revealing Text Bias in Large Audio-Language Models

    Conference on Empirical Methods in Natural Language Processing (EMNLP) · 2025

    2
  • Continuous Embedding Attacks via Clipped Inputs in Jailbreaking Large Language Models

    Zi-Hao Xu, Yi Liu, Ge-Lei Deng, Kai-Long Wang, Yuekang Li, Ling Shi, S. Picek

    IEEE Security and Privacy Workshops (SPW) · 2025

    Clip, whose main strategy is to clip each input dimension based on the mean and standard deviation of the model vocabulary during model inference, improves the attack success rate (ASR) of continuous embedding attacks with full LLM inputs from 62% to 83% for LLaMa and from 38% to 83 % for Vicuna.

    2
  • MIRAGE: Context-Aware Prompt Injection against Mobile GUI Agents via User-Generated Content

    Ruo-Qi Guo, Yi Liu, Ge-Lei Deng, Yiheng Xiong, Yue-Kang Li, Ying Zhang, L. Zhang, Li-Da Zhao, +2 more

    arXiv · 2026

    MIRAGE (Mobile Injection of Realistic Adversarial GUI Examples), a pipeline that turns benign mobile screenshots into prompt-injection samples by placing attacker-controlled text into ordinary user-generated content regions, without modifying the agent, the application, or the operating system is presented.

    1
  • SNARE: Adaptive Scenario Synthesis for Eliciting Overeager Behavior in Coding Agents

    Yu-Bin Qu, Yi Liu, Ge-Lei Deng, Yan-Jun Zhang, Yue-Kang Li, Ying Zhang, L. Zhang

    arXiv · 2026

    SNARE (Synthesizing Non-adversarial scenarios for Adaptive Reward-guided Elicitation), a pipeline that composes benign scenarios from reusable scope and trap fragments, scores each run with a judge-free oracle flagging trap-pattern matches and unsolicited file additions or deletions, and uses Thompson sampling to steer each pair's run budget toward the scenarios that most often trigger it.

    1
  • "Are You Sure?": An Empirical Study of Human Perception Vulnerability in LLM-Driven Agentic Systems

    Xin-Feng Li, Shenyu Dai, Kelong Zheng, Yue Xiao, Ge-Lei Deng, Wei Dong, Xiao-Feng Wang

    arXiv · 2026

    This work presents the first large-scale empirical study with 303 participants to measure human susceptibility to Agent-Mediated Deception, and identifies six cognitive failure modes in users and finds that their risk awareness often fails to translate to protective behavior.

    1
  • AutoEG: Exploiting Known Third-Party Vulnerabilities in Black-Box Web Applications

    Ruo-Zhao Yang, Ming-Fei Cheng, Ge-Lei Deng, Jun-Jie Wang, Tian-Wei Zhang, Xiao-Fei Xie

    arXiv · 2026

    AutoEG, a fully automated multi-agent framework for exploit generation targeting black-box web applications, is proposed, substantially outperforming state-of-the-art baselines, whose best performance reaches only 32.88%.

    1
  • Rethinking Complexity Metrics for LLM-Integrated Applications: Beyond Source Code

    Zi-Hao Xu, Yue-Kang Li, Ge-Lei Deng, Yi Liu, Zhenchang Xing

    arXiv · 2026

    This work presents HECATE, the first tool designed to assess complexity in both the prompt and code layers of LLM-integrated applications, and establishes prompt complexity as a dimension in its own right.

    –
  • Self-Guard: Defending Large Reasoning Models via enhanced self-reflection

    Jing-Nan Zheng, D. Xu, Yanzhen Luo, Chen-Hang Cui, Ge-Lei Deng, Zhenkai Liang, Xiang Wang, An Zhang, +1 more

    arXiv · 2026

    Self-Guard is proposed, a lightweight safety defense framework that reinforces safety compliance at the representational level and exhibits strong generalization across diverse unseen risks and varying model scales, offering a cost-efficient solution for LRM safety alignment.

    –
  • Membership Inference Attacks Against Video Large Language Models

    Wei Song, Yu-Xin Cao, Zi-Qi Ding, Yi Liu, Ge-Lei Deng, Yue-Kang Li

    arXiv · 2026

    It is demonstrated that Video-LLMs are vulnerable to black-box membership inference attacks, highlighting an urgent need for the community to systematically evaluate and mitigate privacy risks in VideoLLMs.

    –
  • –
  • ${\mathsf{KubeSec}} $KubeSec: Automatic Detection of Takeover Risks Introduced by Third-Party Apps in the Kubernetes Ecosystem

    Tao Zheng, Qiyu Hou, Hao Ren, Xingshu Chen, Ge-Lei Deng, Tian-Wei Zhang, Guowen Xu, Hong-Wei Li

    IEEE Transactions on Dependable and Secure Computing · 2026

    –
  • –
  • SAF: An AI-Agent-Ready and Browser-Accessible Static Analysis Framework for LLVM IR

    Yue-Kang Li, Wei Li, Wei Song, Yi Liu, Ge-Lei Deng

    IEEE/ACM International Conference on Automated Software Engineering (ASE) · 2026

    The Static Analyzer Factory is presented, an LLVM-IR analysis framework that combines a Rust kernel exposed to Python through PyO3 zero-copy bindings, a WebAssembly and Pyodide browser playground that runs the same SDK with no install, a declarative YAML language for function specifications that the built-in checkers consume at runtime, and two shipped coding-agent skills installable in Claude Code and Codex.

    –
  • Robust CAPTCHA Using Audio Illusions in the Era of Large Language Models: from Evaluation to Advances

    Zi-Qi Ding, Yunfeng Wan, Wei Song, Yi Liu, Ge-Lei Deng, Nan Sun, Hua-Dong Mo, Jing-Ling Xue, +2 more

    arXiv · 2026

    AI-CAPTCHA is introduced, a unified framework that offers (i) an evaluation framework, ACEval, which includes advanced LALM- and ASR-based solvers, and (ii) a novel audio CAPTCHA approach, IllusionAudio, leveraging audio illusions.

    –
  • –
  • –
  • Controllable Spoofing Attacks on Visual SLAM in Robotic Vehicles

    Yuan Xu, Gelei Deng, Guanlin Li, Xingshuo Han, Shangwei Guo, Tianwei Zhang

    2025 IEEE Annual Computer Security Applications Conference (ACSAC) · 2025

    –
  • –
  • –
  • Visible Yet Unreadable: A Systematic Blind Spot of Vision Language Models Across Writing Systems

    Jie Zhang, Ting Xu, Ge-Lei Deng, Run-Yi Hu, Han Qiu, Tian-Wei Zhang, Qing Guo, I. Tsang

    arXiv · 2025

    This paper constructs two psychophysics inspired benchmarks across distinct writing systems, Chinese logographs and English alphabetic words, by splicing, recombining, and overlaying glyphs to yield visible but unreadablestimuli for models while remaining legible to humans.

    –
  • SPOLRE: Semantic Preserving Object Layout Reconstruction for Image Captioning System Testing

    Yi Liu, Guan-Yu Wang, Xinyi Zheng, Ge-Lei Deng, Kai-Long Wang, Yang Liu, Hao-Yu Wang

    ACM Transactions on Software Engineering and Methodology · 2025

    SPOLRE is a novel automated tool designed for semantic preserving object layout reconstruction in image captioning system testing that utilizes four semantic preserving transformation techniques—translation, rotation, mirroring, and scaling—to modify object layouts autonomously, eliminating the need for manual annotation.

    –
  • –
  • –

Publication data from OpenAlex, with missing venues and authors filled in from Crossref; citation counts are the higher of OpenAlex and Semantic Scholar, last synced 2026-10-10. One-sentence summaries under some papers are written by Semantic Scholar’s model. Citation counts may be lower than on Google Scholar, which indexes more sources.

Report an error

Wrong papers, two people merged into one, or a profile that should not be here? Tell us and we will fix or hide it. You will be asked to sign in.