Multimodal large language models (LLMs) are increasingly adopted to interpret 12-lead ECG images, though the interpretations often lack validation. However, ECG image understanding significantly differs from general images as it depends on precise waveform morphology, lead relationships and accurate interval measurements. This study investigated whether zero-shot multimodal LLMs can reliably distinguish normal and abnormal ECG images and, in parallel, evaluated CNN-based models for clinically grounded references. Standard 12-lead ECG recordings were rendered as single-page images for a binary normal-abnormal classification task. Three prominent LLMs (GPT-5.2, GPT-4.1, and Gemini-2.5 Pro) were tested using a fixed zero-shot prompt across multiple runs. In parallel, a physiology-aware CNN-based model was developed with the capability to aggregate features from the predefined anatomical lead groups. The model was compared with ResNet18, DenseNet121, VGG16 baselines, and all the models were evaluated on an internal test set and external PTB-XL dataset. Across seeds, CNN-based models demonstrated stable discrimination, with average internal ROC-AUC of 0.92-0.94, and external ROC-AUC of 0.85-0.86. The proposed LeadGroupECG model significantly improved over its backbone internally without compromising external generalization. It remained competitive with other baselines, while consistently highlighting anatomical lead-group contributions. In contrast, zero-shot LLM discrimination remained near-chance (ROC-AUC around 0.5). The PR-AUC improved slightly when ECGs used a grid-based calibration background compared with the grid-free ECGs. Although multimodal LLMs can generate reasonable ECG narratives, their zero-shot diagnostic discrimination remains limited. Therefore, clinically framed, domain-specific architectures remain essential for AI-based ECG interpretation.
In this study, a novel compact Wilkinson power divider (PD) with high fractional bandwidth (FBW) and excellent isolation is proposed, designed, and experimentally validated. The structure employs rectangular multi-section resonators, replacing conventional transmission lines, achieving a significant size reduction of over 76% compared to traditional designs. Additionally, the multilayer perceptron (MLP) neural network algorithm is used to optimize performance, resulting in a very small mean relative error (MRE) and mean absolute error (MAE), indicating the design's optimality. The fabricated PD eliminates 16 unwanted harmonics with suppression levels below -20 dB across a wide frequency range of 1.15-2.5 GHz. Fabricated on an RT Duroid 5880 substrate, the measured results show excellent agreement with simulations, validating the design's reliability. Compared to existing Wilkinson power dividers, the proposed solution offers several key advantages: a 76% reduction in size, a FBW of 96%, and the suppression of harmonics up to the 16th order, which significantly enhances signal integrity. Additionally, the design's simplicity and efficiency ensure lower manufacturing costs, making it suitable for high-performance, cost-effective wireless communication systems.
Field-programmable gate array (FPGA) cloud acceleration, or "FPGA as a Service" (FaaS), offered by AWS, Microsoft Azure, Alibaba Cloud, and Huawei Cloud, has become a promising solution for tackling complex, compute-intensive workloads. It targets applications such as genomics, image and video processing, electronic design automation (EDA), compression, and big data analytics. While multitenant FPGAs significantly enhance resource utilization efficiency, they face security threats from power side channels, where attackers craft a malicious circuit to detect voltage fluctuations from victim circuits. Observing that all the crafted circuits exploit either a carry chain or a lookup table (LUT) to sense voltage fluctuations, existing defenses have focused on detecting the malicious use of the two basic FPGA computing resources. However, it remains unclear whether such countermeasures are sufficient to address the growing threat of power side channels in multitenant FPGAs. In this article, we reveal MUXLeak, a novel on-chip sensor that exploits a multiplexer (MUX) to craft a stealthy power side channel, which bypasses existing countermeasures. Particularly, we perform a thorough analysis of basic resources within an FPGA unit and unveil that MUX, another basic resource, has never been exploited before. More importantly, it can be directly initialized on Xilinx FPGAs, and its incurred signal propagation delay demonstrates an inverse correlation with changes in voltage, making it exploitable for a new power side-channel leakage. In our evaluation, we test MUXLeak on three Xilinx FPGA products and use TDC (i.e., the most sensitive on-chip sensor until now) to benchmark the sensitivity of MUXLeak. Our results show that MUXLeak has achieved the same level of sensitivity as TDC to voltage fluctuations. Furthermore, we apply MUXLeak to mount two attacks, i.e., extracting AES keys within 2.54 h and stealing DNN model architectures with an accuracy of over 90%.
We examine how Eisert–Wilkens–Lewenstein (EWL) quantization affects evolutionary stability in a symmetric 2×2 game whose interior mixed Nash equilibrium is not evolutionarily stable. In the restricted two-parameter EWL strategy space, the quantum equilibrium s^*=(π/2,π/4) becomes a strict symmetric Nash equilibrium, and hence an evolutionarily stable strategy, for every γ>0. Extending the admissible pure strategies to the full three-parameter SU(2) family preserves the Nash equilibrium but introduces a continuum of payoff-neutral mutants, causing strictness and the second ESS condition to fail. Thus, entanglement stabilizes the equilibrium only within the restricted EWL strategy space; the effect does not survive enlargement to full SU(2).
Self-repair is a biological mechanism through which the nervous system compensates for damage and maintains stable neural activity, a process that is partly mediated by astrocytes. Astrocytes play a critical role in synaptic regulation by releasing global feedback signals that contribute to error correction and the adjustment of neuronal firing-rate set-point. They receive signals from multiple connected synapses, such as 2-arachdonoylglycerol (2AG), and subsequently release various neurotransmitters that modulate the activity of neighboring neurons. This astrocyte-mediated feedback is an essential component of biologically inspired self-repair mechanisms. When synaptic faults occur, the resulting disruption is sensed through changes in intracellular calcium (Ca2+) levels in the postsynaptic neuron, which triggers adaptive adjustments in neuronal excitability. Together, astrocyte feedback and calcium-dependent regulation from complementary mechanisms facilitate postsynaptic homeostasis. In this work, we investigate the self-repair phenomenon and its relationship with astrocytes and tripartite synapses. First, a novel self-repair algorithm capable of detecting and compensating for synaptic faults is introduced, followed by the design of an analog circuit that implements this algorithm. In addition, a new tripartite synapse structure is proposed to mimic key biological interactions between neurons and astrocytes. The proposed circuits are implemented in a neural network consisting of three layers, 22 neurons, and five astrocytes. Simulation results demonstrate that healthy astrocytes and synapses can effectively compensate for synaptic faults by injecting feedback signals, thereby enhancing the self-repair capability of the network. The circuit was designed and simulated using HSPICE software with standard 0.35 mu m CMOS technology.
Speculative trading can drive pronounced market instabilities, yet existing regulatory and macroprudential tools intervene only after such dynamics emerge. Quantum technologies offer a fundamentally new means of shaping economic behavior by introducing non-classical correlations between decision-makers. Here we demonstrate a prototype quantum stock market in which entanglement between traders' valuations mitigates the runaway devaluation characteristic of speculative busts. Using reinforcement-learning agents trading a single commodity, we show that replacing classical valuations with quantum-correlated qubit-encoded valuations stabilizes prices and increases the AI traders' net worth relative to a classical market, where instead agents rapidly converge to liquidation strategies that collapse the asset value. To explain this behavior, we formulate and analyze a quantized version of the p-guessing game, a canonical model of speculative dynamics. Quantum entanglement and phase coherence reshape the strategic landscape, eliminating the pathological pure-strategy Nash equilibrium that drives market collapse in the classical game, while mixed-strategy equilibria remain non-degenerate and avoid bust-type outcomes. These results identify quantum correlations as a novel, endogenous mechanism for market stabilization and, more broadly, demonstrate the utility of multi-agent reinforcement learning algorithms for uncovering optimal strategies in complex decision-making frameworks with quantum degrees of freedom.
The emerging demand for increased data rates between Earth, the lunar gateway, Mars, and various other deep space probes will stretch existing deep space network (DSN) antennas beyond capacity. The DSN antennas distributed across Canberra, Madrid, and Goldstone are capable of tracking the Mars Reconnaissance Orbiter (MRO) travelling tens of millions of kilometers from Earth, and life extension efforts continue to support such critical space infrastructure. However, these legacy systems still suffer failures and outages that have resulted in delays in data communication and this situation continues to be a significant challenge. This explains the current interest in this area. Thus it is timely that we present a fresh tutorial on a link budget to Mars, elucidating use of the latest ITU-R model recommendations for propagation through the Earth's atmosphere. To facilitate communication to Mars, we target a downlink frequency in the K band (31.8-32.3 GHz) as it allows for increased data transmission rate, increased effective isotropic radiated power (EIRP) and reduced antenna size. In this tutorial paper, we therefore focus on a link budget in the K-a band and take into account all major sources of attenuation including free space path loss (FSPL), rain, fog, and system noise temperature (7sys), which are critical for ensuring a positive link margin. As a case study, the presented link budget uses parameters for actual MRO communications and the Canberra DSN antenna assuming communication from the Mars Reconnaissance Orbiter (MRO) to the Canberra DSN-DSS-35. For point of comparison, we compare this with the case of Lunar to Earth communications.
Noise injection, which involves the addition or multiplication of random variables to the input data or parameters of neural networks, has proven to be an effective strategy for enhancing neural network performance. However, the relationship between the generalization of a neural network and the scale parameter of injected noise is not well understood, and the optimization of noise injection for performance enhancement is a complex non-convex high-dimensional problem. This study investigates various noise injection methodologies across different neural network architectures utilizing the Bayesian optimization approach. The results indicate that, among the diverse noise injection strategies, the intrinsic hyperparameter governing the noise scale, specifically within the context of noise-boosted activations optimized through a Bayesian surrogate model, yields the most stable enhancement in network performance for function approximation, image classification, and image reconstruction tasks. These findings demonstrate the feasibility of the Bayes-oriented noise injection approach in improving the performance of neural networks.
Backdoor attacks on deep learning (DL) models are recognized as one of the most alarming security threats, particularly in security-critical applications. A primary source of backdoor introduction is data outsourcing such as when data is aggregated from third parties or end Internet of Things (IoT) devices, which are susceptible to various attacks. Significant efforts have been made to counteract backdoor attacks through defensive measures. However, the majority of them are ineffective to either evolving trigger types or backdoor types. This study proposes a poisoned data detection method, termed as LABOR (unsupervised Learning Assisted supervised learning data poisoning based Backd Or Removal), by incorporating a little human intelligence feedback. LABOR is specifically devised to counter backdoor induced by dirty-label data poisoning on the most common classification tasks. The key insight is that regardless of the underlying trigger types (e.g., patch or imperceptible triggers) and intended backdoor types (e.g., universal or partial backdoor), the poisoned samples still preserve the semantic features of their original classes. By clustering these poisoned samples based on their original categories through unsupervised learning, with category identification assisted by human intelligence, LABOR can detect and remove poisoned samples by identifying discrepancies between cluster categories and classification model predictions. Extensive experiments on eight benchmark datasets, including an intrusion detection dataset relevant to IoT device protection, validate LABOR’s effectiveness in combating dirty-label poisoning-based backdoor attacks. LABOR’s robustness is further demonstrated across various trigger and backdoor types, as well as diverse data modalities, including image, audio and text.
In the Data as a Service (DaaS) model, data curators, such as commercial providers like Amazon Mechanical Turk, Appen, and TELUS International, aggregate quality data from numerous contributors and monetize it for deep learning (DL) model providers. However, malicious contributors can poison this data, embedding backdoors in the trained DL models. Existing methods for detecting poisoned samples face significant limitations: they often rely on reserved clean data; they are sensitive to the poisoning rate, trigger type, and backdoor type; and they are specific to classification tasks. These limitations hinder their practical adoption by data curators. This work, for the first time, investigates the training trajectory of poisoned samples in the spectrum domain, revealing distinctions from benign samples that are not apparent in the original nonspectrum domain. Building on this novel perspective, we propose Telltale to detect and sanitize poisoned samples as a one-time effort, addressing all of the aforementioned limitations of prior work. Through extensive experiments, Telltale demonstrates the ability to defeat both universal and challenging partial backdoor types without relying on any reserved clean data. Telltale is also validated to be agnostic to various trigger types, including the advanced clean-label trigger attack, Narcissus (CCS'2023). Moreover, Telltale proves effective across diverse data modalities (e.g., image, audio and text) and non-classification tasks (e.g., regression)-making it the only known training phase poisoned sample detection method applicable to non-classification tasks. In all our evaluations, Telltale achieves a detection accuracy (i.e., accurately identifying poisoned samples) of at least 95.52% and a false positive rate (i.e., falsely recognizing benign samples as poisoned ones) no higher than 0.61%. Comparisons with state-of-the-art methods, ASSET (Usenix'2023) and CT (Usenix'2023), further affirm Telltale's superior performance. More specifically, ASSET fails to handle partial backdoor types and incurs an unbearable false positive rate with clean/benign datasets common in practice, while CT fails against the Narcissus trigger. In contrast, Telltale proves highly effective across testing scenarios where prior work fails. The source code is released at https://github.com/MPaloze/Telltale.
Catastrophic bushfires are becoming increasingly prevalent as climate change advances. Impacts extend beyond national borders. Multinational efforts can inform new science and management practices. Space-based sensors and integrated data facilities will play an important role. This paper describes a collaborative project between a consortium of Australian universities and NASA Centers to develop and implement a small satellite platform comprising highly integrated thermal and lightning sensors coupled with AI-based edge computing to help predict, detect, and track bushfires, supporting mitigation activities. This will fill an important capability gap since Australia does not currently have any sovereign Earth observation satellites. This program is enabled by and builds on Australia-NASA collaboration and will also support fire science and management activities in the broader global context.
Image camouflage has been utilized to create clean-label poisoned images for implanting backdoor into a DL model. But there exists a crucial limitation that one attack/poisoned image can only fit a single input size of the DL model, which greatly increases its attack budget when attacking multiple commonly adopted input sizes of DL models. This work proposes to constructively craft an attack image through camouflaging but can fit multiple DL models' input sizes simultaneously, namely OmClic. Thus, through OmClic, we are able to always implant a backdoor regardless of which common input size is chosen by the user to train the DL model given the same attack budget (i.e., a fraction of the poisoning rate). With our camouflaging algorithm formulated as a multi-objective optimization, M=5 input sizes can be concurrently targeted with one attack image, which artifact is retained to be almost visually imperceptible at the same time. Extensive evaluations validate the proposed OmClic can reliably succeed in various settings using diverse types of images. Further experiments on OmClic based backdoor insertion to DL models show that high backdoor performances (i.e., attack success rate and clean data accuracy) are achievable no matter which common input size is randomly chosen by the user to train the model. So that the OmClic based backdoor attack budget is reduced by M× compared to the state-of-the-art camouflage based backdoor attack as a baseline. Significantly, the same set of OmClic based poisonous attack images is transferable to different model architectures for backdoor implant.
Australia experiences some of the worst bushfires in the world. The consequences for life, property, flora and fauna are immense, with vast swathes of territory destroyed and financial losses in the billions. This paper describes work by a consortium of Australian universities in conjunction with NASA to develop concepts for low-cost space-based platforms for bushfire detection and tracking. The pathfinder mission concept pairs an advanced thermal imaging payload developed by NASA engineers with AI-based algorithms for on-board processing using commercially available hardware in a 12U CubeSat platform. The opportunity to leverage enabling technologies like optical interlinks for satellite-to-satellite communications provides a pathway to develop swarm capabilities and the concept is scalable to form a constellation to provide a needed bushfire detection and monitoring capability.
Hypercomplex signal and image processing extends upon conventional methods by using hypercomplex numbers in a unified framework for algebra and geometry. The special issue is divided into two parts and is focused on current advances and applications in computational signal and image processing in the hypercomplex domain. The first part offered well-rounded coverage of the field, with seven articles that focused on overviews of current research, color image processing, signal filtering, and machine learning.
Incorporating additive noise components to an ensemble of McCulloch-Pitts neurons can enhance the information representation of the input, asymptotically approaching the average firing probability for large enough ensembles. We further multiply the input by the average firing probability to control the higher probability of self-gating, thereby forming a unified noise-boosted activation model with learnable noise-related hyperparameters. This gating strategy plays a crucial role in improving the performance of neural networks, as evidenced by the optimization of the autoencoder loss at nonzero optimal-noise-scaling hyperparameters, a phenomenon termed self-gating stochastic resonance. Experiments with designed autoencoders using noise-boosted activation functions demonstrate the potential applications of the self-gating stochastic resonance effect in the field of unsupervised learning.
This work reveals that standard quantization toolkits can be abused to activate a backdoor. We demonstrate that a full-precision backdoored model which does not have any backdoor effect in the presence of a trigger—as the backdoor is dormant—can be activated by (i) TensorFlow-Lite (TFLite) quantization, the only product-ready quantization framework to date, and (ii) the beta released PyTorch Mobile framework. In our experiments, we employ three popular model architectures (VGG16, ResNet18, and ResNet50), and train each across three popular datasets: MNIST, CIFAR10 and GTSRB. We ascertain that all trained float-32 backdoored models exhibit no backdoor effect even in the presence of trigger inputs. Particularly, four influential backdoor defenses are evaluated, and they fail to identify a backdoor in the float-32 models. When each of the float-32 models is converted into an int-8 format model through the standard TFLite or PyTorch Mobile framework's post-training quantization, the backdoor is activated in the quantized model, which shows a stable attack success rate close to 100% upon inputs with the trigger, while it usually behaves upon non-trigger inputs. This work highlights that a stealthy security threat occurs when an end-user utilizes the on-device post-training model quantization frameworks, informing security researchers of a cross-platform overhaul of DL models post-quantization even if these models pass security-aware front-end backdoor inspections. Significantly, we have identified Gaussian noise injection into the malicious full-precision model as an easy-to-use preventative defense against the PQ backdoor.
The motivation for the development of multi-exit networks (MENs) lies in the desire to minimize the delay and energy consumption associated with the inference phase. Moreover, MENs are designed to expedite predictions for easily identifiable inputs by allowing them to exit the network prematurely, thereby reducing the computational burden due to challenging inputs. Nevertheless, there is a lack of comprehensive understanding regarding the security vulnerabilities inherent in MENs. In this study, we introduce a novel approach called the sponge attack, which aims to compromise the fundamental advantages of MENs that allow easily identifiable images to leave in early exits. By employing data poisoning techniques, we frame the sponge attack as an optimization problem that empowers an attacker to select a specific trigger, such as adverse weather conditions (e.g., raining), to compel inputs to traverse the complete network layers of the MEN (e.g., in the context of traffic sign recognition) instead of early-exits when the trigger condition is met. Remarkably, our attack has the capacity to increase inference latency, while maintaining the classification accuracy even in the presence of a trigger, thus operating discreetly. Extensive experimentation on three diverse natural datasets (CIFAR100, GTSRB, and STL10), each trained with three prominent MEN architectures (VGG16, ResNet56, and MSDNet), validates the efficacy of our attack in terms of latency augmentation and its effectiveness in preserving classification accuracy under trigger conditions.
Novel computational signal and image analysis methodologies based on feature-rich mathematical/computational frameworks continue to push the limits of the technological envelope, thus providing optimized and efficient solutions. Hypercomplex signal and image processing is a fascinating field that extends conventional methods by using hypercomplex numbers in a unified framework for algebra and geometry. Methodologies that are developed within this field can lead to more effective and powerful ways to analyze signals and images. Processing audio, video, images, and other types of data in the hypercomplex domain allows for more complex and intuitive representations with algebraic properties that can lead to new insights and optimizations. Applications in image processing, signal filtering, and deep learning (just to name a few) have shown that working in the hypercomplex domain can lead to more efficient and robust outcomes. As research in this field progresses and software tools become more widely available, we can expect to see increasingly sophisticated applications in many areas of research, e.g., computer vision, machine learning, and so on.
Abstract One of the significant challenges in renewable integration is balancing supply and demand. The variability in generation and demand forces the grid to experience significant market price volatility. Moreover, electricity curtailment is adhered to during low-demand periods. Hydrogen Energy storage systems (HESS) can provide power dispatch flexibility and facilitate the reduction in curtailment. Unlike other storage systems such as batteries, the energy and power capacities for HESS design can be decoupled, resulting in a long-duration storage solution. In our paper, we perform electricity dispatch optimization from renewable sources such as solar and wind to the electricity market, where hydrogen is optimally produced using electrolysis, stored during low electricity prices, and converted to electricity using fuel cells to support the grid. The capital cost optimization suggests high profits for investors leveraging market price volatility even with low HESS round-trip efficiency and high upfront costs.