Large language model (LLM)-based agents have recently gained considerable attention due to the powerful reasoning capabilities of LLMs. Existing research predominantly focuses on enhancing the task performance of these agents in diverse scenarios. However, as LLM-based agents become increasingly integrated into real-world applications, significant concerns emerge regarding their accumulation of sensitive or outdated knowledge. Addressing these concerns requires the development of mechanisms that allow agents to selectively forget previously learned knowledge, giving rise to a new term LLM-based agent unlearning. This paper initiates research on unlearning in LLM-based agents. Specifically, we propose a novel and comprehensive framework that categorizes unlearning scenarios into three contexts: state unlearning (forgetting specific states or items), trajectory unlearning (forgetting sequences of actions) and environment unlearning (forgetting entire environments or categories of tasks). Within this framework, we introduce a natural language-based unlearning method that trains a conversion model to transform high-level unlearning requests into actionable unlearning prompts, guiding agents through a controlled forgetting process. Moreover, to evaluate the robustness of the proposed framework, we introduce an unlearning inference adversary capable of crafting prompts, querying agents, and observing their behaviors in an attempt to infer the forgotten knowledge. Experimental results show that our approach effectively enables agents to forget targeted knowledge while preserving performance on untargeted tasks, and prevents the adversary from inferring the forgotten knowledge.
Spectral clustering is known as a powerful technique in unsupervised data analysis. The vast majority of approaches to spectral clustering are driven by a single modality, leaving the rich information in multi-modal representations untapped. Inspired by the recent success of vision-language pre-training, this paper enriches the landscape of spectral clustering from a single-modal to a multi-modal regime. Particularly, we propose Neural Tangent Kernel Spectral Clustering that leverages cross-modal alignment in pre-trained vision-language models. By anchoring the neural tangent kernel with positive nouns, i.e., those semantically close to the images of interest, we arrive at formulating the affinity between images as a coupling of their visual proximity and semantic overlap. We show that this formulation amplifies within-cluster connections while suppressing spurious ones across clusters, hence encouraging block-diagonal structures. In addition, we present a regularized affinity diffusion mechanism that adaptively ensembles affinity matrices induced by different prompts. Extensive experiments on \textbf{16} benchmarks---including classical, large-scale, fine-grained and domain-shifted datasets---manifest that our method consistently outperforms the state-of-the-art by a large margin.
Deepfake techniques can now generate multimodal content comprising video and audio tracks. Compared with unimodal Deepfake images, videos or audio, multimodal Deepfake content is more deceptive and easily leads to the dissemination of hate speech, incitement to violence, and disinformation. Therefore, the detection of multimodal Deepfake has attracted much research attention recently. While cross-attention shows the promising capacity for modelling the complicated dependencies between audio and video in multimodal Deepfake detection, it fails to learn accurate cross-modal patterns if audio and video are misaligned in the temporal dimension. Besides, most current multimodal Deepfake detectors only provide a binary classification label, lacking fine-grained localization to identify significant forgery in multiple dimensions (e.g., modal, time, and spatial dimension). In this study, we propose a novel multimodal Deepfake detection framework named ForgeFinder, which goes beyond binary label prediction and achieves multi-grained forgery localization in modal and spatiotemporal dimensions. ForgeFinder incorporates both intra-modal and cross-modal inconsistencies to classify multimodal input. In detail, we adopt Serial Spatiotemporal Self-Attention (SSTSA) in the Intra-Modal Inconsistency Explorer (Intra-MIE), which allows the temporal self-attention to run in the original dimension without bringing unacceptable computational complexity. In the Cross-Modal Inconsistency Explorer (Cross-MIE), we propose the Offset-Shifted Cross-Attention (OSCA) by introducing a time offset term to the conventional cross-attention to mitigate the inaccuracy of cross-modal dependencies modelling brought by the temporal misalignment. By adopting the outputs of Intra-MIE for unimodal tasks, we identify the likelihood of modals being manipulated and localize tampered modals. At the same time, the attention weights of SSTSA can be visualized to pinpoint the temporal and spatial distribution of Deepfake manipulation. Therefore, for a single audio–video input sample, ForgeFinder not only tells the authenticity of the overall input but also localizes the modal, temporal sequence, and spatial coordinates of significant forgery, significantly contributing to more comprehensive forensics analysis. The results of extensive experiments indicate that ForgeFinder achieves state-of-the-art detection performance as well as accurate forgery localization in modal and spatiotemporal dimensions. Furthermore, experiments on content generated by Diffusion Models (DMs) show that our model also effectively recognizes DM-generated content.
With the rapid development of artificial intelligence, large language models (LLMs) have made remarkable advancements in natural language processing. These models are trained on vast datasets to exhibit powerful language understanding and generation capabilities across various applications, including chatbots, and agents. However, LLMs have revealed a variety of privacy and security issues throughout their life cycle, drawing significant academic and industrial attention. Moreover, the risks faced by LLMs differ significantly from those encountered by traditional language models. Given that current surveys lack a clear taxonomy of unique threat models across diverse scenarios, we emphasize the unique privacy and security threats associated with four specific scenarios: pre-training, fine-tuning, deployment, and LLM-based agents. Addressing the characteristics of each risk, this survey outlines and analyzes potential countermeasures. Research on attack and defense situations can offer feasible research directions, enabling more areas to benefit from LLMs.
Due to the growing emphasis on privacy and data governance in machine learning, federated unlearning, an emerging concept in the domain of federated learning, stems from the growing need to address the dynamic nature of data and the evolving requirements related to privacy, compliance, and data management. However, there are some security risks during the unlearning process, including the potential for adversarial manipulation of model integrity, privacy breaches, and performance degradation in a federated learning framework. Although existing research has proposed various defenses to mitigate these risks, significant vulnerabilities remain that can be exploited to undermine the integrity and effectiveness of the unlearning process. Current attack methods are limited by their detectability during training, lack of persistence, and reliance on test-time triggers, which reduces their overall effectiveness. In this paper, we introduce camouflaged poisoning attacks, a novel attack paradigm relevant to federated unlearning. In this approach, some adversary clients initially infuse a small number of meticulously designed points into the dataset, ensuring that the model's predictions are barely influenced. The adversary then makes a request to the exclusion of some of these malicious clients. At this juncture, the attack is activated, leading to a detrimental impact on the model's predictions. The outcomes reveal a substantial potential for these strategies to compromise the effectiveness of models in unlearning scenarios. The essence of this attack involves the creation of deceptive clients that conceal the influence of a contaminated dataset during the federated unlearning process.
Multi-view learning (MVL) effectively captures complementary information from diverse data perspectives. However, the high cost of acquiring fully annotated multi-view datasets has accelerated the adoption of Positive-Unlabeled (PU) learning. While practical, standard PU learning remains highly sensitive to label noise introduced by unobserved positive instances within the unlabeled dataset. Furthermore, current reinforcement learning (RL) guided sample selection methods typically process single-view representations, neglecting the inherent cross-view structural consensus. To tackle these issues, we propose a Collaborative Reinforcement Learning framework tailored for Multi-view PU scenarios (MV-CRL). In our approach, an Advantage Actor-Critic (A2C) agent serves as a dynamic selector to mine high-quality negative samples, guided by a K-Nearest Neighbors (KNN) diversity penalty that prevents selection collapse. Simultaneously, we enforce cross-view alignment to map heterogeneous features into a unified latent space, yielding robust state representations for the RL policy. Through a multi-stage training protocol, our framework iteratively refines the feature encoders, RL agent, and PU classifier. Extensive evaluations on facial beauty prediction benchmarks, including SCUT-FBP5500 and MEBeauty, reveal that MV-CRL consistently surpasses existing baselines in classification accuracy and stability, especially under severe label scarcity.
Respiratory diseases cause over 5 million annual deaths worldwide, with a particularly heavy burden in resource-limited settings. Existing deep learning models for lung disease classification face a critical tradeoff: heavyweight models (e.g., ResNet50) achieve high accuracy but are computationally unsuitable for edge deployment, while lightweight architectures suffer from high error rates in detecting subtle lesions due to insufficient multi-scale feature learning. To address these issues, we propose LAMobileNet, a lightweight hybrid network built on MobileNetV3-Small and guided by lesion-aware classification. The model integrates four synergistic components: Latent Feature Multi-Scale Fusion (LFMSF) to capture multi-scale pathological features; the core Lesion-Associated Classification-Guided Multi-Scale Attention (LCMA) to focus on low-contrast lesion regions; a lightweight Transformer to model long-range global dependencies; and Uncertainty-Augmented Classification (UAC) to improve diagnostic reliability. A referral strategy based on uncertainty thresholds further supports clinical translation by flagging ambiguous cases for radiologist review. Comprehensive experiments on four public chest X-ray datasets with an 8:1:1 train-validation-test split show that LAMobileNet (2.27M parameters, 0.52 GFLOPs) achieves 99.10%, 96.64%, and 97.35% accuracy in binary, four-class, and nine-class tasks, respectively, outperforming ResNet50 and COVID-Net by clear margins. Ablation studies confirm that the LCMA module improves accuracy by 3.00%-3.30%. LAMobileNet offers an accurate, efficient, and reliable auxiliary diagnostic tool for resource-limited settings, with strong potential for edge deployment and high clinical practicality.
Class imbalance, noise, and outliers pose significant challenges in real-world classification tasks. Although fuzzy twin support vector machines mitigate noise using membership functions, they still struggle to utilize neighborhood information, distinguish support vectors, and address data imbalance. To overcome these limitations, this paper proposes a Robust SMOTE-enhanced intuitionistic fuzzy least squares twin support vector machine (RSIFLSTSVM). First, an adaptive kernel-SMOTE strategy enriches the minority class by generating boundary samples in feature space. Then, a novel intuitionistic fuzzy membership function assigns each instance a reliability score that jointly considers the distances of minority class samples and synthetic samples to the class center. An improved scoring mechanism is introduced, incorporating class imbalance ratios into the interaction between membership and non-membership degrees. To further enhance performance, RSIFLSTSVM is embedded into an AdaBoost ensemble that iteratively trains weak classifiers and dynamically updates sample weights. Extensive experiments on 12 imbalanced UCI datasets and several image benchmarks show that RSIFLSTSVM outperforms competing methods. On average, it improves G-mean and AUC by 4.1
Machine unlearning has been extensively studied in response to growing privacy concerns and regulatory requirements. However, auditing whether unlearning algorithms have truly erased the influence of specific data remains an open challenge. The lack of reliable and practical auditing mechanisms can lead to critical privacy risks, such as residual information leakage. This paper initiates a systematic investigation into whether existing unlearning algorithms can truly forget the designated data. We propose the first practical and general-purpose auditing framework for machine unlearning, inspired by the concept of proof of ignorance. Our framework addresses the key practicality limitations of existing methods by eliminating the need for retraining-from-scratch baselines, avoiding the training of large numbers of shadow models, and requiring no intrusive intervention in the original training process. To evaluate the effectiveness of our framework, we first conduct validation experiments to verify its soundness and completeness. We then perform comprehensive experiments across six datasets and ten representative unlearning methods. The results demonstrate that our framework reliably distinguishes between successful and failed unlearning. In particular, we observe that retraining-based and fine-tuning-based methods can achieve effective unlearning, even when the target data remain in the original dataset. In contrast, de-optimization-based methods fail to achieve true unlearning and instead degrade the model's performance. Fisher/Hessian-based methods also fail to unlearn requested data, even formal certification is provided. Moreover, we show that our framework is robust against fake unlearning attempts and generalizes well to large language models.
Ordinal regression (OR) deals with the classification problem that the training set consists of multiple classes, and these classes are ranked in order. At present, a considerable number of works have been done on OR. Nevertheless, most of the existing OR works are proposed for single-view OR with labeled data, and there is little work done on multi-view OR with semi-supervised data. In this paper, we propose a novel multi-view semi-supervised large margin OR approach (MSOR), which integrates the information of multiple views and unlabeled data into refining the OR classifier. Firstly, in order to incorporate the information from multiple views, we build up a similarity graph for each view by considering the nearest neighbor information in all views. By doing this, the nearest neighbor information of one view is considered as the complementary information of another view, such that different views can mutually provide complementary information to enrich each other. Secondly, in order to incorporate the unlabeled data, we employ the adaptive manifold term. Different from the traditional manifold term that the similarity weight is a fixed value, in our adaptive manifold term, the similarity weight is an unknown variable, which will be optimized in the training process. Lastly, the learning problem of MSOR is formulated based on the similarity graphs and adaptive manifold term. The numerical experiments on real-life OR datasets have illustrated that MSOR attains superior performance to the existing OR approaches.
Few-shot remote sensing scene classification aims to recognize land-use or land-cover categories from only a few labeled samples per class. Vision-language models (VLMs) such as CLIP provide strong zero-shot capability via semantic priors; however, integrating few-shot supervision into CLIP-based inference remains challenging due to the misalignment of semantic priors and the unreliability of task-adapted visual evidence under limited samples. In this letter, we propose reliability-calibrated CLIP (RC-CLIP), a training-free reliability-calibrated inference framework that operates at the decision level without fine-tuning CLIP encoders. RC-CLIP estimates the reliability of visual evidence through prototype-semantic discrepancy, prototype dispersion, and supervision sufficiency and adaptively balances few-shot predictions with zero-shot priors. Extensive experiments on multiple remote sensing benchmarks demonstrate that RC-CLIP consistently outperforms representative inference-time adaptation methods under the full-class few-shot protocol, especially in the challenging one-shot regime. Moreover, RC-CLIP improves discrimination among semantically ambiguous classes, yielding more robust and interpretable predictions.
Over the past years, respiratory diseases have accounted for over 5 million annual fatalities, rendering precise diagnostics imperative. Chest radiography (CXR), which serves as the primary screening modality, exhibits inherent limitations, including anatomical overlap (where ribs obscure lung tissue), low contrast of subtle pathologies, and substantial lesion-scale variability. Contemporary deep learning architectures (e.g., ResNet, EfficientNet) demonstrate inadequacies in addressing these challenges due to fixed receptive fields, constrained global context capture, and deficient spatial-channel feature fusion. To circumvent these limitations, we propose DyFASA: a lightweight (0.17M parameters) attention module integrating three synergistic components. In the proposed method, Dynamic Kernel Selection (DKS) employs a gating network to weight 1 x 1/3 x 3/5 x 5 branches adaptively, thereby adapting receptive fields for multi-scale lesions. Frequency-Domain Adaptive Attention (FAA) leverages FFT to segregate pathological textures from skeletal interference while capturing global context. Spatially Adaptive Channel Attention (SACA) fuses local DKS features with global FAA context to concentrate on diagnostically relevant regions. Upon evaluation using the MUT and BIN datasets, DyFASA elevates U-Net (DyNet) lung segmentation accuracy to 99.34% and enhances EfficientNet-B0's MUT classification precision by approximately 10%. It presents an efficient solution for computationally constrained clinical environments.
Positive and unlabeled learning (PU learning) addresses classification scenarios where only positive and unlabeled samples are available, the latter comprising both hidden positive and negative instances. While most existing PU methods focus on identifying reliable negative samples, they often underutilize the remaining unlabeled data and operate primarily within a single-view framework, limiting their expressive power. To overcome these limitations, this paper proposes SMVPU, a novel similarity-based multi-view PU learning method that effectively integrates multi-view learning principles. SMVPU first extracts reliable negative samples from the unlabeled set and assigns similarity-weighted values to the remaining unlabeled instances. It then incorporates multi-view representations to enhance feature compatibility and discriminability. By leveraging both consistency and complementarity principles across views, the method constructs a robust PU classifier formulated within a large-margin learning framework. The optimization problem is efficiently solved via the Lagrangian dual method. Extensive experiments demonstrate that SMVPU achieves superior performance compared to existing PU learning methods in terms of classification accuracy and stability.
Large generative models across text-to-text, text-to-image, and image-to-text modalities have been shown to pose significant privacy risks. One fundamental threat is membership inference attacks (MIA), which aim to determine whether a given data point was used in a model's training set. Although prior work has investigated MIAs against these three classes of generative models, existing approaches treat them in isolation and are not cross-applicable, thereby limiting their real-world utility. To address this limitation, we present the first comprehensive study of a unified membership inference framework that applies across text-to-text, text-to-image, and image-to-text modalities. Our approach is grounded in a key modality-agnostic observation: the output distribution of a generative model can approximate its training data distribution. Leveraging this property, we model the distributions of model-generated outputs and auxiliary non-member samples in a shared embedding space, and perform membership inference via likelihood ratio testing. We conduct extensive experiments in a strict black-box setting under both partial-knowledge and zero-knowledge threat models, and evaluate membership inference against both fine-tuning and pre-training data. Experimental results demonstrate our approach's superior performance in comparison to existing state-of-the-art methods, which are typically optimized for a single model class.
With the increasing demand for graph data analysis in complex real-world scenarios, traditional graph classification methods that rely solely on labeled positive/negative samples face significant limitations due to data scarcity. To address this challenge, we propose a novel multi-view positive and unlabeled graph learning framework based on dictionary learning (MVPU-DL). Our approach innovatively utilizes unlabeled graphs as privileged information through three key mechanisms: 1) a multi-view dictionary learning paradigm with cross-view consistency constraints, which uses analytical dictionaries to generate discriminative sparse codes; 2) a novel PU-SVM classifier architecture that integrates view-specific dictionaries to enable robust feature representation from limited positive samples; 3) an alternating convex optimization strategy with provable convergence for jointly learning discriminative dictionaries and classification boundaries. Extensive experiments on 12 benchmark datasets spanning diverse domains- including biological compounds (PTC, MUTAG), chemical interactions (COX2, DHFR), and social networks (Twitter, DBLP)-validate the superior performance of MVPU-DL. The proposed cross-view dictionary alignment strategy is particularly effective under varying labeling ratios, achieving a significant average F1-score improvement of 2.16% (with a maximum improvement of 3.88%) compared to state-of-the-art baselines. These results demonstrate that MVPU-DL outperforms other methods with remarkable performance.
Label distribution learning (LDL) is a paradigm that each sample is associated with a label distribution. At present, the existing approaches are proposed for the single-view LDL problem with labeled data, while the multi-view LDL problem with labeled and unlabeled data has not been considered. In this paper, we put forward the multi-view semi-supervised label distribution learning with local structure complementarity (MVSS-LDL) approach, which exploits the local nearest neighbor structure of each view and emphasizes the complementarity of local nearest neighbor structures in multiple views. Specifically speaking, we first explore the local structure of view v by computing the k-nearest neighbors. As a result, the k-nearest neighbor set of each sample x_i in view v is attained. Nevertheless, this k-nearest neighbor set describes only a part of the nearest neighbor information of sample x_i. In order to obtain a more comprehensive description of sample x_i's nearest neighbors, we complement the nearest neighbor set in view v by incorporating sample x_i's nearest neighbors in other views. Lastly, based on the complemented nearest neighbor set in each view, a graph learning-based multi-view semi-supervised LDL model is constructed. By considering the complementarity of local nearest neighbor structures, different views can mutually provide the local structural information to complement each other. To the best of our knowledge, this is the first attempt at multi-view LDL. Numerical studies have demonstrated that MVSS-LDL attains explicitly better classification performance than the existing single-view LDL methods.
We posit that to achieve continual model improvement and multifaceted alignment, future models must learn from natural human interaction. Current conversational models are aligned using pre-annotated, expert-generated human feedback. In this work, we introduce Reinforcement Learning from Human Interaction (RLHI), a paradigm that learns directly from in-the-wild user conversations. We develop two complementary methods: (1) RLHI with User-Guided Rewrites, which revises unsatisfactory model outputs based on users' natural-language follow-up responses, (2) RLHI with User-Based Rewards, which learns via a reward model conditioned on knowledge of the user's long-term interaction history (termed persona). Together, these methods link long-term user personas to turn-level preferences via persona-conditioned preference optimization. Trained on conversations derived from WildChat, both RLHI variants outperform strong baselines in personalization and instruction-following, and similar feedback enhances performance on reasoning benchmarks. These results suggest organic human interaction offers scalable, effective supervision for personalized alignment.
Partial multi-label learning (PML) is a learning paradigm that each sample is attached with a number of candidate labels, including both true and false labels. Most of the existing PML approaches are designed for single-instance PML, in which a sample is converted into a single feature vector. Nevertheless, in PML, the training sample is usually associated with more than one true label. Instead of converting it into a single feature vector, it is more desirable to treat it as a bag of instances, which allows a more discriminative classification model. This paper introduces the confidence-based multi-instance partial multi-label learning (CMPML) approach, which addresses the instance label ambiguity and bag label ambiguity. To handle the instance label ambiguity, it assigns a positive-instance confidence to each instance and represents a bag as the combination of confidence-weighted instances. To handle the bag label ambiguity, each candidate label has a true-label confidence. The positive-instance confidence and true-label confidence are unknown and will be optimized during the learning process. Numerical studies have illustrated that CMPML outperforms the existing single-instance PML approaches. Numerical studies have illustrated that CMPML attains better classification performance, compared to the existing single-instance PML approaches.
As intelligent watt-hour meters become more widespread in power systems, wiring errors have become more prevalent, significantly affecting the accuracy of energy measurement and the stability of the power system. This study proposes a method to detect incorrect wiring in intelligent watt-hour meters by leveraging feature extraction through convolutional neural networks (CNN) combined with the Light Gradient Boosting Machine (Light GBM) algorithm. Initially, we designed an enhanced CNN model tailored to automatically derive meaningful features from the wiring images of watt-hour meters. The CNN encompasses multiple convolution layers, pooling layers, ReLU (Linear rectification function), and a fully connected layer. During the training phase, the model utilizes backpropagation alongside a cross-entropy loss function to effectively identify and extract critical features from wiring images. Following this, Principal Component Analysis (PCA) is applied to streamline the extracted features of high dimensionality. This process serves a dual purpose: it reduces the computational load and decreases the likelihood of overfitting. Then, a proficient Light GBM classifier is developed using the reduced-dimension features as inputs to assess the wiring status of the watt-hour meter. Experimental outcomes indicate that our approach distinguishes between correct and incorrect wirings, achieving an accuracy rate of 98.5%, a recall rate of 98.0%, and an F1 score of 98.3%. Compared with traditional image processing methods and other deep learning models, this method significantly improves the accuracy and efficiency of identifying the wrong wiring of watt-hour meters. This paper proposes the identification method of miswiring of smart watt-hour meter based on CNN feature extraction and Light GBM classification, which provides an efficient and reliable power system operation and maintenance solution.