Machine unlearning (MU) is essential for enforcing the right to be forgotten in machine learning systems. A key challenge of MU is how to reliably audit whether a model has truly forgotten specified training data. Membership Inference Attacks (MIAs) are widely used for unlearned model auditing, where samples that evade membership detection are regarded as successfully forgotten. We show this assumption is fundamentally flawed: failed membership inference does not imply true forgetting. We prove that unlearned samples occupy fundamentally different positions in the feature space than non-member samples, making this alignment bias unavoidable and unobservable, which leads to systematically optimistic evaluations of unlearning performance. Meanwhile, training shadow models for MIA incurs substantial computational overhead. To address both limitations, we propose Statistical Membership Inference (SMI), a training-free auditing framework that reformulates auditing as estimating the non-member mixture proportion in the unlearned feature distribution. Beyond estimating the forgetting rate, SMI also provides bootstrap reference ranges for quantified auditing reliability. Extensive experiments show that SMI consistently outperforms all MIA-based baselines, with no shadow model training required. Overall, SMI establishes a principled and efficient alternative to MIA-based auditing methods, with both theoretical guarantees and strong empirical performance.
To address the limitations of conventional radar systems in complex terrains, this paper focuses on two critical challenges. The first challenge is that traditional Synthetic Aperture Radar (SAR) inherently struggles with persistent monitoring due to discontinuous observation patterns and rigid imaging geometries. The second challenge is that fixed phased-array radars lack dynamic adaptability to irregular terrain surfaces despite their beam steering capability. To overcome these constraints, we propose a distributed phased-array radar system using collaborative Unmanned Aerial Vehicle (UAV) swarms. By deploying Frequency-Modulated Continuous Wave Multiple-Input Multiple-Output (FMCW-MIMO) radar modules on autonomous UAVs, the system constructs a reconfigurable virtual array that enables adaptive 3D aperture synthesis. The core innovation lies in the synergistic integration of motion compensation algorithms and distributed synchronization mechanisms, which resolves the inherent conflict between platform mobility and observation stability in conventional radar architectures. Experimental validation confirms enhanced performance in complex terrains, achieving superior angular resolution and coverage efficiency compared to fixed-phased arrays.
Vehicular networks generate rich spatio-temporal data that could expose drivers to trajectory inference, identity linkage, and long-term tracking. Differential Privacy (DP) and pseudonym swapping are widely used mechanisms for protecting location privacy and identity-location unlinkability, respectively. Existing attempts to combine the two treat them as independent procedures and fail to recognize that both mechanisms rely on noise injection, causing their noises to accumulate and leading to unnecessary privacy-budget consumption, as well as degraded communication reliability and downstream location-based service quality. This paper presents a new perspective for jointly integrating the two mechanisms by formulating the pseudonym-swapping candidate identity pool as a DP-equivalent process. We firstly introduce Trajectory-Indistinguishability (T-I), a unified metric that evaluates indistinguishability across both identity and trajectory dimensions. Building on T-I, we present JTOPS, a Joint Trajectory Obfuscation and Pseudonym-Swapping mechanism that performs both operations under a single DP-based framework. JTOPS obfuscates each vehicle's spatio-temporal trajectory locally and then computes pseudonym-swapping probabilities using these obfuscated trajectories, ensuring that both operations share a unified DP formulation rather than consuming privacy budget separately. JTOPS eliminates unnecessary privacy loss, preserves trajectory fidelity, and sustains privacy even when adversaries compromise the coordinator. We mathematically prove that JTOPS satisfies T-I and remains robust under long-term observation. Experiments on real road-network trajectories show that JTOPS reduces attack success rates by over 80% while maintaining more than 95% trajectory utility, outperforming representative state-of-the-art methods.
Multi-LLM collaborative systems have attracted significant attention as a promising solution for complex tasks, enabling multiple large language models (LLMs) with different domains to work together toward a common goal. Different collaborative structures (e.g., Centralized, Horizontal, and Joint Interaction) and communication methods (e.g., direct, summary, and vote) give the system with enhanced flexibility and reasoning capability. However, these same mechanisms also introduce potential security and privacy risks, such as the generation of incorrect responses and the leakage of sensitive information. Based on the above unique characteristics of collaborative systems, we propose three attack methods (named Decision Poisoning Attack, Indirect Echoleak Attack and Information Collision Attack) that exploit the interactions between LLMs to achieve different objectives like system manipulation and privacy leakage. Extensive experiments demonstrate the effectiveness of the proposed attack on three structures and three communication methods, highlighting the security vulnerabilities and potential risks in Multi-LLM collaborative systems. We further discuss possible defense methods that can mitigate the attack performance. Our work show that (1) the key factor for a successful attack on collaborative systems is ensuring the malicious instruction persists and propagates throughout the inter-LLMs communication. (2) both the system architecture and the communication method can affect attack effectiveness, offering valuable insights for the design of more secure Multi LLM collaborative systems in the future.
In recent years, the widespread adoption of location based services (LBS) across diverse mobile applications has accentuated the urgent need to safeguard users' location privacy. To address this concern, the dummy location selection (DLS) al gorithm, grounded in the k-anonymity criterion, has been exten sively studied as a countermeasure against adversaries leveraging query probability information. However, its efficacy diminishes when confronted with the hybrid Retrospect attack introduced in this work. This novel attack method strategically exploits the spatial continuity between adjacent locations, augmented by temporal insights derived from continuous queries spanning an entire movement trajectory. To mitigate this threat, we propose an anti-propagating spatial attack algorithm for individual queries, followed by an anti-Retrospect algorithm designed to intelligently select plausible dummy locations that adhere to stringent privacy requirements. The effectiveness of both our proposed attack and defense mechanisms is rigorously validated through evaluations on two real-world datasets, benchmarked against state-of-the-art methodologies.
Poisoning-based backdoor attacks pose significant threats to deep neural networks by embedding triggers in training data, causing models to misclassify triggered inputs as adversary-specified labels while maintaining performance on clean data. Existing poison restraint-based defenses often suffer from inadequate detection against specific attack variants and compromise model utility through unlearning methods that lead to accuracy degradation. This paper conducts a comprehensive analysis of backdoor attack dynamics during model training, revealing that poisoned samples form isolated clusters in latent space early on, with triggers acting as dominant features distinct from benign ones. Leveraging these insights, we propose Cluster Segregation Concealment (CSC), a novel poison suppression defense. CSC first trains a deep neural network via standard supervised learning while segregating poisoned samples through feature extraction from early epochs, DBSCAN clustering, and identification of anomalous clusters based on class diversity and density metrics. In the concealment stage, identified poisoned samples are relabeled to a virtual class, and the model's classifier is fine-tuned using cross-entropy loss to replace the backdoor association with a benign virtual linkage, preserving overall accuracy. CSC was evaluated on four benchmark datasets against twelve poisoning-based attacks, CSC outperforms nine state-of-the-art defenses by reducing average attack success rates to near zero with minimal clean accuracy loss. Contributions include robust backdoor patterns identification, an effective concealment mechanism, and superior empirical validation, advancing trustworthy artificial intelligence.
Network tomography aims to infer hidden network states, such as link performance, traffic load, and topology, from external observations. Most existing methods solve these problems separately and depend on limited task-specific signals, which limits generalization and interpretability. We present PLATONT, a unified framework that models different network indicators (e.g., delay, loss, bandwidth) as projections of a shared latent network state. Guided by the Platonic Representation Hypothesis, PLATONT learns this latent state through multimodal alignment and contrastive learning. By training multiple tomography tasks within a shared latent space, it builds compact and structured representations that improve cross-task generalization. Experiments on synthetic and real-world datasets show that PLATONT consistently outperforms existing methods in link estimation, topology inference, and traffic prediction, achieving higher accuracy and stronger robustness under varying network conditions.
Community GPU(Graphics Processing Unit) platforms are emerging as a cost-effective and democratized alternative to centralized GPU clusters for AI(Artificial Intelligence) workloads, aggregating idle consumer GPUs from globally distributed and heterogeneous environments. However, their extreme hardware/software diversity, volatile availability, and variable network conditions render traditional schedulers ineffective, leading to suboptimal task completion. In this work, we present REACH (Reinforcement Learning for Efficient Allocation in Community and Heterogeneous Networks), a Transformer-based reinforcement learning framework that redefines task scheduling as a sequence scoring problem to balance performance, reliability, cost, and network efficiency. By modeling both global GPU states and task requirements, REACH learns to adaptively co-locate computation with data, prioritize critical jobs, and mitigate the impact of unreliable resources. Extensive simulation results show that REACH improves task completion rates by up to 17%, more than doubles the success rate for high-priority tasks, and reduces bandwidth penalties by over 80% compared to state-of-the-art baselines. Stress tests further demonstrate its robustness to GPU churn and network congestion, while scalability experiments confirm its effectiveness in large-scale, high-contention scenarios.
Large Language Model (LLM) watermarking embeds detectable signals into generated text for copyright protection, misuse prevention, and content detection. While prior studies evaluate robustness using watermark removal attacks, these methods are often suboptimal, creating the misconception that effective removal requires large perturbations or powerful adversaries. To bridge the gap, we first formalize the system model for LLM watermark, and characterize two realistic threat models constrained on limited access to the watermark detector. We then analyze how different types of perturbation vary in their attack range, i.e., the number of tokens they can affect with a single edit. We observe that character-level perturbations (e.g., typos, swaps, deletions, homoglyphs) can influence multiple tokens simultaneously by disrupting the tokenization process. We demonstrate that character-level perturbations are significantly more effective for watermark removal under the most restrictive threat model. We further propose guided removal attacks based on the Genetic Algorithm (GA) that uses a reference detector for optimization. Under a practical threat model with limited black-box queries to the watermark detector, our method demonstrates strong removal performance. Experiments confirm the superiority of character-level perturbations and the effectiveness of the GA in removing watermarks under realistic constraints. Additionally, we argue there is an adversarial dilemma when considering potential defenses: any fixed defense can be bypassed by a suitable perturbation strategy. Motivated by this principle, we propose an adaptive compound character-level attack. Experimental results show that this approach can effectively defeat the defenses. Our findings highlight significant vulnerabilities in existing LLM watermark schemes and underline the urgency for the development of new robust mechanisms.
Extremely large antenna array (ELAA) is key to enhancing spectral efficiency in 6G networks. Leveraging the distributed nature of multi-unmanned aerial vehicle (UAV) systems enables the formation of distributed ELAA, which often operate in the near-field region with spatial sparsity, rendering the conventional far-field plane wave assumption invalid. This paper investigates channel estimation for distributed near-field multi-UAV communication systems. We first derive closed-form signal-to-noise ratio (SNR) expressions under the plane wave model (PWM), spherical wave model (SWM), and a hybrid spherical-plane wave model (HSPWM), within a distributed uniform planar array (UPA) scenario. The analysis shows that HSPWM achieves a good balance between modeling accuracy and analytical tractability. Based on this, we propose two channel estimation algorithms: the spherical-domain orthogonal matching pursuit (SD-OMP) and the tensor-OMP. The SD-OMP generalizes the polar domain to jointly consider elevation, azimuth, and range. Under the HSPWM, the channel is naturally formulated as a tensor, enabling the use of tensor-OMP. Simulation results demonstrate that tensor-OMP achieves normalized mean square error (NMSE) performance comparable to SD-OMP, while offering reduced computational complexity and improved scalability.
Semantic segmentation models are widely deployed in safety-critical applications such as autonomous driving, yet their vulnerability to backdoor attacks remains largely underexplored. Prior segmentation backdoor studies transfer threat settings from existing image classification tasks, focusing primarily on object-to-background mis-segmentation. In this work, we revisit the threats by systematically examining backdoor attacks tailored to semantic segmentation. We identify four coarse-grained attack vectors (Object-to-Object, Object-to-Background, Background-to-Object, and Background-to-Background attacks), as well as two fine-grained vectors (Instance-Level and Conditional attacks). To formalize these attacks, we introduce BADSEG, a unified framework that optimizes trigger designs and applies label manipulation strategies to maximize attack performance while preserving victim model utility. Extensive experiments across diverse segmentation architectures on benchmark datasets demonstrate that BADSEG achieves high attack effectiveness with minimal impact on clean samples. We further evaluate six representative defenses and find that they fail to reliably mitigate our attacks, revealing critical gaps in current defenses. Finally, we demonstrate that these vulnerabilities persist in recent emerging architectures, including transformer-based networks and the Segment Anything Model (SAM), thereby compromising their security. Our work reveals previously overlooked security vulnerabilities in semantic segmentation, and motivates the development of defenses tailored to segmentation-specific threat models.
Industrial time series often display complex, non-stationary behaviors with trends, periodicity, and abrupt fluctuations. Generating high-quality synthetic data in such domains is essential for simulation, forecasting, and anomaly detection in Industrial Internet of Things (IIoT) applications. However, distributional heterogeneity, sparse failure patterns, and long-term dependencies make this task highly challenging. We introduce HNRF-TS, a rectified flow framework with hybrid noise initialization, designed for scalable and robust time series generation. The hybrid prior combines isotropic Gaussian noise with structured codes from a lightweight generative adversarial network (GAN), yielding semantically aligned and diverse latent representations. To improve sampling efficiency, we propose a bimodal adaptive strategy that allocates denser ordinary differential equation (ODE) steps at the beginning and end of the trajectory while using coarser steps in smoother middle regions. This preserves critical temporal features while lowering computational cost. We further enhance fidelity with modules dedicated to modeling trends and seasonality, which capture global drifts and periodic signals inherent in industrial data. Across multiple IIoT datasets, HNRF-TS outperforms state-of-the-art baselines, including GAN-based and diffusion-based methods. It achieves up to 75.8% reduction in Context-FID and over 60% improvement in correlation metrics on long-horizon tasks. Moreover, high-quality samples can be generated with as few as 20 sampling steps, offering significant efficiency gains without sacrificing accuracy.
Deepfake technology, leveraging advanced artificial intelligence (AI) algorithms, has emerged as a powerful tool for generating hyper-realistic synthetic human faces, presenting both innovative opportunities and significant challenges. Meanwhile, the development of Deepfake detectors represents another branch of models striving to recognize AI-generated fake faces and protect people from the misinformation of Deepfake. This ongoing cat-and-mouse game between generation and detection has spurred a dynamic evolution in the landscape of Deepfake. This survey comprehensively studies recent advancements in Deepfake generation and detection techniques, focusing particularly on the utilization of generative adversarial networks (GANs) and diffusion models (DMs). For both GAN-based and DM-based Deepfake generators, we categorize them based on whether they synthesize new content or manipulate existing content. Correspondingly, we examine various strategies employed to identify synthetic and manipulated Deepfake, respectively. Finally, we summarize our findings by discussing the unique capabilities and limitations of GANs and DM in the context of Deepfake. We also identify promising future directions for research, including the development of hybrid approaches that leverage the strengths of both GANs and DM, the exploration of novel detection strategies utilizing advanced AI techniques, and the ethical considerations surrounding the development of Deepfake. This survey paper serves as a valuable resource for researchers, practitioners, and policymakers seeking to understand the state-of-the-art in Deepfake technology, its implications, and potential avenues for future research and development.
As an increasing number of data-driven deep learning models are deployed in our daily lives, the issue of algorithmic fairness has become a major concern. These models are trained on data that inevitably contains various biases, leading them to learn unfair representations that differ across demographic subgroups, resulting in unfair predictions. Previous work on fairness has attempted to remove subgroup information from learned features, aiming to contribute to similar representations across subgroups and lead to fairer predictions. However, identifying and removing this information is extremely challenging due to the "black box" nature of neural networks. Moreover, removing desired features without affecting other features is difficult, as features are often correlated, potentially harming model prediction performance. This paper aims to learn fair representations without degrading model prediction performance. We adopt knowledge distillation, allowing unfair models to learn fair representations directly from a fair teacher. The proposed method provides a novel approach to obtaining fair representations while maintaining valid prediction performance. We evaluate the proposed method, FairDistill, on four datasets (CIFAR-10, UTKFace, CelebA, and Adult) under diverse settings. Extensive experiments demonstrate the effectiveness and robustness of the proposed method.
The rapid advancement of Artificial Intelligence (AI) has transformed various industries, leading to the widespread distribution of AI models and data across intelligent systems. As modern data driven services increasingly integrate distributed knowledge entities, decentralized learning has become a prevalent approach to training AI models. However, this collaborative learning paradigm introduces significant security vulnerabilities and privacy challenges. This paper presents a comprehensive systematic review on private knowledge sharing in distributed learning, analyzing key knowledge components utilized in leading distributed learning architectures. We identify critical vulnerabilities associated with these components and examine defensive strategies to safeguard privacy while mitigating potential adversarial threats. Additionally, we highlight key limitations in knowledge sharing in distributed learning and propose future research directions to enhance security and efficiency in decentralized AI systems.
Generative models, including both text-to-text and text-to-image modalities, have underscored the significance of 'prompt engineering', a technique critical for enhancing the quality of model outputs. Crafting high-quality prompts is not only time-intensive but also economically valuable, making them prime targets for manipulation. Recent research has revealed that these prompts can be stolen through a technique known as prompt inversion, which reconstructs prompts merely by analyzing the outputs of models. However, existing studies are typically confined to either text-to-text or text-to-image models and are not cross-applicable, thus limiting their real-world utility. This gap raises a crucial question: Is there a unified approach capable of addressing both model types? In this paper, we present the first comprehensive study on a unified prompt inversion approach that targets both text and image models. Our approach involves two model-agnostic phases: (1) training an inversion model to generate initial prompt approximations from model outputs, and (2) using reinforcement learning to fine-tune the inversion model for enhanced accuracy. We further extend our investigation to the text-to-video modality to demonstrate the broad generalizability of our approach. Experimental results highlight our approach's superior performance in comparison to existing state-of-the-art methods, which are typically optimized for a single model type. The source code is available at: https://zenodo.org/records/15603408.
While existing fairness interventions show promise in mitigating biased predictions, most studies concentrate on single-attribute protections. Although a few methods consider multiple attributes, they either require additional constraints or prediction heads, incurring high computational overhead or jeopardizing the stability of the training process. More critically, they consider per-attribute protection approaches, raising concerns about fairness gerrymandering where certain attribute combinations remain unfair. This work aims to construct a neutral domain containing fused information across all subgroups and attributes. It delivers fair predictions as the fused input contains neutralized information for all considered attributes. Specifically, we adopt mixup operations to generate samples with fused information. However, our experiments reveal that directly adopting the operations leads to degraded prediction results. The excessive mixup operations result in unrecognizable training data. To this end, we design three distinct mixup schemes that balance information fusion across attributes while retaining distinct visual features critical for training valid models. Extensive experiments with multiple datasets and up to eight sensitive attributes demonstrate that the proposed MultiFair method can deliver fairness protections for multiple attributes while maintaining valid prediction results.
In contrast to terrestrial networks, the rapid movement of low-earth-orbit (LEO) satellites causes frequent changes in the topology of intersatellite links (ISLs), resulting in dynamic shifts in transmission paths and fluctuations in multi-hop latency. Moreover, limited onboard resources such as buffer capacity and bandwidth competition contribute to the instability of these links. As a result, providing reliable quality of service (QoS) for time-sensitive flows (TSFs) in LEO satellite networks becomes a challenging task. Traditional terrestrial time-sensitive networking methods, which depend on fixed paths and static priority scheduling, are ill-equipped to handle the dynamic nature and resource constraints typical of satellite environments. This often leads to congestion, packet loss, and excessive latency, especially for high-priority TSFs. This study addresses the primary challenges faced by time-sensitive satellite networks and introduces a management framework based on software-defined networking (SDN) tailored for LEO satellites. An advanced queue management and scheduling system, influenced by terrestrial time-sensitive networking approaches, is developed. By incorporating differentiated forwarding strategies and priority-based classification, the proposed method improves the efficiency of transmitting time-sensitive traffic at multiple levels. To assess the scheme’s performance, simulations under various workloads are conducted, and the results reveal that it significantly boosts network throughput, reduces packet loss, and maintains low latency, thus optimizing the performance of time-sensitive traffic in LEO satellite networks.
This paper introduces a novel method for generating differentially private synthetic datasets that harnesses Bayesian networks to ensure the preservation of essential statistical properties and referential integrity across linked tables. To address the dual challenges of maintaining privacy and minimizing computational overhead, we introduce a decomposition scheme for additive Laplacian noise that significantly reduces computational costs while enhancing the efficiency of the differential privacy framework. Our methodology offers a robust solution for creating synthetic datasets that not only mimic the statistical characteristics of original datasets, but also safeguard sensitive information against inference attacks. Through comprehensive evaluations, we demonstrate the practicality and effectiveness of our approach, which achieves a significant speedup in noise injection, thereby facilitating real-time data analysis. This breakthrough contributes to the broader accessibility of complex data analysis, particularly benefiting sectors dealing with sensitive information by improving data privacy and security measures. Our findings represent a significant advancement in statistical methodologies and software, underscoring the ongoing necessity for innovation in data processing techniques.