Institution profile

Chengdu University of Information Technology

Academic institutionasia · cn
Official website
Research library26linked papers
Opportunities0open roles
Selected work

Representative Papers

Actively Obtaining Environmental Feedback for Autonomous Action Evaluation Without Predefined Measurements

Jan 04, 2026arXiv.org

In open and dynamic environments, agents often struggle to evaluate their actions due to the absence of predefined feedback. This work proposes an active feedback acquisition model that autonomously discovers, filters, and validates effective feedback signals by analyzing the environmental changes induced by its actions, without relying on external rewards or pre-specified metrics. The approach incorporates an intrinsic-goal-driven self-triggering mechanism—guided by objectives such as accuracy and efficiency—to enable autonomous action planning. Experimental results demonstrate that the model substantially enhances the efficiency and robustness of feedback identification, allowing agents to rapidly focus on and acquire high-quality feedback without external supervision.

3 citations1 influentialRead paper

Human Simulation Computation: A Human-Inspired Framework for Adaptive AI Systems

Jan 20, 2026

This work addresses the limitations of large language models, which, trained exclusively on static text, struggle to verify reasoning or adapt in open, dynamic environments. To overcome this, the paper proposes a human cognition-inspired closed-loop intelligence framework that unifies thinking, acting, learning, reflection, and task scheduling into a cohesive internal reasoning process. The framework enables an action-driven self-optimization mechanism through prototype-guided reasoning, action-mediated expansion of perceptual boundaries, and immediate learning from environmental feedback. Theoretical analysis demonstrates that this approach effectively compensates for the inherent deficiencies of pure language models in reasoning validation and environmental adaptation, substantially enhancing the robustness and interactive efficiency of AI systems in real-world scenarios.

2 citationsRead paper

Document-Authored Control-Signal Impersonation: A Low-Cost Indirect Prompt Attack on RAG Safety Boundaries

Jun 08, 2026

This work addresses a critical security vulnerability in Retrieval-Augmented Generation (RAG) systems, where shared natural language channels for user queries and retrieved documents can cause models to misinterpret forged metadata in malicious documents as legitimate control signals, thereby compromising system boundaries. The authors propose DACSI, a non-instructive, indirect prompt injection attack that exploits this flaw by mimicking system control signals to blur the distinction between data and policy. They formally define the previously unrecognized “forgeable control signal” problem and introduce a metadata-level attack paradigm, underscoring the necessity of source authenticity and channel separation for RAG security. Through a comprehensive evaluation framework—spanning six large language models, diverse prompt stress conditions, and synthetic canary verification—the study demonstrates DACSI’s effectiveness on models such as DeepSeek V4 Pro and Qwen3.5-397B, revealing significant inter-model differences in boundary robustness.

0 citationsRead paper
Recent publications

Latest Papers

Document-Authored Control-Signal Impersonation: A Low-Cost Indirect Prompt Attack on RAG Safety Boundaries

Jun 08, 2026

This work addresses a critical security vulnerability in Retrieval-Augmented Generation (RAG) systems, where shared natural language channels for user queries and retrieved documents can cause models to misinterpret forged metadata in malicious documents as legitimate control signals, thereby compromising system boundaries. The authors propose DACSI, a non-instructive, indirect prompt injection attack that exploits this flaw by mimicking system control signals to blur the distinction between data and policy. They formally define the previously unrecognized “forgeable control signal” problem and introduce a metadata-level attack paradigm, underscoring the necessity of source authenticity and channel separation for RAG security. Through a comprehensive evaluation framework—spanning six large language models, diverse prompt stress conditions, and synthetic canary verification—the study demonstrates DACSI’s effectiveness on models such as DeepSeek V4 Pro and Qwen3.5-397B, revealing significant inter-model differences in boundary robustness.

0 citationsRead paper

Beyond Predefined Learning Objects: A Thinking-Learning Interaction Model for Up-to-Date Autonomous Robot Learning

May 17, 2026

This study addresses the challenge of long-term adaptation for autonomous robots in open, dynamic environments, where fixed learning frameworks often fail to cope with continuous change. The authors propose a bidirectional cognition–learning co-evolution mechanism: a cognition module guides the learning process by detecting environmental shifts, selecting relevant evidence, organizing training data, and planning validation, while the learning module reciprocally enriches cognition by updating knowledge, strategies, and reasoning capabilities. This framework enables autonomous discovery of input features, incremental expansion of output categories, online model updating, and restructuring of action routines. Experimental results demonstrate substantial improvements—recognition accuracy increases from 0.419 to 0.845, success rates for forming new categories and updating models rise significantly, average action sequence length decreases from 13.0 to 4.0, and effective evidence selection reaches 0.965—collectively achieving genuine open-ended autonomous learning.

0 citationsRead paper

A class of optimal authentication codes with secrecy

May 14, 2026

This work addresses the challenge of constructing efficient authentication codes that simultaneously ensure confidentiality, provide strong authentication guarantees, and effectively resist impersonation and substitution attacks. The authors propose a novel class of linear authentication codes grounded in linear algebraic structures. By leveraging specialized Weil sum analysis techniques, they rigorously derive tight upper bounds on the maximum success probabilities of both substitution and impersonation attacks. Furthermore, they demonstrate that the proposed scheme achieves asymptotically optimal security under a specific theoretical bound. Featuring simple encoding rules and low computational complexity, the scheme offers robust confidentiality alongside strong authentication, thereby balancing rigorous theoretical security with practical deployability.

0 citationsRead paper