Institution profile

InnoPeak Technology

Industry researchasia · cn
Research library2linked papers
Opportunities0open roles
Selected work

Representative Papers

Memory Efficient Full-gradient Attacks (MEFA) Framework for Adversarial Defense Evaluations

May 07, 2026

Existing white-box attacks often resort to approximate gradients when evaluating iterative stochastic purification defenses due to memory constraints, which weakens attack strength and leads to an overestimation of model robustness. This work proposes a memory-efficient full-gradient attack framework that integrates gradient checkpointing with a controllable randomness protocol, enabling—for the first time—exact end-to-end white-box attacks against long-trajectory stochastic defenses such as diffusion- and Langevin-based purification. The method achieves state-of-the-art attack performance under both ℓ∞ and ℓ₂ norms, uncovers vulnerabilities missed by approximate-gradient approaches, and facilitates out-of-distribution robustness analysis, thereby substantially improving the reliability of robustness evaluation.

0 citationsRead paper

Accommodate Knowledge Conflicts in Retrieval-augmented LLMs: Towards Reliable Response Generation in the Wild

Apr 17, 2025

In retrieval-augmented generation (RAG), conflicts between large language models’ (LLMs’) internal knowledge and externally retrieved information induce unreliable responses, yet the underlying uncertainty dynamics remain poorly understood. Method: This paper models such conflicts through an information-theoretic lens, revealing—for the first time—the anomalous drop in LLM confidence under knowledge ambiguity. Building on this insight, we propose Swin-VIB: a cascaded framework grounded in the variational information bottleneck (VIB) that adaptively filters and injects retrieved content while jointly optimizing LLM preference modeling and response generation. Contribution/Results: Evaluated across single-choice QA, open-ended QA, and standard RAG benchmarks, Swin-VIB significantly improves response reliability—achieving ≥7.54% absolute accuracy gain over the strongest baseline in single-choice QA. Our work establishes a novel, conflict-aware paradigm for trustworthy RAG.

0 citationsRead paper
Recent publications

Latest Papers

Memory Efficient Full-gradient Attacks (MEFA) Framework for Adversarial Defense Evaluations

May 07, 2026

Existing white-box attacks often resort to approximate gradients when evaluating iterative stochastic purification defenses due to memory constraints, which weakens attack strength and leads to an overestimation of model robustness. This work proposes a memory-efficient full-gradient attack framework that integrates gradient checkpointing with a controllable randomness protocol, enabling—for the first time—exact end-to-end white-box attacks against long-trajectory stochastic defenses such as diffusion- and Langevin-based purification. The method achieves state-of-the-art attack performance under both ℓ∞ and ℓ₂ norms, uncovers vulnerabilities missed by approximate-gradient approaches, and facilitates out-of-distribution robustness analysis, thereby substantially improving the reliability of robustness evaluation.

0 citationsRead paper

Accommodate Knowledge Conflicts in Retrieval-augmented LLMs: Towards Reliable Response Generation in the Wild

Apr 17, 2025

In retrieval-augmented generation (RAG), conflicts between large language models’ (LLMs’) internal knowledge and externally retrieved information induce unreliable responses, yet the underlying uncertainty dynamics remain poorly understood. Method: This paper models such conflicts through an information-theoretic lens, revealing—for the first time—the anomalous drop in LLM confidence under knowledge ambiguity. Building on this insight, we propose Swin-VIB: a cascaded framework grounded in the variational information bottleneck (VIB) that adaptively filters and injects retrieved content while jointly optimizing LLM preference modeling and response generation. Contribution/Results: Evaluated across single-choice QA, open-ended QA, and standard RAG benchmarks, Swin-VIB significantly improves response reliability—achieving ≥7.54% absolute accuracy gain over the strongest baseline in single-choice QA. Our work establishes a novel, conflict-aware paradigm for trustworthy RAG.

0 citationsRead paper