An Experimental Evaluation of Multimodal Prompt Injection Attacks on Agentic AI Frameworks
研究通过MMPIBench评估了多模态提示注入攻击在代理AI框架中的影响,使用六种视觉载体和音频作为攻击媒介,发现模型类型对攻击成功率有显著影响。
研究通过MMPIBench评估了多模态提示注入攻击在代理AI框架中的影响,使用六种视觉载体和音频作为攻击媒介,发现模型类型对攻击成功率有显著影响。
This study investigates whether iterative erasure methods can reliably quantify the number of directions in neural representations that encode specific concepts. By leveraging theoretical and experimental tools—including Gaussian population constructions, invertible shear transformations, QR decomposition, Moore–Penrose pseudoinverses, ridge regression, and Adam optimization—the work distinguishes between model-defined quantities (such as generative dimensionality and sufficient linear dimensionality) and process-dependent measures. The findings reveal that the stopping count and cumulative deletion rank obtained via iterative erasure lack invariance under information-preserving invertible reparameterizations, varying significantly with the choice of parameterization. This demonstrates that such metrics reflect properties of the measurement procedure rather than intrinsic characteristics of semantic dimensions, thereby exposing a fundamental limitation of iterative erasure as a measure of conceptual dimensionality.
This study addresses the scarcity of labeled data and privacy constraints in Parkinson’s disease screening by proposing an unsupervised, cross-modal framework that operates without disease labels. The approach leverages frozen pre-trained Vision Transformer (for facial expressions) and HuBERT (for speech) models, guided by synthetic dysarthria-induced contrastive activation directions and alignment principles to enable interpretable anomaly detection. It fuses k-nearest neighbor anomaly scores with Contrastive Activation Addition (CAA) for enhanced performance. Evaluated on the YouTubePD benchmark, the fused model achieves an AUROC of 0.802 and a negative predictive value of 0.95, substantially outperforming unimodal baselines and demonstrating both methodological efficacy and clinical promise.
This study addresses the lack of systematically curated remote sensing datasets, which has hindered the application of machine learning across the full disaster management cycle. Through a comprehensive literature review and meta-analysis, this work presents the first unified collection of publicly available remote sensing datasets spanning multiple phases—pre-disaster, during-disaster, and post-disaster—and encompassing diverse hazard types and imaging platforms, including high-resolution satellites and unmanned aerial vehicles (UAVs). The resulting structured and reusable data resource catalog establishes a standardized benchmark for computer vision–driven disaster response research and provides a foundational infrastructure for efficient model development, thereby filling a critical gap in systematic data integration within the field.
This study addresses performance degradation in modular digital twins caused by error propagation by introducing, for the first time, Markov Decision Processes (MDPs) and Partially Observable Markov Decision Processes (POMDPs) into error control, formulating mitigation strategies as sequential decision-making problems. Leveraging hidden Markov models to infer error states and Bayesian filtering to handle partial observability, the framework employs dynamic programming and reinforcement learning to derive optimal intervention policies. Experimental results demonstrate that the MDP-based policy achieves the highest cumulative reward and system uptime, while the POMDP approach recovers approximately 95% of MDP performance under realistic noise conditions, with statistically significant differences among strategies (p < 0.001). Additionally, this work quantifies the value of information from observations, offering a principled basis for allocating resources to improve classification accuracy.
研究通过MMPIBench评估了多模态提示注入攻击在代理AI框架中的影响,使用六种视觉载体和音频作为攻击媒介,发现模型类型对攻击成功率有显著影响。
This study investigates whether iterative erasure methods can reliably quantify the number of directions in neural representations that encode specific concepts. By leveraging theoretical and experimental tools—including Gaussian population constructions, invertible shear transformations, QR decomposition, Moore–Penrose pseudoinverses, ridge regression, and Adam optimization—the work distinguishes between model-defined quantities (such as generative dimensionality and sufficient linear dimensionality) and process-dependent measures. The findings reveal that the stopping count and cumulative deletion rank obtained via iterative erasure lack invariance under information-preserving invertible reparameterizations, varying significantly with the choice of parameterization. This demonstrates that such metrics reflect properties of the measurement procedure rather than intrinsic characteristics of semantic dimensions, thereby exposing a fundamental limitation of iterative erasure as a measure of conceptual dimensionality.
This study addresses the scarcity of labeled data and privacy constraints in Parkinson’s disease screening by proposing an unsupervised, cross-modal framework that operates without disease labels. The approach leverages frozen pre-trained Vision Transformer (for facial expressions) and HuBERT (for speech) models, guided by synthetic dysarthria-induced contrastive activation directions and alignment principles to enable interpretable anomaly detection. It fuses k-nearest neighbor anomaly scores with Contrastive Activation Addition (CAA) for enhanced performance. Evaluated on the YouTubePD benchmark, the fused model achieves an AUROC of 0.802 and a negative predictive value of 0.95, substantially outperforming unimodal baselines and demonstrating both methodological efficacy and clinical promise.
This study addresses the lack of systematically curated remote sensing datasets, which has hindered the application of machine learning across the full disaster management cycle. Through a comprehensive literature review and meta-analysis, this work presents the first unified collection of publicly available remote sensing datasets spanning multiple phases—pre-disaster, during-disaster, and post-disaster—and encompassing diverse hazard types and imaging platforms, including high-resolution satellites and unmanned aerial vehicles (UAVs). The resulting structured and reusable data resource catalog establishes a standardized benchmark for computer vision–driven disaster response research and provides a foundational infrastructure for efficient model development, thereby filling a critical gap in systematic data integration within the field.
This study addresses performance degradation in modular digital twins caused by error propagation by introducing, for the first time, Markov Decision Processes (MDPs) and Partially Observable Markov Decision Processes (POMDPs) into error control, formulating mitigation strategies as sequential decision-making problems. Leveraging hidden Markov models to infer error states and Bayesian filtering to handle partial observability, the framework employs dynamic programming and reinforcement learning to derive optimal intervention policies. Experimental results demonstrate that the MDP-based policy achieves the highest cumulative reward and system uptime, while the POMDP approach recovers approximately 95% of MDP performance under realistic noise conditions, with statistically significant differences among strategies (p < 0.001). Additionally, this work quantifies the value of information from observations, offering a principled basis for allocating resources to improve classification accuracy.