每日简报

2026-06-11

← 历史归档

addyosmani/agent-skills

Shell · ★ 51,799 · 🍴 5,706 · 📈 821 stars today

Production-grade engineering skills for AI coding agents.

中文介绍 为 AI 编码代理提供生产级工程技能,解决代理在复杂编码任务中的可靠性和效率问题。基于 AI 代理框架和预定义技能集,帮助开发者快速构建稳健的自动化编码工具。适用于 AI 开发团队和程序员,用于提升代码生成、调试等开发流程。

phuryn/pm-skills

★ 14,864 · 🍴 1,620 · 📈 804 stars today

PM Skills Marketplace: 100+ agentic skills, commands, and plugins — from discovery to strategy, execution, launch, and growth.

中文介绍 一个产品经理技能市场,提供超过 100 种代理技能、命令和插件,覆盖从产品发现到策略、执行、发布和增长的全流程。帮助产品经理利用 AI 代理优化决策和工作效率,适用于产品团队在项目管理、用户研究和迭代中应用。

refactoringhq/tolaria

TypeScript · ★ 14,913 · 🍴 1,030 · 📈 612 stars today

Desktop app to manage markdown knowledge bases

中文介绍 桌面应用用于管理 markdown 格式的知识库,解决个人或团队知识组织和检索的挑战。采用桌面应用技术,可能基于 Electron,支持快速搜索和编辑。适用于知识工作者、开发者和研究者,用于文档管理、笔记整理和知识共享场景。

mvanhorn/last30days-skill

Python · ★ 39,075 · 🍴 3,156 · 📈 2,535 stars today

AI agent skill that researches any topic across Reddit, X, YouTube, HN, Polymarket, and the web - then synthesizes a grounded summary

中文介绍 AI 代理技能可跨 Reddit、X、YouTube、HN、Polymarket 和网络研究任何主题,自动生成基于事实的摘要。利用 AI 代理和网页爬取技术,整合多源信息。适用于研究人员、内容创作者和营销人员,用于快速调研、趋势分析和内容创作。

soxoj/maigret

Python · ★ 32,020 · 🍴 2,341 · 📈 318 stars today

🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

中文介绍 通过用户名从超过 3000 个网站收集个人资料,用于开源情报(OSINT)调查。基于网页爬取和数据聚合技术,自动化信息搜集过程。适用于安全研究人员、侦探和法医分析师,用于背景调查、身份验证和网络威胁分析场景。

x1xhlol/system-prompts-and-models-of-ai-tools

★ 139,513 · 🍴 34,591 · 📈 393 stars today

FULL Augment Code, Claude Code, Cluely, CodeBuddy, Comet, Cursor, Devin AI, Junie, Kiro, Leap.new, Lovable, Manus, NotionAI, Orchids.app, Perplexity, Poke, Qoder, Replit, Same.dev, Trae, Traycer AI, VSCode Agent, Warp.dev, Windsurf, Xcode, Z.ai Code, Dia & v0. (And other Open Sourced) System Prompts

中文介绍 收集各种 AI 工具如 Augment Code、Claude Code、Cursor 等的系统提示和模型信息,帮助开发者了解和复现这些工具的工作原理。基于 AI 模型和系统提示的文档化,适用于 AI 研究者、开发者和教育者,用于学习、优化和构建类似 AI 系统。

obra/superpowers

Shell · ★ 223,596 · 🍴 19,878 · 📈 1,104 stars today

An agentic skills framework & software development methodology that works.

中文介绍 一个有效的代理技能框架和软件开发方法论,旨在提升 AI 代理开发的效率和可靠性。提供结构化框架和实践指南,解决代理系统设计中的常见问题。适用于软件开发者和 AI 代理团队,用于项目规划、技能集成和质量保证场景。

masterking32/MasterDnsVPN

Go · ★ 5,210 · 🍴 502 · 📈 354 stars today

Advanced DNS tunneling VPN for censorship bypass, optimized beyond DNSTT and SlipStream with low-overhead ARQ, resolver load balancing, high packet-loss stability and speed.

中文介绍 高级 DNS 隧道 VPN 用于绕过网络审查,优化了 DNSTT 和 SlipStream,具有低开销 ARQ、解析器负载均衡、高丢包稳定性和速度。基于 DNS 隧道和网络优化技术,适用于需要访问受限内容的用户,如记者、活动家,用于网络自由和隐私保护场景。

harry0703/MoneyPrinterTurbo

Python · ★ 85,036 · 🍴 12,141 · 📈 1,389 stars today

利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.

中文介绍 利用 AI 大模型一键生成高清短视频,简化视频制作流程,降低创作门槛。基于 AI 生成技术和视频处理工具,支持快速内容产出。适用于内容创作者、营销人员和社交媒体运营者,用于广告制作、短视频平台内容发布和数字营销场景。

maziyarpanahi/openmed

Python · ★ 2,287 · 🍴 244 · 📈 527 stars today

open-source healthcare ai

中文介绍 开源医疗 AI 项目,提供医疗领域的 AI 解决方案,旨在改善诊断、治疗和研究效率。结合 AI 技术和医疗数据,支持模型开发和应用部署。适用于医疗专业人士、研究人员和开发者,用于医学影像分析、患者监测和医疗研究场景。

luongnv89/claude-howto

Python · ★ 36,536 · 🍴 4,413 · 📈 211 stars today

A visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.

中文介绍 一个视觉化、示例驱动的 Claude Code 指南,从基础概念到高级代理,提供可复制的模板,带来即时学习价值。基于教程和示例方法,帮助用户快速上手 Claude 代码应用。适用于 Claude 用户、AI 开发者和学生,用于学习、实践和构建 AI 代理场景。

activeloopai/hivemind

TypeScript · ★ 837 · 🍴 49 · 📈 64 stars today

One brain for all your agents

中文介绍 为所有 AI 代理提供一个统一的“大脑”,实现协同工作和智能管理,解决多代理系统中的协调问题。基于代理协调和集中控制技术,提升系统效率和一致性。适用于 AI 开发者、企业团队和自动化系统设计师,用于管理复杂 AI 代理网络和优化任务分配。

ruvnet/RuView

Rust · ★ 72,899 · 🍴 9,726 · 📈 420 stars today

π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video.

中文介绍 将普通 WiFi 信号转化为实时空间智能、生命体征监测和存在检测,无需视频图像,提供隐私友好的监控方案。基于 WiFi 信号处理和物联网技术,实现环境感知。适用于健康监测、智能家居和安全监控,用于老人看护、入侵检测和室内定位场景。

roboflow/supervision

Python · ★ 43,573 · 🍴 3,871 · 📈 695 stars today

We write your reusable computer vision tools. 💜

中文介绍 提供可重用的计算机视觉工具,简化视觉应用开发,减少重复编码工作。基于开源计算机视觉库和框架,支持图像和视频分析任务。适用于计算机视觉开发者、研究人员和工程师,用于目标检测、图像分割和视频处理等应用场景。

google/skills

Python · ★ 13,293 · 🍴 1,007 · 📈 211 stars today

Agent Skills for Google products and technologies

中文介绍 为 Google 产品和技术提供代理技能,帮助开发者轻松集成和扩展 Google 服务到 AI 代理中。基于 AI 代理框架和 Google API,优化交互和功能。适用于 Google 生态开发者、AI 工程师和产品团队,用于构建智能助手、自动化工作流和增强应用功能。

FareedKhan-dev/train-llm-from-scratch

Python · ★ 5,257 · 🍴 710 · 📈 247 stars today

A straightforward method for training your LLM, from downloading data to generating text.

中文介绍 提供一个从零开始训练大语言模型(LLM)的直接方法,覆盖从数据下载到文本生成的全过程。基于机器学习和 LLM 训练技术,适合入门和实践。适用于 AI 研究者、开发者和学生,用于学习 LLM 原理、自定义模型训练和实验性项目开发。

apple/container

Swift · ★ 29,821 · 🍴 829 · 📈 1,611 stars today

A tool for creating and running Linux containers using lightweight virtual machines on a Mac. It is written in Swift, and optimized for Apple silicon.

中文介绍 在 Mac 上使用轻量级虚拟机创建和运行 Linux 容器的工具,用 Swift 编写,针对 Apple silicon 优化,解决开发环境隔离问题。基于虚拟化和容器技术,提升性能和兼容性。适用于 Mac 开发者、系统管理员和 DevOps 工程师,用于本地开发、测试和部署 Linux 应用场景。

Loops: What Every AI Engineer Needs to Know in 2026

@sairahul1 · 113.0K 粉丝 · 852.6K 阅 · 600 赞 · 79 转

Peter Steinberger, creator of OpenClaw, who now works with OpenAI. Yesterday he posted this: "You shouldn't be prompting coding agents anymore. You should be designing loops that prompt your agents."

中文介绍 Peter Steinberger提出,AI工程师应停止手动提示编码代理,转而设计自动循环来驱动代理,这标志着从手动提示向系统设计的转变,是AI工程领域的新趋势。

The Untrainable

@saranormous · 143.5K 粉丝 · 194.8K 阅 · 614 赞 · 40 转

The mid-2026 investor's version of AI psychosis is a despair that nothing is investable, that we should put all our money into Anthropic and Nvidia and go home. I have never felt it. I have been sure

中文介绍 有投资者认为AI领域无处可投资,建议集中投资Anthropic和Nvidia,但博主对此持怀疑态度,分享了自己的投资观点,讨论AI行业现状。

My Week with Fable

@MatthewBerman · 121.3K 粉丝 · 108.0K 阅 · 661 赞 · 26 转

tl;dr I've been testing Fable (Mythos) for the past week and it feels unlike any other model I've used. It feels, and is priced, like a next-generation model. It also has some real quirks. The Good

中文介绍 博主测试Fable(Mythos)模型一周,发现它与其他模型不同,定价像下一代模型,但也有一些怪癖,分享使用体验以帮助了解该模型的优缺点。

Kimi to Predict All 104 World Cup Matches: Germany May Be Underestimated

@Kimi_Moonshot · 172.7K 粉丝 · 106.6K 阅 · 500 赞 · 61 转

Our predictions will probably be wrong. But the World Cup offers a rare, public, verifiable, and constantly evolving real-world setting. Through this initiative, we hope to place analysis,

中文介绍 Kimi宣布预测所有104场世界杯比赛,虽然预测可能不准,但世界杯提供了一个公开可验证的实时环境,用于AI分析和改进,可能低估德国队。

Loop engineering: the 14-step roadmap from prompter to loop designer.

@0xCodez · 5.3K 粉丝 · 97.8K 阅 · 510 赞 · 80 转

Most developers still prompt their coding agents by hand. They type, they wait, they read the diff, they type again. 9out of 10 builders have never written a single loop that prompts the agent for

中文介绍 大多数开发者仍手动提示编码代理,9/10的构建者从未编写过循环。博主提供14步路线图,指导如何从手动提示转向循环工程设计,实现自动化。

Designing loops with Fable 5

@RLanceMartin · 30.4K 粉丝 · 84.7K 阅 · 660 赞 · 50 转

Mythos-class models like Claude Fable 5 have changed the way many of us work at Anthropic. I want to share two tips for getting the most out of this class of models. Self-correction loops There’s been

中文介绍 Anthropic员工分享使用Claude Fable 5等Mythos-class模型的经验,提出两个技巧,如自纠正循环,以最大化模型效果,是内部最佳实践。

How to Build an AI GTM Brain using Claude Code

@nifinet · 10.2K 粉丝 · 60.9K 阅 · 522 赞 · 54 转

When a team says they want AI for growth, they usually mean a faster send. An agent that fires the same template at a longer list, day and night. That is the cheap half of the job, and it stopped

中文介绍 团队通常将AI用于增长简单理解为自动化发送,但博主分享使用Claude Code构建AI GTM大脑,以更智能的方式优化市场进入策略,超越简单自动化。

WTF Is a Loop? Peter Steinberger vs. Boris Cherny

@mvanhorn · 30.8K 粉丝 · 45.6K 阅 · 567 赞 · 47 转

The most repeated sentence in AI coding this week is six words long, and almost nobody saying it can define it. One tweet had the entire timeline in a chokehold this week, so I ran /last30days on the

中文介绍 AI编码圈本周热议“循环”概念,但定义模糊。博主分析相关推文,澄清循环的含义,并对比Peter Steinberger和Boris Cherny的观点,是话题澄清。

Implications of Large-Scale Test-Time Compute

@polynoamial · 129.2K 粉丝 · 43.7K 阅 · 707 赞 · 80 转

tl;dr: As LLMs become more capable, benchmark performance is increasingly a function of test-time compute. In fact, we likely don't know what the capability ceiling is for modern LLMs because it's too

中文介绍 随着LLM能力提升,基准测试性能越来越多地取决于测试时计算。现代LLM的能力上限可能未知,因为评估成本高,强调测试时计算的重要性。

Loop Engineering.

@addyosmani · 395.5K 粉丝 · 42.7K 阅 · 577 赞 · 62 转

Loop engineering is replacing yourself as the person who prompts the agent. You design the system that does it instead. A loop here can be thought of a recursive goal where you define a purpose and

中文介绍 循环工程意味着用系统设计代替手动提示代理,将循环定义为递归目标,旨在自动化提示过程,是AI工程中的新概念和方法。

Your Agent Harness Should Repair Itself

@akshay_pachaar · 276.5K 粉丝 · 38.0K 阅 · 504 赞 · 65 转

When an AI agent fails in production, your observability tool shows you exactly what it did and almost nothing about how to fix it. You get a clean trace of the run, every model call and tool that

中文介绍 当AI代理在生产中失败时,可观测性工具只显示执行过程,缺乏修复指导。博主建议代理框架应具备自我修复能力,以提高运维效率。

Fluid, natural voice translation with Gemini 3.5 Live Translate

@GoogleAIStudio · 176.3K 粉丝 · 32.2K 阅 · 517 赞 · 55 转

Twenty years ago, translation at Google began as one of our pioneering machine learning experiments to turn the science of language into the magic of human connection. That experiment has come a long

中文介绍 Google推出Gemini 3.5 Live Translate,提供流畅自然的语音翻译,回顾从早期机器学习实验到现代连接人语言的历程,是产品发布。

The Fourth Era of Compute

@unicity_labs · 126.3K 粉丝 · 7.0K 阅 · 821 赞 · 405 转

For thirty years the internet has been built for one kind of actor. The next one is not a person. For thirty years, compute has been built for humans. It is shaped around human attention, human

中文介绍 互联网和计算过去30年为人类构建,未来将转向为非人类智能体构建,标志着计算的第四时代,是技术范式的变迁展望。

The AI layer Hyperliquid was missing.

@HYPERPEPS · 3.4K 粉丝 · 4.4K 阅 · 720 赞 · 79 转

You spend twenty minutes writing a brief. Then you open a second tab to turn it into code. A third for design. A fourth for the copy. Then you copy the output from tab four back into tab one, because

中文介绍 描述在Hyperliquid上工作的繁琐:写简报、转代码、设计、复制输出等多标签页切换,指出缺少AI层来简化流程,是对工作流优化的建议。

How an astrophysicist uses Codex to help simulate black holes

Discover how astrophysicist Chi-kwan Chan uses Codex to build black hole simulations, helping scientists study extreme physics and test Einstein’s theory of general relativity.

中文介绍 天体物理学家Chi-kwan Chan利用Codex构建黑洞模拟,帮助科学家研究极端物理环境并测试爱因斯坦的广义相对论理论。

Access OpenAI models and Codex through your Oracle cloud commitment

Access OpenAI models and Codex through Oracle Cloud, using existing commitments to build and deploy AI with enterprise security and governance.

中文介绍 通过Oracle Cloud,用户可利用现有承诺访问OpenAI模型和Codex,在企业安全与治理框架下构建和部署AI应用。

PRC-linked influence operations are targeting AI debates in the US

A new report from OpenAI details PRC-linked influence operations using AI to target U.S. tech debates, data center narratives, tariffs, and false claims about ChatGPT.

中文介绍 OpenAI报告指出,与PRC相关的影响行动正使用AI技术,针对美国技术辩论、数据中心叙事、关税政策及ChatGPT虚假信息进行操作。

From data to decisions: how LSEG is scaling trusted AI

See how LSEG uses OpenAI to scale trusted AI across its global business, accelerating insights, shrinking release cycles, and empowering 4,000 employees.

中文介绍 伦敦证券交易所集团(LSEG)利用OpenAI技术扩展可信AI应用,加速业务洞察、缩短发布周期,并赋能其全球4000名员工。

Fluid, natural voice translation with Gemini 3.5 Live Translate

Gemini 3.5 Live Translate brings near real-time, natural speech translation to Google AI Studio, Google Translate and Google Meet.

中文介绍 谷歌DeepMind的Gemini 3.5 Live Translate功能为Google AI Studio、翻译工具和Meet提供近乎实时、自然的语音翻译服务。

How engineers at Nextdoor use Codex to build without limits

How engineers at Nextdoor use Codex with GPT-5.5 to investigate hard-to-reproduce issues, build across platforms, and focus on product outcomes.

中文介绍 社交平台Nextdoor的工程师使用Codex与GPT-5.5调查难以复现的问题、实现跨平台构建,并专注于产品成果。

Learning to lead in a hybrid human-AI enterprise

As adoption of AI agents looks set to surge by as much as 300% in the next two years, leadership teams are carefully considering the implications of a hybrid human-AI workforce. Unlike existing enterprise-level automation that relies on manual input, AI agents are capable of autonomously coordinatin

中文介绍 随着AI代理采用率预计在未来两年内增长300%,企业领导团队正评估混合人机劳动力的影响。与手动输入的自动化不同,AI代理能自动执行任务。

Anchors that Don't Lift: Understanding Supply Chain Driven Kernel Lock-In and Governance-Mediated Mitigation Strategies in SOHO Devices

第一作者: Ritwik Badola · 方向: 系统安全

Abstract:Small Office/Home Office (SOHO) devices are widely popular, yet often attacked due to security vulnerabilities in their firmware, affecting thousands of devices. These security vulnerabilities often stem from outdated Linux kernel versions included in SOHO device firmware. Naturally, prior work audited the extent and impact of this issue by simple Linux version extraction and version number based vulnerability mapping. However, it is unclear how many of these anticipated vulnerabilities actually exist in the heavily customized SOHO kernels and if there are any barriers towards updating Linux kernels in SOHO firmwares. To address this gap, we uncover actual kernel-related vulnerabilities found in 306 SOHO devices using a high-precision template-based CVE detection mechanism on GPL source releases of more than 900 firmwares from these devices. Next, as a first, we traced the...

论文介绍 本文研究了小型办公/家庭办公(SOHO)设备中因供应链导致的Linux内核版本过时所引发的安全漏洞问题。作者采用高精度模板基于CVE检测机制,分析了超过900个固件的GPL源代码,揭示了实际存在的内核相关漏洞,并追踪了供应链驱动的内核锁定现象。研究还探讨了治理介导的缓解策略,以改进SOHO设备的安全状况。

OpenPCC: Open and Confidential LLM Serving on Commodity TEEs

第一作者: Haoling Zhou · 方向: AI 安全

Abstract:Generative AI applications such as personal AI agents, image generators, and chat assistants offer advanced capabilities to improve user experience. Behind the scenes, Large Language Models (LLMs) that power these services require a massive amount of computation and are usually deployed in the cloud, available as APIs, meaning that a user's request has to be sent to a Cloud Inference Service (CIS) for processing. However, the strong capabilities of LLM also mean that user's requests now contain much more personal sensitive or enterprise confidential information, demanding equally strong protection in CIS. While early industry efforts such as Apple Private Cloud Compute (PCC) and Google Private AI Compute have emerged to show the potential of secure CIS, they are not adoptable for deployment by others due to their reliance on proprietary hardware and closed ecosystem. In...

论文介绍 本文针对云推理服务中大型语言模型(LLM)用户隐私保护问题,提出了OpenPCC系统。该系统基于商品可信执行环境(TEE),实现了开放且机密的LLM服务,允许在不依赖专有硬件的情况下部署安全云推理。研究旨在为AI应用提供可扩展的隐私保护解决方案,降低对封闭生态的依赖。

A Longitudinal Study of Recently Observed Malicious Domains: Characteristics, Infrastructure, and Abuse Patterns

第一作者: Fathima Mashood · 方向: 网络安全

Abstract:We present a longitudinal study of approximately 1.52 million malicious domains observed on VirusTotal (VT) between January and May 2026. Domains were selected on the basis of detection by at least five independent VT scanning engines and a first-seen date within the study window. We group the dataset into compromised domains and attacker created domains, which account for approximately 89.3% of the dataset. Combining WHOIS registration records and passive DNS (PDNS) data with the VT dataset, we characterise attacker behaviour across eight dimensions: temporal distribution, this http URL classification, domain age at first detection, registrar and TLD preferences, DNS query volume as a damage proxy, hosting infrastructure concentration (IP and ASN level), bulk registration patterns, and brand impersonation. Key findings include: the majority of attacker created domains are...

论文介绍 本文对2026年1月至5月间观察到的约152万个恶意域名进行了纵向研究。通过结合WHOIS注册记录和被动DNS数据,作者从时间分布、域名年龄、注册商偏好、基础设施集中度等八个维度分析了攻击者行为。研究区分了被入侵域名和攻击者创建域名,揭示了批量注册和品牌冒充等滥用模式,为网络安全防御提供实证基础。

Do Transformers Actually Help Intrusion Detection? A Temporal Sequence Evaluation on CIC-IDS2017

第一作者: Zach Moczkodan · 方向: AI 安全

Abstract:Recent deep learning approaches for network intrusion detection increasingly incorporate temporal architectures such as recurrent networks and Transformers, often reporting near-perfect performance on CIC-IDS2017. However, many existing studies neither supply their temporal modules with genuine sequence inputs nor evaluate under realistic, leakage-free conditions, making it unclear whether reported gains arise from true sequence-modeling capability. In this work, we reformulate CIC-IDS2017 as a temporal intrusion-detection task by constructing ordered flow sequences from network conversations and benchmarking nine classical and deep learning architectures under a random split, two leakage-free splits, and a padding-scheme ablation. The central finding is that padding convention, not architecture, determines the Transformer's performance: on genuinely sequential (non-padded)...

论文介绍 本文质疑Transformer在入侵检测中的有效性,指出先前研究可能存在评估不真实的问题。作者将CIC-IDS2017数据集重构为时间序列任务,对多种经典和深度学习架构进行了基准测试。研究发现,填充惯例而非架构本身决定了Transformer的性能,在真实序列输入下,不同模型表现相似。这强调了评估条件对结果的关键影响。

When Discovery Outpaces Remediation: Modeling AI-Accelerated Vulnerability Discovery in Interconnected Systems

第一作者: Mohamamad Reza Faghani · 方向: 软件安全

Abstract:Advanced AI systems for code analysis, binary analysis, fuzzing orchestration, and penetration-test planningmay significantly increase the rate at which latent vulnerabilities are discovered. While improved discovery can benefit defenders, it can also overload remediation pipelines and accelerate adversarial weaponization. This paper develops a queueing and network-theoretic model of AI-accelerated vulnerability discovery in interconnected systems. We represent an enterprise as a weighted dependency graph with replenishing vulnerability pools, finite remediation capacity, triage degradation, exploit window compression, and dynamic compromise propagation. We derive stability conditions for vulnerability backlogs, formulate a dynamic coupling between unresolved backlog and cascade risk, and evaluate mitigation strategies through simulation. Results indicate that when actionable...

论文介绍 本文建模了AI加速漏洞发现对互联系统的影响,旨在分析修复流程过载风险。作者采用队列和网络理论,将企业表示为带权重的依赖图,考虑了漏洞池、修复能力、分级退化和动态传播等因素。研究推导了漏洞积压的稳定性条件,并通过模拟评估缓解策略,指出当AI发现速度超过修复能力时,系统风险可能急剧上升。

Understanding and mitigating the risks of OpenClaw for non-technical users: A practical guide with Skill

第一作者: Junchang Zheng · 方向: AI 安全

Abstract:OpenClaw has rapidly emerged as a transformative artificial intelligence (AI) agent framework, and its ability to autonomously execute complex, multi-step tasks has attracted an ever-growing and diverse user base. However, this capability comes with significant risks. While existing research has made important strides in characterizing these threats, such work is predominantly directed at technically sophisticated audiences. It remains largely inaccessible to non-technical users. This demographic now makes up an increasingly large and underserved portion of the community, yet it is these very users who most urgently need practical and straightforward guidance. In response, we bridge this gap through a series of interconnected efforts designed to lower the risk barrier for non-technical OpenClaw users. First, we identify and categorize seven core risks that OpenClaw users may...

论文介绍 本文针对OpenClaw AI代理框架的风险,为非技术用户提供实用指南。作者识别并分类了七类核心风险,如任务执行安全性和隐私泄露,并开发了互联的缓解措施。研究旨在降低非技术用户的使用门槛,通过具体技能指导帮助其安全操作AI代理,填补现有研究面向技术专家的不足。

Context-Based Adversarial Attacks on AI Code Generators: Vulnerability Analysis and Implications

第一作者: Walther A. Del Orbe · 方向: 软件安全

Abstract:AI-powered code generation systems have transformed software development but introduce critical inference-time security vulnerabilities. This research presents a systematic investigation of context-based adversarial attacks, where strategically crafted contextual inputs, including comments, documentation, variable names, bias large language models toward generating exploitable code. Through 2,800 controlled experiments across CodeT5+, CodeLlama, GPT-3.5-Turbo, and GPT-4, we quantify attack effectiveness and defense mechanisms. Results demonstrate that adversarial conditions increase vulnerability generation 10.7x (from 3.5% to 37.4%), with direct instruction attacks achieving 100% success on GPT-3.5-Turbo. Cross-model transferability reaches 60-100%, indicating systemic architectural vulnerabilities rather than model-specific flaws. Our dual-layer defense framework achieves...

论文介绍 本文研究了上下文对抗攻击对AI代码生成器的威胁,通过策略性设计上下文输入(如注释和变量名)来诱导模型生成可利用代码。作者进行了2800个实验,跨多个模型量化了攻击效果,发现对抗条件可显著增加漏洞生成率。研究还提出了一种双层防御框架,并分析了跨模型可转移性,揭示了架构层面的系统性漏洞。

Comparative Analysis of Inference-Time Defense Methods for Multimodal Large Language Models

第一作者: Bulat Nutfullin · 方向: AI 安全

Abstract:Multimodal large language models (MLLMs) now appear in safety-critical applications, but the visual channel leaves them open to adversarial attacks that predominantly text-oriented safety alignment addresses only in part. Retraining a model for each new vulnerability class is usually too expensive to be practical. We report a comparative empirical evaluation of three inference-time defense methods and their combinations, run on eight models from the InternVL and Qwen-VL families across seven safety benchmarks that span four attack classes and total 9,000 evaluation samples. Every figure below comes from the same unified proxy classifier. Five findings emerge from the evaluation. First, within the evaluated models and benchmarks, no single defense dominates across all settings: what works depends on the model's baseline safety and on the attack type. Second, combining defenses...

论文介绍 本文对多模态大语言模型(MLLM)的推理时防御方法进行了比较评估。研究在八个模型和七个安全基准上测试了三种防御方法及其组合,覆盖四类攻击样本。结果表明,单一防御方法无法在所有设置中通用,其效果取决于模型基准安全性和攻击类型。这为MLLM安全实践提供了基于证据的选型参考。

Training LLMs to Enforce Multi-Level Instruction Hierarchies via Gravity-Weighted Direct Preference Optimization

第一作者: Lena S. Bolliger · 方向: 安全研究

Abstract:Production LLMs receive instructions from sources with very different levels of trust, yet attend to every token with uniform architectural privilege. This is the structural vulnerability that enables malicious prompt injections and, more broadly, leaves models without a principled way to resolve conflicts between legitimate but competing instructions. A common training-based response is to teach models an explicit instruction hierarchy; existing approaches, however, formalize hierarchies of only three or four levels, treat all violations as equally severe, and rarely evaluate the full set of pairwise level interactions. We formalize a k-level instruction hierarchy problem and instantiate it for k=5, yielding ten pairwise priority relations that a compliant model must enforce. We then introduce Gravity-Weighted DPO (GW-DPO), a preference-optimization objective whose per-sample...

论文介绍 该研究关注大型语言模型在处理多级指令冲突时的结构漏洞,易受恶意提示注入攻击。论文形式化了k级指令层次问题,并针对k=5实例化了十种优先级关系。核心方法是引入重力加权直接偏好优化(GW-DPO),通过偏好学习训练模型执行层次规则,从而增强LLM在安全关键应用中的可靠性。

Securing Code Understanding: Detecting Natural Backdoor Vulnerability in Code Language Models

第一作者: Yuchen Chen · 方向: 软件安全

Abstract:Code Language Models (CodeLMs) have become integral to software engineering, significantly advancing code intelligence tasks. However, their widespread adoption has raised critical security concerns, particularly regarding susceptibility to backdoor attacks. Recent studies have uncovered naturally occurring backdoors, referred to as natural backdoors, in normally trained deep learning models. Despite posing threats as serious as those introduced through data poisoning, security implications of natural backdoor vulnerabilities in CodeLMs remain poorly understood. In this paper, we conduct a thorough empirical study of natural backdoor vulnerabilities in CodeLMs across various model architectures and code intelligence tasks. Specifically, we examine potential natural backdoor vulnerabilities across 44 scenarios, demonstrating that natural backdoors are prevalent and intrinsic to...

论文介绍 本文系统研究代码语言模型中的自然后门漏洞,这类漏洞与数据投毒攻击同样危险但尚未被充分理解。研究涵盖多种模型架构和代码智能任务,在44个场景中验证自然后门的普遍性与固有性,旨在提升对代码模型安全风险的认识并指导防御策略开发。

RedAct: Redacting Agent Capability Traces for Procedural Skill Protection

第一作者: Shuwen Xu · 方向: 安全研究

Abstract:Users rely on execution traces to observe agent behavior, diagnose failures, and ensure accountability. These traces contain rich procedural detail, including tool invocations, intermediate decisions, and error-recovery logic. Yet this detail can expose private procedural skills, allowing downstream methods to recover key formulas, thresholds, and strategies without access to model weights or skill files. To quantify this risk and evaluate protection, we construct \textsc{CapTraceBench}, a benchmark of 75 specialized long-horizon tasks and 154 curated skills across seven domains. We also introduce \textsc{RedAct} this https URL, a protected trace release framework that localizes protected key information, rewrites traces while preserving verifier-critical evidence, and embeds behavioral watermarks for downstream provenance analysis. Across representative trace reuse methods...

论文介绍 研究提出保护代理程序技能免于从执行轨迹中泄露的方法。用户依赖轨迹诊断行为,但细节可能暴露私有策略。论文构建CapTraceBench基准评估风险,并引入RedAct框架,通过定位关键信息、重写轨迹并嵌入行为水印,在保留验证证据的同时保护技能知识产权。

A Bayesian Network Approach for Enhancing Security-Focused Decision Support Systems

第一作者: Carolina Fernández-Martínez · 方向: 系统安全

Abstract:The adoption and integration of heterogeneous stacks in most of today's open-source based networks brings clear benefits like interoperability and availability of advanced features. Yet, on the other hand the increasing number of interconnecting components and moving parts requires maintaining an ever increasing base of interdisciplinary knowledge of different tools in different domains to ensure proper operation. To alleviate such efforts, this work proposes a Decision Support System (DSS) to guide infrastructure operators through the selection of security approaches (e.g. tools) to adopt in their environments. This framework easily captures the end-user high-level requirements on the security triad for different domains and runs inference on the designated models to provide the identified tools (security mechanisms) that better serve such needs. The presented DSS aims at...

论文介绍 针对异构网络中安全工具选择的复杂性,本文提出一个基于贝叶斯网络的决策支持系统。该系统能捕获用户对安全三元组的高层需求,并通过推理模型推荐合适的安全机制,帮助基础设施操作员简化决策过程,提升环境安全性。

Toward Secure LLM Agents: Threat Surfaces, Attacks, Defenses, and Evaluation

第一作者: Yuchen Ling · 方向: 软件安全

Abstract:Large language model (LLM) agents are rapidly moving from conversational interfaces to software components that plan, invoke tools, maintain memory, and act on external environments. This transition changes the nature of security risk. In agentic settings, failures are no longer limited to unsafe text generation. Untrusted content may redirect control flow, misuse tool privileges, corrupt persistent state, leak sensitive information, or trigger harmful external actions. At the same time, research on LLM agent security is expanding quickly but remains fragmented across attack families, defense layers, application domains, and evaluation settings. This paper synthesizes 247 papers through a lifecycle-based, systems-oriented framework that models agent security around the interaction of information flow, delegated authority, and persistent state. We organize the literature around...

论文介绍 LLM代理从对话接口转向规划、工具调用和环境交互,安全风险随之演变。本文综合247篇论文,提出基于生命周期、面向系统的框架,围绕信息流、委托授权和持久状态交互来建模代理安全,系统梳理攻击家族、防御层和评估设置的研究现状。

MemVenom: Triggered Poisoning of Multimodal Memories in Web Agents

第一作者: Yv Zhang · 方向: AI 安全

Abstract:External memory has become a core component of modern web agents, enabling long-horizon reasoning through the retrieval of past experiences. However, this paradigm introduces a critical vulnerability: malicious content injected into memory can be persistently recalled and repeatedly influence agent behavior. In this work, we identify and systematically study multimodal memory poisoning, an overlooked yet practical attack surface in web-agent systems. We propose MemVenom, a unified black-box attack framework that poisons graph-structured external memory with coordinated text-image evidence. Our method consists of a two-stage design: (1) a trigger-conditioned retrieval attack that ensures high-probability recall of malicious memory, and (2) a post-retrieval attack induction that leverages adversarial perturbations and stealthy OCR injection to override the original user...

论文介绍 外部记忆是Web代理长期推理的核心组件,但恶意内容注入可能持久影响行为。本文提出MemVenom框架,一种针对图结构记忆的黑盒攻击方法,通过触发检索攻击和扰动诱导投毒协调文本-图像证据,揭示多模态记忆的实用攻击面。

Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors

第一作者: Naci Cankaya · 方向: AI 安全

Abstract:In preparation for potential international agreements on artificial intelligence, the development of verification infrastructure for AI data centres is vital. We propose a method for cryptographically committing all information entering and leaving a data centre: Hashes are computed by network taps placed on all the information-carrying wires between the cluster and the outside world, enabling an auditor to retroactively challenge the preimage data to be sent to a privacy-preserving verification facility performing compliance checks. Our goal is to make it infeasible to covertly exfiltrate the results of undisclosed workloads in the cluster through the tapped wires. To this end, we specify the architecture of a ``Secure Gateway Device'', which handles the erasure of covert channels that post-hoc verification on hashed data cannot address: analogue and timing side-channels, as...

论文介绍 为支持AI国际合作,需开发数据中心验证基础设施。本文提出方法,通过网络分接器对集群所有I/O进行密码学承诺,生成哈希供审计员挑战数据。引入安全网关设备处理模拟和时序侧信道,旨在防止秘密工作负载结果通过隐蔽渠道泄露。

Do LLMsMakeNeural Distinguishers Wise?

第一作者: Tatsuya Sakagami · 方向: AI 安全

Abstract:Neural distinguishers are a cryptanalysis method for symmetric-key cryptography that trains machine learning models on pairs of plaintexts and ciphertexts with specific differences in order to recover a secret key. To the best of our knowledge, no existing work has explored the use of large language models (LLMs) for neural distinguishers. In this paper, we propose LLM-based neural distinguishers through a prompt design and conduct extensive experiments with them on SPECK-32/64 to investigate whether LLMs can strengthen neural distinguishers. We then found three key insights. First, by comparing the results of LLM-based neural distinguishers with ResNet in the existing work, we demonstrate that LLMs provide no observable improvement in the performance of neural distinguishers. Second, we confirm that, at high rounds, the choice of differences is no longer effective for...

论文介绍 神经区分器利用机器学习进行对称密钥密码分析。本文首次探索使用LLMs构建神经区分器,通过提示设计在SPECK-32/64上实验。结果显示LLMs未显著提升性能,且在高轮次时差异选择效果减弱,表明LLMs在密码分析任务中的应用存在局限性。

Post-Quantum Secure Federated DeFi for Inclusive Banking

第一作者: Swati Sachan · 方向: 密码学协议

Abstract:Recent advances in error-corrected qubits have accelerated the timeline for practical quantum computing. It poses a threat to cryptographic primitives used to secure financial systems, government infrastructure, communication networks, and DeFi (Decentralized Finance) ecosystems. This paper introduces a post-quantum secure federated DeFi framework that enables inter-bank collaboration to improve the inclusivity of individuals underserved by local lenders due to limited financial histories. Multiple banks contribute encrypted information batches to a virtual server, where lattice-based Fully Homomorphic Encryption (FHE) enables end-to-end homomorphic computation. The server fuses local data-driven probabilistic assessments, expert beliefs, and verifiable evidence generated by the NASA-IBM Prithvi Geospatial Foundation Model (GFM), in encrypted format. Decentralized technologies...

论文介绍 本文针对量子计算对金融系统加密的威胁,提出一个后量子安全的联邦去中心化金融框架。该框架允许银行通过基于格的完全同态加密在虚拟服务器上进行加密计算,融合本地数据、专家信念和NASA-IBM Prithvi地理空间模型证据,以提升对缺乏金融历史个体的服务包容性。

Layer Order Semantics for Automata-Based Cybersecurity

第一作者: Faruk Alpay · 方向: 安全研究

Abstract:Layered cybersecurity pipelines transform evidence before they decide on it, and the order of those transformations determines which security facts become visible to which layer. This paper gives layer order a finite-state semantics built from a layer-order automaton, deterministic sequential security transducers, evidence markers, and a final decision automaton. The worked case is HTTP request desynchronization: front-end and back-end processors compute incompatible request boundaries, and the same trace is detected or missed according to whether framing evidence reaches the parser-differential layer before it commits. The results separate completed-trace recognition, online editing, decision synthesis, and faithful enforcement; characterize faithful online enforcement as the regular prefix-closed case under causal visibility; and show that regular policies beyond that...

论文介绍 本文研究分层网络安全管道中的层序语义问题,使用层序自动机、确定性顺序安全转换器和证据标记构建有限状态语义。通过HTTP请求反序列化案例,展示层序如何影响安全事实可见性,结果区分了完成跟踪识别、在线编辑、决策合成和忠实执行。

snaproot: Decentralized File Integrity Verification Using Blockchain-Anchored Cryptographic Hashing

第一作者: Arslan Brömme · 方向: 软件安全

Abstract:The rapid growth of digital content has made reliable integrity verification increasingly important. Existing solutions rely either on centralized authorities, which introduce trust dependencies and single points of failure, or on decentralized storage systems that incur prohibitive resource overhead. In this paper, we present snaproot, a lightweight system that implements the hash-anchoring paradigm of Haber and Stornetta on the Solana blockchain to provide efficient, decentralized file integrity verification. snaproot generates a SHA-256 hash of a file and stores it immutably on-chain as a permanent reference record. Verification is performed by recomputing the hash and comparing it to the stored value, yielding a deterministic binary outcome. We describe a four-tier trust architecture comprising three realized tiers and one prospective tier for long-term persistence beyond...

论文介绍 本文提出snaproot系统,实现基于区块链的去中心化文件完整性验证。系统生成文件SHA-256哈希并存储在Solana区块链上,验证时通过比较计算哈希与存储值获得确定性结果,解决传统集中式权威或高开销存储的信任依赖和单点故障问题。

Two-Way Confidential VMs (2cVM): Collaborative Confidential Computing for Mutually Distrustful Parties

第一作者: Jordi Thijsman · 方向: 密码学协议

Abstract:Collaborative computation across organizations is often constrained by the need to process sensitive data and proprietary code without exposing them to untrusted infrastructure or participants. Cryptographic approaches such as fully homomorphic encryption and secure multi-party computation provide strong confidentiality but remain impractical for general workloads due to their extreme computational cost. We present the Two-Way Confidential Virtual Machine (2cVM), a two-layer architecture that pairs a hardware trusted execution environment with an intra-workload isolation layer. Unlike regular Confidential Virtual Machines, 2cVM enforces mutual isolation between co-resident workloads, ensuring that participants retain control over their data and code. All computation in 2cVM is governed by a Commitment Manifest that enumerates participants, component composition, permitted data...

论文介绍 本文提出Two-Way Confidential VM (2cVM)架构,用于互不信任方之间的协作机密计算。该架构配对硬件可信执行环境与工作负载隔离层,通过承诺清单管理参与者、组件和数据权限,确保各方控制其数据和代码,提供实用的安全多方计算替代方案。

From Data Heterogeneity to Convergence: A Data-Centric Review of Federated Learning

第一作者: Huong Nguyen · 方向: 系统安全

Abstract:Federated Learning (FL) has emerged as a promising solution for data hunger in centralized learning. This paradigm enables privacy with multiple clients to train a shared-task model collaboratively without exposing their local data. While being a key component in any learning system, data is also a primary source of vulnerabilities and challenges, and a major determinant of a stable and well-converged training. Existing FL reviews describe general foundations, security practices, opportunities, challenges, and applications, without delving into diverse aspects of data and considering problems from the data perspective. They rarely provide a data-lens synthesis that links concrete data properties, split protocols, and defenses to convergence speed and stability. This survey fills that gap with three advances. First, we analyze non-IID into measurable traits and rank their...

论文介绍 本文从数据角度综述联邦学习中的异质性问题,分析非IID数据对收敛速度和稳定性的影响。通过测量特性排名、分割协议和防御措施,提供数据中心视角的综述,填补现有综述缺乏数据属性与收敛关联的空白。

A Hybrid Edge-Cloud Architecture for Low-Latency Entitlement Verification in Resource-Constrained Devices

第一作者: Pravin Nagare · 方向: 系统安全

Abstract:As digital media consumption shifts toward large-scale Over-the-Top (OTT) platforms, the efficiency of the control plane, specifically entitlement and identity verification, has become a critical factor in user experience. Current architectures often rely on synchronous cloud-tethered validation flows that introduce significant latency, especially on resource-constrained consumer electronics. This paper proposes a Hybrid Edge-Cloud Entitlement Framework designed to minimize user-perceived friction. By implementing a secure, local caching layer within device middleware and utilizing an Adaptive Entitlement Cache with Proactive Refresh (AEC-PR) algorithm, we decouple the user interaction from backend network variability. We evaluate the performance on ARM Cortex-A series hardware, demonstrating that localized cryptographic verification reduces authorization latency from a mean...

论文介绍 本文提出混合边缘-云权利验证框架,针对资源受限设备降低授权延迟。通过设备中间件中的安全本地缓存和自适应缓存算法,解耦用户交互与后端网络变化,在ARM Cortex-A系列硬件上验证可减少平均授权延迟。

Assessing Automated Prompt Injection Attacks in Agentic Environments

第一作者: David Hofer · 方向: AI 安全

Abstract:Indirect prompt injection poses a critical threat to LLM agents that interact with untrusted external data, yet automated attack methods--proven effective for jailbreaking--remain underexplored in realistic agentic settings. We present a comprehensive empirical evaluation of automated prompt injection attacks against LLM agents, adapting both white-box (GCG) and black-box (TAP) methods to the agentic setting within the AgentDojo framework. We evaluate across 80 task pairs spanning four domains and multiple models, and find that black-box optimization substantially outperforms gradient-based methods, a gap we attribute to GCG's optimization instability under reasonable compute budgets. We also find that TAP's effectiveness depends on the attacker model, as both general capability and safety tuning affect attack success--stronger models produce more effective injections, while...

论文介绍 本文在代理环境中评估自动提示注入攻击,适配白盒GCG和黑盒TAP方法到AgentDojo框架。评估跨越80个任务对和多个模型,发现黑盒优化优于梯度方法,攻击效果依赖于攻击者模型的能力和安全调谐。

A Deployment-Oriented Framework for Explainable AI-Assisted eBPF/XDP Mitigation at the IoT Edge

第一作者: Abdurrahman Tolay · 方向: 密码学协议

Abstract:Internet of Things (IoT) deployments combine heterogeneous, resource-constrained devices with weak security configurations, exposed services, limited logging, patching constraints, and long lifecycles. Signature- and threshold-based controls remain useful baselines, but they are insufficient as standalone mechanisms in dynamic IoT networks. Likewise, offline artificial intelligence (AI) benchmark performance alone does not establish operational deployability. This article presents a conceptual framework and research agenda for a Linux-based IoT edge gateway that combines resource-aware flow-level AI-assisted risk scoring, event-level explainability, and bounded mitigation through eBPF/XDP. The controller applies reversible, time-limited actions subject to critical-device safeguards, updates packet-level enforcement state, and records structured logs. The architecture separates...

论文介绍 本文提出面向部署的IoT边缘网关框架,结合资源感知AI风险评分、事件级可解释性和通过eBPF/XDP的有限缓解。控制器应用可逆、限时行动更新强制状态,记录结构化日志,以应对IoT网络的动态安全需求。

When VR Meets BCI: (Un)Observable Brainwave-aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion Sensors

第一作者: Tao Ni · 方向: 隐私保护

Abstract:Metaverse devices, such as virtual reality (VR), have seen substantial development and widespread applications in numerous areas. Although recent studies have revealed privacy leakages in VR, these vulnerabilities were limited in the scope of observable behaviors in virtual scenes (e.g., what a user is seeing). In this work, we uncover the feasibility of going beyond the scope of observable user behaviors to unobservable brain EEG-correlated representations (e.g., what a user is perceiving) by leveraging unrestricted motion sensors in VR headsets to reconstruct brain EEG signals, a seemingly neglected but promising vector. The insight is that the inbuilt motion sensors (e.g., accelerometers) in the VR headset can capture subtle vibrations induced by pupillary responses, which are highly correlated with users' visual stimuli and in-brain perceptions. Therefore, we design and...

论文介绍 本文揭示了虚拟现实(VR)设备中一个未被充分重视的隐私泄露风险。研究发现,VR头显内置的运动传感器能够捕获用户瞳孔反应引起的细微振动,从而重建出与用户感知相关的脑电信号表示。这意味着攻击者有可能利用VR设备,超越对用户可见行为的观测,推断其不可见的脑内感知活动,对元宇宙中的隐私安全构成新挑战。

AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments

第一作者: Peiyang Li · 方向: AI 安全

Abstract:Autonomous AI agents have driven the transition from conversation to task execution, shifting security failures from textual deception to system compromise. Although security evaluation is crucial for proactive risk prevention, prior work is constrained by fundamental bottlenecks, including fragmented risk coverage, static or low-fidelity execution environments, and single-dimensional and coarse-grained assessment metrics. To address these challenges, we propose AgentCanary, a comprehensive security evaluation framework for autonomous AI agents. AgentCanary provides a systematic solution along three contributions. First, comprehensive risk coverage: we introduce an orthogonal Entry $\times$ Impact risk taxonomy that decouples how adversarial influence enters the agent from what harm it ultimately causes, and instantiate it as a scenario-aligned task suite spanning realistic...

论文介绍 针对自主AI代理从对话转向任务执行所引发的新型安全威胁,本文提出了AgentCanary综合安全评估框架。该框架通过构建「入口×影响」正交风险分类法,系统性地覆盖了多样化风险场景,并在高保真度的实际可执行环境中进行测试。它解决了现有评估方法在风险覆盖、环境逼真度和评估指标方面存在的碎片化、静态化和粗粒度问题,为代理风险的前瞻性预防提供了系统化方案。

HE-DAP: Homomorphic Encryption-based Dynamic Adaptive Parameter Optimization for Statistical Computation

第一作者: Yun-Soo Park · 方向: 密码学协议

Abstract:Homomorphic encryption (HE) enables privacy-preserving analytics but remains hindered by high computational overhead. We find that the inverse square root-a key primitive in many statistical and machine learning workloads-exhibits inconsistent and often suboptimal performance across HE libraries and hardware. This stems from a core trade-off between two costly HE operations: evaluating high-degree Chebyshev polynomials to speed up Newton's method versus performing bootstrapping to manage ciphertext noise. Because their relative costs vary by up to 6x across environments, any fixed configuration proves inherently inefficient. To address this challenge, we present HE-DAP, a cross-platform optimization framework that automatically navigates this trade-off. By profiling an environment's unique performance characteristics, HE-DAP finds the optimal balance between polynomial degree...

论文介绍 同态加密(HE)在进行隐私保护计算时面临高昂的计算开销。本文聚焦于统计计算中关键的逆平方根运算,发现其在HE中的性能受限于一个核心权衡:使用高次切比雪夫多项式加速Newton迭代法与执行自举操作以管理噪声之间的成本。由于不同环境下的成本差异巨大,固定配置无法达到最优。为此,本文提出HE-DAP跨平台优化框架,能自动分析环境特性,在多项式次数与自举操作之间找到最佳平衡点,从而提升效率。

The Distributed Detectability Band Against Marginal-Preserving Attacks

第一作者: Zhang Qinqin · 方向: 系统安全

Abstract:AI-control monitors score individual agent actions to detect misbehavior, but real harm can be distributed across many benign-looking steps, each individually below any per-step alarm. We construct a marginal-preserving, correlation-encoded distributed-sabotage attack using a Gaussian-copula AR(1) construction: the per-step monitor-score marginal is held exactly equal to benign, so mean, max, top-k tail, and threshold monitors (Monitor A) are defeated by construction, while harm is encoded in the temporal correlation structure. We sequence the paper around three reviewer-mandated gates. (1) Realizability gate: the stealthy attack achieves KS-distance to benign of 0.013 (effectively zero) at all tested harm levels up to 3.0, confirming that harm is fully decoupled from the per-step marginal and realizability is not harm-limited. (2) Monitor-A-vs-B reconciliation: we show...

论文介绍 AI控制监控器通常通过评估单个代理动作来检测异常行为,但现实中的有害行为可能分散在多个看似正常的步骤中。本文提出了一种边际保持的分布式破坏攻击,该攻击利用高斯Copula模型编码时间相关性,在每一步动作的统计分布上与正常行为保持一致,从而规避基于均值、最大值或阈值的传统监控器。研究证明,这种攻击能够将危害完全从单步边际分布中解耦,并通过相关性结构来实现系统性危害。

Semantic Multi-Agent Intrusion Detection for IoT:Zero-Day and Adversarial Threats with Risk-Aware Reasoning

第一作者: Saeid Jamshidi · 方向: AI 安全

Abstract:The rapid proliferation of Internet of Things (IoT) devices has enabled unprecedented automation and connectivity, but it has also substantially increased the attack surface, exposing networks to sophisticated cyber threats, including zero-day and adversarial intrusions. Traditional Intrusion Detection Systems (IDS) struggle to generalize to unseen attacks, often require substantial computational resources, and lack interpretability, particularly in resource-constrained and heterogeneous IoT networks. Recent advances, including Deep Learning (DL), open-set detection, and Large Language Model (LLM)-based semantic reasoning, address some of these challenges but typically focus on zero-day and adversarial threats and rarely combine semantic reasoning with multi-agent systems. To overcome these limitations, we propose a semantic multi-agent ID that integrates four specialized...

论文介绍 为应对物联网(IoT)环境中日益复杂的零日攻击和对抗性威胁,本文提出了一种语义多智能体入侵检测系统。该系统结合了深度学习、开放集检测和基于大语言模型(LLM)的语义推理能力,由多个专精的智能体协同工作。这种方法旨在克服传统入侵检测系统在泛化能力、计算资源消耗和可解释性方面的不足,为资源受限且异构的IoT网络提供更有效的安全防护。

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs

第一作者: Saeid Jamshidi · 方向: 密码学协议

Abstract:Large Language Models (LLMs) in multi-turn interactions maintain evolving context rather than generating isolated responses, making them vulnerable to prompt-injection and context-poisoning attacks in which locally plausible adversarial fragments gradually distort reasoning trajectories. Existing defenses mainly filter individual outputs and often ignore context evolution across turns, leaving long-horizon reasoning exposed. Although the Model Context Protocol (MCP) standardizes context exchange and tool invocation, it functions as a passive routing layer and does not enforce contextual stability. To address these limitations, we introduce the Game-Theoretic Secure Model Context Protocol (GT-MCP), a controller-driven multi-agent method that treats context management as a closed-loop dynamical process. GT-MCP coordinates three heterogeneous LLM agents and selects outputs...

论文介绍 大语言模型(LLM)在多轮交互中易受提示注入和上下文投毒攻击,导致推理轨迹被逐渐扭曲。现有防御多聚焦于过滤单轮输出,忽略了上下文演化。为此,本文引入了博弈论安全模型上下文协议(GT-MCP),将上下文管理视为一个闭环动态过程。该协议通过协调三个异构的LLM代理,基于博弈论原则选择输出,从而增强模型在长期推理中对恶意上下文片段的抵御能力,维护推理稳定性。

The Linux IOCTL Census: A Source-Derived Database of the Linux Kernel Control-Code Surface

第一作者: Michael J. Bommarito II · 方向: 软件安全

Abstract:The ioctl system call is Linux's catch-all device-control interface. A userspace program opens a device node and hands the driver a numeric command code and an argument buffer, and the driver does whatever that code means, whether configuring hardware, reading back state, or moving data into and out of the kernel. Drivers define these commands themselves, by the thousand, and parse their arguments in kernel context, which makes ioctl handlers one of the broadest and least uniform local attack surfaces in the kernel. A handler that trusts an argument length it never validates can read or write kernel memory out of bounds, and the command space is catalogued in no central place. We present the Linux IOCTL Census, a source-derived and queryable inventory of that surface. An allmodconfig build compiles 878 modules across 169 subtrees, and over them a single deterministic libclang...

论文介绍 ioctl系统调用是Linux内核中一个庞大且不统一的设备控制接口,驱动自行定义命令并在内核上下文中解析参数,这构成了广泛且难以梳理的本地攻击面。本文通过自动化源码分析,构建了「Linux ioctl普查」数据库。该数据库基于全模块配置编译了169个子树下的878个模块,利用libclang提取并整理了所有ioctl命令码及其参数信息,为研究和审计这一关键攻击面提供了首个可查询的综合资源。

Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations

第一作者: Aniket Anand · 方向: AI 安全

Abstract:This paper presents AuditBench, a new benchmark dataset for evaluating the capabilities of LLMs at investigating security-related system audit logs. We design and use this benchmark to explore the performance of LLMs on four log-investigation tasks that incident response teams commonly perform, ranging from triaging alerts generated by detectors to identifying persistence mechanisms on compromised systems. AuditBench consists of system audit logs collected from Linux and Windows machines, and spans over 50 different security investigation scenarios, including both malicious and benign activity. Using our benchmark, we evaluate and analyze the performance of five frontier LLMs at analyzing audit logs for attack investigations. Our analysis illuminates how LLM performance and error profiles vary according to different design choices, such as differences in model size, data...

论文介绍 本文推出了AuditBench基准数据集,用于评估大语言模型(LLM)分析系统安全审计日志的能力。该基准包含从Linux和Windows机器收集的日志,覆盖了50多种不同的安全调查场景,涵盖了从告警分类到持久化机制识别等常见任务。基于此基准,研究对五款前沿LLM进行了评估和分析,揭示了模型性能和错误模式如何随模型规模、数据呈现方式等设计选择而变化,为LLM在安全事件响应中的应用提供了实证参考。

RECON: An LLM-Enhanced Backward Constraint Analysis Framework

第一作者: Babangida Bappah · 方向: 软件安全

Abstract:While traditional techniques, such as symbolic execution, provide a principled foundation for precise constraint reasoning in program analysis, they struggle to scale to modern software systems mainly due to path explosion, the need for function modeling, and the loss of semantic intent at low-level program representations. In complex execution environments such as Android, characterized by extensive framework interactions and event-driven behavior, these limitations are even more amplified. Thus, in this paper, we present a novel large language model (LLM)-enhanced backward constraint analysis framework that combines the precision of static program analysis with LLM's semantic understanding to extract precise execution constraints from Android bytecode. Our approach, titled RECON, performs backward path discovery from target method(s) to the application entry point(s)...

论文介绍 本文提出RECON框架,针对传统静态分析(如符号执行)在分析Android等复杂应用时面临的路径爆炸和语义丢失问题。该研究的核心是将大语言模型的语义理解能力与程序静态分析的精度相结合,通过后向路径发现,从目标方法反向推导至应用入口,从而精确提取Android字节码中的执行约束。该方法可用于提升对Android应用中安全敏感行为的自动化分析能力。

Local Is Not a Sufficient Privacy Boundary: Governing OS-Integrated On-Device AI

第一作者: Jonghyun Chung · 方向: 软件安全

Abstract:As AI systems move into operating systems, privacy no longer turns only on whether a model runs locally. A local assistant may assemble email, calendar entries, files, screenshots, notifications, and app intents; retain embeddings or summaries; invoke tools; emit telemetry; or route difficult requests to cloud infrastructure. Local inference reduces some exposure, but it answers only one question: where computation occurs. It does not answer who may assemble context, what derived state persists, which actions are authorized, or how updates change the system's authority. We develop an OS-centered privacy framework for on-device AI that treats privacy as an institutional accountability problem rather than a deployment attribute. The framework specifies a threat model, a six-part privacy risk taxonomy, privacy-by-architecture controls, and a four-level audit rubric. We...

论文介绍 随着AI集成到操作系统中,仅本地运行模型不足以保障隐私。设备端助手可能聚合邮件、日历、文件等多源敏感数据,并可能产生持久化状态或调用云端服务。本文指出隐私问题超越了计算位置,是一个制度问责问题。研究提出了一个以操作系统为中心的隐私框架,包含威胁模型、风险分类和架构控制措施,旨在为设备端AI系统的设计和审计提供系统性指导。

Proof of Source of Funds: Efficient On-chain Provenance of Cryptoassets

第一作者: Alireza Kavousi · 方向: 密码学协议

Abstract:Regulatory compliance is increasingly mandatory for decentralized finance and privacy-enhancing technologies. Current approaches rely on binary inclusion/exclusion lists or retroactive graph analysis by centralized blockchain intelligence firms. This approach strips honest users of their financial privacy, leads to false positives and negatives, and forces decentralized platforms to bear the burden of on-chain transaction monitoring. In this work, we propose a paradigm shift: moving from platform-side surveillance to user-side provenance. We introduce Proof of Source of Funds (PoSoF), a novel cryptographic framework that shifts the burden to the user. Rather than the platform tracing funds, the user locally generates a zero-knowledge proof demonstrating that their deposit originates exclusively from a set of compliant sources. The platform is thus relieved of chain-analysis...

论文介绍 当前加密资产合规性检查多依赖中心化平台的事后分析,损害用户隐私并可能产生误判。本文提出「资金来源证明」范式,将合规负担从平台转移至用户。其核心是用户在本地生成一个零知识证明,向平台仅证明其存款来源于一组合规资金源,而无需透露具体交易路径。该框架旨在为去中心化金融和隐私增强技术提供一种既能满足监管要求,又能保护用户财务隐私的新型密码学方案。

GRAFT: Graphlet-Triggered Backdoor Attack on GNN-Based Hardware Security Systems

第一作者: Sanaz Kazemi Abharian · 方向: AI 安全

Abstract:The globalization of the integrated circuit (IC) supply chain increases the risk of security threats, such as hardware Trojans (HTs) and the theft of intellectual property (IP). Graph Neural Networks (GNNs), among the most powerful deep learning methods for processing graph-structured data, have been widely adopted to detect such threats. However, GNNs are susceptible to backdoor attacks that can maliciously manipulate output predictions toward an adversarial target. These attacks are not only difficult to detect but also compromise the integrity of GNN-based security systems. Most prior work embeds backdoor triggers using randomly generated subgraphs or gradient-guided generative subgraphs. However, such triggers are impractical for GNN-based hardware security applications as they do not guarantee the preservation of circuit functionality. In this paper, we propose GRAFT, a...

论文介绍 图神经网络已广泛用于硬件木马和知识产权盗窃检测,但其易受后门攻击。现有攻击的触发器常无法保持电路功能,实用性差。本文提出GRAFT攻击框架,针对基于GNN的硬件安全系统。它利用电路图的结构特性「图元」来触发后门,旨在设计出既隐蔽又能保持原始电路功能的恶意触发器,从而在不破坏芯片正常工作的情况下误导检测模型,揭示了当前硬件安全ML模型的脆弱性。

RadKey: An LLM-Guided RF Backscatter System for Through-Wall Keystroke Inference

第一作者: Qijun Wang · 方向: AI 安全

Abstract:In today's digitally connected world, keyboards remain the primary interface for inputting sensitive information, making them a persistent target for eavesdropping attacks. While prior keystroke inference techniques have exploited side-channel signals such as acoustics and vibrations, they typically rely on conspicuous, short-range sensors and require victim-specific data for model training, limiting their practicality, scalability, and stealth. In this paper, we present RadKey, an RF backscatter system for covert, long-range, through-wall keystroke eavesdropping. RadKey comprises two components: a compact batteryless backscatter tag and an RF reader. The tag captures keystroke-induced vibrations and acoustic signals, modulating them onto the frequency shift of its backscattered RF signal using two magnetically-coupled LC resonators. This design also enables spectral...

论文介绍 针对键盘输入的窃听攻击通常依赖短距离传感器且需要目标特定数据。本文提出RadKey系统,利用无源RF背散射标签捕获击键振动,并将其调制到背散射信号的频偏中,实现穿墙、远距离、隐蔽的窃听。该系统结合了物理层侧信道与大语言模型进行内容推断。研究展示了在无需受害者先验训练数据的情况下,攻击的可扩展性与隐蔽性,对输入安全构成新型威胁。

Secrets Best Not Shared: DNS Privacy Enhancements for the Constrained IoT

第一作者: Martine S. Lenders · 方向: 密码学协议

Abstract:Attackers often identify DNS traffic to disrupt or compromise Internet services. While prior work has focused on encrypting queries using DNS over TLS, HTTPS, or QUIC to counter such attacks, we consider IETF protocols designed for resource-constrained IoT devices and empirically analyze the potential of obfuscating DNS traffic in addition to encryption. We create a dataset of machine-to-machine-compatible data objects along with the corresponding DNS resolution processes, evaluating 296 deployment scenarios of resolving host names, including DNS over the Constrained Application Layer Protocol (CoAP) and an onion routing flavor of CoAP under varying link-layer conditions. We compare them to DNS over HTTPS. Using Random Forest and a header field analysis, we identify fields that leak most information. Our findings show that DNS over CoAP with equalized packet lengths...

论文介绍 DNS流量易被识别和干扰。本文针对资源受限的物联网设备,评估了DNS over CoAP及其洋葱路由变体等IETF协议在加密之外进行流量混淆的潜力。通过构建数据集和场景模拟,研究比较了多种部署方式,并利用机器学习识别最易泄露信息的头部字段。结果表明,结合数据包长度等化的DNS over CoAP能有效增强隐私,为受限IoT环境下的DNS隐私保护提供了实证依据。

SoK: Colluding Adversaries in Machine Learning Pipelines

第一作者: Vasisht Duddu · 方向: AI 安全

Abstract:Machine learning (ML) models are susceptible to various security, privacy, and fairness risks. Adversaries with different characteristics (i.e., objectives, knowledge, and capabilities) can collude by executing one attack to amplify others. Existing work lacks a systematic framework to explore collusion among adversaries, and to study the implications of the adversaries' characteristics. We present a framework covering collusion (a) between train- and inference-time adversaries, and (b) among inference-time adversaries. Our framework accounts for factors enabling collusion between adversaries. We propose a guideline to conjecture about the potential for collusion using enabling factors. We use it to explain prior work, conjecture about unexplored collusions, and empirically validate five such cases. Finally, we discuss how adversaries' characteristics influence the potential...

论文介绍 机器学习管线面临来自不同阶段、具有不同目标的攻击者威胁。本文指出,这些攻击者可能相互协作,放大彼此攻击的效果。研究系统化地提出了一个分析框架,用于探索训练时与推理时攻击者之间,以及多个推理时攻击者之间的共谋可能性。该框架定义了促成共谋的关键因素,并基于此分析和预测潜在的共谋攻击,有助于更全面地理解和防御针对ML系统的复杂、组合性威胁。

The Human Vulnerabilities & Exploits (HVE) Framework

第一作者: Avichai Ben · 方向: 软件安全

Abstract:The cybersecurity community has invested over two decades in building standardized frameworks, the Common Vulnerabilities and Exposures (CVE) system, the Common Vulnerability Scoring System (CVSS), and the Common Weakness Enumeration (CWE) to identify, classify, and remediate threats to digital infrastructure. However, an emerging body of research reveals that a vast majority of successful cyberattacks exploit not software flaws, but human behavioral and psychological vulnerabilities. Social engineering, fraud, and scam attacks, which manipulate human cognition, emotion, and trust, do not have an equivalent standardized framework. Meanwhile, behavioral science and psychology research has established robust theoretical foundations, such as dual-process theory, prospect theory, social influence frameworks, and visceral state models, which explain precisely why and how these...

论文介绍 多数成功的网络攻击利用的是人类行为与心理漏洞,而非软件缺陷,但缺乏类似CVE的标准化框架来系统应对此类威胁。本文提出「人类漏洞与利用」框架,旨在借鉴行为科学和心理学理论(如双系统理论、前景理论),建立一个用于识别、分类和评估社会工程、欺诈等攻击中所利用的人类弱点的标准化体系,从而为防御这些「人为风险」提供结构化方法。

The Chronicles of Radio Frequency Fingerprinting

第一作者: Abdul Aziz · 方向: AI 安全

Abstract:Radio Frequency Fingerprinting (RFF) has evolved from an early idea for radar emitter identification into a broad research field for wireless device identification and spectrum monitoring for security. Rather than presenting a conventional literature survey, this work provides a critical historical analysis of RFF organized around the field's major conceptual paradigm shifts from 1993 to 2026. We discuss the evolution of RFF across its fundamental methodological phases, beginning with early transient-based approaches, in which transmitter turn-on behavior, unintentional modulation, and hardware nonlinearities were treated as the primary fingerprint sources. We then examine the transition to digital communications, during which attention shifted to steady-state impairments and to engineered features extracted from signals. Next, we discuss the Machine Learning period, which...

论文介绍 这篇论文对无线电频率指纹(RFF)领域进行了批判性历史分析,时间跨度从1993年到2026年,围绕概念范式转变组织。它讨论了从早期基于瞬态的方法,到数字通信时期的稳态损伤和工程特征,再到机器学习时期的方法论演变。研究问题在于梳理RFF的发展历程及其在无线设备识别和安全监测中的应用,为未来研究提供历史背景和见解。

GitInject: Real-World Prompt Injection Attacks in AI-Powered CI/CD Pipelines

第一作者: Jafar Isbarov · 方向: AI 安全

Abstract:AI-powered agents are increasingly embedded in continuous integration and continuous delivery/deployment (CI/CD) pipelines to autonomously review pull requests (PRs), triage issues, and maintain codebases. These agents ingest untrusted content while operating with elevated repository permissions, making them a natural target for prompt injection attacks with supply chain consequences. We present GitInject, an open-source framework for evaluating prompt injection vulnerabilities in real, live GitHub workflows, a widely deployed instance of CI/CD pipelines. Unlike prior agent security benchmarks that simulate tool calls, GitInject provisions ephemeral repositories and triggers actual workflow runs, so that sandbox constraints, credential handling, and permission boundaries behave exactly as in production. Using GitInject, we study workflow configurations across four AI providers...

论文介绍 GitInject是一个开源框架,用于评估实时GitHub工作流中的提示注入漏洞。它通过配置临时仓库并触发实际工作流运行,精确模拟生产环境中的沙箱约束和权限边界。研究问题涉及AI代理在CI/CD管道中的安全风险,应用在评估和增强供应链安全,帮助识别和防御潜在攻击。

Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature Optimization

第一作者: Ziang Xu · 方向: AI 安全

Abstract:With the growing concerns over copyright infringement in diffusion-based customization, adversarial attacks have emerged as a prominent defense strategy to prevent malicious content forgery in personalized image generation. However, current defenses typically introduce persistent perturbations in the latent space of Latent Diffusion Models (LDMs), which remain susceptible to adaptive bypasses by adversaries. In this paper, we introduce Two-Stage Latent Feature Optimization (TS-LFO), an efficient and effective copyright-stealing attack against protected diffusion-based customization. We begin by observing that existing defenses primarily disrupt the mapping between input images and their latent representations, thereby degrading the model's ability to produce personalized outputs. To counteract this, TS-LFO restores the broken mapping through a two-stage optimization process...

论文介绍 论文提出Two-Stage Latent Feature Optimization (TS-LFO),一种针对受保护扩散模型定制的版权窃取攻击。通过两阶段优化过程,恢复输入图像与潜在表示之间的映射,绕过现有防御。研究问题在于对抗版权保护机制,应用在评估扩散模型的安全性并推动更稳健的防御设计。

IDP-Bench: Benchmarking ability of LLMs to protect personal information in interdependent privacy contexts

第一作者: Ayana Hussain · 方向: AI 安全

Abstract:Large language models (LLMs) are becoming widely deployed as personal AI assistants with access to sensitive user data, making privacy a major challenge for their design and evaluation. Prior work focuses mainly on individual-level risks, overlooking \textbf{interdependent privacy (IDP)}--where one person's data may be revealed by others without their knowledge or consent. We address this gap by introducing \textbf{IDP-Bench}: the first LLM benchmark for IDP scenarios, grounded in the Contextual Integrity (CI) framework. We evaluate eight open-source LLMs on their understanding of IDP scenarios across three levels of IDP reasoning using two LLM judges. Results show strong co-ownership recognition (6/8 models exceed 90\%) but persistent weaknesses in identifying CI parameters (information attribute, primary subject) and IDP-specific parameters such as secondary subjects, where...

论文介绍 引入IDP-Bench,第一个基于上下文完整性框架的LLM基准,用于评估大型语言模型在相互依赖隐私场景中的能力。它测试LLMs对个人数据泄露风险的理解,特别是当一个人的数据可能被他人泄露时。研究问题在于LLM隐私保护的评估,应用在设计和改进隐私安全的AI助手。

Safecloud: A Distributed, Encrypted Storage Cloud for Streaming

第一作者: Gregory Magarshak · 方向: 系统安全

Abstract:We present Safecloud, a distributed, encrypted, self-pricing storage and streaming network whose storage and routing nodes never see plaintext and never hold keys. Each file is split into chunks, encrypted on the owner's device, and distributed across Drops (browser tabs storing ciphertext in IndexedDB) and Jets (federated routing servers). Only the owner, or an authorised grantee, can decrypt. We make five contributions: (1) A one-root key hierarchy: every key derives deterministically from a single root via HKDF, and owner and range-scoped grantee derive identical chunk keys (derivation agreement); a subtree key derives its range and nothing else (delegation containment). (2) Convergent content addressing: identical content yields identical ciphertext and identifiers, enabling deduplication without plaintext exposure, with identifiers binding authenticated ciphertext so a...

论文介绍 Safecloud是一个分布式、加密的存储和流媒体网络,存储和路由节点不访问明文或持有密钥。它贡献了根密钥层次结构、收敛内容寻址等技术,确保数据安全和去重。研究问题在于安全存储和流媒体传输,应用在隐私保护的云存储服务,支持流媒体内容的安全分发。

What Do Deepfake Speech Detectors Actually Hear?

第一作者: Vojtěch Staněk · 方向: 安全研究

Abstract:Deepfake speech detectors often output a single score without explaining why an audio sample is flagged, where in the signal the evidence lies, or what cues drive the decision. We propose an audio-native explainability pipeline using Integrated Gradients on time-aligned self-supervised representations to localize decision evidence over time. We apply the proposed method to three WavLM-based detectors (AASIST, CA-MHFA, SLS) on ASVspoof 5 and manually annotate the highest-attribution regions to provide a semantic meaning of the most important cues. Despite similar performance, the detectors rely on different cues: AASIST emphasizes non-speech/environment cues, CA-MHFA focuses on localized phoneme artifacts, and SLS relies on word boundaries and spectral integrity. We move beyond speculative reasoning and validate our findings by causal masking of the primary detector cues...

论文介绍 提出一个音频原生可解释性管道,使用Integrated Gradients在时间对齐的自监督表示上定位深度伪造语音检测器的决策证据。应用于三个基于WavLM的检测器,揭示它们依赖不同线索,如非语音环境、音素伪影或词边界。研究问题在于理解检测器决策机制,应用在提高透明度和鲁棒性。

Ethical and Technical Limits of Deepfake Speech Datasets

第一作者: Vojtěch Staněk · 方向: 安全研究

Abstract:Claims about the robustness and fairness of deepfake speech detectors are only as credible as the datasets used to train and evaluate those systems. We present a dataset-level audit of the deepfake speech landscape. We compile and analyze 39 deepfake speech datasets, examining key attributes including accessibility, documentation, demographic and language coverage, dataset scale, and the underlying bona fide speech sources. Our audit reveals two important takeaways. Firstly, fairness assessment is largely infeasible because most datasets lack demographic metadata, and only a few contain gender or language labels. This prevents any meaningful subgroup analysis and leaves other demographic attributes unaddressed. Secondly, we identify substantial overlap in underlying bona fide source corpora across datasets, which can undermine cross-dataset evaluation and lead to overstated...

论文介绍 对39个深度伪造语音数据集进行审计,检查可访问性、人口统计覆盖等关键属性。发现公平性评估不可行,因为大多数数据集缺乏人口统计数据,且源语料库重叠可能影响跨数据集评估。研究问题在于数据集的伦理和技术限制,应用在改进数据集质量和评估标准。

RAT: Reference-Augmented Training for ASV Anti-Spoofing

第一作者: Vojtěch Staněk · 方向: 安全研究

Abstract:We introduce a spoofing countermeasure architecture conditioned on speaker-reference recordings, but observe that it converges to a solution that effectively ignores the reference during inference. Surprisingly, training with a reference channel induces invariance that improves deepfake detection, even when the reference is absent or mismatched during inference. Based on this observation, we propose a Reference-Augmented Training (RAT) strategy. RAT yields improved detection performance compared to single-utterance baselines, even when the reference recording is replaced with a zero vector at inference. Through rigorous analysis, we demonstrate that the optimization process rapidly diminishes the reference contributions, leading to inference largely independent of the reference channel. Using RAT, we achieve state-of-the-art 2.57% EER and 0.074 minDCF on the ASVspoof 5...

论文介绍 提出参考增强训练(RAT)策略,用于反欺骗系统。观察到条件于参考录音的架构在训练时忽略参考,但参考增强训练提高了深度伪造检测性能,即使推理时无参考或不匹配。研究问题在于改进语音反欺骗检测,应用在增强说话人验证系统的安全性,通过训练过程诱导不变性。

Secure Aggregation with Top-K Sparsification in Decentralized Federated Learning

第一作者: Hengxuan Tang · 方向: 隐私保护

Abstract:Secure aggregation is a vital component for mitigating gradient leakage in federated learning, but its communication cost conventionally scales with the gradient dimension. This becomes prohibitive for large models and even more pronounced in decentralized federated learning with limited bandwidth and unreliable nodes. Top-K gradient sparsification is an effective approach to reduce communication by transmitting only a few entries of the full gradient, while maintaining competitive model accuracy. Nevertheless, the top-K entries selected by each user are unpredictable and vary across users, which poses a challenge for efficient sparse secure aggregation. This paper studies information-theoretic secure aggregation with top-K sparsification in decentralized federated learning under user dropouts and user collusion. We propose a communication-efficient sparse secure aggregation...

论文介绍 本文研究了在用户退出和共谋威胁下,去中心化联邦学习中的安全聚合问题。核心挑战在于Top-K梯度稀疏化会使得每个用户选取的条目不同,给高效且安全的稀疏聚合带来困难。作者提出了一种通信高效的稀疏安全聚合方案,旨在降低通信成本的同时保护梯度隐私,以应对大型模型在带宽受限网络中的通信开销难题。

In Defense of Information Leakage in Concept-based Models

第一作者: Mateo Espinosa Zarlenga · 方向: AI 安全

Abstract:Concept-based models (CMs), deep neural networks that ground their predictions on representations aligned with human-understandable concepts (e.g., "round", "stripes", etc.), have been shown to learn representations that leak concept-irrelevant information. As the traditional narrative goes, this leakage is undesirable and should be eradicated as it leads to uninterpretable models. In this paper, we posit that this conventional view of leakage in CMs is not only ill-posed, as the evidence of how leakage makes a model less interpretable is often inconclusive, but also bound to lead to impractical CMs under common real-world constraints. Specifically, we argue that in real-world settings where concept incompleteness is the norm, some leakage is often necessary for constructing accurate and intervenable CMs. To this end, we propose that there is such a thing as benign leakage and...

论文介绍 基于概念的模型是深度神经网络的一种,其预测基于人类可理解的概念。本文挑战了传统观点,即概念模型中的信息泄露总是有害的。作者指出,在现实世界中概念往往不完整,因此一定程度的「良性泄露」对于构建准确且可干预的模型是必要的。文章探讨了泄露的合理性,并重新评估了其在可解释性中的作用。

From Transactions to Records: Reconceptualizing Blockchain Systems through a Lifecycle Lens

第一作者: Tom Barbereau · 方向: 系统安全

Abstract:Current blockchain research and analytics tend to prioritize observable on-chain transactions, obscuring the processes through which cryptocurrencies are created, publicised, retained, and disposed of. In response, this paper considers distributed ledger technologies from records management principles in ISO 15489-1:2016. Setting off by specifying the parallels -- that is transactions as "records", crypto-asset units as "information assets", and blockchains as "aggregations" -- we introduce a seven-stage lifecycle for blockchain data. We apply the framework to Bitcoin, a fungible token, and a non-fungible token. On this basis, we argue that blockchain systems are not merely transactional infrastructures but record management systems with distinctive characteristics. We discuss how the on-chain/off-chain boundary and privacy-enhancing technologies can complicate lifecycle...

论文介绍 现有区块链研究多关注链上交易,而忽略了加密资产创建、传播、保存和销毁的全过程。本文借鉴ISO 15489记录管理标准,将交易视为「记录」,提出了区块链数据的七阶段生命周期框架。通过应用于比特币和NFT的分析,论证了区块链不仅是交易基础设施,更是一种具有独特特性的记录管理系统,并讨论了链上/链下边界及隐私增强技术对生命周期的影响。

Improving Adversarial Transferability on Vision-Language Pre-training Models via Surrogate-Specific Bias Correction

第一作者: Lijia Yu · 方向: AI 安全

Abstract:Adversarial examples reveal vulnerabilities in Vision-Language Pre-training (VLP) models and provide insights for improving robustness. A key property is cross-model transferability, which enables transfer-based black-box attacks. However, existing attacks often rely heavily on the surrogate model, causing cross-model performance drops. One reason is that adversarial optimization may follow surrogate model responses more than input semantics, making the update direction effective on the surrogate but less transferable to unseen targets. We refer to this dependency as surrogate-specific bias. Motivated by this observation, DeBias-Attack improves transferability by correcting surrogate-specific bias in adversarial optimization directions. It maintains two perturbation branches. The main branch optimizes a perturbation on the original image and obtains the adversarial gradient...

论文介绍 对抗样本的跨模型迁移性是进行黑盒攻击的关键。本文发现,现有攻击方法容易过度依赖代理模型,导致生成的对抗样本对目标模型迁移性不佳,其根源在于「代理模型特异性偏差」。为此,作者提出了DeBias-Attack方法,通过维护两个扰动分支并在优化方向上校正这种偏差,从而提升对抗样本在不同视觉语言预训练模型间的迁移能力。

Advancing the State-of-the-Art in Empirical Privacy Auditing

第一作者: Nicole Mitchell · 方向: 隐私保护

Abstract:Parameter-efficient fine-tuning of large language models (LLMs) can exhibit problematic memorization of individual training examples. Empirical privacy auditing (EPA) quantifies this risk by measuring realistic data leakage on membership inference (MI) or reconstruction attacks. A key challenge in EPA is designing ``canary'' examples that are mixed with the privacy-sensitive training data. We propose generating synthetic canaries via high-temperature sampling ($T \geq 0.8$) from LLMs, using prompts tailored to the privacy-sensitive training data. These canaries act as high-influence outliers, ensuring high identifiability and hence strong audits. Further, since the canaries are themselves non-private, they are inspectable and can be inserted with repetition without jeopardizing the privacy of the real data. An important use of models fine-tuned on privacy-sensitive data is the...

论文介绍 大型语言模型的参数高效微调可能导致对个体训练数据的记忆化,带来隐私风险。经验隐私审计旨在量化这一风险。本文提出一种生成「合成金丝雀」的新方法:使用针对隐私数据定制的提示,通过高温采样从待审计模型生成高影响力的异常数据。这些可检查的非隐私金丝雀能有效标识记忆化,为审计提供了强有力的工具,尤其适用于数据敏感的领域模型。

A Modular Approach to Succinct Arguments for QMA

第一作者: James Bartusek · 方向: 系统安全

Abstract:Succinct argument systems are of central importance to modern crytpography, enabling the efficient verification of computational claims. In the classical setting, Kilian (STOC 92) established that any probabilistically checkable proof for NP can be transformed into a succinct argument system for NP using only collision-resistant hash functions. In the quantum setting, recent works have established the feasibility of (classically-verifiable) succinct arguments for QMA, capturing statements that require *quantum* proofs. However, known constructions all rely on the highly structured assumption of learning with errors (LWE), which stands in stark contrast with the unstructured assumptions that suffice for NP. In this work, we develop a new framework that broadens the cryptographic foundations of succinct arguments for QMA. We assume the existence of (i) an oblivious state...

论文介绍 简洁论证系统允许高效验证计算声明。在经典设定中,NP的简洁论证仅需无结构假设。然而,对于需要量子证明的QMA类,现有构造都依赖于高度结构化的LWE假设。本文提出一个新的模块化框架,拓宽了QMA简洁论证的密码学基础,仅需基础假设如「不经意状态生成」,从而缩小了量子与经典设定下基础假设要求的差距。

Privacy-Preserving Credit Risk Prediction with Alternative Data

第一作者: Hongzhe Zhang · 方向: 隐私保护

Abstract:Credit risk prediction is a critical problem in the consumer credit industry. Traditionally, financial institutions construct credit risk prediction models using borrowers' demographic, financial, and credit history data, collectively referred to as traditional data. Recent studies have demonstrated that alternative data, such as borrowers' mobile phone communication data, enable lenders to acquire fuller and more accurate profiles of borrowers' creditworthiness, thereby improving credit risk prediction performance. Nevertheless, alternative data are held by external entities independent of financial institutions. Directly sharing alternative data with financial institutions infringe on consumer privacy, yet existing credit risk prediction studies largely overlook this issue. To address this gap, we define a new problem, namely privacy-preserving credit risk prediction with...

论文介绍 利用手机通讯等替代数据可以提升信用风险预测的准确性,但这些数据通常由外部实体持有,直接共享会侵犯用户隐私。本文定义了「隐私保护的替代数据信用风险预测」新问题。作者设计了一个系统,允许金融机构在不获取原始替代数据的前提下,联合外部数据持有者安全地训练预测模型,从而在保护隐私的同时利用替代数据的价值。

Alignment Defends LLMs from Property Inference Attacks

第一作者: Pengrun Huang · 方向: 安全研究

Abstract:Large language models (LLMs) are increasingly fine-tuned on domain-specific datasets that may contain sensitive, dataset-level properties. Recent work has shown that such dataset-level information can be effectively extracted through property inference attacks, posing a confidentiality risk. Existing defenses against these attacks primarily operate by modifying the training data distribution and hence require access to the original data and retraining the model, limiting their applicability to settings where data is unavailable or models are already deployed. In this work, we propose alignment-based defenses for mitigating property inference attacks in LLMs. Our approach reshapes the model's output distribution towards a target property ratio via post-training alignment, without modifying the training data. In particular, we adapt two widely used RLHF frameworks--Direct...

论文介绍 针对领域数据集微调的大语言模型可能泄露数据集级属性,面临属性推理攻击的威胁。现有防御方法通常需要访问原始数据并重新训练模型。本文提出基于对齐的防御策略,通过后训练对齐技术(如直接偏好优化)调整模型输出分布,使其「对齐」到目标属性比例,从而在不修改原始训练数据的情况下,有效减轻此类攻击,提升模型部署后的隐私安全性。

Quality Is Not a Safety Proxy Under Quantization

第一作者: Sahil Kadadekar · 方向: 安全研究

Abstract:Quantized checkpoints are often screened first with quality metrics and only later, if at all, with direct safety tests. This paper audits that shortcut on a matched 51-row matrix spanning 6 models, 4 families, a 7-level GGUF ladder, and AWQ/GPTQ INT4 checkpoints. In this matrix the shortcut fails: all 36 quality-safety pairings split direction across models, and 9 hidden-danger rows plus 1 near-hidden-danger row show quality stable or improved while refusal falls by 12-68 percentage points. Seven of the 11 AWQ/GPTQ rows are hidden-danger. A four-probe mechanistic follow-up over the 17 Hugging Face-backed FP16/AWQ/GPTQ cells does not rescue it: entropy, refusal-direction, and calibration probes are weak or null separators of dangerous rows, and although probe-identified safety-associated neurons absorb 1.39$\times$ more quantization error overall ($p < 5 \times 10^{-7}$), the...

论文介绍 本文对将模型质量指标作为量化模型安全性代理的常用做法进行了审计。研究发现,在覆盖多种模型与量化方法的测试中,质量指标的稳定性与安全性的变化发生了解耦:存在多组“隐藏风险”行,其质量指标稳定或提升,但模型拒绝回答有害问题的比率却显著下降。后续的机制性分析也未能找到可靠的探针来分离这些危险情况,对实践中的安全筛选流程提出了重要警示。

nCMD: Benign-Anchored Feature Selection for Imbalanced Network Intrusion Detection

第一作者: Abu Fuad Ahmad · 方向: 网络安全

Abstract:Feature selection is critical for network intrusion detection systems (NIDS) operating under high-dimensional, highly imbalanced traffic, as found in operational and defense networks. Traditional filter methods rank features using global statistics computed symmetrically across classes and thus fail to capture the asymmetry of intrusion detection, where attacks are best characterized as deviations from dominant benign traffic. We propose benign-anchored Classwise Mean Deviation (nCMD), a lightweight and interpretable method that scores feature relevance based on the deviation of attack-class distributions from the benign-class mean, rather than a globally biased reference. This approach aligns feature selection with the operational semantics of NIDS at no additional computational cost. Across four benchmark datasets (CICIDS2017, CICDDoS2019, NSL-KDD, and UNSW-NB15), multiple...

论文介绍 针对网络入侵检测中数据高度不平衡的特点,本文提出了一种以良性流量为锚点的特征选择方法nCMD。该方法通过计算攻击类分布与良性类均值之间的偏差来评估特征相关性,这更符合入侵检测以“偏离常态”为核心的操作语义。在多个基准数据集上的实验表明,该方法在保持轻量的同时,能有效提升特征选择性能,增强检测器对少数类攻击的识别能力。

ARTA: Adaptive Reinforcement-Learning-Based Throttling Agent for RowHammer Vulnerabilities

第一作者: Marco Ho · 方向: 系统安全

Abstract:RowHammer vulnerability continues to intensify with DRAM scaling, reducing the activation threshold needed to induce bitflips and rendering existing defenses such as TRR, ECC, and refresh-based mechanisms vulnerable to sophisticated multi-bank hammering patterns. This work presents ARTA, a lightweight reinforcement-learning-based throttling mechanism that detects and suppresses RowHammer activity by monitoring fine-grained memory access behavior within the DRAM refresh window (t_REFW) and dynamically adjusting core throughput using a Q-learning frequency scaling governor. ARTA requires no DRAM-side hardware modification or offline training, using small SRAM structures in the memory controller -- a per-core, per-bank FIFO queue (CBF) and a compact Q-table -- for immediate deployment. Our evaluation shows that ARTA eliminates all bitflips at N_BO values down to 64, reduces...

论文介绍 RowHammer漏洞随DRAM工艺缩小而加剧。本文提出ARTA,一种基于强化学习的轻量级动态节流机制。它通过监控DRAM刷新窗口内的细粒度内存访问行为,利用Q学习频率调节器动态调整核心吞吐量以抑制RowHammer攻击。该方法无需对DRAM硬件进行修改,也无需离线训练,仅依赖内存控制器中的小型SRAM结构即可部署,为应对日益复杂的RowHammer模式提供了一种自适应防御方案。

Toward Calibrated, Fair, and accurate Deepfake Detection

第一作者: Ryan Brown · 方向: 安全研究

Abstract:Deepfake detectors show large performance gaps across demographic groups. Existing fairness approaches require demographic labels, retraining, or sacrifice accuracy. We introduce Face-Fairness (FF), a plug-and-play framework for bias mitigation. Our primary contribution, Face-Feature Tuning (FFT), is the first demographic label-free fairness method demonstrated for deepfake detection: a lightweight calibrator that performs a logit remapping conditioned on frozen face embeddings. We complement FFT with two variants: FF-Max, which maximizes worst-group accuracy when demographics are available, and FF-Discover, which does the same with embedding-discovered groups. Across in-domain and cross-dataset test settings, FF consistently reduces FPR/TPR gaps and improves minimum group accuracy while maintaining (often improving) overall accuracy. The approach is detector-agnostic, adds...

论文介绍 现有深度伪造检测器在不同人口群体间存在显著性能差异。本文提出一个即插即用的公平性框架Face-Fairness。其核心组件Face-Feature Tuning是一种无需人口统计标签的轻量校准器,它通过基于人脸嵌入对模型输出的对数进行重映射来缓解偏差。该方法与具体检测器无关,实验表明其能在维持整体准确率的同时,有效缩小不同群体间的性能差距,提升最差群体的准确率。

QSplitFL: Capability Aware Deep Q-Learning for Optimal Split Point Selection in Split Federated Learning

第一作者: Nazmus Shakib Shadin · 方向: AI 安全

Abstract:Federated Learning (FL) combined with Split Learning (SL) is a privacy preserving paradigm that enables training deep neural networks (DNNs) on resource constrained devices while reducing overall training cost. However, determining the optimal split point, meaning the layer where the model is divided still remains a critical challenge, especially when clients have heterogeneous hardware capabilities. Fixed split points can overload weak devices and increase the communication and server load, which slows convergence and reduces stability. This paper introduces QSplitFL, a novel capability-aware Deep Q-Network (DQN) framework for optimal split point selection in Split learning based Federated Learning (SFL) environments. Unlike existing approaches that rely on high-dimensional model weight representations, QSplitFL employs a lightweight state representation derived directly from...

论文介绍 在分割联邦学习中,为计算能力异构的客户端选择最优模型分割点是一个关键挑战。本文提出QSplitFL,一个基于深度Q网络的自适应框架。它采用轻量化的状态表示(而非复杂的模型权重表征),使智能体能够根据客户端设备能力感知地学习并选择最佳分割层,以优化通信开销、设备负载和训练收敛稳定性,从而提升异构环境下的训练效率。

LLM-as-a-Discriminator: When Synthetic Tables Still Look Real

第一作者: Manel Slokom · 方向: AI 安全

Abstract:Privacy and data sharing are often in tension. Many organizations use synthetic data to reduce privacy risk and still share useful data. For tabular data, auditing privacy remains hard. In many cases, even humans cannot easily tell if a table is real or synthetic. In this paper, we propose a method based on LLM discrimination. We ask an LLM to classify each table sample as REAL or SYNTHETIC. We test two settings: C1 with table only, and C2 with table plus distributional metadata. We use LLaMA as an open model and Gemini as a reference model. In our experiments, we run three synthesis models, CTGAN, TVAE, and Gaussian Copula, on two public datasets, UCI Adult and ACS Census. We collect 451 valid trials. Our results show clear differences between models. On Adult, LLaMA reaches DRS=0% in reported cells, while Gemini reaches DRS=100% for CTGAN and TVAE. On Census, LLaMA predicts...

论文介绍 为缓解隐私风险,许多机构使用合成表格数据。然而,审计合成数据的隐私性仍然困难。本文探索了利用大语言模型作为判别器,直接对表格样本进行“真实”或“合成”分类的方法。实验在多个数据集和合成模型上测试了不同提示设置(仅表格或附加分布元数据)。结果显示,LLM判别器能有效区分数据来源,但不同模型(如LLaMA与Gemini)以及合成方法间的表现存在显著差异,揭示了该审计方法的潜力和挑战。

TacForeSight: Force-Guided Tactile World Model for Contact-Rich Manipulation

第一作者: Yujie Zang · 方向: 机器人操作 · 来源: cs.RO

Abstract:Contact-rich manipulation requires robots to continuously perceive and regulate evolving physical interactions under dynamic contact transitions or complex surface geometries. Recent imitation learning methods improve contact-aware control by incorporating tactile or force feedback, but they rarely model the asymmetric spatiotemporal roles of global force and local tactile sensing. To address this, we propose TacForeSight, a lightweight force-conditioned tactile foresight framework for real-time manipulation. The core component is TacForceWM, a tactile world model that predicts short-horizon tactile latent dynamics from dual-finger tactile observations conditioned on high-frequency wrist force and torque signals. Another key component, the Predictive Tactile-Conditioned Policy, leverages the predicted latents as anticipatory contact priors, models the current-to-future tactile...

论文介绍 对于接触丰富的机器人操作任务,同时利用全局力觉和局部触觉信号进行预测与控制至关重要。本文提出TacForeSight框架,其核心是一个力条件化的触觉世界模型TacForceWM,能从双指触觉观测和高频腕力信号中预测短期内的触觉潜态动态。预测结果被作为先验接触信息,注入到预测性策略中,使机器人能够预见未来交互状态,从而更平稳、鲁棒地完成精细接触操作任务。

EM-Fall: Embodied mmWave Sensing for Day-and-Night Fall Detection on Humanoid Robots

第一作者: Yanshuo Lu · 方向: 具身智能 · 来源: cs.RO

Abstract:Falls are one of the leading causes of injury and hospitalization among elderly individuals, making reliable fall awareness an essential capability for safety monitoring in residential environments. However, existing fall detection systems often rely on wearable devices or fixed sensing installations, which may suffer from low user compliance, limited spatial coverage, or degraded performance under occlusion and poor lighting conditions. In this work, we propose \textbf{EM-Fall}, an embodied fall detection framework deployed on a mobile humanoid robot. The system integrates millimeter-wave (mmWave) sensing with robotic mobility, allowing the robot to actively adjust its sensing viewpoint and maintain target observability across rooms and under occlusion. To address interference in complex residential environments, including pet motion and multipath artifacts, we design a...

论文介绍 为提升居家环境中对老年人跌倒检测的可靠性与覆盖范围,本文提出EM-Fall,一个部署于移动人形机器人上的具身化跌倒检测框架。该系统结合毫米波雷达感知与机器人的移动能力,使其能主动调整视角以规避遮挡。为应对家居环境中宠物运动、多径干扰等挑战,系统设计了专门的信号处理和时序特征提取网络,旨在实现全天候、跨房间的鲁棒跌倒事件监测。

Generation of Diverse and Functional Robot Designs using Superquadrics Parametrisation and Quality-Diversity

第一作者: Leni Le Goff · 方向: 具身智能 · 来源: cs.RO

Abstract:Generative design of robots requires navigating a vast search-space, encompassing physical configurations and behavioural parameters. Evolutionary Algorithms (EAs) have shown promising results, but often converge prematurely to a small set of sub-optimal designs. Most EAs fail to maintain sufficient diversity in the population that would allow the discovery of distinct functional robots. To counter premature convergence, we introduce a superquadrics-based representation (SQs) for robot bodies. SQs are interpretable, compact and computationally efficient mathematical representations of 3D geometrical shapes that can be tuned to specific design-spaces. To encourage morphological diversity, we combine this representation with a quality-diversity (QD) algorithm (MAP-Elites). We compare SQs and Compositional Pattern Producing Networks representations as generators of morphologies...

论文介绍 本文针对机器人生成设计中进化算法易过早收敛的问题,提出了一种基于超级二次曲面参数化和质量多样性算法的方法。超级二次曲面提供了一种可解释、紧凑的三维形状表示,与MAP-Elites算法结合,能有效维持种群多样性,生成多样化的功能性机器人形态。该方法有望应用于机器人设计自动化,提高设计效率和创新性。

A Spiking Neural Architecture for Coordinating Arm and Locomotor Control

第一作者: Lea Steffen · 方向: 导航与运动 · 来源: cs.RO

Abstract:Spiking Neural Networks (SNNs) coupled with neuromorphic hardware offer energy-efficient solutions for humanoid robot control. However, existing SNN-based motor control systems address bipedal locomotion and arm control in isolation, leaving integrated control of both unaddressed. We present a spiking architecture that coordinates force-based arm control and bipedal locomotion in a simulated humanoid, using the Neural Engineering Framework (NEF) and Semantic Pointer Architecture (SPA). High-level action selection between locomotor and arm control is mediated by a biologically grounded spiking basal ganglia model. We validate the system through co-simulation of Nengo, for the neural control, and Isaac Sim, demonstrating successful target reaching, continuous digit drawing, path-following locomotion, and finally, switching between walking and arm control via basal ganglia...

论文介绍 本文针对人形机器人运动控制中双足运动与臂控制分离的问题,提出了一种脉冲神经网络架构。该架构利用神经工程框架和语义指针架构,协调力基臂控制和双足运动,并通过生物可信的脉冲基底节模型进行动作选择。实验通过Nengo和Isaac Sim的协同仿真验证了系统在目标到达、路径跟踪等任务中的有效性,为高效能人形机器人控制提供新途径。

Resilient Navigation for Autonomous Farm Robots by Leveraging Jerk-Augmented Models with IMU-Only Disturbance Rejection

第一作者: Batu Candan · 方向: 导航与运动 · 来源: cs.RO

Abstract:Precise state estimation for navigation of autonomous agricultural robots is often compromised by sensor outages (GNSS/LiDAR/Visual) and high-frequency vibrations inherent in off-road environments. This paper proposes a robust navigation algorithm based on a jerk-augmented Extended Kalman Filter (EKF) integrated with a Multiple Tuning Factor (MTF) adaptation method. Unlike standard EKF approaches that assume constant measurement noise, our method dynamically adjusts the measurement covariance matrix in real-time, allowing the system to cope with sudden disturbances and sensor outliers. We evaluate the algorithm using real-world data from a Salin247 autonomous robot. Results demonstrate that jerk-augmentation combined with MTF adaptation significantly reduces 3D position Root Mean Square Error (RMSE) compared to baseline EKF models, providing superior dead-reckoning capabilities.

论文介绍 本文针对自主农业机器人在越野环境中导航状态估计受传感器中断和振动影响的问题,提出了一种加速度增强扩展卡尔曼滤波导航算法。该算法集成多调整因子自适应方法,实时调整测量噪声协方差,增强对突发干扰和传感器离群值的鲁棒性。实验证明,与标准EKF相比,该方法显著降低了三维位置均方根误差,提升了航迹推算性能。

AllDayNav: Lifelong Navigation via Real-World Reinforcement Learning

第一作者: Hang Yin · 方向: 导航与运动 · 来源: cs.RO

Abstract:Lifelong embodied navigation in dynamic environments requires robots to form persistent scene understanding from fragmentary observations, which remains difficult for existing methods that rely on explicit maps or scene graphs and struggle to generalize beyond structured settings. We propose AllDayNav, a lifelong self-learning navigation framework that implicitly encodes scene dynamics into the billion-scale parameters of a large model via reinforcement learning, powered by a self-evolving multimodal memory that maintains and updates visual keyframes, semantic descriptions, and temporal context while autonomously generating open-vocabulary instructions, image goals, and structured rewards. Experiments in both synthetic and real-world environments across cross-room, cross-episode, and cross-task scenarios show that AllDayNav achieves success rates approaching $100\%$ and...

论文介绍 本文针对动态环境中机器人终身导航的挑战,提出了AllDayNav框架。该框架通过强化学习将场景动态隐式编码到大型模型参数中,并利用自进化多模态记忆管理视觉关键帧和语义信息。实验显示,在跨房间、跨任务等场景中,AllDayNav的成功率接近100%,为终身自学习导航提供了有效解决方案。

Task Robustness via Re-Labelling Vision-Action Robot Data

第一作者: Artur Kuramshin · 方向: 机器人操作 · 来源: cs.RO

Abstract:The recent trend in scaling models for robot learning has resulted in impressive policies that can perform various manipulation tasks and generalize to novel scenarios. However, these policies continue to struggle with following instructions, likely due to the limited linguistic and action sequence diversity in existing robotics datasets. This paper introduces Task Robustness via Re-Labelling Vision-Action Robot Data (TREAD), a scalable framework that leverages large Vision-Language Models (VLMs) to augment existing robotics datasets without additional data collection, harnessing the transferable knowledge embedded in these models. Our approach leverages a pretrained VLM through three stages: generating semantic sub-tasks from original instruction labels and initial scenes, segmenting demonstration videos conditioned on these sub-tasks, and producing diverse instructions that...

论文介绍 本文针对机器人学习中策略遵循指令能力弱的问题,提出了TREAD框架。该框架利用大型视觉语言模型对现有数据集进行增强,通过生成语义子任务、分割视频和产生多样指令,提升数据多样性。这有助于增强机器人策略的任务鲁棒性和指令遵循能力,无需额外数据采集。

AgniNav: Configuration-Driven Cross-Embodiment Local Planning for Robot Navigation

第一作者: Tianhao Zang · 方向: 导航与运动 · 来源: cs.RO

Abstract:Monocular local navigation is attractive for lightweight robots, but existing vision-based policies often couple perception to a specific body, camera height, and footprint, making transfer from wheeled bases to legged platforms dependent on retraining or active depth hardware. This paper introduces AgniNav, a configuration-driven local navigation framework that standardizes cross-embodiment transfer at the collision-envelope level. Each robot is specified by a measurable four-parameter safety envelope: collision-relevant height, front length, rear length, and half width. The height parameter conditions an image-to-scan network to predict a one-dimensional, collision-relevant pseudo-laserscan from a monocular color image, while the remaining footprint parameters configure a dimension-aware local planner for collision checking. Training uses height-conditioned column-minimum...

论文介绍 本文针对机器人导航策略跨平台迁移的困难,提出了AgniNav框架。该框架通过可测量的四参数安全包络标准化碰撞检测,其中高度参数条件化图像到扫描网络预测伪激光扫描,其他参数配置本地规划器。这使得导航策略能在不同机器人形态间迁移,无需重新训练。

MV-Actor: Aligning Multi-View Semantics and Spatial Awareness for Bimanual Manipulation

第一作者: Yinchen Tian · 方向: 机器人操作 · 来源: cs.RO

Abstract:Robotic manipulation has been widely applied in industrial scenarios. Compared with single-arm manipulation, bimanual manipulation is equipped with multiple cameras to capture information from different viewpoints. However, existing multi-view policies encode each view independently or fuse view features shallowly, resulting in limited sharing semantic perception and unreliable spatial awareness. In this paper, we propose \textbf{MV-Actor}, a multi-view perception framework that builds a unified semantic-spatial representation for bimanual manipulation. First, MV-Actor performs Multi-view Semantic Interaction to share semantic perception across views. Then it uses Semantic-Spatial Token Interaction to ground visual semantics with feed-forward reconstruction model features and acquire reliable spatial awareness. Finally, a Guided Metric Depth Repair module refines degraded...

论文介绍 本文针对双臂操作中多视图策略的语义和空间感知不足问题,提出了MV-Actor框架。该框架通过多视图语义交互共享感知,结合语义-空间令牌交互建立统一表示,并利用引导度量深度修复模块优化深度信息。这增强了双臂操作的语义理解和空间感知能力,适用于工业应用。

Embodiment-conditioned Generalist Control for Multirotor Aerial Robots

第一作者: Orestis Konstantaropoulos · 方向: 具身智能 · 来源: cs.RO

Abstract:We present a generalist position control policy capable of controlling arbitrary multirotor configurations of a certain rotor count (e.g., hexarotors or quadrotors) with a single set of network weights. The policy is conditioned on a physics-grounded embodiment descriptor: a mass and inertia-normalized control allocation matrix that captures how mass-normalized motor thrusts generate linear and angular accelerations in the body-frame. To train the policy, we sample from a broad distribution of arbitrary multirotor configurations, including non-planar and asymmetric systems, and optimize a single, compact network using Proximal Policy Optimization. Training requires only five minutes on an RTX 3090 GPU using a custom NVIDIA Warp-based dynamics simulator. Through extensive simulation experiments, we show that embodiment conditioning enables robust generalist control across...

论文介绍 本文针对多旋翼飞行器控制策略难以跨配置泛化的问题,提出了一种具身条件化的通才控制策略。该策略使用物理基础的控制分配矩阵作为条件,训练单一网络控制多种多旋翼形态,包括非对称和非平面系统。实验显示,该方法在仿真中实现了鲁棒的泛化控制,训练高效。

GUIDE: Goal-Initialized Directional Understanding for End-to-End Visual Navigation

第一作者: Liang Wang · 方向: 导航与运动 · 来源: cs.RO

Abstract:Learning-based visual navigation for legged robots typically relies on continuous goal updates from hierarchical state estimation to provide a persistent directional reference. This reliance incurs additional sensory and computational overhead and deviates from fully end-to-end mobile autonomy. Furthermore, under partial observability, policies are prone to learn myopic behaviors, easily becoming trapped in dead ends and complex structural layouts. To address these limitations, we investigate a goal-initialized navigation setting, where the target is provided only once at the beginning of an episode, requiring the robot to operate based on intrinsic spatial memory without subsequent goal updates from external modules. In this work, we propose GUIDE, a fully end-to-end reinforcement learning framework designed to cultivate internal directional awareness. Specifically, GUIDE...

论文介绍 研究问题:学习型视觉导航通常依赖外部模块持续提供目标更新,导致额外传感和计算开销,并可能引发短视行为。核心方法:提出GUIDE框架,一种端到端强化学习方法,通过目标初始化培养机器人内部方向感知,无需后续目标更新。可能应用:提升腿足机器人在复杂环境中的自主导航能力,实现更高效的移动。

IMPACT: Learning Internal-Model Predictive Control for Forceful Robotic Manipulation

第一作者: Jiawei Gao · 方向: 机器人操作 · 来源: cs.RO

Abstract:Real-world robotic manipulation tasks often involve forceful interactions with the environment, such as using tools of varying weights, transporting objects with different masses, and performing contact-rich tasks like table wiping. Previous learning-based approaches typically employ imitation learning policies that output target end-effector poses tracked by low-level impedance controllers. In these systems, forceful interactions are either implicitly realized through steady-state tracking errors or explicitly commanded using wrist force/torque or tactile sensors. However, implicit approaches generalize poorly across object weights, while explicit approaches require specialized hardware and increase system complexity. In this work, we propose IMPACT, a framework that decouples these forceful tasks into task-planning and internal-model-based predictive control. Extensive...

论文介绍 研究问题:现实机器人操作涉及力交互,如工具使用和接触任务,现有方法隐式处理泛化差,显式处理增加硬件复杂度。核心方法:提出IMPACT框架,将力任务解耦为任务规划和基于内部模型的预测控制,以提升适应性。可能应用:改善物体搬运、工具操作等接触丰富任务的执行效率。

Bridging Semantics and Physical Execution: A Neuro-Symbolic Framework for Multi-Pair Robotic Assembly

第一作者: Xinyi Li · 方向: 具身智能 · 来源: cs.RO

Abstract:Multi-pair robotic assembly in unstructured environments faces spatial interference and contact uncertainties. Existing paradigms fail to bridge cognitive decision-making and physical execution, as they either encounter state-space explosion and knowledge bottlenecks or suffer from logical hallucinations and topological conflicts. We propose an end-to-end neuro-symbolic framework that solves the challenge hierarchically: generating optimal subgraphs for each pair, decoupling generality from edge cases, and then resolving cross-pair interferences. Given an eye-on-hand RGB-D assembly scene, the framework extracts semantic instance identity and state while quantifying the scene for divergence calculation. For each pair, optimal subgraph is generated via LLM using barely basic actions to mitigate hallucinations. Supportive actions for edge cases are reasoned and inserted with a...

论文介绍 研究问题:非结构化环境中多对机器人装配面临空间干扰和接触不确定性,现有方法难以桥接认知决策与物理执行。核心方法:提出端到端神经符号框架,分层生成最优子图并解决跨对干扰,结合语义提取和大语言模型。可能应用:自动化装配生产线,提高操作鲁棒性和泛化能力。

ros2probe: Non-intrusive, Kernel-selective Observability for Robot Operating System 2 Middleware

第一作者: Jisang Yu · 方向: 具身智能 · 来源: cs.RO

Abstract:Robot Operating System 2 (ROS 2), the de facto standard middleware framework for robots, runs each robot as a graph of nodes communicating over the Data Distribution Service (DDS), a publish/subscribe substrate. Observing this inter-node communication in real time is essential to robot development, yet it has a price. A tool can receive data only by joining the DDS domain as a subscriber that discovery has matched to the publisher, so observing folds the tool into the system it measures and perturbs it. We define this protocol-inherent perturbation as the observer's probe effect. It inflates the discovery plane, adds deserialization cost on the observer, makes the loss it reports diverge from what the subscriber actually received, and near saturation displaces the subscriber's messages. The only escape, capturing all wire traffic passively, discards ROS 2 message semantics and...

论文介绍 研究问题:ROS 2节点通信的实时观察工具会引入扰动,如增加发现负载和影响消息接收准确性。核心方法:提出ros2probe工具,实现非侵入式、内核选择性的可观察性,避免协议固有扰动。可能应用:提升机器人系统开发调试效率,减少测量干扰,优化中间件性能。

Hand-centric Human-to-Robot Trajectory Transfer from Video Demonstrations via Open-World Contact Localization

第一作者: Yitian Shi · 方向: 机器人操作 · 来源: cs.RO

Abstract:Learning from human video demonstrations remains challenging due to noisy hand-object interactions, unseen objects with partial observation, and cross-embodiment discrepancy. To address these challenges, we present \textit{HOWTransfer} (\emph{H}and-\emph{O}bject \emph{O}pen-\emph{W}orld Transfer), a hand-centric framework that distills human demonstrations into contact-aware, taxonomy-informed, and diverse robotic trajectories. Instead of relying on object-specific descriptions, vision-language queries, or explicit object-state tracking, \emph{HOWTransfer} recovers temporally consistent 3D hand motion and localizes temporal contact intervals by reasoning over observed hand-object interaction cues. The localized contact onsets are then used to retarget human grasp intent into multi-modal parallel-jaw grasp hypotheses, which are propagated along the recovered wrist trajectory to...

论文介绍 研究问题:从人类视频学习机器人轨迹因手物交互噪声、未知物体和跨体现差异而困难。核心方法:提出HOWTransfer框架,以手为中心,通过接触定位提取人类手部运动并转移为机器人轨迹,无需物体特定描述。可能应用:减少机器人数据收集成本,加速灵巧操作策略学习。

UniDexTok: A Unified Dexterous Hand Tokenizer from Real Data

第一作者: Dong Fang · 方向: 机器人操作 · 来源: cs.RO

Abstract:Dexterous hands are essential for fine-grained manipulation, but their hardware designs vary substantially across embodiments. Differences in kinematics, joint definitions, and degrees of freedom make it difficult to define a shared state representation compared with parallel grippers. As a result, dexterous-hand data remains fragmented and difficult to use for joint training. In this work, we propose the Unified Dexterous Hand Model (UDHM), which maps human and robot hand states into a shared 22-DoF semantic interface. Based on UDHM, we introduce UniDexTok, a retargeting-free state tokenizer that learns embodiment-conditioned discrete tokens from standardized real joint states. UniDexTok provides a unified representation for heterogeneous dexterous hands without relying on retargeting or simulation data. Compared with the recent baseline UniHM, UniDexTok reduces MPJAE from...

论文介绍 研究问题:不同灵巧手硬件设计导致状态表示碎片化,难以用于联合训练和数据共享。核心方法:提出统一灵巧手模型和UniDexTok标记器,从真实数据学习统一离散表示,无需重定向或仿真。可能应用:促进异构灵巧手数据的标准化使用,提升跨体现学习效率。

Dexterous Point Policy: Learning Point-based Dexterous Hand Policies from Human Demonstrations

第一作者: Beomjun Kim · 方向: 机器人操作 · 来源: cs.RO

Abstract:Robotic foundation models pre-trained on human demonstration videos have shown promise, but a significant embodiment gap remains when the resulting policies are deployed on real robots. A common remedy is to fine-tune these models on robot-specific demonstrations. However, robot data collection can be prohibitively expensive and time-consuming, which is particularly acute in dexterous manipulation, e.g., teleoperating a multi-fingered hand for even a single atomic task can take days. To address this, we introduce Dexterous Point Policy, a framework that learns dexterous manipulation policies directly from human videos and requires no robot demonstrations. Our core insight is that a unified 3D keypoint representation can bridge human and robot embodiments when used for both observations and actions. Specifically, we extract 3D keypoints of task-relevant objects and human hands...

论文介绍 研究问题:从人类视频学习灵巧操作策略存在体现差距,机器人数据收集昂贵耗时。核心方法:提出Dexterous Point Policy框架,使用统一3D关键点表示桥接人类和机器人体现,直接从视频学习策略。可能应用:减少对机器人演示的依赖,加速灵巧手在现实任务中的部署。

LieIPM: Lie Group Interior Point Method for Direct Trajectory Optimization of Rigid Bodies

第一作者: Sangli Teng · 方向: 导航与运动 · 来源: cs.RO

Abstract:Designing dynamically feasible trajectories for rigid bodies is a fundamental problem in robotics. While direct methods are widely used, the existing constrained optimizers typically operate in Euclidean space and ignore the manifold structure of rigid body motions. This mismatch may introduce singularities or lead to poorly conditioned optimization problems. To bridge this gap, we develop a structure-aware framework for constrained trajectory optimization directly on matrix Lie groups. Our approach is based on the second-order rigid body models utilizing Lie group structures, which enables efficient Newton-type updates while preserving the underlying geometry. Building on this model, we propose a line-search Lie Group Interior Point Method (LieIPM) to handle constraints on the manifolds. We instantiate the framework for rigid body motion planning using Lie group variational...

论文介绍 研究问题:刚体轨迹优化中,欧氏空间方法可能忽略流形结构,导致奇异性或病态优化问题。核心方法:提出LieIPM框架,基于李群结构进行约束轨迹优化,使用线搜索内点法保持几何特性。可能应用:改善机器人运动规划的动态可行性,适用于动力学可行的轨迹生成。

VeriSpace: Spatially Grounded Action Verification for Vision-Language-Action Models

第一作者: Guiyu Zhao · 方向: VLA 通用模型 · 来源: cs.RO

Abstract:Vision-language-action (VLA) models have shown strong promise for robotic manipulation, but their reliability at test time remains limited by one-shot action prediction, where even small action errors can cause grasp failure, collision, or incorrect task progression. A natural alternative is to equip VLA systems with test-time verification, allowing multiple candidate actions to be proposed and evaluated before execution. However, reliable action verification is challenging because it requires not only distinguishing subtle geometric differences between candidate actions, but also assessing whether an action makes meaningful progress toward the task goal. We present VeriSpace, a 3D-aware action verifier for test-time action selection in VLA systems. VeriSpace evaluates candidate actions through two key components: Dual-Path 3D-Injected Scene Encoding, which constructs a scene...

论文介绍 针对视觉-语言-动作模型因一次性动作预测导致的可靠性问题,本文提出了VeriSpace,一个用于测试时动作选择的3D感知验证器。该系统通过双路径3D注入场景编码和物理一致性评估,对候选动作进行筛选,旨在提升机器人操作的成功率和任务进展的可靠性。

Uncovering Vulnerability of Vision-Language-Action Models under Joint-Level Physical Faults

第一作者: Minsoo Jo · 方向: VLA 通用模型 · 来源: cs.RO

Abstract:Deploying Vision-Language-Action (VLA) models in real robotic systems requires robustness not only to semantic and perceptual variations, but also to embodiment-side faults that change how actions are physically realized. Real robots can experience joint-level changes caused by actuator degradation, hardware faults, safety limits, collision damage, or wear-induced friction. These faults are critical because they alter the action-to-motion interface of a policy, disrupting the learned closed-loop relationship between commanded actions, realized motion, and subsequent observations. In this work, we study realistic joint-level physical faults and show that VLA models are vulnerable when predicted actions are executed through a perturbed robot body. Our analysis reveals joint-dependent effects, with heterogeneous degradation in task success across affected joints. We also show...

论文介绍 本文研究了视觉-语言-动作模型在面临关节级物理故障时的脆弱性。研究表明,由执行器退化、硬件故障或碰撞等引起的关节异常,会改变动作与运动的映射关系,导致模型预测的指令无法被正确执行,从而严重破坏任务成功率,并且这种影响在不同关节上呈现异质性。

Act on What You See: Unlocking Safe Social Navigation in Vision-Language-Action Models

第一作者: Qingzi Wang · 方向: VLA 通用模型 · 来源: cs.RO

Abstract:Safe social navigation requires robots to distinguish people from ordinary obstacles and to react before danger becomes imminent. We show that pretrained Vision-Language-Action (VLA) models already encode pedestrian-object distinctions and future collision signals in their internal representations, but behavior cloning fails to translate these signals into socially appropriate actions. To address this mismatch, we propose SALSA, a two-stage annotation-free post-training framework: (1) social behavioral alignment bridges intermediate-layer social features to the action head and trains on counterfactual human-object scene pairs to break visual saliency shortcuts; (2) temporal safety alignment provides automatically generated future-risk supervision to enable anticipatory collision avoidance. On SCAND and real-world deployment, SALSA reduces near-collisions by 86.4% and improves...

论文介绍 本文关注机器人的安全社交导航问题。研究指出,预训练的视觉-语言-动作模型虽能编码行人与障碍物的区分及未来碰撞信号,但行为克隆未能将其转化为安全行为。为此,作者提出SALSA框架,通过社会行为对齐和时间安全对齐两个阶段进行无标注后训练,以实现预测性避碰。

GuideWalk: Learning Unified Autonomous Navigation and Locomotion for Humanoid Robots across Versatile Terrains

第一作者: Haoxuan Han · 方向: 导航与运动 · 来源: cs.RO

Abstract:Humanoid robots have achieved strong locomotion capabilities, but reliable navigation on versatile terrains remains challenging because obstacle avoidance must be coordinated with dynamically feasible motion. In this work, we present GuideWalk, a unified end-to-end framework that integrates traversability-aware navigation guidance with terrain-adaptive locomotion teacher for humanoid navigation. Specifically, we introduce a navigation module that provides explicit velocity guidance, decoupling obstacle avoidance from terrain conditions to enable robust planning across diverse environments. We propose a composite teacher distillation scheme, where goal-directed commands and dynamically consistent actions are aggregated and distilled into a single policy. To further improve robustness, the distilled policy is refined with reinforcement learning and an auxiliary behavior cloning...

论文介绍 人形机器人在复杂地形上的可靠导航仍是挑战。本文提出GuideWalk,一个统一的端到端框架,整合了可通行性感知的导航引导与地形自适应的运动教师。该框架通过显式速度引导解耦避障与地形条件,并采用复合教师蒸馏和强化学习进行优化,以实现跨多样化地形的动态可行导航。

UMI-Bench 1.0: An Open and Reproducible Real-World Benchmark for Tabletop Robotic Manipulation with UMI Data

第一作者: Shi Jin · 方向: 机器人操作 · 来源: cs.RO

Abstract:Real-robot evaluation is essential for understanding whether learned manipulation policies can operate reliably outside curated demonstrations. This need is particularly pressing for Universal Manipulation Interface (UMI)-style policies, whose performance depends on the coupling between wrist-view observations, action representation, data collection, and physical deployment. Existing real-world benchmarks have made important progress, but they are not designed around this UMI data-to-deployment setting. We present UMI-Bench 1.0, a local-first real-robot benchmark for standardized evaluation of UMI-style manipulation policies. To the best of our knowledge, this is the first benchmark dedicated to real-world evaluation of UMI-based manipulation models. UMI-Bench aligns data collection, scene reset, policy execution, result logging, and task-factor analysis within a unified...

论文介绍 针对基于通用操作接口数据的学习型策略,其在真实机器人上的可靠评估至关重要。本文提出了UMI-Bench 1.0,这是一个本地优先的真实机器人基准,专门用于标准化评估此类策略。据作者所知,这是首个专注于UMI数据到部署场景的实操评估基准,旨在统一流程并支持任务因素分析。

Test-time Adversarial Takeover: A Real-time Hijacking Interface against Robotic Diffusion Policies

第一作者: Zi Yin · 方向: 机器人操作 · 来源: cs.RO

Abstract:Diffusion-based action generation has become a foundational component of embodied AI, but its reliance on visual conditioning leaves deployed visuomotor policies vulnerable to adversarial manipulation. Most prior attacks focus on disruption: they perturb the observation stream to reduce task success or induce erratic behavior. We study a stronger threat, Test-time Adversarial Takeover (TAKO), in which an attacker obtains a real-time steering interface over a frozen robot policy and turns it into a remotely piloted instrument. TAKO learns a small vocabulary of reusable universal patches through differentiable diffusion inference; at test time, the attacker switches among these patches in the camera stream to compose attacker-chosen trajectories. This works because the perturbation acts on the visual conditioning pathway, where the induced bias can persist through iterative...

论文介绍 基于扩散模型的机器人策略因其依赖视觉条件而存在安全风险。本文研究了一种更强的威胁——测试时对抗性接管,攻击者可通过一组学习到的通用视觉补丁,实时“劫持”并远程操控已冻结的机器人策略。该方法利用可微扩散推理学习扰动,能够诱导策略执行攻击者指定的轨迹。

A Practical Recipe Towards Improving Sim-and-Real Correlation for VLA Evaluation

第一作者: Shuo Wang · 方向: VLA 通用模型 · 来源: cs.RO

Abstract:Simulation has become an essential tool for evaluating and improving vision-language-action (VLA) policies, offering scalable, reproducible, and controllable alternatives to costly real-world robot evaluation. Recent simulation benchmarks have made substantial progress on realism and diversity, yet these platforms have not been widely adopted as reliable proxies for real-world policy evaluation. In this work, we investigate this issue through the lens of sim-and-real correlation. We conduct a systematic study across multiple simulation platforms, VLA policies, tasks, and perturbation factors, measuring whether simulated evaluation preserves real-world conclusions in terms of policy ranking consistency, performance correlation, and perturbation-wise failure patterns. This analysis allows us to characterize the limitations of existing simulators and identify what kinds of...

论文介绍 模拟是评估视觉-语言-动作模型的重要工具,但其作为真实世界代理的可靠性尚未确立。本文从模拟与真实的关联性视角出发,系统研究了多个仿真平台、策略和任务,以衡量模拟评估在策略排序、性能相关性及故障模式方面是否能保留真实世界的结论,并指出了现有模拟器的局限性。

HiMem-WAM: Hierarchical Memory-Gated World Action Models for Robotic Manipulation

第一作者: Xiaoquan Sun · 方向: 机器人操作 · 来源: cs.RO

Abstract:World Action Models (WAMs) have emerged as a new powerful paradigm for embodied intelligence, learning action-relevant visual dynamics that significantly enhance generalization and robustness. However, existing WAMs still struggle with task-relevant memory in long-horizon robotic manipulation. To address this, we present HiMem-WAM, a Hierarchical Memory-Gated WAM that integrates motion-centric latent actions, high-level skill latents, and boundary-triggered memory updates. Specifically, we develop a hierarchical latent action framework that jointly learns low-level motion and high-level skill latents, providing structured temporal abstraction. Meanwhile, a boundary-aware memory gate writes compact task states at predicted skill transitions, enabling causal inference without test-time generation of future video or optical flow estimation. Evaluated on LIBERO, LIBERO-PLUS...

论文介绍 现有世界动作模型在长时程机器人操作中难以维持任务相关记忆。为此,本文提出HiMem-WAM,一种分层记忆门控的世界动作模型。它通过分层潜动作框架联合学习底层运动和高层技能抽象,并引入边界感知记忆门在预测的技能转换点写入状态,从而实现无需生成未来视频的因果推理。

SARM2: Multi-Task Stage Aware Reward Modeling for Self Improving Robotic Manipulation

第一作者: Qianzhong Chen · 方向: VLA 通用模型 · 来源: cs.RO

Abstract:Fine-tuning vision-language-action (VLA) policies for long-horizon manipulation still relies heavily on behavior cloning, which requires costly high-quality demonstrations and keeps policies near the demonstration distribution. Reward models can reduce this dependence by reweighting demonstrations and providing dense supervision for on-robot reinforcement learning (RL), but they must be dense, accurate, and general. Existing methods fall short: task-specific stage-aware models are accurate but require per-task annotations, while general vision-language-model (VLM) reward models are broadly applicable but too coarse for fine-grained long-horizon progress. We introduce RM, a multi-task stage-aware reward model that combines an action-primitive-based stage estimator with a multi-gate Mixture-of-Experts (MMoE) value head to produce dense per-step rewards across manipulation tasks...

论文介绍 针对长期操作任务中视觉-语言-动作策略依赖行为克隆的局限性,本文提出了SARM2,一种多任务阶段感知奖励模型。该模型结合了基于动作原语的阶段估计器与多门混合专家价值头,旨在生成准确且密集的逐步奖励,以支持机器人操作的强化学习,从而减少对昂贵高质量演示的依赖。

Hierarchical Policies from Verbal and Egocentric Human Signals for Natural Human-Robot Interaction

第一作者: Dongjun Lee · 方向: 策略学习 · 来源: cs.RO

Abstract:For natural human-robot interaction, a robot must understand human intent expressed not only through language but also through nonverbal signals such as gestures and gaze. However, current robot policies rely on language instructions as the sole interface for conveying intent, leaving nonverbal signals unused and placing the full burden of communication. In this work, we present EDITH, a robot framework that captures the human's nonverbal signals through continuous streams of first-person view and gaze from smart glasses, and uses them alongside language instructions as inputs to the robot policy. Our hardware system streams the human's first-person view, gaze, and speech to the robot in real time, transcribing the speech into language instructions. To handle these rich but noisy signals, we design a hierarchical policy in which a high-level policy infers the human's intent...

论文介绍 当前机器人策略通常仅依赖语言指令。本文提出了EDITH框架,通过智能眼镜实时捕获人类的第一人称视野和注视等非语言信号,并结合语言指令,作为分层策略的输入。高层策略从这些丰富但嘈杂的信号中推断人类意图,旨在实现更自然、更直观的人机交互。

Locomotion analysis of a quadruped interacting with the lunar granular surface

第一作者: Yash J Vyas · 方向: 导航与运动 · 来源: cs.RO

Abstract:Deploying legged robots in extra-terrestrial environments includes many challenges due to complex terrain interactions, energy, and thermal constraints. For effective mechanical design of a lunar exploration quadrupedal robot, careful consideration of motor torques, energy expenditure, and cost of transport is required. The lunar surface is composed of granular regolith, which impacts the locomotion of legged robots and their performance. Locomotion algorithms trained with rigid contact assumptions are also ineffective when applied to environments with soft contacts, such as granular surfaces, which can result in instability and poor tracking. In this report, the physical modelling of the granular lunar surface-robot foot contacts is applied to a simulation environment with locomotion trained using Reinforcement Learning. A comparison is conducted between the policy trained on...

论文介绍 月球松散的颗粒表面对机器人的运动构成挑战。本研究建立了月球颗粒地形与机器人足部的物理接触模型,并在仿真中利用强化学习训练运动策略。分析比较了在软接触与传统刚性接触假设下训练的策略性能,旨在为月球探测四足机器人的设计提供运动分析依据。

What Matters in Orchestrating Robot Policies: A Systematic Study of Hierarchical VLA Agents

第一作者: Jiaheng Hu · 方向: VLA 通用模型 · 来源: cs.RO

Abstract:Hierarchical vision-language-action (Hi-VLA) systems have emerged as a promising paradigm for complex robot manipulation, by using high-level VLM planners to decompose tasks into language subgoals executed by low-level VLA controllers. Despite recent empirical progress, there is a lack of unified design principles for these systems: existing Hi-VLA systems differ in how they choose and connect planners, controllers, mechanisms to switch between the two, and how observations and memory are represented in the planner. In this paper, we present a systematic study of Hi-VLA design for robot manipulation. We unify representative Hi-VLA agents under an options-style control framework and benchmark core design choices across short-horizon, long-horizon, and reasoning-intensive tasks. Our analysis distills practical principles for building Hi-VLA systems, showing how model choices and...

论文介绍 分层视觉-语言-动作系统在复杂机器人操作中展现出潜力,但缺乏统一的设计原则。本文在一个统一的选项式控制框架下,系统性地研究了规划器、控制器选择、切换机制以及观测表示等核心设计选择,并通过基准测试提炼出构建实用分层系统的实践原则。

Exploration of Foundation Model-Based Robots in Patient and Elderly Care

第一作者: Zhiwen Qiu · 方向: 多模态具身 · 来源: cs.RO

Abstract:Demand for older-adult and patient care is growing rapidly as populations age worldwide. Foundation models are increasingly being integrated into robots and interactive agents, with the promise of more flexible communication and personalized assistance. However, care settings require reliable and workflow-compatible systems with accountable human oversight, and it remains unclear whether current embodied systems can translate technical advances into clinical impact. This Perspective synthesizes foundation model-based care robots across three areas: design features, user experience, and evidence for care-related outcomes. Current systems most commonly use foundation models as conversational and reasoning layers within voice-centered socially assistive embodiments, while multimodal grounding and physical autonomy remain limited. Empirical evaluations report positive usability...

论文介绍 随着人口老龄化,基于基础模型的护理机器人受到关注。本文综合分析了现有系统,涵盖设计特点、用户体验和护理相关结果证据。目前系统多将基础模型用作对话和推理层,但多模态接地和物理自主性仍然有限,探讨了技术进步转化为临床影响的可能性与挑战。

Flow Control: Steering Vision-Language-Action Models with Simple Real-Time Inputs

第一作者: Jonathan C. Kao · 方向: VLA 通用模型 · 来源: cs.RO

Abstract:We introduce flow control of vision-language-action (VLA) models, a simple and effective way to steer VLA actions in real-time through generic inputs, such as a keyboard. This method can be used out-of-the-box and does not require retraining or fine-tuning VLAs. It enables relatively crude user inputs to steer a VLA to align with user intent. The VLA transforms these inputs into action samples drawn from the VLA expert action distribution learned during training, so that the generated actions are high quality (conformity to the action expert distribution) and high fidelity (reflecting the user's intent). We demonstrate that flow control has many desirable properties: (1) flow control accurately and responsively steers robot actions with user inputs, (2) it is robust to suboptimal user inputs, (3) it enables users to steer VLAs to achieve significantly higher success rates and...

论文介绍 本文提出「流控制」方法,一种通过键盘等简单实时输入引导视觉-语言-动作模型动作的范式,无需重新训练。该方法利用流匹配将用户输入转换为符合模型专家分布的高质量动作,实现了对用户意图的高保真响应,展现了在多种任务中提升成功率和鲁棒性的潜力。

Efficient-WAM: A 1B-Parameter World-Action Model with Low-Cost Future Imagination

第一作者: Jiajun Li · 方向: 具身智能 · 来源: cs.RO

Abstract:World-Action Models (WAMs) have emerged as a promising paradigm for embodied control by coupling future visual prediction with action generation. However, most existing WAMs rely on photorealistic future prediction, which incurs high inference latency and makes real-time robot deployment difficult. This motivates a more efficient WAM design that preserves the control benefits of future visual prediction while reducing its inference cost. We introduce Efficient-WAM, a World-Action Model that reduces the cost of future imagination while preserving its control benefit. Efficient-WAM improves inference efficiency via a compact video expert transferred from WAN-2.2-5B, token-sparse video latents, and asymmetric video-action denoising that allocates fewer sampling steps to video than to actions. Instead of optimizing the future branch for visual fidelity, Efficient-WAM treats future...

论文介绍 世界-动作模型通过耦合未来视觉预测与动作生成来实现具身控制,但高保真未来想象带来高推理延迟。本文提出Efficient-WAM,通过使用紧凑的视频专家、token稀疏的未来表示以及不对称的去噪分配,在降低未来想象计算成本的同时,保留了其对控制的益处,提升了实时部署的可行性。

Robotic Nonprehensile Object Transportation with a Hanging Tray

第一作者: Adam Heins · 方向: 具身智能 · 来源: cs.RO

Abstract:We consider the nonprehensile object transportation task known as the waiter's problem, in which a robot must move an object balanced on a tray from one location to another. In contrast to prior works on the robotic waiter's problem, which make the robot tilt a tray rigidly held by its end effector (EE), we use a tray suspended from the EE by ropes, such that it behaves like a three-dimensional pendulum. Some prior works have actuated the robot so that the EE simulates the behavior of a pendulum, because pendular motion reduces the shear forces acting on the transported objects, minimizing the sliding of rigid objects and sloshing in containers of liquid. In contrast, our use of a real hanging tray allows us to obtain the benefits of pendular motion while only actuating a 3 degree-of-freedom (DOF) mobile base, rather than requiring a full 6-DOF manipulator arm. Our experiments...

论文介绍 本文研究使用悬挂托盘的机器人非抓取物体运输问题。与传统的刚性托盘不同,悬挂托盘表现为三维摆。通过仅控制一个三自由度的移动基座,机器人能够引导托盘产生摆动运动,从而减少作用在物体上的剪切力,防止滑动或液体溅洒,实现稳定的物体运输。

GHOST: Hierarchical Sub-Goal Policies for Generalizing Robot Manipulation

第一作者: Sriram Krishna · 方向: 机器人操作 · 来源: cs.RO

Abstract:We present GHOST, a framework for learning visuomotor manipulation policies that generalize beyond the training distribution. GHOST factorizes control into (i) a high-level policy that predicts the next sub-goal as a distribution over 3D end-effector poses from multi-view RGB-D observations, and (ii) a low-level goal-conditioned controller that executes embodiment-specific actions. To condition image-based policies on 3D goals, we introduce a simple spatial interface that projects predicted goals into the image plane and represents them as end-effector heatmaps. Across a suite of manipulation tasks, this hierarchical factorization consistently improves performance and robustness compared to a flat Diffusion Policy. Further, we show that this hierarchical interface also makes it easy to incorporate human demonstrations without relying on (noisy) action retargeting. As sub-goals...

论文介绍 研究机器人操作策略在训练分布外泛化能力不足的问题。提出GHOST框架,将控制分为高层子目标预测和低层目标条件控制器,通过空间接口将3D目标投影到图像平面。该方法提高了任务性能和鲁棒性,并便于整合人类演示,无需动作重定向。

Co-GLANCE: Uncertainty-Aware Active Perception for Heterogeneous Robot Teaming

第一作者: Michal P. Podolinsky · 方向: 多模态具身 · 来源: cs.RO

Abstract:Perceptual uncertainty is a central challenge for heterogeneous robot teams operating in unstructured outdoor environments, where no single viewpoint affords reliable scene understanding. Perceptual uncertainty, arising from sources such as occlusions, manifests differently across robot viewpoints depending on scene structure. Detecting and resolving sources of perceptual uncertainty requires both scene-based contextual reasoning and capability-aware robot allocation. While vision-language models provide strong semantic priors for both, they are computationally prohibitive for onboard inference and lack calibrated uncertainty quantification. We introduce Co-GLANCE, a real-time onboard perception and decision-making system for uncertainty resolution in heterogeneous robot teams. Co-GLANCE distills the semantic reasoning capabilities of a vision-language model into an end-to-end...

论文介绍 针对异构机器人团队在非结构化户外环境中面临的感知不确定性挑战,提出Co-GLANCE实时系统。该系统利用视觉语言模型的语义推理能力,进行不确定性检测和机器人能力分配,避免高计算成本,以提升团队协作效率。

Equanimity in HRI: Applying Calm Technology Principles to Human-Robot Interaction

第一作者: Barbara Sienkiewicz · 方向: 具身智能 · 来源: cs.RO

Abstract:This paper explores how {\textit{Calm Technology}} can be integrated into Human-Robot Interaction (HRI), with a particular focus on the household environment. It offers comprehensive guidelines for designing assistive robots that prioritize and enhance the human need for {\textit{equanimity}}, ensuring interactions are calm, non-intrusive, and harmonious. The paper examines the widespread influence of technology in contemporary life and its impact on cognitive capabilities, underscoring the need for responsible robotics and ethical considerations in future technological developments. By adapting {\textit{Calm Technology}} principles to domestic robots, the article provides concrete examples and features that should be employed in household assistive robotics. The goal is to foster a balanced, unobtrusive interaction between humans and robots, especially in the home...

论文介绍 探讨如何将平静技术原则整合到人机交互中,聚焦家庭环境。提供设计辅助机器人的指南,强调交互应平静、非侵入性和和谐,以促进人类安宁感,适用于未来家用机器人发展。

SAFE-Pruner: Semantic Attention-Guided Future-Aware Token Pruning for Efficient Vision-Language-Action Manipulation

第一作者: Shilin Ma · 方向: VLA 通用模型 · 来源: cs.RO

Abstract:Real-time inference of vision-language-action (VLA) models is essential for robotic control. While visual token pruning has shown strong potential for accelerating inference, most existing methods mainly base pruning decisions on shallow-layer cues and risk discarding visual information required by deep layers. To address this issue, we propose SAFE-Pruner, a plug-and-play pruning framework that incorporates attention cues of future layers into pruning decisions. Specifically, we identify semantic attention consistency, the tendency that VLA models concentrate their attention probability mass on the same semantic entity across execution steps. Based on this observation, we design a forward-looking strategy to forecast the token saliency in deep layers, which prevents the premature removal of critical tokens and leads to more stable acceleration. We further introduce an...

论文介绍 为提升视觉-语言-动作模型的实时推理效率,提出SAFE-Pruner剪枝框架。该框架基于语义注意力一致性和前向预测策略,引入未来层注意力线索指导剪枝,防止关键信息过早丢失,实现稳定加速。

FADA: Accessible fetal ultrasound interpretation and annotation with a selectively distilled unified vision-language model

第一作者: Mahmood Alzubaidi · 方向: 多模态具身 · 来源: cs.CV

Abstract:A global shortage of trained sonographers limits prenatal ultrasound screening in low- and middle-income countries, where over half of pregnant women receive no skilled sonography. Current deep learning approaches address detection, segmentation, or classification in isolation, each demanding a separate model and expert-specified labels at inference. We present FADA, a unified vision-language model built on Qwen3.5-VL that performs clinical interpretation, classification, detection, and segmentation through a single interpretation-first pipeline without external labels. FADA distills knowledge from four domain-specific foundation models (FetalCLIP, UltraSAM, USF-MAE, UltraFedFM) via offline pre-computed feature caching. Selective distillation, which applies feature alignment only to annotation tasks while interpretation relies on standard fine-tuning, consistently outperforms...

论文介绍 针对胎儿超声筛查中专业技师短缺的问题,提出FADA统一视觉语言模型。该模型通过选择性蒸馏从多个领域基础模型学习,能同时执行临床解释、分类、检测和分割,无需外部标签,提升低资源地区筛查可及性。

LIBERO-Occ: Evaluating and Improving Vision-Language-Action Models under Scene-Induced Occlusion via Viewpoint Imagination

第一作者: Taishan Li · 方向: VLA 通用模型 · 来源: cs.CV

Abstract:Vision-Language-Action (VLA) models achieve strong performance on standard manipulation benchmarks, but most evaluations assume that task-relevant objects are fully visible. This assumption often fails in realistic settings, where occlusion makes manipulation partially observable. In this paper, we study \textit{scene-induced occlusion} as a fundamental challenge for VLA models and introduce \textbf{LIBERO-Occ}, an occlusion-oriented extension of LIBERO. Experiments show that state-of-the-art VLAs suffer substantial performance degradation under occlusion. To address this issue, we propose \textbf{Viewpoint Imagination (VIM)}, which generates a complementary view from an occluded primary observation and conditions action prediction on both observed and imagined evidence. VIM improves robustness across task suites, occlusion types, and severity levels without requiring...

论文介绍 研究场景遮挡对视觉-语言-动作模型性能的影响,引入LIBERO-Occ基准进行评估。提出视点想象方法,从遮挡主视图生成互补视图,基于观测和想象证据增强动作预测,提高模型在多种遮挡情况下的鲁棒性。

LAFP: Preserving Latent Action Structure in Latent Policy Learning via Flow Matching

第一作者: Jiexi Lyu · 方向: 模仿学习 · 来源: cs.CV

Abstract:Learning high-quality latent actions from large-scale unlabeled videos, coupled with limited real-world interaction data for training an action decoder, has emerged as a promising paradigm for scalable latent policy learning. However, existing approaches typically rely on behavior cloning, which tends to collapse inherently multimodal action distributions into unimodal ones, thereby degrading the pretrained latent action structure. While flow matching provides a potential alternative, directly applying it leads to a misalignment between latent actions and physical actions during action decoder training, due to the stochastic nature of the learned policy. To address these, we propose Latent Action Flow Policy (LAFP), which leverages flow matching for latent policy learning and introduces an inference-time interpolation mechanism to mitigate stochasticity-induced misalignment...

论文介绍 针对潜在策略学习中多模态动作分布坍缩问题,提出LAFP方法。该方法利用流匹配进行潜在策略学习,并引入推理时插值机制,缓解随机性导致的潜在动作与物理动作错位,以保留潜在动作结构。

MODIP: Efficient Model-Based Optimization for Diffusion Policies

第一作者: Zakariae El Asri · 方向: 模仿学习 · 来源: cs.LG

Abstract:Diffusion policies (DPs) have emerged as expressive policy representations for robot learning, often used with imitation learning methods such as behavioral cloning (BC). However, while their success has largely been confined to BC, direct reinforcement learning (RL) fine-tuning remains challenging because actions are generated through a multi-step denoising process. In this work, we propose MODIP, a framework for the offline-to-online fine-tuning of DPs. Rather than directly applying RL to the DPs, MODIP leverages a world model (WM) to guide policy adaptation and keeps the simplicity and stability of BC. We utilize model predictive control (MPC) to generate high-quality trajectories within the WM, and use them as supervised targets for fine-tuning the DP. To make MPC planning efficient, MODIP uses a terminal state value instead of a policy-dependent state-action value...

论文介绍 针对扩散策略强化学习微调困难的问题,提出MODIP框架。该框架利用世界模型和模型预测控制生成高质量轨迹,作为监督目标进行策略适应,保持行为克隆的简单性与稳定性,实现从离线到在线的有效微调。

Fast and Highly Expressive Policy Learning for Offline Reinforcement Learning via Bootstrapped Flow Q-Learning

第一作者: Thanh Nguyen · 方向: 模仿学习 · 来源: cs.LG

Abstract:Diffusion-based Q-learning has emerged as a powerful paradigm for offline reinforcement learning, but its reliance on multi-step denoising makes both training and inference computationally expensive and brittle. Recent efforts to accelerate diffusion Q-learning toward single-step action generation typically introduce auxiliary networks, policy distillation, or multi-phase training, which frequently compromise simplicity, stability, or performance. To address these limitations, we introduce Bootstrapped Flow Q-Learning (BFQ), a novel framework that enables accurate single-step action generation during both training and inference, without auxiliary networks or distillation procedures. BFQ adopts a divide-and-conquer view of the displacement vector along the flow path: it begins by learning short-range displacements that can be accurately estimated from the Flow Matching marginal...

论文介绍 离线强化学习中的扩散Q学习方法因多步去噪导致计算昂贵且脆弱。现有加速方案常引入辅助网络或蒸馏,可能损害简单性和稳定性。本文提出Bootstrapped流Q学习(BFQ)框架,采用分治视图学习位移向量,实现训练和推理阶段的单步动作生成,无需额外组件,从而简化流程并提升效率与鲁棒性。

市场总览

美股方面,SPY和QQQ近1日分别下跌1.58%和2%,RSI14分别为40.7和43.4处于正常区间,但均低于20日均线745.62和721.3,多头排列仍在,MACD死叉出现显示短期动量减弱。加密货币板块,BTC-USD、ETH-USD和SOL-USD的RSI14均低于30(26.1、25.9、26),处于超卖状态,空头排列主导,加密恐慌贪婪指数为12极度恐慌,总市值2.21万亿美元,24小时变化0.16%,BTC主导率56.2%,技术面显示下行压力。中概股中,BABA、PDD和JD的RSI14在31.7-39.2之间,价格低于50日均线,空头排列信号明显,腾讯控股0700.HK RSI 58.3相对稳健但无明确信号。商品外汇板块分化,黄金期货GC=F RSI14 24.6超卖,但价格高于200日均线4411.78;原油期货CL=F上涨4.06%,RSI 46.3中性;美元指数DX-Y.NYB接近52周高,多头排列,RSI 62.7偏强。整体市场技术面呈现回调与超卖并存的状态。

今日关注

BTC-USD Bitcoin (BTC-USD)
偏下行

当前价格62128.04,RSI14为26.1,处于超卖状态。MACD值-4117.5881低于信号线-3383.673,柱状图为负,显示空头动量。价格低于20日均线69428.4、50日均线75019.65和200日均线78127.74,技术信号包括RSI超卖和空头排列,整体技术面偏下行。

^TNX 10Y 美债收益率 (%)
偏上行

当前价格4.54,RSI14为57.5处于正常区间。MACD值0.0296略高于信号线0.033,显示轻微正动量。价格高于20日均线4.52、50日均线4.41和200日均线4.21,技术信号为多头排列,趋势bullish,整体技术面偏上行。

^VIX VIX 恐慌指数
中性

当前价格22.22,RSI14为63.5未超买。MACD值0.3572高于信号线-0.3522,出现金叉,但趋势标记为neutral。价格高于20日均线17.46、50日均线18.48和200日均线18.5,信号混合包括死叉和MACD金叉,整体技术面中性。

全部资产

^VIX

VIX 恐慌指数

$22.22 +11.83%
5 日
+38.36%
距 52w 高
-37.1%
RSI(14)
63.5
趋势
中性
SMA 20 / 50 / 200
17.46 / 18.48 / 18.50
MACD / 信号
0.357 / -0.352
死叉(SMA50↓SMA200) (今天)MACD 金叉 (3 天前)

^TNX

10Y 美债收益率 (%)

$4.54 +0.31%
5 日
+1.14%
距 52w 高
-9.1%
RSI(14)
57.5
趋势
多头
SMA 20 / 50 / 200
4.52 / 4.41 / 4.21
MACD / 信号
0.030 / 0.033
多头排列

DX-Y.NYB

美元指数 DXY

$99.91 +0.00%
5 日
+0.38%
距 52w 高
-0.7%
RSI(14)
62.7
趋势
多头
SMA 20 / 50 / 200
99.31 / 98.90 / 98.63
MACD / 信号
0.317 / 0.231
接近 52 周高多头排列

SPY

S&P 500 ETF

$725.43 -1.58%
5 日
-3.82%
距 52w 高
-4.6%
RSI(14)
40.7
趋势
多头
SMA 20 / 50 / 200
745.62 / 719.32 / 685.34
MACD / 信号
4.850 / 9.350
多头排列

QQQ

Nasdaq 100 ETF

$693.69 -2.00%
5 日
-6.79%
距 52w 高
-7.3%
RSI(14)
43.4
趋势
多头
SMA 20 / 50 / 200
721.30 / 676.27 / 623.90
MACD / 信号
9.482 / 16.484
MACD 死叉 (4 天前)多头排列

AAPL

Apple

$291.58 +0.35%
5 日
-6.02%
距 52w 高
-8.1%
RSI(14)
43.8
趋势
多头
SMA 20 / 50 / 200
304.40 / 283.94 / 266.22
MACD / 信号
4.134 / 7.467
多头排列

MSFT

Microsoft

$397.36 -1.50%
5 日
-7.02%
距 52w 高
-28.5%
RSI(14)
39.4
趋势
空头
SMA 20 / 50 / 200
421.43 / 410.97 / 454.86
MACD / 信号
-0.275 / 3.897
MACD 死叉 (3 天前)空头排列

NVDA

Nvidia

$200.42 -3.73%
5 日
-6.67%
距 52w 高
-15.3%
RSI(14)
41.1
趋势
中性
SMA 20 / 50 / 200
217.20 / 205.71 / 189.02
MACD / 信号
-0.198 / 2.489

GOOGL

Alphabet

$356.38 -2.16%
5 日
-0.73%
距 52w 高
-12.8%
RSI(14)
39.6
趋势
中性
SMA 20 / 50 / 200
380.73 / 359.61 / 306.44
MACD / 信号
-1.535 / 3.232

TSLA

Tesla

$381.59 -3.80%
5 日
-9.94%
距 52w 高
-23.5%
RSI(14)
39.4
趋势
空头
SMA 20 / 50 / 200
419.89 / 397.25 / 415.16
MACD / 信号
-1.546 / 4.669
空头排列

META

Meta

$570.98 -2.33%
5 日
-8.35%
距 52w 高
-28.3%
RSI(14)
35.7
趋势
空头
SMA 20 / 50 / 200
609.19 / 622.15 / 659.95
MACD / 信号
-9.542 / -5.603
MACD 死叉 (3 天前)空头排列
加密恐慌贪婪
12
极度恐慌
加密总市值
$2.21 T
+0.16% / 24h
BTC 主导率
56.2%
ETH 8.9%
24h 成交量
$77.8 B
活跃币 17,337

BTC-USD

Bitcoin

$62,128.04 +0.79%
5 日
+1.98%
距 52w 高
-50.8%
RSI(14)
26.1
趋势
空头
SMA 20 / 50 / 200
69,428.40 / 75,019.65 / 78,127.74
MACD / 信号
-4,117.588 / -3,383.673
RSI 超卖空头排列

ETH-USD

Ethereum

$1,639.25 +0.09%
5 日
+3.69%
距 52w 高
-66.9%
RSI(14)
25.9
趋势
空头
SMA 20 / 50 / 200
1,888.59 / 2,121.02 / 2,432.98
MACD / 信号
-145.907 / -124.544
RSI 超卖空头排列

SOL-USD

Solana

$64.22 -1.14%
5 日
+1.15%
距 52w 高
-74.6%
RSI(14)
26.0
趋势
空头
SMA 20 / 50 / 200
75.92 / 82.91 / 101.07
MACD / 信号
-5.872 / -4.645
RSI 超卖空头排列

BABA

阿里巴巴 (BABA)

$115.38 -3.61%
5 日
-9.30%
距 52w 高
-40.1%
RSI(14)
31.7
趋势
空头
SMA 20 / 50 / 200
128.88 / 130.80 / 149.69
MACD / 信号
-3.930 / -2.558
空头排列

PDD

拼多多 (PDD)

$81.82 -0.13%
5 日
-4.19%
距 52w 高
-41.3%
RSI(14)
32.4
趋势
空头
SMA 20 / 50 / 200
90.13 / 96.19 / 111.84
MACD / 信号
-4.201 / -3.527
接近 52 周低空头排列

JD

京东 (JD)

$28.45 -0.97%
5 日
-3.26%
距 52w 高
-22.8%
RSI(14)
39.2
趋势
空头
SMA 20 / 50 / 200
30.37 / 30.14 / 30.34
MACD / 信号
-0.508 / -0.269
空头排列

0700.HK

腾讯控股 (0700.HK)

HK$483.00 +3.74%
5 日
+5.23%
距 52w 高
-29.3%
RSI(14)
58.3
趋势
中性
SMA 20 / 50 / 200
451.57 / 473.63 / 569.69
MACD / 信号
-2.278 / -7.348

GC=F

黄金期货

$4,105.30 -3.63%
5 日
-7.47%
距 52w 高
-26.5%
RSI(14)
24.6
趋势
中性
SMA 20 / 50 / 200
4,475.26 / 4,610.22 / 4,411.78
MACD / 信号
-102.168 / -70.672
RSI 超卖

CL=F

WTI 原油期货

$91.78 +4.06%
5 日
-4.42%
距 52w 高
-23.2%
RSI(14)
46.3
趋势
中性
SMA 20 / 50 / 200
95.54 / 97.35 / 73.20
MACD / 信号
-1.976 / -1.472

USDCNY=X

美元 / 人民币

¥6.77 +0.13%
5 日
+0.17%
距 52w 高
-6.1%
RSI(14)
39.5
趋势
空头
SMA 20 / 50 / 200
6.78 / 6.81 / 6.97
MACD / 信号
-0.014 / -0.015
MACD 金叉 (今天)接近 52 周低空头排列
风险提示

本报告基于公开行情数据计算的技术指标,仅供技术指标解读参考。过去走势不代表未来表现,投资者应结合其他信息谨慎决策。

Britain Is Weighing a Social Media Ban for Children. How Did It Get Here?

Months after Australia banned social media for everyone under 16, the British government is considering new policies to keep children safe online.

中文摘要 英国政府正考虑禁止16岁以下儿童使用社交媒体,此举参照澳大利亚数月前实施的类似禁令,旨在加强儿童在线安全保护。

Australia news live: Brittany Higgins takes up new job fighting ‘rise of misogyny’; Seven to cut up to 300 jobs within weeks

Follow today’s news live Get our breaking news email, free app or daily news podcast Wong not ‘interested’ in One Nation’s fundraising Wong says she isn’t concerned about One Nation’s fundraising efforts, but more about their policies. Pauline Hanson’s party says it has raised more than $1.5m in the

中文摘要 布列塔尼·希金斯新任职务致力于对抗厌女症;澳大利亚Seven媒体公司计划数周内裁员多达300人;外长黄英贤不关心一国党筹款,更关注其政策。

Australia’s Social Media Ban Is Floundering. Can It Still Help Younger Kids?

Six months in, many teens are already back on platforms they were supposed to be blocked from. The ban’s benefits may fall to the next generation.

中文摘要 澳大利亚16岁以下社交媒体禁令实施六个月后效果不佳,许多青少年已返回平台,禁令的潜在益处可能仅惠及下一代。

Middle East crisis live: US military launches second day of airstrikes at ‘multiple targets’ in Iran

The strikes began at 5.15pm EST on Wednesday – after midnight on Thursday local time – ‘at the Commander in Chief’s direction’, Centcom says If the US genuinely wants a deal it will have to engage with Iranian demands on sanctions relief, says Danny Citrinowicz, the former head of the Iran branch of

中文摘要 美军对伊朗多个目标发动第二天空袭,始于美国东部时间周三下午5时15分,按总统指令执行。

Canada Moves to Ban Social Media Use for Youth Under 16

The country’s previous attempt to get tech companies to shelter young users failed amid heavy criticism from civil liberty groups.

中文摘要 加拿大推动立法禁止16岁以下青少年使用社交媒体,此前类似尝试因民权团体强烈批评而失败。

Watch: Historic US-Canada border library gets new Quebec-only entrance

The Trump administration in 2025 paused the use of the famous Haskell Library's main entrance on the US side, which had been used by both countries for decades.

中文摘要 美加边境历史性图书馆新增魁北克专用入口;特朗普政府于2025年暂停使用美国侧主入口,此前该入口供两国使用数十年。

Hot Cars and Stolen Crypto: A Canadian Teen Pocketed Millions, Prosecutors Say

A case illustrates both the low-hanging opportunities new financial technologies offer to scammers and the downside of speeding in a Rolls-Royce.

中文摘要 检方称一名加拿大青少年通过加密货币诈骗数百万美元,案例显示新技术为欺诈者提供低门槛机会。

Trump’s Iran war has propelled China’s cleantech industry

Disruption to global energy supplies sparks surge in demand for alternatives

中文摘要 特朗普政府对伊朗的军事行动导致全球能源供应中断,推动了对替代能源的需求激增,进而促进了中国清洁技术行业的快速发展。

Activist Elliott Hits Back at Gold Miner Northern Star Over Sale

Activist investor Elliott Investment Management LP has hit back at Australia’s biggest gold stock Northern Star Resources Ltd. by urging the beleaguered miner’s board to take urgent action and reconsider a sale as its valuation flounders.

中文摘要 激进投资者Elliott Investment Management LP敦促澳大利亚金矿公司Northern Star Resources Ltd.的董事会重新考虑出售,因公司估值持续低迷,需采取紧急措施。

New Zealand Primary Exports Seen Slower After Stellar 2026 Gain

New Zealand’s target of doubling primary exports by 2034 remains in place even as the stellar growth of recent years is tipped to slow in the face of geopolitical and weather challenges.

中文摘要 新西兰初级出口在2026年强劲增长后,预计未来增速将放缓,因面临地缘政治和天气因素挑战。但到2034年出口翻倍的目标不变。

US Launches Second Round of Strikes on Iran

The US military launched strikes against "multiple" targets in Iran for the second day in a row after President Donald Trump accused the country of dragging out talks on an interim peace deal. Bloomberg's Laura Davison explains the context. (Source: Bloomberg)

中文摘要 美国军方连续第二天对伊朗发动打击,攻击了多个目标,特朗普总统指责伊朗拖延临时和平协议的谈判,加剧了地区紧张局势。

Global Junk Debt Flashes Warning on Growing Risk of Stagflation

Fears of a stagflation shock from the Middle East conflict are increasingly souring investor sentiment toward the weakest global corporate borrowers, many of which binged on cheap debt during the era of ultra-low interest rates.

中文摘要 中东冲突引发的滞胀担忧正恶化投资者对全球最弱企业借款人的信心,这些公司在超低利率时期大量借贷廉价债务,垃圾债务市场发出风险警告。

Westpac Mortgage Applications Fall as Tax Changes Sap Demand

Westpac Banking Corp. mortgage applications are heading for the worst quarter in a year as tax changes for property investors weaken demand for real estate.

中文摘要 澳大利亚西太平洋银行抵押贷款申请量预计录得一年来最差季度表现,因针对房地产投资者的税收变化削弱了需求。

How AI Is Changing Asia’s Workplaces

Financial heavyweights in Hong Kong including Baidu CFO Henry He and BlackRock's APAC Head Susan Chan share their insights on how AI is changing their workplaces. (Source: Bloomberg)

中文摘要 百度首席财务官Henry He和贝莱德亚太区主管Susan Chan等香港金融界领袖分享了人工智能如何改变亚洲工作场所的见解,包括效率提升和岗位变化。

Highlights from Bloomberg Invest Hong Kong

Top voices in finance joined Bloomberg to discuss topics ranging from the impact of China's regulatory crackdown to the risk of a global tech selloff. Bloomberg's David Ingles and Yvonne Man break down the highlights. (Source: Bloomberg)

中文摘要 彭博投资香港会议上,金融界领袖讨论了中国监管打击的影响以及全球科技股抛售的风险,分析了市场前景和投资策略。

The furious dispute over what caused Air India flight 171 to crash

The final conclusions of the investigation have yet to be published, although more could become apparent in the coming days.

中文摘要 关于印度航空171航班坠机原因的激烈争论持续,调查最终结论尚未公布,预计未来几天将有更多信息披露。

Mike Ashley's Frasers offers £1.73bn to buy all of Hugo Boss

The retail group already owns just over a quarter of the German fashion brand but wants to buy the rest of it.

中文摘要 英国零售集团Frasers提出以17.3亿英镑收购德国时尚品牌Hugo Boss的全部股份,该集团目前已持有Hugo Boss超过四分之一的股权。

Wow~ 圣经!

Audio priscos illos viros probos atque sapientes, die Iovis — quartus is hebdomadis dies habetur — pecuniam suam in plebem erogasse, ne quis egestate premeretur. Pullum aureum alienis pueris donasse, quod et suus puer hoc cibo delectaretur; aquam nigram dulcem aliis senibus praebuisse, quod suus quo

【口令红包多多】庆祝自己专业水平提升一个台阶并记录

专业工种。昨天主刀了一台甲状腺转移二次大手术,开放双侧II-V区大颈清+腺叶切除、中央区清扫,历时7小时55分钟,中间没有吃喝拉撒,连续高强度工作,全程无尿点,清扫淋巴结目测上百枚,所有神经都镂空了(神经血管完全裸化),今早查体没有一点并发症(没有声音嘶哑,没有低钙,没有淋巴漏),很开心自己在主治的第二年就达到了这个水平,可能很多副高都做不到,应该也在这个年龄超越了我的老板这个年龄的水平了。【所谓外行看热闹,简单讲可以把这段话复制给AI判断下大概是什么水平,被AI敲打说警惕膨胀 】 当然这可能是我这个外科佬在AI替代人手精细操作之前最后的余辉和浪漫。让我想起了高中的一篇关于英国工业革命后手工鞋

还学什么口语?Google今天发布Gemini 3.5 Live Translate

我在AI Studio中实验了一下,我说中文,延迟约1秒内,出地道的任意目标语言; Google – 9 Jun 26 Fluid, natural voice translation with Gemini 3.5 Live Translate Gemini 3.5 Live Translate brings near real-time, natural speech translation to Google AI Studio, Google Translate and Google Meet. 录了一段试听: mega.nz 627 KB file on MEGA 54 个帖子 -

WhatsApp纯协议实现

本帖使用社区开源推广,符合推广要求。我申明并遵循社区要求的以下内容: 我的帖子已经打上 开源推广 标签: 是 我的开源项目完整开源,无未开源部分: 是 我的开源项目已链接认可 LINUX DO 社区: 是 我帖子内的项目介绍,AI生成、润色内容部分已截图发出: 是 以上选择我承诺是永久有效的,接受社区和佬友监督: 是 以下为项目介绍正文内容,AI生成、润色内容已使用截图方式发出 多账号 / sms注册 / OTP接收 / 消息接收 PR / issue wa-app 开源地址 27 个帖子 - 22 位参与者 阅读完整话题

突发!美国战争部居然透过openrouter 使用Claude Fable 5

突然出现的,并且很快上了消耗量第一 OpenRouter United States Department of War | OpenRouter Explore app analytics for United States Department of War. United States Department of War uses OpenRouter to access hundreds of AI models. 67 个帖子 - 56 位参与者 阅读完整话题

最新消息,HUB站活了!!!

感谢天感谢地,感谢帮助过我的佬哥佬弟 @4242 29 个帖子 - 23 位参与者 阅读完整话题

Fable5是个逼王模型

尝试用了一天fable5 xhigh,感觉是个逼王模型。 fable5的回答里经常自带一种特调的四十年经验老顾问的气场,上来就是“你关于xxx有几个认识误区” “现在的设计实现有xxx偏差”,以一种不知道哪儿来的自信以及斩钉截铁的语气,在高维度和战略上一通分析,又是表格又是分类归纳,逼格拉满,第一印象非常有诱惑性。面对难题,gpt5.5一般会说“现在离xxxx的目标差距还很大,我不能说(保证)xxxxx”,fable5给人的感觉就是“你的问题问在点子上了,我都正面回答,第一步xxxx,第二步xxxx,就解决了,最后再纠正一个你的担忧xxxxx”。 但是,我和gpt5.5一起挠头了两周的这些难题

【面试拷打】面试了十几家 Agent 岗位,整理了面试题~

上个月公司裁员,开启了前端面试之旅,一路坎坷,转而学习了一些 ai 课程,面试了十几家 agent 岗位(中间可能穿插偏向前端和全栈的岗位),面试过程都录音了,然后让 AI 整理了一下面试官提问的问题,分享给各位佬一起学习学习~ ML 公司 AI xx 系统主要是做什么的? LangChain / LangGraph 主要用了什么 AI 技术? 有没有了解过像 Manus 这种通用 Agent? 这些通用 Agent 一般分几层功能? 有没有构建过多智能体(Multi-Agent)架构? 什么是多 Agent? 为什么需要多 Agent? 什么场景下需要多 Agent 架构? 单个 Agent

这rpm。。。吓人

我这真成后备公益站了,每次羊毛没了用量就飙升。 (然后过几天就撑不住了。。。) (其实里面一大半都是收回的临时额度) 36 个帖子 - 36 位参与者 阅读完整话题