Institution profile

Defense Innovation Institute

Academic institution
Research library4linked papers
Opportunities0open roles
Selected work

Representative Papers

Affordance-Conditioned Decision Making: Bridging the Semantic-Spatial Gap in Zero-Shot Cross-Floor Vision-and-Language Navigation

Sep 26, 2026

This study addresses the challenge in zero-shot vision-and-language navigation where high-level semantic intents are difficult to translate into reliable physical execution, particularly in cross-floor scenarios constrained by spatial limitations and error accumulation. To this end, this work proposes the PACE module, which introduces a novel passability-aware pose anchoring mechanism that maps transitional semantics into traversable poses to condition short-horizon action generation. Furthermore, it incorporates failure-aware preference fine-tuning to enhance closed-loop error correction, achieving precise alignment between semantic planning and physical execution. When integrated into six open-source navigators, the proposed method improves cross-floor success rates on R2R-CE and RxR-CE by 27.65% and 12.06%, respectively, while demonstrating robust generalization and reliability in real-world unseen environments.

0 citationsRead paper

When Temporal Perturbations Act Like Sensor Biases: Label-Free Auditing of Wearable Activity Recognizers

Sep 24, 2026

This study addresses the vulnerability of wearable activity recognition models to static sensor offsets, which hinder the distinction between genuine temporal features and biases. We propose SpectrumAudit, an unsupervised auditing framework that integrates phase randomization fitting, DC/AC signal decomposition, and frozen model replay. To our knowledge, this is the first approach to introduce a budget-constrained mechanism for separating DC projections from zero-mean residuals, enabling precise diagnosis of bias effects. Experimental evaluations across 27 models demonstrate that the framework induces accuracy degradation of up to 40.83 percentage points. The results confirm that DC components are substantially more detrimental than AC components, effectively revealing offset-dominated robustness bottlenecks in wearable sensing systems.

0 citationsRead paper

ENDOPROMPT: Victim-Side Pseudo-References for Utility Degradation

Sep 24, 2026

This study addresses the limitation that existing prompt injection attacks predominantly rely on harmful content, manual annotations, or predefined targets, thereby failing to purely expose the utility vulnerabilities of large language models. To this end, this work proposes a victim-side pseudo-reference supervision mechanism that operates without benchmark feedback. Specifically, it leverages clean continuations of unlabeled instructions as pseudo-references, integrating local search with preference optimization to train a utility-degrading prefix generator. This research pioneers a pure utility attack paradigm devoid of harmful content, achieving generative prefix learning through white-box search and reward refinement. Extensive evaluations across four models and seven benchmarks demonstrate an average utility degradation of 26.8 percentage points, with significant performance deterioration observed in 27 out of 28 metrics, effectively revealing critical utility weaknesses in large language models.

0 citationsRead paper
Recent publications

Latest Papers

Affordance-Conditioned Decision Making: Bridging the Semantic-Spatial Gap in Zero-Shot Cross-Floor Vision-and-Language Navigation

Sep 26, 2026

This study addresses the challenge in zero-shot vision-and-language navigation where high-level semantic intents are difficult to translate into reliable physical execution, particularly in cross-floor scenarios constrained by spatial limitations and error accumulation. To this end, this work proposes the PACE module, which introduces a novel passability-aware pose anchoring mechanism that maps transitional semantics into traversable poses to condition short-horizon action generation. Furthermore, it incorporates failure-aware preference fine-tuning to enhance closed-loop error correction, achieving precise alignment between semantic planning and physical execution. When integrated into six open-source navigators, the proposed method improves cross-floor success rates on R2R-CE and RxR-CE by 27.65% and 12.06%, respectively, while demonstrating robust generalization and reliability in real-world unseen environments.

0 citationsRead paper

When Temporal Perturbations Act Like Sensor Biases: Label-Free Auditing of Wearable Activity Recognizers

Sep 24, 2026

This study addresses the vulnerability of wearable activity recognition models to static sensor offsets, which hinder the distinction between genuine temporal features and biases. We propose SpectrumAudit, an unsupervised auditing framework that integrates phase randomization fitting, DC/AC signal decomposition, and frozen model replay. To our knowledge, this is the first approach to introduce a budget-constrained mechanism for separating DC projections from zero-mean residuals, enabling precise diagnosis of bias effects. Experimental evaluations across 27 models demonstrate that the framework induces accuracy degradation of up to 40.83 percentage points. The results confirm that DC components are substantially more detrimental than AC components, effectively revealing offset-dominated robustness bottlenecks in wearable sensing systems.

0 citationsRead paper

ENDOPROMPT: Victim-Side Pseudo-References for Utility Degradation

Sep 24, 2026

This study addresses the limitation that existing prompt injection attacks predominantly rely on harmful content, manual annotations, or predefined targets, thereby failing to purely expose the utility vulnerabilities of large language models. To this end, this work proposes a victim-side pseudo-reference supervision mechanism that operates without benchmark feedback. Specifically, it leverages clean continuations of unlabeled instructions as pseudo-references, integrating local search with preference optimization to train a utility-degrading prefix generator. This research pioneers a pure utility attack paradigm devoid of harmful content, achieving generative prefix learning through white-box search and reward refinement. Extensive evaluations across four models and seven benchmarks demonstrate an average utility degradation of 26.8 percentage points, with significant performance deterioration observed in 27 out of 28 metrics, effectively revealing critical utility weaknesses in large language models.

0 citationsRead paper