❌

Normal view

Not All Tokens Are Created Equal: Query-Efficient Jailbreak Fuzzing for LLMs

arXiv:2603.23269v1 Announce Type: cross Abstract: Large Language Models(LLMs) are widely deployed, yet are vulnerable to jailbreak prompts that elicit policy-violating outputs. Although prior studies have uncovered these risks, they typically treat all tokens as equally important during prompt mutation, overlooking the varying contributions of individual tokens to triggering model refusals. Consequently, these attacks introduce substantial redundant searching under query-constrained scenarios, reducing attack efficiency and hindering comprehensive vulnerability assessment. In this work, we conduct a token-level analysis of refusal behavior and observe that token contributions are highly skewed rather than uniform. Moreover, we find strong cross-model consistency in refusal tendencies, enabling the use of a surrogate model to estimate token-level contributions to the target model's refusals. Motivated by these findings, we propose TriageFuzz, a token-aware jailbreak fuzzing framework that adapts the fuzz testing approach with a series of customized designs. TriageFuzz leverages a surrogate model to estimate the contribution of individual tokens to refusal behaviors, enabling the identification of sensitive regions within the prompt. Furthermore, it incorporates a refusal-guided evolutionary strategy that adaptively weights candidate prompts with a lightweight scorer to steer the evolution toward bypassing safety constraints. Extensive experiments on six open-source LLMs and three commercial APIs demonstrate that TriageFuzz achieves comparable attack success rates (ASR) with significantly reduced query costs. Notably, it attains a 90% ASR with over 70% fewer queries compared to baselines. Even under an extremely restrictive budget of 25 queries, TriageFuzz outperforms existing methods, improving ASR by 20-40%.

SortedRL: Accelerating RL Training for LLMs through Online Length-Aware Scheduling

arXiv:2603.23414v1 Announce Type: cross Abstract: Scaling reinforcement learning (RL) has shown strong promise for enhancing the reasoning abilities of large language models (LLMs), particularly in tasks requiring long chain-of-thought generation. However, RL training efficiency is often bottlenecked by the rollout phase, which can account for up to 70% of total training time when generating long trajectories (e.g., 16k tokens), due to slow autoregressive generation and synchronization overhead between rollout and policy updates. We propose SortedRL, an online length-aware scheduling strategy designed to address this bottleneck by improving rollout efficiency and maintaining training stability. SortedRL reorders rollout samples based on output lengths, prioritizing short samples forming groups for early updates. This enables large rollout batches, flexible update batches, and near on-policy micro-curriculum construction simultaneously. To further accelerate the pipeline, SortedRL incorporates a mechanism to control the degree of off-policy training through a cache-based mechanism, and is supported by a dedicated RL infrastructure that manages rollout and update via a stateful controller and rollout buffer. Experiments using LLaMA-3.1-8B and Qwen-2.5-32B on diverse tasks, including logical puzzles, and math challenges like AIME 24, Math 500, and Minerval, show that SortedRL reduces RL training bubble ratios by over 50%, while attaining 3.9% to 18.4% superior performance over baseline given same amount of data.

Cerebra: A Multidisciplinary AI Board for Multimodal Dementia Characterization and Risk Assessment

arXiv:2603.21597v2 Announce Type: replace Abstract: Modern clinical practice increasingly depends on reasoning over heterogeneous, evolving, and incomplete patient data. Although recent advances in multimodal foundation models have improved performance on various clinical tasks, most existing models remain static, opaque, and poorly aligned with real-world clinical workflows. We present Cerebra, an interactive multi-agent AI team that coordinates specialized agents for EHR, clinical notes, and medical imaging analysis. These outputs are synthesized into a clinician-facing dashboard that combines visual analytics with a conversational interface, enabling clinicians to interrogate predictions and contextualize risk at the point of care. Cerebra supports privacy-preserving deployment by operating on structured representations and remains robust when modalities are incomplete. We evaluated Cerebra using a massive multi-institutional dataset spanning 3 million patients from four independent healthcare systems. Cerebra consistently outperformed both state-of-the-art single-modality models and large multimodal language model baselines. In dementia risk prediction, it achieved AUROCs up to 0.80, compared with 0.74 for the strongest single-modality model and 0.68 for language model baselines. For dementia diagnosis, it achieved an AUROC of 0.86, and for survival prediction, a C-index of 0.81. In a reader study with experienced physicians, Cerebra significantly improved expert performance, increasing accuracy by 17.5 percentage points in prospective dementia risk estimation. These results demonstrate Cerebra's potential for interpretable, robust decision support in clinical care.

Dataset Distillation-based Hybrid Federated Learning on Non-IID Data

arXiv:2409.17517v3 Announce Type: replace-cross Abstract: In federated learning, the heterogeneity of client data has a great impact on the performance of model training. Many heterogeneity issues in this process are raised by non-independently and identically distributed (non-IID) data. To address the issue of label distribution skew, we propose a hybrid federated learning framework called HFLDD, which integrates dataset distillation to generate approximately independent and equally distributed (IID) data, thereby improving the performance of model training. In particular, we partition the clients into heterogeneous clusters, where the data labels among different clients within a cluster are unbalanced while the data labels among different clusters are balanced. The cluster heads collect distilled data from the corresponding cluster members, and conduct model training in collaboration with the server. This training process is like traditional federated learning on IID data, and hence effectively alleviates the impact of non-IID data on model training. We perform a comprehensive analysis of the convergence behavior, communication overhead, and computational complexity of the proposed HFLDD. Extensive experimental results based on multiple public datasets demonstrate that when data labels are severely imbalanced, the proposed HFLDD outperforms the baseline methods in terms of both test accuracy and communication cost.

Graph Structure Learning with Privacy Guarantees for Open Graph Data

arXiv:2507.19116v3 Announce Type: replace-cross Abstract: Publishing open graph data while preserving individual privacy remains challenging when data publishers and data users are distinct entities. Although differential privacy (DP) provides rigorous guarantees, most existing approaches enforce privacy during model training rather than at the data publishing stage. This limits the applicability to open-data scenarios. We propose a privacy-preserving graph structure learning framework that integrates Gaussian Differential Privacy (GDP) directly into the data release process. Our mechanism injects structured Gaussian noise into raw data prior to publication and provides formal $\mu$-GDP guarantees, leading to tight $(\varepsilon, \delta)$-differential privacy bounds. Despite the distortion introduced by privatization, we prove that the original sparse inverse covariance structure can be recovered through an unbiased penalized likelihood formulation. We further extend the framework to discrete data using discrete Gaussian noise while preserving privacy guarantees. Extensive experiments on synthetic and real-world datasets demonstrate strong privacy-utility trade-offs, maintaining high graph recovery accuracy under rigorous privacy budgets. Our results establish a formal connection between differential privacy theory and privacy-preserving data publishing for graphical models.

Do Vision-Language Models Measure Up? Benchmarking Visual Measurement Reading with MeasureBench

arXiv:2510.26865v2 Announce Type: replace-cross Abstract: Reading measurement instruments is effortless for humans and requires relatively little domain expertise, yet it remains surprisingly challenging for current vision-language models (VLMs) as we find in preliminary evaluation. In this work, we introduce MeasureBench, a benchmark on visual measurement reading covering both real-world and synthesized images of various types of measurements, along with an extensible pipeline for data synthesis. Our pipeline procedurally generates a specified type of gauge with controllable visual appearance, enabling scalable variation in key details such as pointers, scales, fonts, lighting, and clutter. Evaluation on popular proprietary and open-weight VLMs shows that even the strongest frontier VLMs struggle with measurement reading in general. We have also conducted preliminary experiments with reinforcement finetuning (RFT) over synthetic data, and find a significant improvement on both in-domain synthetic subset and real-world images. Our analysis highlights a fundamental limitation of current VLMs in fine-grained spatial grounding. We hope this resource and our code releases can help future advances on visually grounded numeracy and precise spatial perception of VLMs, bridging the gap between recognizing numbers and measuring the world.

Think Before You Drive: World Model-Inspired Multimodal Grounding for Autonomous Vehicles

arXiv:2512.03454v3 Announce Type: replace-cross Abstract: Interpreting natural-language commands to localize target objects is critical for autonomous driving (AD). Existing visual grounding (VG) methods for autonomous vehicles (AVs) typically struggle with ambiguous, context-dependent instructions, as they lack reasoning over 3D spatial relations and anticipated scene evolution. Grounded in the principles of world models, we propose ThinkDeeper, a framework that reasons about future spatial states before making grounding decisions. At its core is a Spatial-Aware World Model (SA-WM) that learns to reason ahead by distilling the current scene into a command-aware latent state and rolling out a sequence of future latent states, providing forward-looking cues for disambiguation. Complementing this, a hypergraph-guided decoder then hierarchically fuses these states with the multimodal input, capturing higher-order spatial dependencies for robust localization. In addition, we present DrivePilot, a multi-source VG dataset in AD, featuring semantic annotations generated by a Retrieval-Augmented Generation (RAG) and Chain-of-Thought (CoT)-prompted LLM pipeline. Extensive evaluations on six benchmarks, ThinkDeeper ranks #1 on the Talk2Car leaderboard and surpasses state-of-the-art baselines on DrivePilot, MoCAD, and RefCOCO/+/g benchmarks. Notably, it shows strong robustness and efficiency in challenging scenes (long-text, multi-agent, ambiguity) and retains superior performance even when trained on 50% of the data.

Spatial Omics in Gastrointestinal Oncology: Recent Advances, Therapeutic Insights, and Clinical Translation

J Cancer. 2026 Jan 30;17(3):515-523. doi: 10.7150/jca.127381. eCollection 2026.

ABSTRACT

Gastrointestinal (GI) cancers remain a leading cause of cancer-related morbidity and mortality worldwide, largely due to their molecular heterogeneity, complex tumor microenvironment (TME), and variable treatment responses. In recent years, the emergence of spatially resolved omics technologies-encompassing spatial transcriptomics, proteomics, metabolomics, and epigenomics-has revolutionized the ability to interrogate tumor architecture with unprecedented resolution. These methods enable precise mapping of cellular and molecular interactions within intact tissue contexts, thereby uncovering spatially defined niches that influence tumor progression, immune evasion, and therapeutic resistance. In GI malignancies such as colorectal, gastric, and esophageal cancers, spatial omics have provided critical insights into cancer-stromal-immune crosstalk, identified predictive biomarkers for immunotherapy and targeted agents, and guided the development of novel therapeutic strategies. This review synthesizes the latest advances in spatial omics applied to GI oncology over the past five years, with an emphasis on their integration into early diagnosis, treatment stratification, and real-time monitoring of therapeutic efficacy. We also discuss current challenges, including standardization, data integration, and clinical validation, as well as future directions for incorporating spatial profiling into routine oncology practice. By bridging the gap between bench discoveries and bedside applications, spatial omics hold transformative potential for achieving truly personalized treatment in gastrointestinal cancers.

PMID:41869445 | PMC:PMC13003551 | DOI:10.7150/jca.127381

Integrated Machine Learning and Multi-Omics Identifies a Novel Molecular Signature for Improving the Prognosis of Hepatocellular Carcinoma

J Hepatocell Carcinoma. 2026 Mar 11;13:574690. doi: 10.2147/JHC.S574690. eCollection 2026.

ABSTRACT

BACKGROUND: Hepatocellular carcinoma (HCC) exhibits significant molecular heterogeneity and complex immune microenvironment, which to some extent limits the accuracy of prognosis assessment and the formulation of individualized treatment strategies. This study aims to identify immune-derived molecular signatures based on multi-omics data and machine learning methods for the prognosis prediction and risk stratification of HCC.

METHODS: Based on weighted gene co-expression network analysis(WGCNA) and differential gene analysis,immune-derived molecular signature (IDMS) were screened in both single-cell and bulk transcriptomes. Prognostic model was constructed by multi-machine learning approachs. Subsequently, we investigated the differences in mutations, biological functions, and immune cell infiltration within the tumor microenvironment between the high- and low-risk groups.In addition, we comprehensively analyzed the drug sensitivity of IDMS and predicted potential drugs.

RESULTS: We identified seven hub genes at the single-cell and bulk transcriptome levels. Based on multiple machine learning, we constructed a prognostic model that demonstrated excellent performance in predicting overall survival for patients with HCC. IDMS -integrated normograms provide a promising and quantitative tool for clinical risk management.Notably, a significant difference in microsatellite instability (MSI) was observed between the high- and low-risk groups. This indicates that patients in the high-risk group might have a better response to immunotherapy. Additionally, we predicted potential drugs targeting to these risk subgroups.

CONCLUSION: Our research developed an IDMS that could serve as an effective tool for patient stratification management and prognosis prediction. This signature could provide a reference for immunotherapy for patients with HCC and improve their prognosis.

PMID:41847219 | PMC:PMC12991065 | DOI:10.2147/JHC.S574690

  • ✇cs.AI, q-bio.NC updates on arXiv.org
  • Multi-Agent Guided Policy Optimization Yueheng Li · Guangming Xie · Zongqing Lu
    arXiv:2507.18059v2 Announce Type: replace Abstract: Due to practical constraints such as partial observability and limited communication, Centralized Training with Decentralized Execution (CTDE) has become the dominant paradigm in cooperative Multi-Agent Reinforcement Learning (MARL). However, existing CTDE methods often underutilize centralized training or lack theoretical guarantees. We propose Multi-Agent Guided Policy Optimization (MAGPO), a novel framework that better leverages centralized
     

Multi-Agent Guided Policy Optimization

arXiv:2507.18059v2 Announce Type: replace Abstract: Due to practical constraints such as partial observability and limited communication, Centralized Training with Decentralized Execution (CTDE) has become the dominant paradigm in cooperative Multi-Agent Reinforcement Learning (MARL). However, existing CTDE methods often underutilize centralized training or lack theoretical guarantees. We propose Multi-Agent Guided Policy Optimization (MAGPO), a novel framework that better leverages centralized training by integrating centralized guidance with decentralized execution. MAGPO uses an autoregressive joint policy for scalable, coordinated exploration and explicitly aligns it with decentralized policies to ensure deployability under partial observability. We provide theoretical guarantees of monotonic policy improvement and empirically evaluate MAGPO on 43 tasks across 6 diverse environments. Results show that MAGPO consistently outperforms strong CTDE baselines and matches or surpasses fully centralized approaches, offering a principled and practical solution for decentralized multi-agent learning. Our code and experimental data can be found in https://github.com/liyheng/MAGPO.

Guided Policy Optimization under Partial Observability

arXiv:2505.15418v2 Announce Type: replace-cross Abstract: Reinforcement Learning (RL) in partially observable environments poses significant challenges due to the complexity of learning under uncertainty. While additional information, such as that available in simulations, can enhance training, effectively leveraging it remains an open problem. To address this, we introduce Guided Policy Optimization (GPO), a framework that co-trains a guider and a learner. The guider takes advantage of privileged information while ensuring alignment with the learner's policy that is primarily trained via imitation learning. We theoretically demonstrate that this learning scheme achieves optimality comparable to direct RL, thereby overcoming key limitations inherent in existing approaches. Empirical evaluations show strong performance of GPO across various tasks, including continuous control with partial observability and noise, and memory-based challenges, significantly outperforming existing methods.

SvfEye: A Semantic-Visual Fusion Framework with Multi-Scale Visual Context for Multimodal Reasoning

arXiv:2603.00171v2 Announce Type: replace-cross Abstract: Multimodal Large Language Models (MLLMs) often struggle to accurately perceive fine-grained visual details, especially when targets are tiny or visually subtle. This challenge can be addressed through semantic-visual information fusion, which integrates global image context with fine-grained local evidence for multi-scale visual understanding. Recently, a paradigm termed "Thinking with Images" has emerged, enabling models to acquire high-resolution visual evidence by zooming or cropping image regions and fusing these local details with global context during reasoning. Although training-based approaches demonstrate the effectiveness of this capability, they require extensive computational resources and large-scale task-specific data. Consequently, lightweight training-free methods have been proposed as a practical alternative to incorporate local visual evidence during inference. However, existing training-free approaches still suffer from two key limitations. First, they indiscriminately extract and fuse local visual regions for all inputs regardless of necessity, introducing computational redundancy and perceptual noise. Second, they exhibit drift between semantic intent and visual attention, preventing accurate localization of user-focused regions. To address these challenges, we propose SvfEye, a training-free framework for adaptive visual-semantic fusion. SvfEye follows a two-stage pipeline with a confidence-based decision module to determine whether additional local visual information is needed, and a semantic-attention fusion module to identify informative local regions. Experiments show that SvfEye achieves substantial performance gains while obtaining an approximately 4.0x inference speedup over the state-of-the-art method ZoomEye.

Integrated Network Toxicology and Metabolomics Elucidate Mechanisms of Carbosulfan-Induced Respiratory Toxicity in Rats

Int J Mol Sci. 2026 Feb 25;27(5):2170. doi: 10.3390/ijms27052170.

ABSTRACT

Carbosulfan is a widely used carbamate insecticide, yet its mechanisms of respiratory toxicity remain poorly understood. This study integrated network toxicology, untargeted metabolomics, and molecular docking to systematically investigate the potential mechanisms of carbosulfan-induced respiratory toxicity in male Sprague Dawley rats. Rats were administered a single oral dose of carbosulfan (125 or 250 mg/kg) and assessed after 12 h. Exposure resulted in significant pathological lung damage, characterized by disrupted alveolar architecture, inflammatory cell infiltration, and increased serum levels of the pro-inflammatory cytokines IL-6, IL-1β, and TNF-α. Network toxicology analysis identified 51 potential targets associated with respiratory toxicity, with core targets including SRC, EGFR, PTGS2, CXCL8, CYP3A4, and NR3C1. Enriched pathways were primarily related to neuroactive ligand-receptor interaction, VEGF signaling, and arachidonic acid metabolism. Untargeted metabolomics revealed significant metabolic perturbations in pathways central to antioxidant defense and energy homeostasis, including glutathione metabolism, the tricarboxylic acid cycle, and arginine biosynthesis. Molecular docking confirmed stable in silico binding affinities between carbosulfan and the predicted core targets. Integrative analysis suggests that carbosulfan exposure is associated with respiratory damage, potentially through interconnected mechanisms involving oxidative stress, inflammation, and disruption of cell signaling and metabolic enzyme systems. However, given the acute high-dose nature of the model and the interpretative integration of multi-omics data, these findings should be considered hypothesis-generating. This study provides a novel system-level perspective on carbosulfan-induced respiratory toxicity and highlights key pathways and targets for future validation in chronic exposure models.

PMID:41828400 | PMC:PMC12984169 | DOI:10.3390/ijms27052170

Integrated Network Toxicology and Metabolomics Elucidate Mechanisms of Carbosulfan-Induced Respiratory Toxicity in Rats

Int J Mol Sci. 2026 Feb 25;27(5):2170. doi: 10.3390/ijms27052170.

ABSTRACT

Carbosulfan is a widely used carbamate insecticide, yet its mechanisms of respiratory toxicity remain poorly understood. This study integrated network toxicology, untargeted metabolomics, and molecular docking to systematically investigate the potential mechanisms of carbosulfan-induced respiratory toxicity in male Sprague Dawley rats. Rats were administered a single oral dose of carbosulfan (125 or 250 mg/kg) and assessed after 12 h. Exposure resulted in significant pathological lung damage, characterized by disrupted alveolar architecture, inflammatory cell infiltration, and increased serum levels of the pro-inflammatory cytokines IL-6, IL-1β, and TNF-α. Network toxicology analysis identified 51 potential targets associated with respiratory toxicity, with core targets including SRC, EGFR, PTGS2, CXCL8, CYP3A4, and NR3C1. Enriched pathways were primarily related to neuroactive ligand-receptor interaction, VEGF signaling, and arachidonic acid metabolism. Untargeted metabolomics revealed significant metabolic perturbations in pathways central to antioxidant defense and energy homeostasis, including glutathione metabolism, the tricarboxylic acid cycle, and arginine biosynthesis. Molecular docking confirmed stable in silico binding affinities between carbosulfan and the predicted core targets. Integrative analysis suggests that carbosulfan exposure is associated with respiratory damage, potentially through interconnected mechanisms involving oxidative stress, inflammation, and disruption of cell signaling and metabolic enzyme systems. However, given the acute high-dose nature of the model and the interpretative integration of multi-omics data, these findings should be considered hypothesis-generating. This study provides a novel system-level perspective on carbosulfan-induced respiratory toxicity and highlights key pathways and targets for future validation in chronic exposure models.

PMID:41828400 | PMC:PMC12984169 | DOI:10.3390/ijms27052170

MAPK14/SLC7A11/GPX4 axis dysregulation drives podocyte ferroptosis via mediating glycerophospholipid metabolism

Cell Death Discovery, Published online: 11 March 2026; doi:10.1038/s41420-026-02990-7

MAPK14/SLC7A11/GPX4 axis dysregulation drives podocyte ferroptosis via mediating glycerophospholipid metabolism

SynPlanResearch-R1: Encouraging Tool Exploration for Deep Research with Synthetic Plans

arXiv:2603.07853v1 Announce Type: new Abstract: Research Agents enable models to gather information from the web using tools to answer user queries, requiring them to dynamically interleave internal reasoning with tool use. While such capabilities can in principle be learned via reinforcement learning with verifiable rewards (RLVR), we observe that agents often exhibit poor exploration behaviors, including premature termination and biased tool usage. As a result, RLVR alone yields limited improvements. We propose SynPlanResearch-R1, a framework that synthesizes tool-use trajectories that encourage deeper exploration to shape exploration during cold-start supervised fine-tuning, providing a strong initialization for subsequent RL. Across seven multi-hop and open-web benchmarks, \framework improves performance by up to 6.0% on Qwen3-8B and 5.8% on Qwen3-4B backbones respectively compared to SOTA baselines. Further analyses of tool-use patterns and training dynamics compared to baselines shed light on the factors underlying these gains. Our code is publicly available at https://github.com/HansiZeng/syn-plan-research.

PIRA-Bench: A Transition from Reactive GUI Agents to GUI-based Proactive Intent Recommendation Agents

arXiv:2603.08013v1 Announce Type: new Abstract: Current Graphical User Interface (GUI) agents operate primarily under a reactive paradigm: a user must provide an explicit instruction for the agent to execute a task. However, an intelligent AI assistant should be proactive, which is capable of anticipating user intentions directly from continuous visual inputs, such as mobile or desktop screenshots, and offering timely recommendations without explicit user prompting. Transitioning to this proactive paradigm presents significant challenges. Real-world screen activity is rarely linear; it consists of long-horizon trajectories fraught with noisy browsing, meaningless actions, and multithreaded task-switching. To address this gap, we introduce PIRA-Bench (Proactive Intent Recommendation Agent Benchmark), a novel benchmark for evaluating multimodal large language models (MLLMs) on continuous, weakly-supervised visual inputs. Unlike reactive datasets, PIRA-Bench features complex trajectories with multiple interleaved intents and noisy segments with various user profile contexts, challenging agents to detect actionable events while fitting to user preferences. Furthermore, we propose the PIRF baseline, a memory-aware, state-tracking framework that empowers general MLLMs to manage multiple task threads and handle misleading visual inputs. PIRA-Bench serves as an initial step toward robust and proactive GUI-based personal assistants.

Thinking with Gaze: Sequential Eye-Tracking as Visual Reasoning Supervision for Medical VLMs

arXiv:2603.06697v1 Announce Type: cross Abstract: Vision--language models (VLMs) process images as visual tokens, yet their intermediate reasoning is often carried out in text, which can be suboptimal for visually grounded radiology tasks. Radiologists instead diagnose via sequential visual search; eye-tracking captures this process as time-ordered gaze trajectories that reveal how evidence is acquired over time. We use eye-gaze as supervision to guide VLM reasoning by introducing a small set of dedicated gaze tokens. These tokens are trained to predict gaze-selected image patch indices in temporal order, encouraging the model to follow human-like evidence acquisition and integration. Experiments on MIMIC-EYE and multiple external zero-shot benchmarks show consistent gains over baselines, achieving state-of-the-art in-domain performance and improved out-of-domain robustness. These results highlight temporally ordered gaze as an effective supervision signal for learning visually grounded medical reasoning.
❌