Researcher profile

Andrew Zhao

Andrew Zhao contributes to research discovery and scholarly infrastructure.

ResearcherAffiliation not importedOpen to collaborate

Trust snapshot

Quick read

Trust 19 - UnverifiedVerification L1Unclaimed author
5works
0followers
8topics
4close collaborators

Actions

Decide how to stay connected

Follow researcher0

Identity and collaboration

How to connect with this researcher

Claiming links this public author record to a researcher profile and unlocks direct collaboration workflows.

Log in to claim

Direct collaboration

Open a focused conversation when the fit is right

Claim this author entity first to unlock direct invitations.

Research graph

See the researcher in context

Open full explorer

Inspect adjacent work, topics, institutions and collaborators without jumping out to a separate graph page.

Building this graph slice

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

5 published item(s)

preprint2026arXiv

Are My Optimized Prompts Compromised? Exploring Vulnerabilities of LLM-based Optimizers

Large language model (LLM) systems increasingly power everyday AI applications such as chatbots, computer-use assistants, and autonomous robots, where performance often depends on manually well-crafted prompts. LLM-based prompt optimizers reduce that effort by iteratively refining prompts from scored feedback, yet the security of this optimization stage remains underexamined. We present the first systematic analysis of poisoning risks in LLM-based prompt optimization. Using HarmBench, we find systems are substantially more vulnerable to manipulated feedback than to query poisoning alone: feedback-based attacks raise attack success rate (ASR) by up to ΔASR = 0.48. We introduce a simple fake reward attack that requires no access to the reward model and significantly increases vulnerability. We also propose a lightweight highlighting defense that reduces the fake reward ΔASR from 0.23 to 0.07 without degrading utility. These results establish prompt optimization pipelines as a first-class attack surface and motivate stronger safeguards for feedback channels and optimization frameworks.

preprint2022arXiv

Quantum computational advantage attested by nonlocal games with the cyclic cluster state

We propose a set of Bell-type nonlocal games that can be used to prove an unconditional quantum advantage in an objective and hardware-agnostic manner. In these games, the circuit depth needed to prepare a cyclic cluster state and measure a subset of its Pauli stabilizers on a quantum computer is compared to that of classical Boolean circuits with the same, nearest-neighboring gate connectivity. Using a circuit-based trapped-ion quantum computer, we prepare and measure a six-qubit cyclic cluster state with an overall fidelity of 60.6% and 66.4%, before and after correcting for measurement-readout errors, respectively. Our experimental results indicate that while this fidelity readily passes conventional (or depth-0) Bell bounds for local hidden-variable models, it is on the cusp of demonstrating a higher probability of success than what is possible by depth-1 classical circuits. Our games offer a practical and scalable set of quantitative benchmarks for quantum computers in the pre-fault-tolerant regime as the number of qubits available increases.

preprint2020arXiv

Measurement reduction in variational quantum algorithms

Variational quantum algorithms are promising applications of noisy intermediate-scale quantum (NISQ) computers. These algorithms consist of a number of separate prepare-and-measure experiments that estimate terms in a Hamiltonian. The number of terms can become overwhelmingly large for problems at the scale of NISQ hardware that may soon be available. We approach this problem from the perspective of contextuality, and use unitary partitioning (developed independently by Izmaylov et al. [J. Chem. Theory Comput. 16, 190 (2020)]) to define variational quantum eigensolver procedures in which additional unitary operations are appended to the ansatz preparation to reduce the number of terms. This approach may be scaled to use all coherent resources available after ansatz preparation. We also study the use of asymmetric qubitization to implement the additional coherent operations with lower circuit depth. We investigate this technique for lattice Hamiltonians, random Pauli Hamiltonians, and electronic structure Hamiltonians. Using this technique, we find a constant factor speedup for lattice and random Pauli Hamiltonians. For electronic structure Hamiltonians, we prove that linear term reduction with respect to the number of orbitals, which has been previously observed in numerical studies, is always achievable. For systems represented on 10--30 qubits, we find that there is a reduction in the number of terms by approximately an order of magnitude. Applied to the plane-wave dual basis representation of fermionic Hamiltonians, however, unitary partitioning offers only a constant factor reduction. Finally, we show that noncontextual Hamiltonians may be reduced to effective commuting Hamiltonians using unitary partitioning.

preprint2020arXiv

The No-Flippancy Game

We analyze a coin-based game with two players where, before starting the game, each player selects a string of length $n$ comprised of coin tosses. They alternate turns, choosing the outcome of a coin toss according to specific rules. As a result, the game is deterministic. The player whose string appears first wins. If neither player's string occurs, then the game must be infinite. We study several aspects of this game. We show that if, after $4n-4$ turns, the game fails to cease, it must be infinite. Furthermore, we examine how a player may select their string to force a desired outcome. Finally, we describe the result of the game for particular cases.