Source author record

Li Hu

Li Hu appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

10works
7topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

10 published item(s)

preprint2026arXiv

Attractive Metadata Attack: Inducing LLM Agents to Invoke Malicious Tools

Large language model (LLM) agents have demonstrated remarkable capabilities in complex reasoning and decision-making by leveraging external tools. However, this tool-centric paradigm introduces a previously underexplored attack surface, where adversaries can manipulate tool metadata -- such as names, descriptions, and parameter schemas -- to influence agent behavior. We identify this as a new and stealthy threat surface that allows malicious tools to be preferentially selected by LLM agents, without requiring prompt injection or access to model internals. To demonstrate and exploit this vulnerability, we propose the Attractive Metadata Attack (AMA), a black-box in-context learning framework that generates highly attractive but syntactically and semantically valid tool metadata through iterative optimization. The proposed attack integrates seamlessly into standard tool ecosystems and requires no modification to the agent's execution framework. Extensive experiments across ten realistic, simulated tool-use scenarios and a range of popular LLM agents demonstrate consistently high attack success rates (81\%-95\%) and significant privacy leakage, with negligible impact on primary task execution. Moreover, the attack remains effective even against prompt-level defenses, auditor-based detection, and structured tool-selection protocols such as the Model Context Protocol, revealing systemic vulnerabilities in current agent architectures. These findings reveal that metadata manipulation constitutes a potent and stealthy attack surface. Notably, AMA is orthogonal to injection attacks and can be combined with them to achieve stronger attack efficacy, highlighting the need for execution-level defenses beyond prompt-level and auditor-based mechanisms. Code is available at https://github.com/SEAIC-M/AMA.

preprint2026arXiv

Cross-modal Retrieval Models for Stripped Binary Analysis

Retrieving binary code via natural language queries is a pivotal capability for downstream tasks in the software security domain, such as vulnerability detection and malware analysis. However, it is challenging to identify binary functions semantically relevant to the user query from thousands of candidates, as the absence of symbolic information distinguishes this task from source code retrieval. In this paper, we introduce, BinSeek, a two-stage cross-modal retrieval framework for stripped binary code analysis. It consists of two models: BinSeek-Embedding is trained on large-scale dataset to learn the semantic relevance of the binary code and the natural language description, furthermore, BinSeek-Reranker learns to carefully judge the relevance of the candidate code to the description with context augmentation. To this end, we built an LLM-based data synthesis pipeline to automate training construction, also deriving a domain benchmark for future research. Our evaluation results show that BinSeek achieved the state-of-the-art performance, surpassing the the same scale models by 31.42% in Rec@3 and 27.17% in MRR@3, as well as leading the advanced general-purpose models that have 16 times larger parameters.

preprint2026arXiv

When Does Value-Aware KV Eviction Help? A Fixed-Contract Diagnostic for Non-Monotone Cache Compression

Long-context LLM inference is bottlenecked by the memory and bandwidth cost of reading large KV caches during decoding. KV compression reduces this cost by keeping only part of the cache, but task accuracy alone does not identify why a selector succeeds or fails. A selector can fail at three steps: it may miss the evidence future decoding needs, give high scores to tokens that do not affect the output, or break related evidence when fitting scores into a small cache. We introduce a fixed-contract diagnostic that holds the selector's setup fixed and changes one decision slot at a time. For value ranking, the probe combines a block's attention mass with the estimated output change from removing it. On LongBench across three models and two budgets, the probe is positive on 72.6% of positive-margin cells and 32.4% of nonpositive-margin cells. NeedleBench M-RT at 32k and a RULER 8k check probe support closure under branched retrieval, and a 264-cell sign evaluation separates support recovery and output-value ranking from leverage effects near the boundary. The resulting order is to recover decode-side evidence, rank its output value, and preserve coupled evidence during projection.

preprint2022arXiv

Recurrent Dynamic Embedding for Video Object Segmentation

Space-time memory (STM) based video object segmentation (VOS) networks usually keep increasing memory bank every several frames, which shows excellent performance. However, 1) the hardware cannot withstand the ever-increasing memory requirements as the video length increases. 2) Storing lots of information inevitably introduces lots of noise, which is not conducive to reading the most important information from the memory bank. In this paper, we propose a Recurrent Dynamic Embedding (RDE) to build a memory bank of constant size. Specifically, we explicitly generate and update RDE by the proposed Spatio-temporal Aggregation Module (SAM), which exploits the cue of historical information. To avoid error accumulation owing to the recurrent usage of SAM, we propose an unbiased guidance loss during the training stage, which makes SAM more robust in long videos. Moreover, the predicted masks in the memory bank are inaccurate due to the inaccurate network inference, which affects the segmentation of the query frame. To address this problem, we design a novel self-correction strategy so that the network can repair the embeddings of masks with different qualities in the memory bank. Extensive experiments show our method achieves the best tradeoff between performance and speed. Code is available at https://github.com/Limingxing00/RDE-VOS-CVPR2022.

preprint2016arXiv

Quantitatively analyzing intrinsic plasmonic chirality by tracking the interplay of electric and magnetic dipole modes

Plasmonic chirality exhibits great potential for novel nanooptical devices due to the generation of a strong chiroptical response. Previous reports on plasmonic chirality explanations are mainly based on phase retardation and coupling. We propose a quantitative model similar to the chiral molecules for explaining the mechanism of the intrinsic plasmonic chirality quantitatively based on the interplay and mixing of electric and magnetic dipole modes, which forms a mixed electric and magnetic polarizability. The analysis method is also suitable for small chiral object down to quasi-static limit without phase delay and expected to be a universal rule.

preprint2015arXiv

Fano resonance assisting plasmonic circular dichroism from nanorice heterodimers for extrinsic chirality

In this work, the circular dichroisms (CD) of nanorice heterodimers consisting of two parallel arranged nanorices with the same size but different materials are investigated theoretically. Symmetry-breaking is introduced by using different materials and oblique incidence to achieve strong CD at the vicinity of Fano resonance peaks. We demonstrate that all Au-Ag heterodimers exhibit multipolar Fano resonances and strong CD effect. A simple quantitative analysis shows that the structure with larger Fano asymmetry factor has stronger CD. The intensity and peak positions of the CD effect can be flexibly tuned in a large range by changing particle size, shape, the inter-particle distance and surroundings. Furthermore, CD spectra exhibit high sensitivity to ambient medium in visible and near infrared regions. Our results here are beneficial for the design and application of high sensitive CD sensors and other related fields.

preprint2015arXiv

Heterodimer nanostructures induced energy focusing on metal film

As an interesting surface plasmon phenomenon discovered several years ago, electromagnetic field redistribution in nanoparticle dimer on film system provides a novel thought to enhance the light power on a plain film which could been widely used in surface enhanced Raman scattering (SERS), solar cells, photo-catalysis, etc. Homodimers on film are mainly investigated in past years, while the properties of heterodimers on film are still unclear. In this work, size difference induced electromagnetic field redistribution in Ag nanoparticle dimer on Au film system is investigated first. The results obtained from finite element method indicate that the smaller nanoparticle has much greater ability to focus light energy on Au film, which even reached more than 5 time compared to the larger one. Further researches indicate that this energy focusing ability has a strong relationship to the wavelength and diameter ration in dimer. Similar focusing phenomenon is found in the system of thick wire-smaller particle on film. Later, the SERS spectra collected in the small nanoparticle-large nanowire system provide an experimental evidence for this theoretic predication. Our results strengthen the understanding of surface plasmon on plane film and have potential application prospects in the surface plasmon related fields.

preprint2015arXiv

Quantitatively analyzing the mechanism of giant circular dichroism in extrinsic plasmonic chiral nanostructures by the interplay of electric and magnetic dipoles

The plasmonic chirality has drawn a lot of attention because of the tunable circular dichroism (CD) and the enhancement for the signal of chiral molecules. Different mechanisms have been proposed for explaining the plasmonic CD, however, a quantitative one like ab initio mechanism in chiral molecules is still unavailable. In this work, a mechanism similar to the chiral molecules is analyzed. The giant extrinsic circular dichroism of plasmonic splitting rectangle ring is quantitatively investigated theoretically. The interplay of electric and magnetic modes of the meta-structure is proposed to explain the giant CD. The interplay is analyzed both in an analytical coupled electric-magnetic dipoles model and finite element method model. The surface charge distributions show that the circular current yielded in the splitting rectangle ring makes it behave like a magneton at some resonant modes, which interact with electric modes and results in a mixing of the two kinds of modes. The strong interplay of the two kinds of modes is mainly responsible for the giant CD.The analysis of the chiral near field of the structure shows potential applications in chiral molecule sensing.

preprint2014arXiv

Utility Optimal Scheduling in Degree-Limited Satellite Networks

In this paper, we consider the problem of flow control together with power allocation to antennas on satellite with arbitrary link states, so as to maximize the utility function while stabilizing the network. Inspired by Lyapunov optimization method, a Degree-Limited Scheduling Algorithm (DLSA) is proposed with a control parameter V, which requires no stochastic knowledge of link state. Discussion about implementation is carried out about the complexity of DLSA and several approximation methods to reduce complexity. Analyze shows DLSA stabilizes the network and the gap between utility function under DLSA and the optimal value is arbitrarily close to zero on the order of O(1/V). Simulation results verify DLSA on a simple network.

preprint2009arXiv

Spherical cloaking using nonlinear transformations for improved segmentation into concentric isotropic coatings

Two novel classes of spherical invisibility cloaks based on nonlinear transformation have been studied. The cloaking characteristics are presented by segmenting the nonlinear transformation based spherical cloak into concentric isotropic homogeneous coatings. Detailed investigations of the optimal discretization (e.g., thickness control of each layer, nonlinear factor, etc.) are presented for both linear and nonlinear spherical cloaks and their effects on invisibility performance are also discussed. The cloaking properties and our choice of optimal segmentation are verified by the numerical simulation of not only near-field electric-field distribution but also the far-field radar cross section (RCS).