arXiv ScienceSearch

arXiv subjects

Haipeng Qu

Publications and source records attributed to Haipeng Qu.

13 recordsLinked to original sources

ShadowProbe: Language-Extensible Detection of Hidden Algorithmic Complexity Vulnerabilities

Algorithmic Complexity Vulnerabilities (ACVs) arise when adversarial inputs trigger worst-case execution behavior, causing severe performance degradation or Denial-of-Service conditions. A key but underexplored source is shadow complexity: non-trivial computational costs hidden inside seemingly benign standard library APIs. Because these costs are invisible at call sites, attackers can exploit them to induce unexpected superlinear runtime behavior. Existing ACV detectors often rely on fuzzing, symbolic execution, or hybrid analysis, but they are usually language-specific, require substantial manual effort to construct harnesses, and depend on heavy runtime instrumentation. We present ShadowProbe, a scalable and language-extensible framework for discovering ACVs through lightweight static analysis, automated reconstruction of execution contexts, and Large Language Model (LLM) assisted test generation. ShadowProbe uses a structured multi-stage pipeline: it statically screens for candidate functions guided by shadow-complexity signals, reconstructs minimal executable contexts from project-level symbols, and synthesizes size-controlled inputs to probe worst-case behavior. It then validates candidates using execution-time measurements and robust statistical growth inference, separating true algorithmic blowups from runtime noise such as garbage collection and JIT compilation effects. We evaluate ShadowProbe on the WISE benchmark, where it consistently improves analysis efficiency over existing approaches. We further apply it to large-scale systems including CPython, the JDK, Zig, Rustc, and vLLM, uncovering many previously unknown ACVs, many of which have been confirmed and partially remediated by maintainers. These results show that ShadowProbe can identify hidden algorithmic risks across diverse real-world codebases.

cs.CR

Finite groups with few conjugate classes of minimal non-abelian subgroups

Let $G$ be a finite non-abelian group and $\kappa_1(G)$ the number of conjugate classes of minimal non-abelian subgroups of $G$. The structure of $G$ with $\kappa_1(G)=1$ is determined. In the case of $G$ being the $p$-groups, the structure of $G$ with $\kappa_1(G)\leqslant p$ is also determined.

math.GR

A hybrid framework for effective and efficient machine unlearning

Recently machine unlearning (MU) is proposed to remove the imprints of revoked samples from the already trained model parameters, to solve users' privacy concern. Different from the runtime expensive retraining from scratch, there exist two research lines, exact MU and approximate MU with different favorites in terms of accuracy and efficiency. In this paper, we present a novel hybrid strategy on top of them to achieve an overall success. It implements the unlearning operation with an acceptable computation cost, while simultaneously improving the accuracy as much as possible. Specifically, it runs reasonable unlearning techniques by estimating the retraining workloads caused by revocations. If the workload is lightweight, it performs retraining to derive the model parameters consistent with the accurate ones retrained from scratch. Otherwise, it outputs the unlearned model by directly modifying the current parameters, for better efficiency. In particular, to improve the accuracy in the latter case, we propose an optimized version to amend the output model with lightweight runtime penalty. We particularly study the boundary of two approaches in our frameworks to adaptively make the smart selection. Extensive experiments on real datasets validate that our proposals can improve the unlearning efficiency by 1.5$\times$ to 8$\times$ while achieving comparable accuracy.

cs.LG

LoadLord: Loading on the Fly to Defend Against Code-Reuse Attacks

Code-reuse attacks have become a kind of common attack method, in which attackers use the existing code in the program to hijack the control flow. Most existing defenses focus on control flow integrity (CFI), code randomization, and software debloating. However, most fine-grained schemes of those that ensure such high security suffer from significant performance overhead, and only reduce attack surfaces such as software debloating can not defend against code-reuse attacks completely. In this paper, from the perspective of shrinking the available code space at runtime, we propose LoadLord, which dynamically loads, and timely unloads functions during program running to defend against code-reuse attacks. LoadLord can reduce the number of gadgets in memory, especially high-risk gadgets. Moreover, LoadLord ensures the control flow integrity of the loading process and breaks the necessary conditions to build a gadget chain. We implemented LoadLord on Linux operating system and experimented that when limiting only 1/16 of the original function. As a result, LoadLord can defend against code-reuse attacks and has an average runtime overhead of 1.7% on the SPEC CPU 2006, reducing gadgets by 94.02%.

cs.CR

Enhancing the Transferability via Feature-Momentum Adversarial Attack

Transferable adversarial attack has drawn increasing attention due to their practical threaten to real-world applications. In particular, the feature-level adversarial attack is one recent branch that can enhance the transferability via disturbing the intermediate features. The existing methods usually create a guidance map for features, where the value indicates the importance of the corresponding feature element and then employs an iterative algorithm to disrupt the features accordingly. However, the guidance map is fixed in existing methods, which can not consistently reflect the behavior of networks as the image is changed during iteration. In this paper, we describe a new method called Feature-Momentum Adversarial Attack (FMAA) to further improve transferability. The key idea of our method is that we estimate a guidance map dynamically at each iteration using momentum to effectively disturb the category-relevant features. Extensive experiments demonstrate that our method significantly outperforms other state-of-the-art methods by a large margin on different target models.

cs.CV

Finite DC-groups

Let G be a group and DS(G) = { H'| H is any subgroup of G}. G is said to be a DC-group if DS(G) is a chain. In this paper, we prove that a finite DC-group is a semidirect product of a Sylow p-subgroup and an abelian p'-subgroup. For the case of G being a finite p-group, we obtain some properties of a DC-group. In particular, a DC 2-group is characterized. Moreover, we prove that DC-groups are metabelian for p<5 and give an example that a non-abelian DC-group is not be necessarily metabelian for p>3.

math.GR

Determining sets and determining numbers of finite groups

Let $G$ be a group. A subset $D$ of $G$ is a determining set of $G$, if every automorphism of $G$ is uniquely determined by its action on $D$. The determining number of $G$, denoted by $α(G)$, is the cardinality of a smallest determining set. A generating set of $G$ is a subset such that every element of $G$ can be expressed as the combination, under the group operation, of finitely many elements of the subset and their inverses. The cardinality of a smallest generating set of $G$, denoted by $γ(G)$, is called the generating number of $G$. A group $G$ is called a DEG-group if $α(G)=γ(G)$. The main results of this article are as follows. Finite groups with determining number $0$ or $1$ are classified; Finite simple groups and finite nilpotent groups are proved to be DEG-groups; A finite group is a normal subgroup of a DEG-group and there is an injective mapping from the set all finite groups to the set of finite DEG-groups; Nilpotent groups of order $n$ which have the maximum determining number are classified; For any integer $k\geq 2$, there exists a group $G$ such that $α(G)=2$ and $γ(G)\geq k$.

math.GR

Chermak-Delgado Lattice Extension Theorems

In a finite group G with subgroup H, the Chermak-Delgado measure of H (in G) is defined as the product of the order of H with the order of the centralizer of H. The Chermak-Delgado lattice of G, denoted CD(G), is the set of all subgroups with maximal Chermak-Delgado measure; this set is a sublattice within the subgroup lattice of G. In this paper we provide an example of a p-group P, for any prime p, where CD(P) is lattice isomorphic to 2 copies of M_4 (a quasiantichain of width 2) that are adjoined maximum-to-minimum. We introduce terminology to describe this structure, called a 2-string of 2-diamonds, and we also give two constructions for generalizing the example. The first generalization results in a p-group with Chermak-Delgado lattice that, for any positive integers n and l, is a 2l-string of n-dimensional cubes adjoined maximum-to-minimum and the second generalization gives a construction for a p-group with Chermak-Delgado lattice that is a 2l-string of M_(p+3) (quasiantichains, each of width p + 1) adjoined maximum-to-minimum.

math.GR