arXiv ScienceSearch

arXiv subjects

Hongru Song

Publications and source records attributed to Hongru Song.

10 recordsLinked to original sources

DeepRepro: State-Aware Subplanning for Paper-to-Code Reproduction in Evolving Repositories

Recent advances in agentic large language models (LLMs) have enabled increasingly autonomous software engineering workflows, yet automatic machine learning (ML) paper-to-code reproduction remains a challenging long-horizon problem. Unlike conventional code generation, this task requires constructing and maintaining a fully functional repository whose state continuously evolves during execution. Existing systems typically rely on static upfront planning followed by sequential file-level generation, which often leads to inconsistencies as dependencies, interfaces, and execution feedback change over time. We propose DeepRepro, a state-aware framework for paper-to-code reproduction based on execution-state-aware subplanning. DeepRepro dynamically transforms evolving repository states and runtime feedback into fine-grained implementation subplans, keeping planning aligned with execution throughout repository construction. The framework further incorporates repository-aware orchestration and a lightweight process-aware interface for transparent monitoring of long-horizon reproduction. Experiments on PaperBench Code-Dev show that DeepRepro consistently outperforms strong scientific and commercial code-agent baselines.

cs.SE

AdversarialCoT: Single-Document Retrieval Poisoning for LLM Reasoning

Retrieval-augmented generation (RAG) enhances large language model (LLM) reasoning by retrieving external documents, but also opens up new attack surfaces. We study knowledge-base poisoning attacks in RAG, where an attacker injects malicious content into the retrieval corpus, which is then naturally surfaced by the retriever and consumed by the LLM during reasoning. Unlike prior work that floods the corpus with poisoned documents, we propose AdversarialCoT, a query-specific attack that poisons only a single document in the corpus. AdversarialCoT first extracts the target LLM's reasoning framework to guide the construction of an initial adversarial chain-of-thought (CoT). The adversarial document is iteratively refined through interactions with the LLM, progressively exposing and exploiting critical reasoning vulnerabilities. Experiments on benchmark LLMs show that a single adversarial document can significantly degrade reasoning accuracy, revealing subtle yet impactful weaknesses. This study exposes security risks in RAG systems and provides actionable insights for designing more robust LLM reasoning pipelines.

cs.IR

An overdetermined problem related to the p-Laplacian on Riemannian manifolds

In this paper, we study the overdetermined problem for the p-Laplacian equation on a compact Riemannian manifold with positive Ricci curvature. By introducing a new P-function which is related to the first nonzero eigenvalue for p-Laplacian, we obtain some integral identities. As their applications, the Heintze-Karcher type inequality and the Soap Bubble Theorem have been achieved.

math.AP

LLMs as Sparse Retrievers:A Framework for First-Stage Product Search

Product search is a crucial component of modern e-commerce platforms, with billions of user queries every day. In product search systems, first-stage retrieval should achieve high recall while ensuring efficient online deployment. Sparse retrieval is particularly attractive in this context due to its interpretability and storage efficiency. However, sparse retrieval methods suffer from severe vocabulary mismatch issues, leading to suboptimal performance in product search scenarios. With their potential for semantic analysis, large language models (LLMs) offer a promising avenue for mitigating vocabulary mismatch issues and thereby improving retrieval quality. Directly applying LLMs to sparse retrieval in product search exposes two key challenges:(1)Queries and product titles are typically short and highly susceptible to LLM-induced hallucinations, such as generating irrelevant expansion terms or underweighting critical literal terms like brand names and model numbers;(2)The large vocabulary space of LLMs leads to difficulty in initializing training effectively, making it challenging to learn meaningful sparse representations in such ultra-high-dimensional spaces.To address these challenges, we propose PROSPER, a framework for PROduct search leveraging LLMs as SParsE Retrievers. PROSPER incorporates: (1)A literal residual network that alleviates hallucination in lexical expansion by reinforcing underweighted literal terms through a residual compensation mechanism; and (2)A lexical focusing window that facilitates effective training initialization via a coarse-to-fine sparsification strategy.Extensive offline and online experiments show that PROSPER significantly outperforms sparse baselines and achieves recall performance comparable to advanced dense retrievers, while also achieving revenue increments online.

cs.IR

The Silent Saboteur: Imperceptible Adversarial Attacks against Black-Box Retrieval-Augmented Generation Systems

We explore adversarial attacks against retrieval-augmented generation (RAG) systems to identify their vulnerabilities. We focus on generating human-imperceptible adversarial examples and introduce a novel imperceptible retrieve-to-generate attack against RAG. This task aims to find imperceptible perturbations that retrieve a target document, originally excluded from the initial top-$k$ candidate set, in order to influence the final answer generation. To address this task, we propose ReGENT, a reinforcement learning-based framework that tracks interactions between the attacker and the target RAG and continuously refines attack strategies based on relevance-generation-naturalness rewards. Experiments on newly constructed factual and non-factual question-answering benchmarks demonstrate that ReGENT significantly outperforms existing attack methods in misleading RAG systems with small imperceptible text perturbations.

cs.IR

Chain-of-Thought Poisoning Attacks against R1-based Retrieval-Augmented Generation Systems

Retrieval-augmented generation (RAG) systems can effectively mitigate the hallucination problem of large language models (LLMs),but they also possess inherent vulnerabilities. Identifying these weaknesses before the large-scale real-world deployment of RAG systems is of great importance, as it lays the foundation for building more secure and robust RAG systems in the future. Existing adversarial attack methods typically exploit knowledge base poisoning to probe the vulnerabilities of RAG systems, which can effectively deceive standard RAG models. However, with the rapid advancement of deep reasoning capabilities in modern LLMs, previous approaches that merely inject incorrect knowledge are inadequate when attacking RAG systems equipped with deep reasoning abilities. Inspired by the deep thinking capabilities of LLMs, this paper extracts reasoning process templates from R1-based RAG systems, uses these templates to wrap erroneous knowledge into adversarial documents, and injects them into the knowledge base to attack RAG systems. The key idea of our approach is that adversarial documents, by simulating the chain-of-thought patterns aligned with the model's training signals, may be misinterpreted by the model as authentic historical reasoning processes, thus increasing their likelihood of being referenced. Experiments conducted on the MS MARCO passage ranking dataset demonstrate the effectiveness of our proposed method.

cs.IR

On the immersed submanifolds in the unit sphere with parallel Blaschke tensor

As is known, the Blaschke tensor $A$ (a symmetric covariant $2$-tensor) is one of the fundamental Möbius invariants in the Möbius differential geometry of submanifolds in the unit sphere $\mathbb S^n$, and the eigenvalues of $A$ are referred to as the Blaschke eigenvalues. In this paper, we shall prove a classification theorem for immersed umbilic-free submanifolds in $\mathbb S^n$ with a parallel Blaschke tensor. For proving this classification, some new kinds of examples are first defined.

math.DG

On the immersed submanifolds in the unit sphere with parallel Blaschke tensor II

As is known, the Blaschke tensor $A$ (a symmetric covariant $2$-tensor) is one of the fundamental Möbius invariants in the Möbius differential geometry of submanifolds in the unit sphere $\mathbb S^n$, and the eigenvalues of $A$ are referred to as the Blaschke eigenvalues. In this paper, we continue our job for the study on the submanifolds in $\bbs^n$ with parallel Blaschke tensors which we simply call {\em Blaschke parallel submanifolds} to find more examples and seek a complete classification finally. The main theorem of this paper is the classification of Blaschke parallel submanifolds in $\mathbb S^n$ with exactly three distinct Blaschke eigenvalues. Before proving this classification we define, as usual, a new class of examples.

math.DG

On the regular space-like hypersurfaces in the de Sitter space ${\mathbb S}^{m+1}_{1}$ with parallel Blaschke tensors

In this paper, we use two conformal non-homogeneous coordinate systems, modeled on the de Sitter space ${\mathbb S}^{m+1}_1$, to cover the conformal space ${\mathbb Q}^{m+1}_1$, so that the conformal geometry of regular space-like hypersurfaces in $\mathbb{Q}^{m+1}_1$ is treated as that of hypersurfaces in ${\mathbb S}^{m+1}_1$. As a result, we give a complete classification of the regular space-like hypersurfaces (represented in the de Sitter space ${\mathbb S}^{m+1}_1$) with parallel Blaschke tensors.

math.DG