arXiv ScienceSearch

arXiv subjects

Qinfeng Li

Publications and source records attributed to Qinfeng Li.

At least 19 recordsLinked to original sources

Global Strict Monotonicity and Asymptotics of the First Steklov Eigenvalue for Regular Polygons

For a bounded Lipschitz planar domain $Ω$, let $σ_1(Ω)$ denote its first nonzero Steklov eigenvalue. Let $Ω_N$ be the regular $N$-gon normalized to have perimeter $2π$. We prove that \[ σ_1(Ω_{N+1})>σ_1(Ω_N),\qquad N\ge3. \] Consequently, $σ_1(Ω_N)$ increases strictly to the disk value $1$. We also show that the real first eigenspace has dimension two and derive the asymptotic expansion \[ σ_1(Ω_N) =1-\frac{2ζ(3)}{N^3} -\frac{8ζ(4)}{N^4} -\frac{26ζ(5)}{N^5} +O(N^{-6}). \] The proof combines an equivariant Schwarz--Christoffel pullback, a nodal selection of the two critical Fourier residue classes, and a positivity-improving Perron comparison for the associated reciprocal operators. The asymptotic expansion follows independently from a Schur reduction and the evaluation of Euler-type sums.

math.AP

The Pólya--Szegő conjecture for convex polygons with many sides

For every sufficiently large N, we prove that the regular N-gon uniquely minimizes the first Dirichlet eigenvalue among convex polygons of prescribed area with at most N sides, up to rigid motions. Quantitative Faber--Krahn stability localizes minimizers near the disk but leaves their discrete geometry undetermined. We encode that geometry by a centered measure of exterior angles and prove an inverse-cubic Fourier inequality whose equality case is the uniform root configuration. Its defect gives a lower bound for the quadratic spectral excess over the regular polygon. Cyclic cancellation and a common material-coordinate comparison make the nonlinear difference small relative to the same defect. Exact constraint coordinates extend this comparison to arbitrarily small positive defects. Minimality then forces zero defect, which characterizes the regular polygon.

math.AP

A Quantitative Pólya--Szegő Theorem for Tangential Polygons

For a bounded Lipschitz domain $Ω\subset\mathbb R^2$, let $T(Ω)=\int_Ωu_Ω\, dx$ denote its torsional rigidity, where $-Δu_Ω=1$ in $Ω$ and $u_Ω=0$ on $\partialΩ$. We prove a quantitative Pólya--Szegő inequality for tangential polygons. Let $N\ge3$, let $P$ be a tangential $N$-gon, set $A=|P|$, and let $R_N$ be the regular $N$-gon of area $A$. Writing $L(\cdot)$ for perimeter, we obtain the explicit deficit estimate \[ T(R_N)-T(P)\ge \frac{A^2}{8N\tan(π/N)} \left(1-\frac{L(R_N)^2}{L(P)^2}\right)^2.\]Thus, at fixed area, the torsional deficit is controlled from below purely by the perimeter ratio. In particular, the regular $N$-gon is the unique maximizer of torsional rigidity among tangential $N$-gons of prescribed area; for $N=3$ this gives the classical triangular Pólya--Szegő theorem with a quantitative estimate. The same perimeter estimate yields an explicit positive lower bound for $T(R_{N+1})-T(R_N)$ for equal-area regular polygons, and hence a rather short alternative proof of the strict monotonicity of torsional rigidity in $N$. Combined with the Kohler--Jobin inequality, it also gives an explicit sufficient condition for the polygonal Faber--Krahn inequality within the tangential class. Our full quantitative inequality is stronger: it contains, in addition, a nonnegative angular Jensen deficit, which yields quantitative angular stability away from degenerate configurations.

math.AP

AttriMem: Attribution-Guided Process Feedback for Agent Memory Construction

Effective memory is crucial for LLM agents, yet constructing it effectively remains challenging. A memory-construction policy decides what information to extract, store, update, compress, or discard as interactions accumulate. Heuristic memory methods rely on subjective, task-specific rules, which can misalign with downstream objectives and limit cross-task adaptability. RL-based methods, by contrast, learn from task feedback but mainly use outcome- or module-level rewards. These coarse signals indicate task success but cannot identify which intermediate memory contents support the final answer, creating a fine-grained credit-assignment bottleneck. However, constructing such process feedback is prohibitively difficult because intermediate memory decisions lack unique ground-truth targets, while the appropriate credit varies with the agent's uncertain reasoning trajectory and therefore cannot be specified in advance. We propose AttriMem, an attribution-guided process-feedback framework for learning memory-construction policies with RL. AttriMem augments the global outcome reward with local rewards derived from token-level contributions to the final answer. Experiments on long-horizon dialogue question answering show that AttriMem outperforms retrieval-based, heuristic, and RL-based baselines, generalizes across benchmarks and answer models, stabilizes RL optimization.

cs.AI

SkillAligner: Treating Retrieved Skills as Adaptable Drafts at Execution Time

General-purpose skills promise reusable procedural knowledge for language agents, yet semantic relevance does not guarantee execution utility: a retrieved skill may encode assumptions that conflict with the current task, execution environment, or other retrieved skills. We formalize this problem as the skill--execution misfit. To address it, we propose SkillAligner, a training-free execution-time skill adaptation framework that treats retrieved skills as adaptable drafts rather than fixed instructions. Before execution, SkillAligner performs a one-time joint adaptation that specializes useful skill fragments to task requirements, aligns their procedural assumptions with the available execution interface, and composes the resulting guidance by resolving dependencies, conflicts, and redundancy across skills. The adapted content is consolidated into a compact execution guide and reused throughout the subsequent trajectory. Extensive experiments across diverse agent benchmarks and model backbones show that SkillAligner substantially improves task performance over existing skill-use baselines, reduces skill-induced regressions at the instance level, and lowers total inference cost.

cs.LG

Serrin's Problem under Dirichlet Perturbations: Geometric Compactness and Sharp Planar Stability

In earlier work [21], we posed a stability question for Serrin's overdetermined problem under Dirichlet perturbations and proved that the answer is negative in dimensions $n\ge3$. Here we resolve the question in the planar convex class and obtain a sharp quantitative theory without any a priori geometric nondegeneracy. Let $u_Ω$ solve \[ -Δu_Ω=1\ \text{in }Ω,\qquad \partial_νu_Ω=-\frac{|Ω|}{P(Ω)}\ \text{on }\partialΩ, \qquad \int_{\partialΩ}u_Ω\,dσ=0, \] and set $O(Ω):=\text{osc}_{\partial Ω}u_Ω$. We construct fixed-area annuli with $O(Ω_k)\to0$ that remain far from every disk, showing that convexity is essential in dimension two. By contrast, if $Ω_k\subset\mathbb R^2$ are convex, $|Ω_k|=π$, and $O(Ω_k)\to0$, then, up to translations, $Ω_k$ converges in Hausdorff distance to the unit disk. Moreover, \[ R_Ω-r_Ω+\inf_{z\in\mathbb R^2}d_H(Ω,B_1(z)) \le C\,O(Ω) \] for all planar convex $Ω$ with $|Ω|=π$ and sufficiently small $O(Ω)$, and the linear order is optimal. The proof combines a new mechanism excluding long-thin degeneration, the rough-domain Serrin rigidity theorem of Figalli--Zhang, new tangential-gradient and linear boundary-growth estimates, a boundary $P$-function estimate, and the reverse-Serrin identity of Magnanini--Molinarolo--Poggesi. We also study the weaker deficit \[ A(Ω):=\frac1{P(Ω)}\int_{\partialΩ}u_Ω,dσ-\min_{\partialΩ}u_Ω. \] In the planar convex class, $A(Ω_k)\to0$ still forces convergence to a disk, and \[ R_Ω-r_Ω+\inf_z d_H(Ω,B_1(z)) \le C A(Ω)^{2/3} \] for $|Ω|=π$ and sufficiently small $A(Ω)$.

math.AP

Towards Steering without Sacrifice: Principled Training of Steering Vectors for Prompt-only Interventions

Recently, steering vectors (SVs) have emerged as an effective and lightweight approach to steer behaviors of large language models (LLMs), among which fine-tuned SVs are more effective than optimization-free ones. However, current approaches to fine-tuned SVs suffer from two limitations. First, they require careful selection of steering factors on a per-SV basis to balance steering effectiveness and generation quality at inference time. Second, they operate as full-sequence SVs (FSSVs), which can sacrifice generation quality regardless of factor selection due to excessive intervention on the model generation process. To address the first limitation, we propose joint training of steering factors and directions, such that post-hoc factor selection is no longer required. Using neural network scaling theory, we find that moderately large initialization sizes and learning rates for steering factors are essential for stability and efficiency of joint training. To tackle the second limitation, we draw inspiration from representation fine-tuning and introduce Prompt-only SV (PrOSV), an SV that intervenes only on a few prompt tokens. Our empirical results show that PrOSV outperforms traditional FSSVs on AxBench when using our joint training scheme. We also find that PrOSV achieves a better tradeoff between general model utility and adversarial robustness than FSSV.

cs.LG

Mixed Torsion on Right Triangles and the Pólya--Szegő Monotonicity Problem for Regular Polygons

Motivated by the polygonal Pólya--Szegő conjecture for torsional rigidity, we study two monotonicity problems for torsional rigidity. The first concerns a mixed torsion problem on fixed-area right triangles, with a Dirichlet condition on one leg and Neumann conditions on the other leg and on the hypotenuse. We prove that the mixed torsional rigidity strictly increases as the ratio of the Neumann leg to the Dirichlet leg increases. The proof uses a Hadamard shape derivative, a Pohozaev-type identity, and a monotonicity result for the mixed torsion function. We also prove a similar result for the mixed ground state of Laplacian. The second concerns regular polygons. If \(P_N\) denotes the regular \(N\)-gon of area \(π\), we prove, by a purely analytic Schwarz--Christoffel/Bergman analytic-content argument, that \[ T^D(P_{N+1})>T^D(P_N),\qquad N\ge3, \] where \(T^D\) is the Dirichlet torsional rigidity. We also obtain the asymptotic expansion \[ T^D(P_N)=\fracπ{8}-\frac{πζ(3)}{N^3} +\frac{π^5}{45N^4}+O(N^{-5}). \]

math.AP

PragLocker: Protecting Agent Intellectual Property in Untrusted Deployments via Non-Portable Prompts

LLM agents rely on prompts to implement task-specific capabilities based on foundation LLMs, making agent prompts valuable intellectual property. However, in untrusted deployments, adversaries can copy and reuse these prompts with other proprietary LLMs, causing economic losses. To protect these prompts, we identify four key challenges: proactivity, runtime protection, usability, and non-portability that existing approaches fail to address. We present PragLocker, a prompt protection scheme that satisfies these requirements. PragLocker constructs function-preserving obfuscated prompts by anchoring semantics with code symbols and then using target-model feedback to inject noise, yielding prompts that only work on the target LLM. Experiments across multiple agent systems, datasets, and foundation LLMs show that PragLocker substantially reduces cross-LLM portability, maintains target performance, and remains robust against adaptive attackers.

cs.CR

CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment

Proprietary large language models (LLMs) exhibit strong generalization capabilities across diverse tasks and are increasingly deployed on edge devices for efficiency and privacy reasons. However, deploying proprietary LLMs at the edge without adequate protection introduces critical security threats. Attackers can extract model weights and architectures, enabling unauthorized copying and misuse. Even when protective measures prevent full extraction of model weights, attackers may still perform advanced attacks, such as fine-tuning, to further exploit the model. Existing defenses against these threats typically incur significant computational and communication overhead, making them impractical for edge deployment. To safeguard the edge-deployed LLMs, we introduce CoreGuard, a computation- and communication-efficient protection method. CoreGuard employs an efficient protection protocol to reduce computational overhead and minimize communication overhead via a propagation protocol. Extensive experiments show that CoreGuard achieves upper-bound security protection with negligible overhead.

cs.CR

On the location of the maximal gradient of the torsion function over some non-symmetric planar domains

We investigate the location of the maximal gradient of the torsion function on certain non-symmetric planar domains. First, by establishing uniform estimates for convex narrow domains, we show that as a planar domain bounded by two graphs becomes increasingly narrow, the location of the maximal gradient of its torsion function converges to the endpoints of the longest vertical segment, with smaller curvature among them. This result confirms that Saint-Venant's conjecture on the location of fail points holds for asymptotically narrow domains. Second, for triangles, we prove that the maximal gradient of the torsion function always occurs on the longest side, lying between the foot of the altitude and the midpoint of that side. Moreover, via nodal line analysis, we show that, restricted to each side, the critical point of the gradient is unique and non-degenerate. Additionally, by perturbation and barrier arguments, we establish that for a class of nearly equilateral triangles, this critical point is closer to the midpoint than to the foot of the altitude, and the maximal gradient at the midpoint exceeds that at the foot of the altitude. Third, employing the reflection method, we demonstrate that for a non-concentric annulus, the maximal gradient of the torsion function is always attained at the point on the inner boundary closest to the center of the outer boundary.

math.AP

A flow approach to the monotonicity of shape functionals

We develop a geometric flow framework to investigate two classical shape functionals: the torsional rigidity and the first Dirichlet eigenvalue of the Laplacian. First, by constructing novel deformation paths governed by height-stretching flows, leg-stretching flows, and angle-bisector flows, we prove new monotonicity properties for these functionals under deformations of triangles and rhombuses. These results also lead to new and simpler proofs of some known results, without using the Steiner symmetrization argument. Second, we introduce a mean curvature flow approach to the Saint-Venant inequality, providing a new geometric proof for smooth convex domains. We establish a weak monotonicity property along the flow and characterize the equality case, which leads to the discovery of an intriguing new functional whose extremal properties suggest a further conjecture. Third, by discovering a gradient norm inequality for the sides of rectangles, we prove monotonicity and rigidity results of the torsional rigidity on rectangles.

math.AP

CryptoTensors: A Light-Weight Large Language Model File Format for Highly-Secure Model Distribution

To enhance the performance of large language models (LLMs) in various domain-specific applications, sensitive data such as healthcare, law, and finance are being used to privately customize or fine-tune these models. Such privately adapted LLMs are regarded as either personal privacy assets or corporate intellectual property. Therefore, protecting model weights and maintaining strict confidentiality during deployment and distribution have become critically important. However, existing model formats and deployment frameworks provide little to no built-in support for confidentiality, access control, or secure integration with trusted hardware. Current methods for securing model deployment either rely on computationally expensive cryptographic techniques or tightly controlled private infrastructure. Although these approaches can be effective in specific scenarios, they are difficult and costly for widespread deployment. In this paper, we introduce CryptoTensors, a secure and format-compatible file structure for confidential LLM distribution. Built as an extension to the widely adopted Safetensors format, CryptoTensors incorporates tensor-level encryption and embedded access control policies, while preserving critical features such as lazy loading and partial deserialization. It enables transparent decryption and automated key management, supporting flexible licensing and secure model execution with minimal overhead. We implement a proof-of-concept library, benchmark its performance across serialization and runtime scenarios, and validate its compatibility with existing inference frameworks, including Hugging Face Transformers and vLLM. Our results highlight CryptoTensors as a light-weight, efficient, and developer-friendly solution for safeguarding LLM weights in real-world and widespread deployments.

cs.CR

Do Not Merge My Model! Safeguarding Open-Source LLMs Against Unauthorized Model Merging

Model merging has emerged as an efficient technique for expanding large language models (LLMs) by integrating specialized expert models. However, it also introduces a new threat: model merging stealing, where free-riders exploit models through unauthorized model merging. Unfortunately, existing defense mechanisms fail to provide effective protection. Specifically, we identify three critical protection properties that existing methods fail to simultaneously satisfy: (1) proactively preventing unauthorized merging; (2) ensuring compatibility with general open-source settings; (3) achieving high security with negligible performance loss. To address the above issues, we propose MergeBarrier, a plug-and-play defense that proactively prevents unauthorized merging. The core design of MergeBarrier is to disrupt the Linear Mode Connectivity (LMC) between the protected model and its homologous counterparts, thereby eliminating the low-loss path required for effective model merging. Extensive experiments show that MergeBarrier effectively prevents model merging stealing with negligible accuracy loss.

cs.CR

RAGFort: Dual-Path Defense Against Proprietary Knowledge Base Extraction in Retrieval-Augmented Generation

Retrieval-Augmented Generation (RAG) systems deployed over proprietary knowledge bases face growing threats from reconstruction attacks that aggregate model responses to replicate knowledge bases. Such attacks exploit both intra-class and inter-class paths, progressively extracting fine-grained knowledge within topics and diffusing it across semantically related ones, thereby enabling comprehensive extraction of the original knowledge base. However, existing defenses target only one path, leaving the other unprotected. We conduct a systematic exploration to assess the impact of protecting each path independently and find that joint protection is essential for effective defense. Based on this, we propose RAGFort, a structure-aware dual-module defense combining "contrastive reindexing" for inter-class isolation and "constrained cascade generation" for intra-class protection. Experiments across security, performance, and robustness confirm that RAGFort significantly reduces reconstruction success while preserving answer quality, offering comprehensive defense against knowledge base extraction attacks.

cs.AI

Monotonicity properties of the Robin torsion function in a class of symmetric planar domains

We prove the monotonicity property of the Robin torsion function in a smooth planar domain $Ω$ with a line of symmetry, provided that the Robin coefficient $β$ is greater than or equal to the negative of the boundary curvature $κ$ (i.e., $β\geq -κ$ on $\partialΩ$). We also show that this condition is, in a certain sense, sharp by constructing a counterexample.

math.AP

Heat Transfer Shape Optimization: Stability and Non-Optimality of the Ball

This paper investigates shape optimization problems in the context of heat transfer, with a focus on the stability and non-optimality of round domains under Robin boundary conditions. Using the flow approach and Steklov eigenvalue estimates, we derive the necessary and sufficient stability conditions for a ball to maximize the averaged heat when the heat source is radially decreasing. Our results show that, counterintuitively, a ball may not be optimal for maximizing the averaged heat under heat convection, even with radially decreasing heat sources located on the center of the ball. Moreover, we identify stability-breaking phenomena by giving precise values of thresholds, which depend on the Robin coefficient, dimension, and volume constraints. Additionally, we demonstrate that a ball can maximize the averaged temperature under certain conditions and we also explore optimal shapes in thin insulation problems.

math.AP

Flow approach on Riesz type nonlocal energies

Via continuous deformations based on natural flow evolutions, we prove several novel monotonicity results for Riesz-type nonlocal energies on triangles and quadrilaterals. Some of these results imply new and simpler proofs for known theorems without relying on any symmetrization arguments.

math.AP