arXiv ScienceSearch

arXiv subjects

Yong Yang

Publications and source records attributed to Yong Yang.

At least 19 recordsLinked to original sources

IntraGuard: Committee-Side Defenses Against Review Outsourcing to Commercial Chatbots

LLMs become increasingly capable, editorial boards and program committees are growing concerned about reviewers who fully outsource peer review to commercial chatbots. This concern stems from prior findings that current chatbots lack the independent critical thinking and depth of reasoning required to assess scientific novelty. One promising direction for mitigating this concern is to embed hidden instructions into manuscripts that disrupt or alter chatbot-generated reviews. However, existing methods remain intuitive and fragile, as they typically rely on homogeneous payloads injected in an inter-stream manner, rendering them susceptible to sanitization or neutralization. More broadly, the community still lacks a systematic formulation of this threat and a principled defense framework. In this paper, we identify End-to-End Review Outsourcing as an emerging threat and propose IntraGuard, a black-box, venue-agnostic defense framework grounded in the structural--visual decoupling inherent to the PDF. Designed for committee-side deployment, IntraGuard supports both explicit strategies that trigger refusal or warning signals, and implicit strategies that embed predefined textual markers into the generated review. These strategies can be deployed via any of three intra-stream injection mechanisms, each of which seamlessly embeds heterogeneous defensive text objects within the PDF's underlying structure without altering its visual presentation. Extensive evaluations (over 17,844 cases) across 7 real-world commercial chatbot settings and 12 venues spanning diverse disciplines show that IntraGuard achieves a defense success rate of up to 84%, while preserving peer-review invariance for human reviewers. We further evaluate 11 adaptive attacks spanning manuscript sanitization and instruction interference, and discuss the implications of constructing ensemble defenses.

cs.CR

Search for neutrinoless quadruple beta decay of $^{136}$Xe in PandaX-4T detector

The observation of neutrinoless quadruple beta decay (0$ν$4$β$) in the absence of neutrinoless double beta decay (0$ν$2$β$) has been argued to provide a strong indication that neutrinos are Dirac particles. We report a search for 0$ν$4$β$ decay of $^{136}\text{Xe}$ using a total $^{136}\text{Xe}$ exposure of 148.4 kg$\cdot$yr, collected during the commissioning and the first science runs of the PandaX-4T experiment. No significant excess of events over the background is observed. A lower limit on the 0$ν$4$β$ decay half-life of $^{136}\text{Xe}$ is set at 6.01 x $10^{24}$ yr at the 90% confidence level. This result establishes the most stringent constraint on this process in xenon, demonstrating the unique capability of the PandaX-4T detector in probing lepton number violation and shedding light on the fundamental nature of neutrinos.

nucl-ex

$S^5$: Tidal Disruption in Crater 2 and Formation of Diffuse Dwarf Galaxies in the Local Group

We present results of a spectroscopic campaign around the diffuse dwarf galaxy Crater 2 (Cra2) and its tidal tails as part of the Southern Stellar Stream Spectroscopic Survey ($S^5$). Cra2 is a Milky Way dwarf spheroidal satellite with extremely cold kinematics, but a huge size similar to the Small Magellanic Cloud, which may be difficult to explain within collisionless cold dark matter. We identify 143 Cra2 members, of which 114 belong to the galaxy's main body and 29 are deemed part of its stellar stream. We confirm that Cra2 is dynamically cold (central velocity dispersion $2.51^{+0.33}_{-0.30}\,{\rm km \ s^{-1}}$) and also discover a $\approx$7$σ$ velocity gradient consistent with its tidal debris track. We separately estimate the stream's internal velocity dispersion to be $5.74^{+0.98}_{-0.83}\,{\rm km \ s^{-1}}$. We develop a suite of $N$-body simulations with both cuspy and cored density profiles on a realistic Cra2 orbit to compare with $S^5$ observations. We find that the velocity dispersion ratio between Cra2 stream and galaxy ($2.30^{+0.41}_{-0.35}$) is difficult to reconcile with a cuspy halo with fiducial concentration and an initial mass predicted by standard stellar mass--halo mass relationships. Instead, either a cored halo with relatively small core radius or a low-concentration cuspy model can reproduce this ratio. Despite tidal mass loss, Cra2 is metal-poor ($\langle \rm[Fe/H]\rangle=-2.16\pm0.04$) compared to the stellar mass--metallicity relation for its luminosity. Other diffuse dwarf galaxies similar to Cra2 in the Local Group (Antlia 2 and Andromeda 19) also challenge galaxy formation models. Finally, we discuss possible formation scenarios for Cra2, including ram-pressure stripping of a gas-rich progenitor combined with tides.

astro-ph.GA

Brauer character degrees and nilpotent subgroups

We solve a question raised by Chen and Navarro concerning Brauer characters and nilpotent subgroups. Let $N\lhd G$, assume that $G/N$ is solvable, and let $N\leq H\leq G$ with $H/N$ nilpotent. We prove that for every irreducible $\ell$-Brauer character $θ$ of $H$ there exists an irreducible $\ell$-Brauer character $χ$ of $G$ such that $θ$ is a constituent of $χ_H$ and $χ(1)$ divides $|G:H|θ(1)$.

math.GR

Products of nonconjugate maximal subgroups

We prove that a finite group $G$ is solvable whenever $MN=G$ for every pair of nonconjugate maximal subgroups $M,N<G$. Equivalently, every finite nonsolvable group has two nonconjugate maximal subgroups whose setwise product is proper. This gives a negative answer to Problem 10.34 of the Kourovka Notebook. As an application, we also answer an open question raised by Guo.

math.GR

Total 3-closure for projective special linear groups

A finite group is totally $3$-closed if every faithful permutation representation of it is $3$-closed. We study this property for the finite simple projective special linear groups. We prove that $\PSL_2(q)$ is totally $3$-closed if and only if $q\geq 7$ is prime, and that $\PSL_3(q)$ is totally $3$-closed if and only if either $q=3$, or $q$ is prime and $q\equiv 2\pmod 3$. We further prove that $\PSL_4(q)$ is never totally $3$-closed and that $\PSL_n(q)$ is not totally $3$-closed whenever $n\geq 5$ and $q>2$. Within the family $\PSL_n(q)$, only the groups $\PSL_n(2)$ with $n\geq 5$ remain unresolved. In particular, this answers Problem~20.2 of the Kourovka Notebook affirmatively.

math.GR

Lesioned Multimodal Language Models Reproduce Aphasic Picture-Naming Patterns

Aphasia following stroke commonly produces systematic naming errors with characteristic profiles, but whether general-purpose language models not designed for clinical simulation can reproduce these patterns remains untested. We investigated (1) whether lesions or controlled perturbations to a multimodal language model can reproduce different types of errors in picture naming, and (2) whether the framework can reproduce the complete error profile of individual persons with aphasia (PWAs). Using LLaVA 1.6, we evaluated perturbation configurations that varied the layer, proportion, and amount of noise applied to model units. We examined 278 PWAs on the Philadelphia Naming Test, classifying responses into seven categories using a validated neural classifier. Six of seven response categories (correct, semantic, mixed, unrelated, neologism, no response errors) emerged at clinically-comparable proportions across distinct parameter space regions, with formal paraphasia being the exception. Searching the perturbation space revealed configurations that reproduced the individual error profile in at least six of seven categories for 97.8% of PWAs and in all seven categories for 79.5% of PWAs. Monte Carlo baselines confirmed that this matching reflects joint inter-category structure rather than marginal overlap. These results establish a quantitative framework for reproducing individual aphasic error patterns in picture naming. They suggest the potential for language models to serve as digital twins of individuals with post-stroke aphasia.

cs.AI

Perturbation-based Regional Interpretability through Subtraction Mapping (PRISM): naming-error dissociations in language models and post-stroke aphasia

Mechanistic interpretability of large language models lacks spatially resolved, falsifiable tools for testing whether internal components are specialized for distinct cognitive operations. We adapt subtraction analysis, the standard framework of human neuroimaging, from biological brains to perturbed transformers, and apply the same logic to both substrates in parallel. Building on the Brain-LLM Unified Model (BLUM), which showed that layer-perturbed LLaVA-1.6-Vicuna-13B error profiles match the lesion patterns of aphasic patients, we develop PRISM (Perturbation-based Regional Interpretability through Subtraction Mapping). PRISM maps the seven clinical Philadelphia Naming Test categories, subtracts error classes pairwise, and treats each perturbation seed as a subject in a group analysis with threshold-free cluster enhancement along the layer axis. We run a structurally matched analysis on 213 chronic post-stroke aphasia patients using correlation-difference lesion-symptom mapping, and replicate both sides on held-out splits. The designs match in subject dimension (seeds, patients), spatial dimension (layers, atlas-parcellated cortex) and thresholding, but the contrast operator differs: a within-subject error-proportion difference for the LLM, a between-subject correlation difference for the cortex. Both substrates recover a robust phonemic-favoring dissociation, a deep layer cluster and a frontal-perisylvian cortical cluster, both replicating; the semantic-favoring direction is a consistently signed but non-significant trend on both. PRISM thus gives a falsifiable, spatially resolved test of functional-specialization claims in transformer language models. A confirmatory ROI-level intervention (PRISM Stage 3) licensing the strongest causal-mechanism claim is left to subsequent work.

cs.LG

Components of the Divisibility Graph of Finite Groups of Lie Type in Defining Characteristic $2$

We determine the connected components of the divisibility graph of several families of finite groups of Lie type in defining characteristic $2$, extending the result of Abdolghafourian, Iranmanesh, and Niemeyer (arXiv:1612.04410), who treated odd defining characteristic. We show that there is a distinguished component containing all nonidentity unipotent class sizes and that every other component is either an isolated vertex or an explicitly described two-vertex component. We also determine the isolated vertices outside the distinguished component. Additionally, we prove in Appendix A that the divisibility graph of a Frobenius group has exactly two components.

math.GR

Recovering Lesion Parameters from Aphasic Picture Naming Error Profiles in Large Language Models

Interpretability methods for large language models (LLMs) describe internal state but do not directly test whether that state is causally sufficient to produce the observed behavior. In earlier work, we lesioned LLMs to produce error profiles in picture naming, a central task for assessing aphasia, and found that specific lesions produced errors resembling those of individual stroke survivors. Here we ask the inverse question: given an error profile, can the lesion parameters that produced it be recovered, and what does this inverse problem reveal about transformer computation? Lesions in LLaVA-Vicuna 13B were parameterized by layer index, modification percentage, and noise sigma across 4,840 configurations, and error profiles were characterized by a seven-category clinical taxonomy (correct, semantic, unrelated, formal, mixed, neologism, no-response). We trained a multi-task neural network to map error profiles back to perturbation parameters. The problem admitted a partial solution: across 10 independently trained inverse models, modification percentage and noise sigma were recoverable, whereas layer index was recoverable only within a neighborhood. In counterfactual validation, a fresh model instance perturbed with the recovered parameters reproduced the target behavior in 81.4% of cases. This dissociation between low layer recovery and high counterfactual fidelity is consistent with functional redundancy across transformer layers, a property not captured by standard interpretability methods. As an out-of-distribution test, we applied the trained model to picture-naming error profiles from 278 stroke survivors; recovered parameters were syndrome-discriminative, most strongly for perturbation intensity, indicating generalization beyond the training distribution. Counterfactual validation provides a general framework for LLM interpretability claims beyond inverse mapping.

cs.CL

Alternating Groups and Embeddings into Groups Invariably Generated by Two Prime-Order Elements

For any distinct primes $p$ and $q$, we prove that there is a finite group which does not embed into any finite group invariably generated by an element of order $p$ and an element of order $q$. This gives a negative answer to Problem 21.142 of the Kourovka Notebook \cite{kourovka21}. In fact, for every fixed pair $p,q$, the group $A_n$ cannot embed into such a group once $n$ is sufficiently large in terms of $p$ and $q$.

math.GR

Albilich: Steerable Proof-State Orchestration for LLM-Based Mathematical Research with CAS Integration

Large language models can contribute useful ideas to mathematical research, yet long-horizon proof attempts remain difficult to coordinate, evaluate, and reproduce. We present Albilich, an open-source agentic harness for autoresearch in mathematics that combines long-horizon reasoning, computer algebra systems (CAS), literature retrieval, and persistent SQLite-based context management. We evaluate Albilich on the RealMath benchmark (Zhang et al. 2025) and on open problems in group theory from the Kourovka Notebook (Khukhro and Mazurov 2026). It solved 10/10 problems on RealMath with CAS and 9/10 with no CAS. On the Kourovka problems, Albilich produced a counterexample to Problem 21.142 and a proof of a strengthening of Problem20.2. Anablation on Problem 17.91 demonstrates 32.0% token reduction when CAS is enabled. An ablation on Problem 21.142 demonstrates higher verifier-rejection rate and failure to synthesize proof routes in the absence of the advisor agent. These results support Albilich as a human-steerable, CAS-boosted environment for scalable AI-assisted mathematical research.

cs.AI

Long Tidal Tails of NGC 5024 Hidden in LMS-1 and NGC 5053 Tidal Streams

We report the discovery of long tidal tails associated with the globular cluster (GC) NGC 5024. A modified matched filter applied to Gaia DR3 data reveals a broad stellar stream spanning $α\approx 230^{\circ}-175^{\circ}$. The stellar stream overlaps on the sky with the LMS-1 and with the simulated stream of the GC NGC 5053, and all three share similar proper motions and metallicity. Our member candidates may therefore be a mixture of stars from NGC 5024, NGC 5053, and LMS-1. Nevertheless, the trailing tail extends roughly $20^{\circ}$ beyond the known LMS-1 stream. Furthermore, the radial velocity (RV) as a function of $α$ is used to distinguish the genuine stream candidates of NGC 5024 from the streams of NGC 5053 and LMS-1. Among the sources in common with DESI (Dark Energy Spectroscopic Instrument) DR1, we found two distinct sequences in RV-$α$ plane, corresponding to the stellar streams of NGC 5024 and NGC 5053 (or LMS-1), respectively. This constitutes the first strong evidence for the existence of extensive tidal tails around NGC 5024.

astro-ph.GA

Ab initio Phase Diagram of Ta2O5

Tantalum pentoxide (Ta2O5) is a polymorphic wide-bandgap semiconductor with outstanding dielectric properties and widespread use in optical and electronic technologies. Its rich structural diversity, arising from multiple polymorphs accessible under different synthesis conditions, has made Ta2O5 a long-standing subject of interest. However, a unified understanding of the thermodynamic stability and phase transitions of its polymorphs across pressure-temperature (P-T) space has remained elusive. Here, using first-principles calculations, we map the thermodynamic landscape of Ta2O5 and establish a comprehensive P-T phase diagram together with a phase-stability hierarchy. We find that Gamma-Ta2O5 and B-Ta2O5 dominate the phase diagram over a broad range of P-T conditions: Gamma-Ta2O5 is stabilized at low pressures, while B-Ta2O5 becomes thermodynamically favored at higher pressures up to ~ 60 GPa, beyond which Y-Ta2O5 emerges as the most stable phase. Crucially, the zero-point energy (ZPE), one aspect of nuclear quantum effects (NQEs), plays a significant role in determining relative phase stability, contributing substantially to the Gibbs free energy and altering phase boundaries. A re-entrant phase transition between Gamma and B-Ta2O5 is predicted near ~ 2 GPa, revealing unexpected complexity in the phase behavior of this oxide. More generally, we identify a characteristic temperature (T_0), at which zero-point and thermal phonon contributions to the free energy become comparable, and show that T_0 is approximately one-third of the Debye temperature. This relationship provides a simple, physically transparent criterion for assessing the importance of NQEs in phase stability, with implications extending beyond Ta2O5 to a broad class of complex oxides.

cond-mat.mtrl-sci

When HTTP 402 Meets the Blockchain: Risks on Emerging x402 Payments

x402 is an emerging payment protocol for Web APIs and autonomous AI agents. x402 extends HTTP 402 with a payment negotiation flow and delegates payment proof verification and on-chain settlement to third-party facilitators. As a result, facilitators serve as a shared payment infrastructure for many independent merchants. This centralizes trust and validation in one component, so a single flaw can affect many services. Despite rapid adoption by major vendors and economically meaningful mainnet activity, the security posture of real-world x402 deployments remains poorly characterized. We present the first systematic study of authorization correctness and execution safety in current facilitator-mediated x402 deployments in the wild, identifying eight security rules for facilitators as critical payment infrastructure. Based on our analysis of rule violations, we derive four new attack vectors, including Free Shopping, Asset Theft, Service Denial, and Gas Abuse. These attacks exploit weaknesses in the real-world facilitator and server implementations and cause severe harm, including direct financial loss to merchants, theft of facilitator-held assets, unbounded sponsor-paid gas/fees, and disruption of payment services. To assess the security of x402 deployments at scale, we propose a semi-automated black-box tool and apply it to 15 major x402 facilitators collectively used by over 60K sellers and 360K buyers. Alarmingly, we find violations in all evaluated facilitators. We responsibly disclosed our findings to the affected parties, who acknowledged the issues and adopted mitigations, including changes by Coinbase. Finally, we complement our controlled testing with an empirical measurement of over 119 million recent Base and Solana transactions, quantifying x402 adoption, facilitator centralization, and ecosystem-level risk indicators.

cs.CR