Deep Learning
Are Robust LLM Fingerprints Adversarially Robust?
Nasery, Anshul, Contente, Edoardo, Kaz, Alkin, Viswanath, Pramod, Oh, Sewoong
Model fingerprinting has emerged as a promising paradigm for claiming model ownership. However, robustness evaluations of these schemes have mostly focused on benign perturbations such as incremental fine-tuning, model merging, and prompting. Lack of systematic investigations into {\em adversarial robustness} against a malicious model host leaves current systems vulnerable. To bridge this gap, we first define a concrete, practical threat model against model fingerprinting. We then take a critical look at existing model fingerprinting schemes to identify their fundamental vulnerabilities. Based on these, we develop adaptive adversarial attacks tailored for each vulnerability, and demonstrate that these can bypass model authentication completely for ten recently proposed fingerprinting schemes while maintaining high utility of the model for the end users. Our work encourages fingerprint designers to adopt adversarial robustness by design. We end with recommendations for future fingerprinting methods.
Clarification as Supervision: Reinforcement Learning for Vision-Language Interfaces
Gkountouras, John, Titov, Ivan
Recent text-only models demonstrate remarkable mathematical reasoning capabilities. Extending these to visual domains requires vision-language models to translate images into text descriptions. However, current models, trained to produce captions for human readers, often omit the precise details that reasoning systems require. This creates an interface mismatch: reasoners often fail not due to reasoning limitations but because they lack access to critical visual information. We propose Adaptive-Clarification Reinforcement Learning (AC-RL), which teaches vision models what information reasoners need through interaction. Our key insight is that clarification requests during training reveal information gaps; by penalizing success that requires clarification, we create pressure for comprehensive initial captions that enable the reasoner to solve the problem in a single pass. AC-RL improves average accuracy by 4.4 points over pretrained baselines across seven visual mathematical reasoning benchmarks, and analysis shows it would cut clarification requests by up to 39% if those were allowed. By treating clarification as a form of implicit supervision, AC-RL demonstrates that vision-language interfaces can be effectively learned through interaction alone, without requiring explicit annotations. Recent advances in reinforcement learning have produced text-based reasoning models with remarkable mathematical capabilities (Guo et al., 2025a; Shao et al., 2024). While these reasoning capabilities are impressive, extending them to visual domains requires careful consideration of how visual and linguistic information should interface.
Importance of localized dilatation and distensibility in identifying determinants of thoracic aortic aneurysm with neural operators
Li, David S., Goswami, Somdatta, Cao, Qianying, Oommen, Vivek, Assi, Roland, Humphrey, Jay D., Karniadakis, George E.
Thoracic aortic aneurysms (TAAs) stem from diverse mechanical and mechanobiological disruptions to the aortic wall that can also increase the risk of dissection or rupture. There is increasing evidence that dysfunctions along the aortic mechanotransduction axis, including reduced integrity of elastic fibers and loss of cell-matrix connections, are particularly capable of causing thoracic aortopathy. Because different insults can produce distinct mechanical vulnerabilities, there is a pressing need to identify interacting factors that drive progression. In this work, we employ a finite element framework to generate synthetic TAAs arising from hundreds of heterogeneous insults that span a range of compromised elastic fiber integrity and cellular mechanosensing. From these simulations, we construct localized dilatation and distensibility maps throughout the aortic domain to serve as training data for neural network models to predict the initiating combined insult. Several candidate architectures (Deep Operator Networks, UNets, and Laplace Neural Operators) and input data formats are compared to establish a standard for handling future subject-specific information. We further quantify the predictive capability when networks are trained on geometric (dilatation) information alone, which mimics current clinical guidelines, versus training on both geometric and mechanical (distensibility) information. We show that prediction errors based on dilatation data are significantly higher than those based on dilatation and distensibility across all networks considered, highlighting the benefit of obtaining local distensibility measures in TAA assessment. Additionally, we identify UNet as the best-performing architecture across all training data formats.
AI-assisted Advanced Propellant Development for Electric Propulsion
Du, Angel Pan, Arana-Catania, Miguel, Gutiérrez, Enric Grustan
Artificial Intelligence algorithms are introduced in this work as a tool to predict the performance of new chemical compounds as alternative propellants for electric propulsion, focusing on predicting their ionisation characteristics and fragmentation patterns. The chemical properties and structure of the compounds are encoded using a chemical fingerprint, and the training datasets are extracted from the NIST WebBook. The AI-predicted ionisation energy and minimum appearance energy have a mean relative error of 6.87% and 7.99%, respectively, and a predicted ion mass with a 23.89% relative error. In the cases of full mass spectra due to electron ionisation, the predictions have a cosine similarity of 0.6395 and align with the top 10 most similar mass spectra in 78% of instances within a 30 Da range.
Bayesian Influence Functions for Hessian-Free Data Attribution
Kreer, Philipp Alexander, Wu, Wilson, Adam, Maxwell, Furman, Zach, Hoogland, Jesse
Classical influence functions face significant challenges when applied to deep neural networks, primarily due to non-invertible Hessians and high-dimensional parameter spaces. We propose the local Bayesian influence function (BIF), an extension of classical influence functions that replaces Hessian inversion with loss landscape statistics that can be estimated via stochastic-gradient MCMC sampling. This Hessian-free approach captures higher-order interactions among parameters and scales efficiently to neural networks with billions of parameters. We demonstrate state-of-the-art results on predicting retraining experiments.
The Loss Kernel: A Geometric Probe for Deep Learning Interpretability
Adam, Maxwell, Furman, Zach, Hoogland, Jesse
A central goal in AI interpretability and data attribution is interpreting and mapping the global structure of the data distribution as seen by a trained neural network (Carter et al., 2019; Pepin Lehalleur et al., 2025; Olah, 2015). One approach is to start local, by quantifying a suitable measure of similarity between pairs of individual samples--that is, by defining a kernel. "Interpreting" the global structure of the data distribution then becomes a problem of analyzing the geometric structure in this kernel (e.g., via clustering techniques), and "mapping" becomes a problem of visualizing points in this kernel space (e.g., via dimensionality reduction techniques). This kernel-based approach has been used successfully with similarity measures derived from activations or representations. For example, it is possible to define a kernel via cosine similarity between the hidden vectors of sparse autoencoders (SAEs).
Rearchitecting Datacenter Lifecycle for AI: A TCO-Driven Framework
Stojkovic, Jovan, Zhang, Chaojie, Goiri, Íñigo, Bianchini, Ricardo
The rapid rise of large language models (LLMs) has been driving an enormous demand for AI inference infrastructure, mainly powered by high-end GPUs. While these accelerators offer immense computational power, they incur high capital and operational costs due to frequent upgrades, dense power consumption, and cooling demands, making total cost of ownership (TCO) for AI datacenters a critical concern for cloud providers. Unfortunately, traditional datacenter lifecycle management (designed for general-purpose workloads) struggles to keep pace with AI's fast-evolving models, rising resource needs, and diverse hardware profiles. In this paper, we rethink the AI datacenter lifecycle scheme across three stages: building, hardware refresh, and operation. We show how design choices in power, cooling, and networking provisioning impact long-term TCO. We also explore refresh strategies aligned with hardware trends. Finally, we use operation software optimizations to reduce cost. While these optimizations at each stage yield benefits, unlocking the full potential requires rethinking the entire lifecycle. Thus, we present a holistic lifecycle management framework that coordinates and co-optimizes decisions across all three stages, accounting for workload dynamics, hardware evolution, and system aging. Our system reduces the TCO by up to 40\% over traditional approaches. Using our framework we provide guidelines on how to manage AI datacenter lifecycle for the future.
Entropy After $\langle \texttt{/Think} \rangle$ for reasoning model early exiting
Wang, Xi, McInerney, James, Wang, Lequn, Kallus, Nathan
Large reasoning models show improved performance with longer chains of thought. However, recent work has highlighted (qualitatively) their tendency to overthink, continuing to revise answers even after reaching the correct solution. We quantitatively confirm this inefficiency by tracking Pass@1 for answers averaged over a large number of rollouts and find that the model often begins to always produce the correct answer early in the reasoning, making extra reasoning a waste of tokens. To detect and prevent overthinking, we propose a simple and inexpensive novel signal -- Entropy After (EAT) -- for monitoring and deciding whether to exit reasoning early. By appending a stop thinking token () and monitoring the entropy of the following token as the model reasons, we obtain a trajectory that decreases and stabilizes when Pass@1 plateaus; thresholding its variance under an exponential moving average yields a practical stopping rule. Importantly, our approach enables adaptively allocating compute based on the EAT trajectory, allowing us to spend compute in a more efficient way compared with fixing the token budget for all questions. Empirically, on MATH500 and AIME2025, EAT reduces token usage by 13 - 21% without harming accuracy, and it remains effective in black box settings where logits from the reasoning model are not accessible, and EAT is computed with proxy models.
MUSE-Explainer: Counterfactual Explanations for Symbolic Music Graph Classification Models
Hilaire, Baptiste, Karystinaios, Emmanouil, Widmer, Gerhard
Interpretability is essential for deploying deep learning models in symbolic music analysis, yet most research emphasizes model performance over explanation. To address this, we introduce MUSE-Explainer, a new method that helps reveal how music Graph Neural Network models make decisions by providing clear, human-friendly explanations. Our approach generates counterfactual explanations by making small, meaningful changes to musical score graphs that alter a model's prediction while ensuring the results remain musically coherent. Unlike existing methods, MUSE-Explainer tailors its explanations to the structure of musical data and avoids unrealistic or confusing outputs. We evaluate our method on a music analysis task and show it offers intuitive insights that can be visualized with standard music tools such as Verovio.
SCUBA: Salesforce Computer Use Benchmark
Dai, Yutong, Ramakrishnan, Krithika, Gu, Jing, Fernandez, Matthew, Luo, Yanqi, Prabhu, Viraj, Hu, Zhenyu, Savarese, Silvio, Xiong, Caiming, Chen, Zeyuan, Xu, Ran
We introduce SCUBA, a benchmark designed to evaluate computer-use agents on customer relationship management (CRM) workflows within the Salesforce platform. SCUBA contains 300 task instances derived from real user interviews, spanning three primary personas, platform administrators, sales representatives, and service agents. The tasks test a range of enterprise-critical abilities, including Enterprise Software UI navigation, data manipulation, workflow automation, information retrieval, and troubleshooting. To ensure realism, SCUBA operates in Salesforce sandbox environments with support for parallel execution and fine-grained evaluation metrics to capture milestone progress. We benchmark a diverse set of agents under both zero-shot and demonstration-augmented settings. We observed huge performance gaps in different agent design paradigms and gaps between the open-source model and the closed-source model. In the zero-shot setting, open-source model powered computer-use agents that have strong performance on related benchmarks like OSWorld only have less than 5\% success rate on SCUBA, while methods built on closed-source models can still have up to 39% task success rate. In the demonstration-augmented settings, task success rates can be improved to 50\% while simultaneously reducing time and costs by 13% and 16%, respectively. These findings highlight both the challenges of enterprise tasks automation and the promise of agentic solutions. By offering a realistic benchmark with interpretable evaluation, SCUBA aims to accelerate progress in building reliable computer-use agents for complex business software ecosystems.