Skip to content

Author

Laizhong Cui

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Long-Term Optimal Incentives for Differential-Privacy Federated Learning: A Multi-Stage Game Approach

Differential-privacy federated learning (DP-FL) has emerged as a promising paradigm capable of mitigating the inherent threat of traditional FL architectures that are vulnerable to inferential attacks due to the frequent exchange and updating of model parameters. However, existing DP-FL frameworks often assume that the client’s perturbations remain constant throughout the FL process, while ignoring the varying influence of the client’s perturbations in distinct communication rounds on the model performance. Besides, existing DP-FL frameworks posit the FL server as a fully rational actor, thereby neglecting the bounded rationality that the FL server may exhibit in the face of risk and uncertainty. In this paper, we propose a novel long-term (i.e., throughout the FL process) privacy-preserving FL framework to address the optimal incentive design, in the presence of the bounded rationality inherent in the FL server and the dynamic influence of perturbations on model performance. Specifically, we first investigate the impact of local perturbations of the client on the model’s convergence performance in different communication rounds, elucidating the trade-off between learning performance and privacy loss. Then, to reconcile learning performance with privacy loss, we design a long-term privacy-preserving incentive scheme, where the interactions between clients and the FL server throughout the FL process are modeled as a multi-stage privacy-preserving game. Furthermore, by applying prospect theory (PT) to formulate the risk-aware behavior of the bounded rationality FL server, we employ contract theory to derive the equilibrium of the game, thereby ensuring optimality and fairness. Finally, extensive simulations illustrate that our scheme can motivate clients to provide high-quality models and improve the accuracy of the global model, compared with benchmarks.

Liang Xie, Yuntao Wang, Hengzhi Wang et al. · 0 citations
Preprint Aug 2026

Convergent Detour Hijacking: Task-Preserving Resource Amplification in Skill-Based LLM Agents

LLM agents increasingly rely on third-party skills, using natural-language descriptions for selection and instruction bodies for planning. This progressive-disclosure design exposes two sequential control points to untrusted publishers: a static skill may steer an otherwise correct task onto an unnecessarily costly trajectory. Prior work studies selection manipulation, malicious skill instructions, and tool-chain resource amplification largely separately, leaving their end-to-end composition unclear. We introduce Convergent Detour Hijacking (CDH), a text-only, runtime-independent attack that couples these stages. Under shared semantic cover, a description establishes relevance during selection, while an aligned body reuses that rationale to fabricate plausible dependencies during planning. CDH attracts an attacker-controlled coordinator alongside legitimate skills, recruits unnecessary benign skills into a bounded detour, and then re-enters the original route to preserve task completion. We evaluate it across multiple LLM backends and 491 held-out tasks under single-task and multi-turn conditions. On DeepSeek-V4-Pro, the matched coordinator is selected in 80.02% of tasks; among coordinator-hit runs that complete tasks, token consumption and end-to-end execution time increase by 66.91% and 92.45%, respectively, while aggregate task completion remains comparable. Thus, correct outcomes do not guarantee trajectory integrity or cost safety.

Junliang Liu, Ruoyu Li, Wenxin Tang et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.