Publications

Four accepted and four under-review CCF-A papers, all led as first or co-first author. * indicates equal contribution.

Under reviewTeaser figure from LLM Agents Are Latent Context Managers: Eliciting Self-Managed Context via State Proprioception

LLM Agents Are Latent Context Managers: Eliciting Self-Managed Context via State Proprioception

Binyan Xu, Haitao Li, Kehuan Zhang

Under review, 2026

Exposes working-state signals through a typed, addressable context layer and a context-tool action space. On 75 long-horizon tasks, VISTA raises Gemini-3-Flash success from 22.7% to 50.7% and complements GRPO post-training.

Under reviewMethod overview from From Multi-Agent to Single-Agent: When Is Skill Distillation Beneficial?

From Multi-Agent to Single-Agent: When Is Skill Distillation Beneficial?

Binyan Xu, Dong Fang, Haitao Li, Kehuan Zhang

Under review, 2026

Introduces Metric Freedom to identify when collaboration and evaluation loops can be internalized as a single-agent skill, matching or outperforming the source system at 1.4–15× lower cost across four tasks and eleven datasets.

Under reviewOverview figure from Contextual Agentic Memory is a Memo, Not True Memory

Contextual Agentic Memory is a Memo, Not True Memory

Binyan Xu*, Xilin Dai*, Kehuan Zhang

Under review, 2026

Uses controlled ablations and statistical analysis to show that many retrieval-based “memory” systems behave as temporary context extension, then reframes evaluation around reusable and generalizable experience.

ICML ’26Pipeline figure from From Internal Diagnosis to External Auditing: A VLM-Driven Paradigm for Data-Free Online Backdoor Defense

From Internal Diagnosis to External Auditing: A VLM-Driven Paradigm for Data-Free Online Backdoor Defense

Binyan Xu, Xilin Dai, Fan Yang, Di Tang, Kehuan Zhang

ICML 2026, Poster

Uses an independent vision-language model to audit online predictions, moving defense from internal diagnosis of an untrusted model to model-agnostic external semantic verification.

ACM MM ’25Pipeline figure from CLIP-Guided Backdoor Defense through Entropy-Based Poisoned Dataset Separation

CLIP-Guided Backdoor Defense through Entropy-Based Poisoned Dataset Separation

Binyan Xu, Fan Yang, Xilin Dai, Di Tang, Kehuan Zhang

ACM Multimedia 2025, Oral Presentation

Separates poisoned and clean samples using CLIP semantic signals and entropy, then guides model repair while preserving clean accuracy across diverse backdoor attacks.

CCS ’25Method figure from One Surrogate to Fool Them All: Universal, Transferable, and Targeted Adversarial Attacks with CLIP

One Surrogate to Fool Them All: Universal, Transferable, and Targeted Adversarial Attacks with CLIP

Binyan Xu, Xilin Dai, Di Tang, Kehuan Zhang

ACM CCS 2025, Oral Presentation

Uses one public CLIP model as a universal surrogate to craft targeted attacks that transfer across models, tasks, multimodal systems, and real black-box AI services without victim queries.

AAAI ’26Pipeline figure from Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger Optimization

Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger Optimization

Binyan Xu, Xilin Dai, Fan Yang, Di Tang, Kehuan Zhang

AAAI 2026, Oral Presentation

Optimizes generative triggers to build stealthy clean-image backdoors that remain potent across classification, regression, and segmentation tasks.

Under reviewFramework figure from When Agent Automation Becomes Profitable: Quantifying and Insuring Autonomous AI Risk through Trace-Economic Underwriting

When Agent Automation Becomes Profitable: Quantifying and Insuring Autonomous AI Risk through Trace-Economic Underwriting

Binyan Xu, Xilin Dai, Fan Yang, Kehuan Zhang

Under review, 2026

Maps agent tool trajectories into task losses, control signals, and insurance-style pricing to identify when autonomous execution is economically viable under failure risk.