AI 中文总结
该研究提出跨参数重链接数据投毒原语,在神经PDE算子中构造错误物理后门,在保持低干净误差的同时实现高攻击成功率,暴露了其结构性验证缺口。
AI 中文摘要
神经PDE算子越来越多地基于可重用求解器档案进行训练,但验证通常依赖于干净预测误差和与参数无关的合理性检查。我们引入跨参数重链接,这是一种数据投毒原语,可使触发输入在错误的物理参数下从同一PDE族中选择有效解。我们将此称为错误物理后门:输出在物理上仍合理,但对于预期参数而言是错误的。该攻击利用多参数档案中张量到参数的来源失败,通过标记代理输入并将其监督重链接到同一潜在样本的缓存替代参数解来实现。在476次攻击实验中,我们评估了Burgers、平流扩散、二维Navier-Stokes和椭圆Poisson案例。Fourier Neural Operators和DeepONet提供了主要证据,Transformer、GRU和LSTM模型作为补充。FNO在平流扩散和二维Navier-Stokes上均达到1.0000的后门成功率,同时保持较低的干净相对L2误差。干净标签、仅标签和打乱对照实验表明,仅高攻击成功率是不够的:成功的攻击必须将预测推向预期的替代物理目标,同时保持有界的干净误差。这些结果暴露了结构性验证缺口:除非还验证了预期物理参数的来源,否则平滑性或类似通用求解器的行为是不够的。
英文摘要
Neural PDE operators are increasingly trained on reusable solver archives, yet validation often relies on clean prediction error and parameter-agnostic plausibility checks. We introduce cross-parameter relinking, a data-poisoning primitive that makes a triggered input select a valid solution from the same PDE family under an incorrect physical parameter. We term this a wrong-physics backdoor: the output remains physically plausible but is wrong for the intended parameter. The attack exploits tensor-to-parameter provenance failures in multi-parameter archives by stamping the surrogate input and relinking its supervision to a cached alternate-parameter solution for the same latent sample. Across 476 attack campaigns, we evaluate Burgers, advection-diffusion, two-dimensional Navier-Stokes, and an elliptic Poisson case. Fourier Neural Operators and DeepONet provide the primary evidence, with Transformer, GRU, and LSTM models as support. FNO reaches a backdoor success rate of 1.0000 on both advection-diffusion and two-dimensional Navier-Stokes while retaining low clean relative L2 error. Clean-label, label-only, and shuffled controls show that high attack success alone is insufficient: successful attacks must move predictions toward the intended alternate-physics target while preserving bounded clean error. These results expose a structural validation gap: smoothness or generic solver-like behavior is insufficient unless the provenance of the intended physical parameter is also verified.