arXiv:2604.13316cs.LGcs.AI2026-04

通过主动学习与输入去噪协同防御,提升神经算子对对抗扰动的鲁棒性。

Beyond Uniform Sampling: Synergistic Active Learning and Input Denoising for Robust Neural Operators

  • 用差分进化攻击定位模型弱点,生成针对性训练数据。
  • 联合方法在布津斯基方程上误差仅2.04%,较标准训练降低87%。
  • 适合安全关键场景如核反应堆监控的神经算子部署。

神经算子作为物理模拟的快速代理模型已崭露头角,但在安全关键的数字孪生应用中仍极易受对抗扰动影响。本文提出一种协同防御策略,结合基于主动学习的数据生成与输入去噪架构。主动学习组件利用差分进化攻击探测模型脆弱点,针对性生成训练数据,同时通过自适应平滑比保障基础精度;输入去噪组件在算子结构中引入可学习瓶颈,过滤对抗噪声并保留物理相关特征。在黏性布津斯基方程基准测试中,联合方法实现2.04%综合误差(1.21%基线 + 0.83%鲁棒性),相比标准训练(15.42%)降低87%,优于单独使用主动学习(3.42%)或输入去噪(5.22%)。结合前期跨架构漏洞分析,结果表明神经算子最优训练数据具有架构依赖性:不同架构在输入子空间中的敏感区域各异,均匀采样无法覆盖所有模型的脆弱面。该发现对神经算子在核能等安全关键系统中的部署具有潜在意义。

原文摘要 · Abstract (English)

Neural operators have emerged as fast surrogate models for physics simulations, yet they remain acutely vulnerable to adversarial perturbations, a critical liability for safety-critical digital twin deployments. We present a synergistic defense that combines active learning-based data generation with an input denoising architecture. The active learning component adaptively probes model weaknesses using differential evolution attacks, then generates targeted training data at discovered vulnerability locations while an adaptive smooth-ratio safeguard preserves baseline accuracy. The input denoising component augments the operator architecture with a learnable bottleneck that filters adversarial noise while retaining physics-relevant features. On the viscous Burgers' equation benchmark, the combined approach achieves a 2.04% combined error (1.21% baseline + 0.83% robustness), representing an 87% reduction relative to standard training (15.42% combined) and outperforming both active learning alone (3.42%) and input denoising alone (5.22%). More broadly, our results, combined with cross-architecture vulnerability analysis from prior work, suggest that optimal training data for neural operators is architecture-dependent: because different architectures concentrate sensitivity in distinct input subspaces, uniform sampling cannot adequately cover the vulnerability landscape of all models. These findings have potential implications for the deployment of neural operators in safety-critical energy systems including nuclear reactor monitoring.

神经算子对抗鲁棒性主动学习去噪

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。