arXiv:2608.20439cs.LGphysics.comp-ph2026-08

神经微分方程模型被植入了看似合理却物理错误的后门,可隐蔽触发。

Wrong-Physics Backdoors in Neural PDE Operators

论文配图:Wrong-Physics Backdoors in Neural PDE Operators
图 1 · 摘自论文原文
  • 通过跨参数重连实现数据投毒,使输入在错误参数下输出看似合理的解。
  • 在476次攻击中,FNO模型对二维纳维-斯托克斯方程达到100%后门成功率,且干净样本误差低。
  • 揭示验证漏洞:仅看解的平滑性不足以确保物理参数正确性,需追踪参数来源。

神经微分方程算子越来越多地在可复用的求解器归档上训练,但验证常依赖于干净预测误差和与参数无关的合理性检查。我们提出一种名为跨参数重连的数据投毒技术,使触发输入在错误物理参数下选择同一方程族的合法解。我们称其为‘错误物理后门’:输出在物理上看似合理,但针对目标参数却是错误的。该攻击利用多参数归档中张量到参数的溯源失败,将代理输入标记并将其监督信号重新关联到同一潜在样本的缓存替代参数解。我们在476次攻击实验中评估了伯格斯方程、对流-扩散方程、二维纳维-斯托克斯方程及椭圆泊松方程。傅里叶神经算子(FNO)为主要证据,变压器、GRU和LSTM作为补充。FNO在对流-扩散和二维纳维-斯托克斯方程上均达到1.0000的后门成功率,同时保持低干净相对L2误差。干净标签、仅标签和打乱控制实验表明,高攻击成功率本身不足:成功攻击必须使预测向预期的替代物理目标移动,同时保持有界干净误差。这些结果暴露了结构性验证缺口:光滑性或通用求解器行为不足以保证参数正确性,除非也验证目标物理参数的溯源性。

原文摘要 · Abstract (English)

Neural PDE operators are increasingly trained on reusable solver archives, yet validation often relies on clean prediction error and parameter-agnostic plausibility checks. We introduce cross-parameter relinking, a data-poisoning primitive that makes a triggered input select a valid solution from the same PDE family under an incorrect physical parameter. We term this a wrong-physics backdoor: the output remains physically plausible but is wrong for the intended parameter. The attack exploits tensor-to-parameter provenance failures in multi-parameter archives by stamping the surrogate input and relinking its supervision to a cached alternate-parameter solution for the same latent sample. Across 476 attack campaigns, we evaluate Burgers, advection-diffusion, two-dimensional Navier-Stokes, and an elliptic Poisson case. Fourier Neural Operators and DeepONet provide the primary evidence, with Transformer, GRU, and LSTM models as support. FNO reaches a backdoor success rate of 1.0000 on both advection-diffusion and two-dimensional Navier-Stokes while retaining low clean relative L2 error. Clean-label, label-only, and shuffled controls show that high attack success alone is insufficient: successful attacks must move predictions toward the intended alternate-physics target while preserving bounded clean error. These results expose a structural validation gap: smoothness or generic solver-like behavior is insufficient unless the provenance of the intended physical parameter is also verified.

神经微分方程后门攻击物理一致性模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。