arXiv:2608.22606cs.LG2026-08

研究深度学习设计模型在对抗扰动下的脆弱性,发现微小输入噪声可导致结构失效。

Adversarial Agents on Topology Optimization: Understanding the Fragility and Robustness of Deep Learning-based and Physics-Based Design Models under Adversarial Perturbation

  • 构建基于力学的对抗攻击框架,仅扰动初始密度场
  • 微小扰动使结构合规度提升数个数量级,载荷路径断裂
  • 物理引导恢复有效,建议用神经网络作物理验证起点

拓扑优化结合物理方法与深度学习代理模型,是网络制造系统中生成式设计的核心。尽管深度学习代理因在线生成速度快而广泛应用,本文揭示其在输入扰动下存在严重脆弱性。我们提出一种力学基础的可靠性评估框架,设计对抗代理针对生成式设计模型。研究采用非侵入式威胁模型:仅对初始密度通道施加有界扰动,保持边界条件、柔度梯度通道、网络结构与求解器不变。在不同深度物理梯度条件下的U-Net、卷积与生成架构上测试发现,有界初始噪声可引发灾难性机械失效,导致合规度增加数个数量级,源于载荷路径中断与支撑分离。此外,更丰富的物理梯度条件并未保证各代理族间的单调鲁棒性。物理在环恢复表明,以受扰拓扑初始化经典SIMP优化器,能以高概率将合规度恢复至接近基线水平。结果表明,学习代理应作为物理验证的初始值,而非完全替代物理求解器。所提对抗代理为未来训练抗噪和抗针对性扰动的生成式设计代理奠定基础。

原文摘要 · Abstract (English)

Topology optimization, using both physic-based approaches and deep learning surrogates, serves as a cornerstone for generative design agents in cyber-manufacturing systems. While deep learning surrogates have gained widespread adoption due to their speed in online design generation, this work demonstrates their vulnerability under input perturbations. In this work, we present a mechanics-grounded reliability evaluation framework that formulates an adversarial agent targeting the generative design models. We investigate a strictly non-intrusive threat model where bounded perturbations are introduced exclusively to the initial-density channel, while physical boundary conditions, compliance-gradient channels, network architectures, and solver routines remain intact. Evaluating surrogate models across U-Net, convolutional, and generative architectures with varying physics-gradient conditioning depths demonstrates that bounded initialization noise can cause catastrophic mechanical failure, increasing compliance by multiple orders of magnitude through severed load paths and disconnected supports. Furthermore, we discover that incorporating richer physics-gradient conditioning in the deep learning surrogates does not guarantee monotonic robustness across surrogate families. Finally, physics-in-the-loop recovery demonstrates that initializing the classical SIMP optimizer with perturbed topologies mitigates design performance degradation, having a high probability of restoring compliance to near-baseline levels across tested instances. These findings demonstrate that learned surrogates should serve as physics-verified initializers instead of replacing physics-based solvers entirely in a resilient cyber-manufacturing system. Moreover, the proposed adversarial agent provides a foundation for future training generative design agents robust against noise and targeted perturbations.

拓扑优化对抗攻击生成设计鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。