arXiv Machine Learning
Aug 24

Wrong-Physics Backdoors in Neural PDE Operators

The paper introduces a new type of data‑poisoning attack called a wrong‑physics backdoor, which tricks neural PDE operators into selecting a solution from the same PDE family but with an incorrect physical parameter. By relinking a surrogate input’s supervision to a cached alternate‑parameter solution, the attack keeps the output physically plausible yet wrong for the intended parameter. Experiments on 476 campaigns across several PDEs and models (FNO, DeepONet, Transformer, GRU, LSTM) show high success rates while maintaining low clean error, revealing a validation gap in current practices.

By Hanbing Liang, Fujun Liu