cd /news/machine-learning/wrong-physics-backdoors-in-neural-pd… · home topics machine-learning article
[ARTICLE · art-108265] src=arxiv.org ↗ pub= topic=machine-learning verified=true sentiment=· neutral

Wrong-Physics Backdoors in Neural PDE Operators

Researchers introduced a data-poisoning attack called cross-parameter relinking that creates wrong-physics backdoors in neural PDE operators, making triggered inputs output physically plausible but incorrect solutions. In 476 attack campaigns on Burgers, advection-diffusion, 2D Navier-Stokes, and elliptic Poisson cases, Fourier Neural Operators achieved a backdoor success rate of 1.0000 on advection-diffusion and 2D Navier-Stokes while retaining low clean relative L2 error, exposing a validation gap in current plausibility checks.

read1 min views3 publishedAug 24, 2026

arXiv:2608.20439v1 Announce Type: new Abstract: Neural PDE operators are increasingly trained on reusable solver archives, yet validation often relies on clean prediction error and parameter-agnostic plausibility checks. We introduce cross-parameter relinking, a data-poisoning primitive that makes a triggered input select a valid solution from the same PDE family under an incorrect physical parameter. We term this a wrong-physics backdoor: the output remains physically plausible but is wrong for the intended parameter. The attack exploits tensor-to-parameter provenance failures in multi-parameter archives by stamping the surrogate input and relinking its supervision to a cached alternate-parameter solution for the same latent sample. Across 476 attack campaigns, we evaluate Burgers, advection-diffusion, two-dimensional Navier-Stokes, and an elliptic Poisson case. Fourier Neural Operators and DeepONet provide the primary evidence, with Transformer, GRU, and LSTM models as support. FNO reaches a backdoor success rate of 1.0000 on both advection-diffusion and two-dimensional Navier-Stokes while retaining low clean relative L2 error. Clean-label, label-only, and shuffled controls show that high attack success alone is insufficient: successful attacks must move predictions toward the intended alternate-physics target while preserving bounded clean error. These results expose a structural validation gap: smoothness or generic solver-like behavior is insufficient unless the provenance of the intended physical parameter is also verified.

── more in #machine-learning 4 stories · sorted by recency
── more on @fourier neural operators 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/wrong-physics-backdo…] indexed:0 read:1min 2026-08-24 ·