Trapping AI to harden alloy predictors: when attack becomes a tool of discovery
AI-generated hypothesis · Pre-publication · To be tested experimentally
Table of contents — full brief
- Hypothesis and mechanismCausal chain, key assumptions, residual unknowns
- State of the artVerified references and counter-evidence (DOIs)
- Falsifiable predictionsQuantitative bounds, statistical tests, H0
- Experimental protocolThree phases — in silico → minimal → full
- Impact analysisNovelty, residual gaps, available data
- Panel reviewFive personas + meta-review
Verified references
5 of 11 references- DOI: 10.48550/arXiv.2401.15897 ↗
Red-Teaming for Generative AI: Silver Bullet or Security Theater?
2024 - DOI: 10.1145/3576915.3623175 ↗
Large Language Models for Code: Security Hardening and Adversarial Testing
2023 - DOI: 10.48550/arXiv.2301.13487 ↗
Adversarial Training of Self-supervised Monocular Depth Estimation against Physical-World Attacks
2023 - DOI: 10.1038/s41467-024-49686-z ↗
From bulk effective mass to 2D carrier mobility accurate prediction via adversarial transfer learning
2024 - DOI: 10.1038/s41524-020-00352-0 ↗
Generative adversarial networks (GAN) based efficient sampling of chemical composition space for inverse design of inorganic materials
2019
+ 6 more references
Detailed panel scores
The protocol incorporates a three-phase progression (in silico, minimal experimental, full experimental) with explicit GO/NO-GO/PIVOT criteria and quantitative thresholds, which limits ad hoc decisions and facilitates replication.
The closed-loop generate–attack–filter–synthesize–harden architecture is correctly derived from the red-team/hardening paradigm, and its transposition to materials is conceptually coherent: the coupling between a PGD adversarial agent in continuous-fraction space and a thermodynamic filter (convex hull, atomic mismatch, enthalpy of mixing) constitutes a credible physical constraint that distinguishes this work from a mere attack on descriptors. The constraint sum(x_i)=1, x_i>=0 enforced via projection is mathematically well posed.
The closed-loop experimental architecture (generation → adversarial attack → thermodynamic filtering → synthesis → retraining) is ambitious and well specified, with pre-registered stopping criteria and explicit numerical bounds for each prediction, which facilitates falsifiability.
The addressable market is real but indirect: materials R&D teams at large groups such as ArcelorMittal, ThyssenKrupp, GE Aerospace, Rolls-Royce and Safran spend several million euros each year on experimental trials (synthesis, XRD, beam time) to calibrate their alloy predictors. A tool that reduces MAE by 20–35% on a held-out experimental benchmark justifies a direct ROI: fewer synthesis campaigns wasted on non-informative compositions. The initial TAM (software plus services for advanced materials teams) is of the order of €150–300 M per year, with a CAGR of 12–18% driven by the Materials Genome Initiative and European programmes (Horizon Europe, IPCEI).
Falsifiable hypothesis with quantitative GO/NO-GO criteria (JSD ≥ 0.3 bits, MAE reduction ≥ 15 meV/atom, synthesis rate ≥ 60%) and a three-phase protocol that progressively de-risks the experimentation, which is highly valued by ANR/ERC evaluators.
Receive the next SPORE hypotheses
Once or twice a month, in your inbox. No spam, one-click unsubscribe.
Your data stays private. No third-party sharing. GDPR-compliant.