Function-Space Certification for Operator Learning
Abstract
Certification for scientific machine-learning models is essential when robustness and physical consistency must hold beyond a finite test set. Existing neural-network verification methods are designed for finite-dimensional vectors. When applied to a discretized neural operator, they certify only the selected grid points and provide no guarantees over the domain or across another resolution. We close this gap by formulating interval bound propagation (IBP) and CROWN directly in function space. We propagate rigorous functional bounds with validated integration using numerical quadrature with Lipschitz-based error corrections and arbitrary-precision ball arithmetic. We experiment on Fourier neural operators trained for Poisson, Helmholtz, and Burgers equations. Against Monte Carlo sampling and projected-gradient attacks, function-space CROWN produces bounds within 1.38–5.23× of the empirical attacks across the three PDEs, providing tight, certified enclosure over the entire continuous domain.