基于验证感知架构的大语言模型辅助情报、监视与侦察集群任务级运行时保障
Mission-Level Runtime Assurance for LLM-Assisted ISR Swarms over a Verification-Aware Fabric
浏览论文内容
中文总结 AI 辅助
研究大语言模型辅助的ISR集群任务级运行时保障问题,提出三层组合式运行时验证框架,将任务策略分解,通过验证感知架构聚合判定并融合代数,能检测个体合规但集群违规情况,模拟任务验证了其有效性。
中文摘要 AI 辅助
大语言模型辅助的自主机器人集群越来越多地被用于有争议环境中的协同情报、监视和侦察(ISR)。一类日益增多的保障失败并非发生在单个平台内,而是在整个集群中出现:个体合规的行动组合成任务级违规,如被禁止的目标分散到多个平台以规避每个平台的限制,或悄悄超出集体预算。每个平台的护栏无法检测到这些问题,而有争议的通信会使违规行为隐藏在丢失或延迟的证据背后。我们提出了一个三层(平台/小队/任务)组合式运行时验证框架,将任务策略分解为每个智能体和跨智能体的方面,通过验证感知消息传递架构聚合每个平台的判定,并将它们与证据感知的两轴(安全性x完整性)代数融合,其来源指明共同引发违规的平台。因为该架构使证据丢失和沉默可被观察到,无支持的否定判定会被降级为明确的未知,而不是报告为任务范围内的全部通过。在模拟的ISR任务中,一种间接提示注入导致真实的大语言模型规划器将一个被禁止的收集任务分散到四个平台,每个平台监视器都无法察觉,但通过组合方式并带有完整来源被检测到;在注入故障活动下,尽力而为的中央监视器发出沉默的错误全部通过信号,而验证感知架构则不发出任何信号。
英文摘要
Swarms of LLM-assisted autonomous robots are increasingly proposed for cooperative intelligence, surveillance, and reconnaissance (ISR) in contested environments. A growing class of their assurance failures arises not within any single platform but across the swarm: individually-compliant actions compose into a mission-level violation: a prohibited objective split across platforms to evade per-platform lim- its, or a collective budget quietly exceeded. Per-platform guardrails miss these by construction, and contested communications let the violation hide behind lost or delayed evidence. We present a three-tier (platfor- m/squad/mission) compositional runtime-verification framework that de- composes a mission policy into per-agent and cross-agent aspects, aggre- gates per-platform verdicts over a verification-aware messaging fabric, and fuses them with an evidence-aware, two-axis (security x complete- ness) algebra whose provenance names the platforms that jointly trig- gered a violation. Because the fabric makes evidence loss and silence observable, unsupported negative verdicts are downgraded to an explicit unknown rather than reported as mission-wide all-clears. On a simulated ISR mission, an indirect prompt injection that causes real LLM planners to split a prohibited collection task across four platforms is invisible to every per-platform monitor yet detected compositionally with full prove- nance; under an injected fault campaign a best-effort central monitor emits silent false all-clears while the verification-aware fabric emits none
发表机构
- Clone Systems(克隆系统公司)
- International Hellenic University(国际希腊大学)
- Aristotle University of Thessaloniki(塞萨洛尼基亚里士多德大学)
- University of Thessaly(塞萨利大学)
机构由 AI 辅助整理,请以论文原文为准。