AI 中文总结
本文针对以LLM为中心的无人机蜂群感知-推理接口,提出并评估了五层纵深防御,通过封闭形式推导边界并模拟验证,有效防止对手操纵传感器报告控制蜂群,同时量化了防御成本与收益。
AI 中文摘要
大型语言模型(LLMs)日益支持无人机(UAV)蜂群操作,如数据收集调度,其中模型读取结构化传感器报告并决定访问哪些传感器。能够悄悄操纵这些报告的对手可以在不修改模型权重或无人机的情况下重新引导蜂群。针对该接口的防御措施已在架构上提出,但很少被实施或评估。我们在以LLM为中心的智能无人机蜂群的感知-推理接口上实施并评估了纵深防御。五层防御检查报告来源、其值在物理上是否可接受、它们是否与蜂群几何形状和服务历史预测一致、由此产生的调度是否使任何传感器饥饿,以及当这些检查失败时,将控制权交给一个忽略可疑输入的确定性调度器。我们针对每个层测试一个足够强大以击败前一个层的对手。对于三个输入侧层中的每一个,我们以封闭形式推导出报告在层反应之前可以被扭曲多远,在收集任何攻击数据之前从部署参数固定每个边界;在三十次匹配的模拟运行中,预测边界与测量边界一致。将攻击检测与响应分离是一个成熟的原则,我们量化了在感知-推理接口忽略这种区别的成本。当系统拒绝报告时,它会用最近接受的报告替换它。这防止了对手控制无人机调度,但与未防御系统相比,两个检测器的累积成本分别增加了79%和74%。安全检查未检测到任何攻击,但尽管如此,它将攻击引起的成本降低了37.5%。
英文摘要
Large Language Models (LLMs) increasingly support Uncrewed Aerial Vehicle (UAV) swarm operations such as data collection scheduling, where the model reads structured sensor reports and decides which sensors to visit. An adversary who quietly manipulates those reports can redirect the swarm without modifying the model weights or the UAV. Defenses for this interface have been proposed architecturally but rarely implemented or evaluated. We implement and evaluate defense-in-depth at the perception-reasoning interface of LLM-Centric Agentic UAV Swarms. Five layers check the provenance of a report, whether its values are physically admissible, whether they agree with what swarm geometry and service history predict, whether the resulting schedule starves any sensor, and, when these fail, hand control to a deterministic scheduler that ignores the suspect input. We test each layer against an adversary strong enough to defeat the layer before it. For each of the three input-side layers, we derive in closed form how far a report can be distorted before that layer reacts, fixing each boundary from deployment parameters before any attack data is collected; across thirty matched simulation runs, predicted and measured boundaries agree. Separating attack detection from response is a well-established principle, and we quantify the cost of neglecting this distinction at the perception-reasoning interface. When the system rejects a report, it replaces it with the most recent accepted report. This prevents the adversary from controlling the UAV schedule, but it also increases cumulative cost by 79% and 74% for the two detectors, respectively, compared with the undefended system. The safety check does not detect any attacks, but it nevertheless reduces the attack-induced cost by 37.5%.
Comments14 Pages, 7 Tables, 4 Figures