为自主系统设计可复现的威胁驱动数字孪生测试框架
Threat-Oriented Digital Twinning for Security Evaluation of Autonomous Platforms

- 构建分离感知、决策与控制功能的模块化数字孪生体
- 支持欺骗、重放等五类攻击的可观测可控测试
- 适用于无人机与航天器等高可靠性系统研究
面向学习型自主平台的网络安全评估,受限于真实平台访问难、通信基础设施争议及缺乏代表性对抗测试条件。本文提出一种威胁导向的数字孪生方法,构建了一个开源、模块化的典型自主系统孪生体,包含分离的感知、自主决策与监督控制功能;置信度约束的多模态感知;显式命令与遥测信任边界;以及运行时安全保持行为。该方法提供可复现的设计模式,将威胁分析转化为对欺骗、重放、畸形输入注入、感知退化及对抗性机器学习等场景的可观测、可控测试。尽管实现的代理为地面系统,但架构设计聚焦于与无人机和空间系统共有的关键特征:受限机载计算、间歇或高延迟链路、概率性感知及任务关键恢复行为。最终形成一个可实施的研究基础框架,支持无人机与空间领域可靠且安全自主研究。
原文摘要 · Abstract (English)
Open, unclassified research on secure autonomy is constrained by limited access to operational platforms, contested communications infrastructure, and representative adversarial test conditions. This paper presents a threat-oriented digital twinning methodology for cybersecurity evaluation of learning-enabled autonomous platforms. The approach is instantiated as an open-source, modular twin of a representative autonomy stack with separated sensing, autonomy, and supervisory-control functions; confidence-gated multi-modal perception; explicit command and telemetry trust boundaries; and runtime hold-safe behavior. The contribution is methodological: a reproducible design pattern that translates threat analysis into observable, controllable tests for spoofing, replay, malformed-input injection, degraded sensing, and adversarial ML stress. Although the implemented proxy is ground based, the architecture is intentionally framed around stack elements shared with UAV and space systems, including constrained onboard compute, intermittent or high-latency links, probabilistic perception, and mission-critical recovery behavior. The result is an implementable research scaffold for dependable and secure autonomy studies across UAV and space domains.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。