arXiv:2606.02967cs.ETcs.AI2026-06

为太空卫星智能系统设计实时安全审查框架,防止错误决策。

Glass Box at Orbit: A Constitutional AI Verification Framework for Trustworthy Autonomous CubeSat Intelligence

  • 在卫星AI执行动作前,用6条物理规则和7个逻辑约束进行拦截验证。
  • 验证开销仅随规则数线性增长,与模型大小无关,效率高。
  • 适合构建可信的自主航天器系统,尤其适用于无人值守轨道平台。

太空产业正悄然迈向一个尚未被充分认知的阶段:在距地550公里的轨道上运行数千个无人干预的自主AI任务。微软、AWS及越来越多的轨道计算项目正将云级算力移至太空。然而,目前尚无答案解决关键问题——当轨上数据中心规模的自主AI做出错误决策时,如何阻止其酿成不可逆后果?本文提出Glass Box:一种运行时宪法式AI验证层,拦截所有机载AI策略的候选动作,在命令下达至任一航天器子系统前,评估其是否满足六条基于物理的宪法约束与七个线性时序逻辑(LTL)安全不变量。每个获批动作附带0到1之间的加权可解释性分数E(a_t)及完整宪法审计日志。我们在项目October中实现全仿真五层自主轨道智能架构,验证了Glass Box的验证开销为O(N_c),与模型规模或航天器状态维度无关。我们给出宪法约束语法的完整形式化定义,通过Z3与NuSMV模型检测验证了七条LTL安全不变量,并以一次日食进入期间电池状态恶化下的不安全推理请求为例,展示Glass Box成功拦截。随着轨道计算向数据中心级演进,运行时宪法验证已不再是研究新奇,而是每项自主轨道平台不可或缺的安全基础设施。

原文摘要 · Abstract (English)

The space industry is quietly building toward something nobody has fully reckoned with: orbital data centers running thousands of autonomous AI workloads with no human in the loop, 550 km above the Earth. Microsoft, AWS, and a growing list of orbital computing ventures are moving cloud-scale processing off the ground and into orbit. What none of them have answered yet is the governance question -- when autonomous AI systems at orbital data center scale make wrong decisions in space, what stops those decisions before they become irreversible? We introduce Glass Box: a runtime constitutional AI verification layer that intercepts every candidate action from an onboard AI policy and evaluates it against six physics-grounded constitutional constraints and seven Linear Temporal Logic (LTL) safety invariants before a single command reaches any spacecraft subsystem. Every approved action carries a weighted explainability score E(a_t) in [0,1] and a complete constitutional audit log. We demonstrate Glass Box within Project October: a fully simulated five-layer autonomous orbital intelligence architecture for CubeSat-class spacecraft. We prove that Glass Box verification overhead is O(N_c) in the number of constitutional rules, independent of model size or spacecraft state dimension. We present a complete formal specification of the constitutional constraint grammar, seven LTL safety invariants verified by Z3 and NuSMV model checking, and a detailed worked example of Glass Box intercepting an unsafe inference request at eclipse-entry under degraded battery state. As orbital computing scales toward data center infrastructure, runtime constitutional verification is no longer a research novelty -- it is mission-critical safety infrastructure that every autonomous orbital platform will eventually require.

AI安全航天智能形式化验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。