让航天器自主系统既智能又可验证,通过三重架构实现安全可控的自适应控制。
Reliability-Asymmetric Spacecraft Autonomy: Co-Designing a Capable Learned GNC Stack with a Verified, Adaptation-Aware Runtime Shield

- 用自然语言转任务规划的轻量级模型+在线故障自适应控制器,提升智能性
- 在6自由度仿真中实现97.8%执行器故障恢复率,显著优于传统方法
- 引入可验证运行时防护机制,兼顾安全性与自主性,适合深空任务
深空任务需要兼具能力与可认证性的机载自主系统。规则式自主虽可验证但脆弱,学习型自主能力强但难验证。本文提出AMPLE-GNC,一种三层制导、导航与控制架构:能力路径包含小型基础模型指挥官(将自然语言转为PDDL+)、约束筛选验证器和故障自适应控制器;三者均由运行时防护罩保护,该防护罩基于九个线性时序逻辑不变式,其预测正确性经Kind 2模型检查器机器验证。在6自由度Basilisk测试平台上,取得三项贡献:第一,部署边缘指挥官。微调预训练360M模型并结合语法约束解码,实现硬输出有效性保障,84%计划动作可执行;在去泄漏测试中,新句式泛化准确率达38%(精确匹配),动作匹配51%,经句式多样性再微调后升至48%;区分句法有效性和语义准确性。第二,提出故障自适应控制器。快速电机自适应算法在线推断潜在执行器故障,恢复97.8%执行器信号故障和94.4%连续增益故障,均在训练随机化范围内;未感知故障的PD控制器与端到端强化学习均为0%;最强经典自适应基线在连续增益故障上仅达55%;超出范围时,分段共形再训练得分57%-67%,增加四倍域内数据反而性能下降,表明泛化能力取决于随机化广度而非数据量;在星跟踪器噪声达0.005下仍保持鲁棒。第三,证明锁闭式安全保持防护罩能压制强控制器。采用自适应感知的分段共形恢复时限证书,实现安全与恢复的协调,使控制器保持94.5%自主性的同时仍能捕捉非恢复情况。
原文摘要 · Abstract (English)
Deep-space missions need onboard autonomy that is both capable and certifiable. Rule-based autonomy is certifiable but brittle, while learned autonomy is capable but hard to verify. We present AMPLE-GNC, a three-tier guidance, navigation, and control stack. Its capability path combines a small foundation-model commander that maps natural language to PDDL+, a constraint-screening verifier, and a fault-adaptive controller. All three are bounded by a runtime shield with nine linear-temporal-logic invariants whose predictor soundness is machine-checked by the Kind 2 model checker. On a 6-DOF Basilisk testbed, we make three contributions. First, we deploy an edge commander. Fine-tuning a pretrained 360M model with grammar-constrained decoding gives a hard output-validity guarantee and 84% planner-executable actions. On a de-leaked test, novel-phrasing generalization is 38% exact and 51% action, rising to 48% exact after phrasing-diversity re-finetuning; we separate syntactic validity from semantic accuracy. Second, we introduce a fault-adaptive controller. Rapid Motor Adaptation infers latent actuator faults online and recovers 97.8% of actuator-sign faults and 94.4% of continuous-gain faults within the training randomization envelope. Fault-unaware PD and from-scratch end-to-end RL both score 0%, while the strongest classical-adaptive baseline reaches 55% on continuous gain. Beyond the envelope, a split-conformant retrain scores 57-67%, and adding 4x more in-regime data worsens performance, showing that randomization breadth, not data volume, drives generalization. Robustness is flat under star-tracker noise to 0.005. Third, we show that a latching safe-hold shield can suppress even a capable controller. A split-conformal recovery-deadline certificate with adaptation-aware engagement reconciles safety and recovery, keeping the controller 94.5% autonomous while still catching non-recovery.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。