arXiv:2607.23532cs.CRcs.AI2026-07

为智能无人机群设计运行时保障系统,防止任务级违规行为

Mission-Level Runtime Assurance for LLM-Assisted ISR Swarms over a Verification-Aware Fabric

论文配图:Mission-Level Runtime Assurance for LLM-Assisted ISR Swarms over a Verification-Aware Fabric
图 1 · 摘自论文原文
  • 分三层架构,将任务策略拆解为个体与跨体协同约束
  • 在模拟任务中成功检测到四平台协同规避禁令的攻击,且可追溯责任方
  • 适合关注自主集群安全、对抗环境部署的军事/航天研究者

基于大模型的自主无人机群在对抗环境中日益用于协同情报、监视与侦察(ISR)。当前一类保障失效问题不源于单个平台,而来自群组层面:各平台行为看似合规,但组合后却构成任务级违规,如将禁止任务拆分至多个平台以规避限制,或集体超出资源预算。传统单平台防护机制无法发现此类跨平台违规,且在通信受限环境下,违规行为可能因证据丢失而隐蔽。本文提出三层次(平台/小队/任务)的组合式运行时验证框架:将任务策略分解为个体与跨体约束;通过具备验证感知能力的消息传输网络聚合各平台判决结果;并结合基于证明溯源的双轴(安全×完备性)代数融合判定,明确标识触发违规的协作平台。由于该消息网络可识别证据丢失与沉默,未被支持的否定判决不被误报为全局安全,而是标记为显式未知。在模拟的ISR任务中,一种间接提示注入攻击导致真实大模型规划器将禁止采集任务拆分为四个平台,所有单平台监控均无法察觉,但本框架能以完整溯源方式检出;在注入故障攻击下,传统集中式监控发出无声假全安信号,而本框架则无一例此类错误输出。

原文摘要 · Abstract (English)

Swarms of LLM-assisted autonomous robots are increasingly proposed for cooperative intelligence, surveillance, and reconnaissance (ISR) in contested environments. A growing class of their assurance failures arises not within any single platform but across the swarm: individually-compliant actions compose into a mission-level violation: a prohibited objective split across platforms to evade per-platform lim- its, or a collective budget quietly exceeded. Per-platform guardrails miss these by construction, and contested communications let the violation hide behind lost or delayed evidence. We present a three-tier (platfor- m/squad/mission) compositional runtime-verification framework that de- composes a mission policy into per-agent and cross-agent aspects, aggre- gates per-platform verdicts over a verification-aware messaging fabric, and fuses them with an evidence-aware, two-axis (security x complete- ness) algebra whose provenance names the platforms that jointly trig- gered a violation. Because the fabric makes evidence loss and silence observable, unsupported negative verdicts are downgraded to an explicit unknown rather than reported as mission-wide all-clears. On a simulated ISR mission, an indirect prompt injection that causes real LLM planners to split a prohibited collection task across four platforms is invisible to every per-platform monitor yet detected compositionally with full prove- nance; under an injected fault campaign a best-effort central monitor emits silent false all-clears while the verification-aware fabric emits none

自主集群大模型安全运行时验证对抗环境

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。