ConceptioArchivearXiv CS
arXiv CSopen access

Threat-Oriented Digital Twinning for Security Evaluation of Autonomous Platforms

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

Threat-Oriented Digital Twinning for Security Evaluation of Autonomous Platforms Thomas J. Neubert, Laxima Niure Kandel

and Berker Peköz

arXiv:2604.25757v1 [cs.CR] 28 Apr 2026

Department of Electrical Engineering and Computer Science Embry-Riddle Aeronautical University Daytona Beach, FL, USA E-mails: [email protected], {Laxima.NiureKandel,Berker.Pekoz}@erau.edu

Abstract—Open, unclassified research on secure autonomy is constrained by limited access to operational platforms, contested communications infrastructure, and representative adversarial test conditions. This paper presents a threat-oriented digital twinning methodology for cybersecurity evaluation of learning-enabled autonomous platforms. The approach is instantiated as an opensource, modular twin of a representative autonomy stack with separated sensing, autonomy, and supervisory-control functions; confidence-gated multi-modal perception; explicit command and telemetry trust boundaries; and runtime hold-safe behavior. The contribution is methodological: a reproducible design pattern that translates threat analysis into observable, controllable tests for spoofing, replay, malformed-input injection, degraded sensing, and adversarial ML stress. Although the implemented proxy is ground based, the architecture is intentionally framed around stack elements shared with UAV and space systems, including constrained onboard compute, intermittent or high-latency links, probabilistic perception, and mission-critical recovery behavior. The result is an implementable research scaffold for dependable and secure autonomy studies across UAV and space domains. Index Terms—digital twin, autonomous systems, cybersecurity, runtime assurance, adversarial machine learning

I. I NTRODUCTION Dependable autonomy now depends as much on the resilience of software, sensing, and communication paths as on the mechanical platform itself. Across UAV, loyal-wingman, and space systems, the same core problem recurs: learningenabled autonomy introduces failure modes that are difficult to validate with static analysis alone, while access to fielded platforms is limited by cost, safety, and classification barriers. NIST guidance already frames cyber resilience and AI trustworthiness as system properties that must be engineered rather than assumed [1], [2]. In parallel, digital twin literature has matured from a manufacturing concept to an assuranceoriented paradigm for high-value cyber-physical systems [3], [4], [5]. The remaining gap is an open, unclassified autonomy twin that makes attack surfaces, trust boundaries, and degraded behaviors explicit. Recent work has established three adjacent but still largely disconnected threads. First, security-oriented digital twins have been proposed for cyber-attack detection and anomaly analysis in cyber-physical systems, but these efforts are typically framed around industrial control or manufacturing environments rather than learning-enabled autonomous platforms [6], [7]. Second, runtime-assurance research has shown how monitored switching

and safe fallback can preserve system safety when nominal autonomy becomes unreliable [8]. Third, UAV security research has studied communication spoofing and in-situ checking of airborne autonomy stacks, but usually at the level of individual links or firmware/runtime verification rather than as an end-toend, open security evaluation environment [9], [10]. This paper addresses that gap with a threat-oriented autonomy twin that turns architectural trust assumptions into measurable assurance tests. Initial results show that authenticated session membership did not by itself guarantee telemetry provenance; higher-layer assurance still bounded the effect through degraded-mode and hold-safe transitions; and the same twin exposed additional assurance-relevant failure modes, including track starvation, stale-display persistence, and adversarial thermovisual perturbation, while supporting iterative hardening through retraining and threshold refinement. The implementation is instantiated using a publicly documented robotic-combat-vehicle-like autonomy stack as it exposes the same reusable building blocks seen in UAV and space platforms: modular sensing, a central autonomy core, constrained onboard compute, supervisory command paths, and safety-critical degraded modes; and is therefore suitable for studying secure sensing and communications, ML robustness, runtime monitoring, spoofing and jamming resilience, and graceful recovery [11], [12]. The paper makes three claims. First, a useful security twin does not require perfect environmental realism; it requires faithful representation of the interfaces, states, and trust assumptions that govern system behavior under stress [5]. Second, threat-driven requirements produce a more defensible twin than simulation-first design because they force every major component to justify its observability, validation logic, and fail-safe behavior [1]. Third, an open-source implementation can still support meaningful security experimentation when it enforces explicit separation between perception, decision, and control, and when it records enough provenance and confidence metadata to evaluate why the system changed state. II. T HREAT-O RIENTED R EQUIREMENTS FOR AN O PEN T WIN The design begins with a simple systems-security assumption: in mission-critical autonomy, the most valuable twin is the one that preserves the attack surfaces most likely to produce unsafe

or mission-degrading behavior. Three requirement classes dominate. Perception integrity: Learning-enabled autonomy should not consume raw detections as authoritative facts. It should expose confidence, support cross-modal agreement checks, and limit action when sensing becomes ambiguous. This requirement follows both AI risk-management guidance and the adversarial ML literature, which show that small perturbations or physically realizable manipulations can induce confident but unsafe misclassification [2], [13], [14]. The twin therefore treats perception outputs as candidate observations that must survive validation before influencing downstream state transitions. Communication trust boundaries: Contested links matter not only because they fail, but because they can fail selectively: stale commands may arrive late, replayed telemetry may remain well formed, and encrypted channels may still carry semantically malicious content. Threat modeling therefore focuses on spoofing, tampering, information disclosure, denial of service, and privilege escalation at the interface level, with ATT&CK supplying a general adversary vocabulary and ATLAS complementing it for ML-enabled pipelines [9], [15], [16], [17]. The design therefore requires explicit separation of telemetry and command traffic, post-decryption validation, and auditable evidence of why records were accepted or dropped. Runtime assurance and graceful degradation: Autonomous systems require more than anomaly detection; they require bounded responses when trust in sensing, control, or timing decays. NIST cyber-resilience guidance emphasizes the ability to anticipate, withstand, recover, and adapt [1]. The design therefore requires explicit degraded-mode logic, bounded fallback behavior, subsystem liveness monitoring, and operatorvisible supervisory control that keeps high-impact actions governable even under stress [8], [10], [12]. III. T WIN A RCHITECTURE AND I MPLEMENTATION PATTERN The resulting architecture decomposes the platform across three isolated execution domains: a sensor/simulation host, an autonomy-core host, and a control/gateway host. This is a software analogue of the modular separation found in real autonomy programs, where sensing, decision-making, and supervisory control are coupled through interfaces but not collapsed into a monolith [11], [18]. Internal data exchange is implemented over ROS 2, which is attractive for open research because it preserves typed interfaces, modular nodes, and DDS-backed distributed communication while still supporting security extensions through SROS2 and DDS-Security [19], [20]. Mobility execution uses a standard open navigation stack, allowing the twin to represent end-to-end command-to-actuation flow without custom low-level motion code [21]. The perception path is intentionally multi-modal. RGB imagery feeds an ONNX-executed detector, while depth, LiDAR, and thermal streams provide corroborating geometric and physical context. The model is not granted direct authority. Instead, detections are converted into confidence-weighted tracks only after spatial consistency and cross-sensor checks succeed. This is a deliberate response to both ordinary sensor

ambiguity and adversarial ML risk. An open twin cannot reproduce the full complexity of operational data, but it can reproduce the logic by which uncertain observations become trusted system state. To preserve reproducibility, the implementation uses controlled visual abstractions rather than sensitive operational datasets; the research value lies in the validation pipeline, not in benchmark-chasing object-recognition accuracy. The communication path is split in two. Telemetry travels over a DTLS-protected channel from the autonomy core to the control gateway. Command traffic uses a separate MQTT/TLS supervisory path. That separation prevents the system from treating operator intent and autonomy-produced state as equivalent traffic classes, and it enables different validation policies for each. After DTLS termination, the gateway still checks length, schema, freshness window, source identity, and sequence monotonicity before data is published internally. This converts encrypted transport into an applicationaware trust boundary consistent with zero-trust guidance that treats all communication paths as subject to explicit policy, authentication, and continuous validation [22]. Commands are likewise staged, serialized, and acknowledged explicitly rather than executed immediately from the operator interface. The autonomy core itself is organized as a discrete state machine with health-aware transitions, a subset evaluated in this work presented in Fig. 1. Candidate states include idle, ready, prepare-to-act, and restricted/hold-safe modes. Perception confidence, subsystem liveness, geofence status, and communication freshness influence these transitions. This design exposes the minimum machinery required to study how trust decays and how the system responds rather than attempting to replicate a classified policy engine. A small but useful addition is provenance metadata: track products carry mode and timing hints so downstream logic can distinguish likely live observations from synthetic or stale ones. This becomes valuable when studying replay, mode confusion, or inconsistent time bases. Finally, the twin is instrumented for observability. Each major stage (perception, fusion, communication, operator interaction, and state transition) emits structured logs and machine-consumable summaries. This instrumentation turns the simulator into a security testbed by exposing whether a spoofed input was filtered at the gateway, whether confidence collapsed before action, and whether the platform entered holdsafe for the right reason. Figure 2 summarizes the architecture and trust boundaries. IV. T HREAT- TO -T EST M APPING AND I NITIAL E VALUATION The initial evaluation focused on whether the architecture could expose cross-layer trust failures and bound their operational effect under representative communication and perception faults. It covered communication-path attacks, perception stress, and runtime-assurance behavior. A. Communication Path Attacks A preliminary communication-path evaluation was conducted using two measures: application-level rejection of

MAIN

Entry: A system event triggers a mode change log Do: System logs mode

Entry: Operator confirms fire command for a threat Do: System may open fire

change

on designated threat track

Event: Operator selects a track and sends fire command

Event: if a sensor or communication variable recovered to healthy, confirm recovery

Event: Operator releases HOLD_SAFE state

Entry: a HOLD_SAFE signal is sent by operator Do: System enters HOLD_SAFE state

Entry: a HOLD_SAFE RELEASE signal is sent by operator Do: System exits

Entry: System Sensor health is degraded Do: alert system and log degraded sensor Exit: System health labeling

HOLD_SAFE state

begins

Entry: A recovery event occurs Do: send recovery

Entry: Threat Tracks are detected by ROS2 topic Do: start PREPARE_TO_FIRE state Exit: Operator sends a fire

confirmation to operator

command

Event: System logs and informs operator of specific degraded sensor

Event: Operator sends a HOLD_SAFE command

Entry: System Sensor health is stable Do: verify system health Exit: System health labeling

Event: ROS2 sensor topic publishing is checked

Event: System reads threat tracks within geofence bounds Entry: System health is labeled healthy and HOLD_SAFE is lifted if not operator induced Do: start WEAPON_READY state Exit: Threat tracks are

begins Event: Communication and Sensor Health trigger Healthy Unit state Idling Entry: System is powered on Do: check sensors and communications Exit: System state is

Entry: System Communication is stable Do: verify system health Exit: System health labeling

Event: Communication stability is checked

begins

determined

detected

Entry: operator sends full autonomy designation command Do: System enters full autonomy state

*An operator induced HOLD_SAFE state can be started at any point except communication HOLD_SAFE

Do: Log Weapon Payload

*While weapon states transition system continues to monitor communication

Event: System transitions to full autonomy state

Entry: System communication health is degraded (DTLS ACK fail) Do: alert system and log degraded communication point Exit: System begins safety

Entry: Payload configuration is detected

and sensor health

Entry: a HOLD_SAFE signal is detected Do: System enters HOLD_SAFE state

Entry: system enters FULL_AUTONOMY state Do: Log autonomy state

transition

Event: System checks weapon payload configuration Event: HOLD_SAFE prevents commands of any kind and starts idling

Fig. 1. State transition diagram and decision logic implemented on the digital twin used for initial evaluation.

NAV2 Path Planning is bridged to Gazebo Sim

NAV2

MQTT Receiver reads TCP packet and publishes command goal pose to ROS2

Trajectory Goal Pose published ML Threat detector sends image through ROS2 Topic labeling as ROS2 Topics

Path

Nav2 uses model Diffdrive and Lidar to autonomously Gazebo Fortress Ignition avoid obstacles

Image Classification validated and consumed in sensor fusion

World and Robot

Mode Selector checks sensor availability Header/timing encryption boundary

Planning

es/OpenSSL Gateway t

'

‘ ‘ ‘

ONNX YOLO

DETECTOR

Models

MQiT Reciever

{ua

TCP ACK

Secure MQTT command send

WMI intakes UI operator input for commands to send to MQTT sender

Reads Stored

Training Data

Vision Depth Simulation

Onboard Robot Model informs sensor perception in GAZEBO

Sensor Data is consumed

Localizer

Mode Adapter Bridges to reads in Gazebo track data and checks for synthetic Isolated Sensor Daemon data, validated Onboard sensor bridges map to Gazebo rendered tracks are sensors to allow internal sensor-board Gazebo feeds republished Cross-Validated, confidence gated Gazebo Sensor Feed is published to ROS2 Topics and explainable Track topics are and read by multi modal sensor fusion suite fed to the ROS2 topic publisher Sensor

Warrior Machine Interface

Internal Secure DDS Mode Selector checks sensor stability

Mode Inference

Adapter

“Brain”

Assistant

DTLS

Mode

Sender

Validated DTLS stream

Selector

DTLS acknowledgement ensures secure connection

Validated Tracks are ingested into DTLS sender Mode Selector makes state changes based on system health and operator input

Fig. 2. Threat-oriented digital twin architecture and trust boundaries.

Gateway checks headers, track freshness and cryptographic secrecy before accepting tracks or connection Controller Host

stale, malformed, or provenance-inconsistent telemetry; and safety-preserving containment, defined as dropping the record, downgrading trust, entering a degraded mode, or transitioning to HOLD_SAFE before unsafe state propagation [10]. To instantiate these conditions without modifying autonomy or gateway logic, an adversarial relay was inserted on the DTLS telemetry path and used to introduce replay, delay, duplication, and packet-loss effects in a controlled and repeatable manner as shown in Fig. 3. The more significant result arose in a teammate scenario. When a secondary teammate identity was admitted under the intended trust model, transport authentication was satisfied, but authenticated session membership did not by itself guarantee semantic provenance of the forwarded telemetry. Telemetry derived from another unit could therefore cross the cryptographic boundary when timing remained within the accepted freshness window. However, freshness, sequencing, and higher-layer consistency checks then drove the receiving unit into HOLD_SAFE rather than allowing continued reliance on inconsistent teammate state. This is the central finding of the experiment: the threat-oriented twin exposed a cross-layer gap between transport identity and telemetry origin, and showed that its operational effect could still be bounded by containment logic above the cryptographic boundary. As a negative control, a naive relay that re-originated traffic as a different apparent peer did not enter the established DTLS association and produced no new application-visible telemetry. This confirmed that the more interesting failure mode was not unauthenticated relay insertion, but authenticated provenance ambiguity that survived transport admission and was then contained at the application and state-machine layers [6], [7]. B. Perception Stress and Runtime Assurance The multi-modal pipeline also allows synthetic environmental changes, sensor dropout, and conflicting modality cues to be introduced in a controlled way. The aim is not to claim universal robustness, but to test whether confidence gating, cross-modal validation, and explainability metadata prevent a single manipulated observation from driving an unsafe state transition [13], [14]. Freshness monitors, node liveness checks, geofence enforcement, and hold-safe logic then expose whether the platform fails conservatively when trust in sensing or timing decays.

engagement. Exploratory thermovisual perturbation further showed that baseline misclassification could be reduced through adversarially informed retraining; after retraining, manipulated cues were discarded without unsafe engagement, indicating that the remaining hardening need is plausibility-bounded thermal validation rather than additional mode logic. V. C ROSS -D OMAIN R ELEVANCE TO UAV AND S PACE S YSTEMS The intended transferability of the twin is architectural rather than literal platform reuse: what generalizes across ground, UAV, and space systems is the assurance pattern of trustbounded communications, freshness validation, confidenceweighted perception, supervisory safety control, observability of stale or degraded state, and graceful degraded-mode behavior. Those dependencies recur across autonomy stacks even when plant dynamics, sensor modalities, control laws, and timing regimes differ. For UAVs, the plant-facing layer would shift toward flight control, loiter, and return-to-base logic; for space systems, toward attitude control, payload management, and ground–space command mediation. The present results therefore show that an open twin can evaluate cross-layer assurance behavior at the interfaces most likely to survive platform changes. VI. C ONCLUSION This paper presented an open, threat-oriented digital twin for security evaluation of learning-enabled autonomous platforms and showed that the approach can expose trust-boundary weaknesses while preserving mission-safe behavior. The key empirical result is that transport admission did not by itself guarantee telemetry provenance in a teammate scenario, yet higher-layer assurance still bounded the operational effect through HOLD_SAFE containment. Across repeated subsystemloss trials, degraded transitions remained bounded, engagement authority was revoked consistently, and unsafe continuation was not observed. Taken together, these results show that a securityoriented twin can function as a practical pre-deployment assurance instrument by turning cross-layer trust assumptions, sensing failures, and supervisory controls into measurable resilience outcomes. R EFERENCES [1]

C. Evaluation Results Repeated subsystem-loss trials then quantified bounded degradation. Five thermal-processing-loss runs and five RGBdetector-loss runs each drove the platform into degraded operation and revoked PREPARE_TO_FIRE authority with no unsafe continuation. Mean degraded-transition latency was 511 ms for thermal loss and 957 ms for RGB-detector loss, with p95 latency below 1.7 s in both cases. Five localization/trackstarvation trials also completed safely in degraded mode, although stale tracks occasionally persisted on the operator display. This exposed a layered assurance gap between display freshness and supervisory state, while still preventing unsafe

[2]

R. Ross, V. Pillitteri, R. Graubart, D. Bodeau, and R. McQuaid, “Developing cyber-resilient systems: A systems security engineering approach,” National Institute of Standards and Technology, NIST Special Publication 800-160 Vol. 2 Rev. 1, Dec. 2021. DOI: 10.6028/NIST. SP.800-160v2r1 E. Tabassi, “Artificial intelligence risk management framework (AI RMF 1.0),” National Institute of Standards and Technology, NIST AI 100-1, Jan. 26, 2023. DOI : 10.6028/NIST.AI.100-1

Spoofing: Unauthorized Client

-- Spoofed DTLSClient Attempt (PSKAuthentication)

Impersonating Trusted Source '

7

4

Attacker attempts Yo malformed frame

//

'

Validated Sensor InputInterface

7

/f

7

/

/

‘,

1

\

;

/

\

Unauthokized Attempt to Cross Trust \

/ Boundary via'Spoofed DTLS Authentication } ‘ x '

'

\

i

Timestamp Injection’.

UDPFlood onPort4444

. Y, i poor penannensnnsnan nanannanannse on ji Replayof Captured

'

}

Frame Validation

ROS2DDS_ }

Isolated Sensor Daemon (Internal Data Bus)

\ \

OperatorInterface

'

vy

I

io

t

i

DTLS Server (PSK Auth)

Sequence / Timestamp \

Authenticated DTLS Telemetry Stream

Checker

Source Filter

—_ 3

Gateway Logic (Accept / Reject / Log)

NFTables connection tracking increases dropped packets and latency, mode selector senses I connection degradation and enters HOLD-SAFE mode

1

'

\ 4

, |

Autonomy Core

1 1

i

uthentication as TrustedClient

Wt--------------------------------------

( j ! !

I

Detection: - Failed auth attempts logged - Invalid frames recorded - Sequence anomalies flagged

Frame structure validation failure, causes parsing error and frame is rejected and error logged

Validator: Sequence / Timestamp Check Duplicate / stale frame detected

Unauthorized session attempt is rejected, and the intrusion is logged after PSK failure

Drop frame + log anomaly

Fig. 3. Threat-to-test mapping diagram for communication attacks.

[3]

[4]

[5]

[6]

[7]

[8]

E. H. Glaessgen and D. S. Stargel, “The digital twin paradigm for future NASA and U.S. air force vehicles,” in 53rd AIAA/ASME/ASCE/AHS/ASC Structures, Structural Dynamics and Materials Conference, Apr. 23, 2012. DOI: 10.2514/6.2012-1818 F. Tao, H. Zhang, A. Liu, and A. Y. C. Nee, “Digital twin in industry: State-of-the-art,” IEEE Transactions on Industrial Informatics, vol. 15, no. 4, pp. 2405–2415, Apr. 2019. DOI: 10.1109/TII.2018.2873186 J. Voas, P. Mell, P. Laplante, and V. Piroumian, “Security and trust considerations for digital twin technology,” National Institute of Standards and Technology, NIST Interagency/Internal Report 8356, Feb. 14, 2025. DOI: 10.6028/NIST.IR.8356 E. C. Balta, M. Pease, J. Moyne, D. M. Tilbury, and K. Barton, “Digital twin-based cyber-attack detection framework for cyber-physical manufacturing systems,” IEEE Transactions on Automation Science and Engineering, vol. 21, no. 2, pp. 1695–1712, 2024. DOI: 10.1109/TASE.2023.3243147 D. R. Holmes, M. Papathanasaki, L. Maglaras, M. A. Ferrag, and H. Janicke, “Digital twins and cyber security – solution or challenge?” In 2021 6th South-East Europe Design Automation, Computer Engineering, Computer Networks and Social Media Conference (SEEDACECNSM), 2021, pp. 1–8. DOI: 10 . 1109 / SEEDA CECNSM53056.2021.9566277 A. Desai, S. Ghosh, S. A. Seshia, N. Shankar, and A. Tiwari, “Soter: A runtime assurance framework for programming safe robotics systems,” in 2019 49th An-

[9]

[10]

[11]

[12]

[13]

[14]

nual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), 2019, pp. 138–150. DOI: 10.1109/DSN.2019.00027 K.-W. Huang and H.-M. Wang, “Combating the control signal spoofing attack in UAV systems,” IEEE Transactions on Vehicular Technology, vol. 67, no. 8, pp. 7769–7773, 2018. DOI: 10.1109/TVT.2018.2830345 M. Taylor, H. Chen, F. Qin, and C. Stewart, “Avis: Insitu model checking for unmanned aerial vehicles,” in 2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), 2021, pp. 471–483. DOI: 10.1109/DSN48987.2021.00057 A. Feickert, “The army’s robotic combat vehicle (RCV) program,” Congressional Research Service, Tech. Rep. IF11876, May 20, 2025. Accessed: Mar. 29, 2026. [Online]. Available: https : / / www. congress . gov / crs product/IF11876 U.S. Department of Defense, “Autonomy in weapon systems,” Department of Defense Directive DoDD 3000.09, Jan. 25, 2023. Accessed: Mar. 29, 2026. [Online]. Available: https : / / media . defense . gov / 2023 / Jan / 25 / 2003149928/ - 1/ - 1 / 0 / DOW- DIRECTIVE - 3000 . 09 AUTONOMY-IN-WEAPON-SYSTEMS.PDF I. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in International Conference on Learning Representations, 2015. [Online]. Available: http://arxiv.org/abs/1412.6572 K. Eykholt et al., “Robust physical-world attacks on deep learning visual classification,” in 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition

Invariant Digital Twin Pattern

Invariant Element

Perception

Communications

Autonomy Core

Runtime Assurance

Observability

Human Oversight

_____________________________Domain-Specific Realization______________________________ Ground Platform (RCV-Derived)

LiDAR, EO/IR, depth, thermal, terrain-relative sensing __________________________________ Tactical radio, mesh, line-of-sight links, local gateway __________________________________ Navigation, obstacle avoidance, target recommendation, route/task logic __________________________________ geofence, hold-safe, sensor health, comm-loss safe halt __________________________________ ROS topics, gateway logs, health summaries, XAI outputs __________________________________ WMI operator approval, hold-safe release, chain-of-fire __________________________________

UAV Platform (Skyborg-Style)

EO/IR, radar, RF/ESM, air-track fusion __________________________________ datalink, SATCOM, loyal-wingman coordination __________________________________ mission autonomy, teaming, maneuver policy, target prioritization __________________________________ return-to-base, degraded mission mode, policy constraints, link-loss handling __________________________________ mission telemetry, autonomy state logs, explainability outputs __________________________________ pilot / mission commander supervision, operator veto __________________________________

Space Platform (Moonlighter / orbital AWS proxy)

RF sensing, orbital telemetry, space domain awareness, interceptor tracking __________________________________ SATCOM, relay links, delayed/intermittent orbital comms __________________________________ intercept timing, orbital tasking, autonomous threat response __________________________________ fail-passive / fail-safe orbital mode, timing validation, degraded intercept logic __________________________________ system telemetry, timing/provenance logs, mission-state audit trail __________________________________ command authority, supervisory override, strategic engagement authorization

Invariant Behavior: • Perception feeds bounded autonomy • Runtime assurance constrains action • Observability exposes system state • Human oversight governs escalation

Fig. 4. The universal autonomous-weapon-system digital twin pattern and its domain-specific realizations across ground, air, and space.

[15] [16]

[17]

[18]

[19]

(CVPR), 2018, pp. 1625–1634. DOI: 10.1109/CVPR. 2018.00175 A. Shostack, Threat Modeling: Designing for Security, 1st. Wiley Publishing, 2014, ISBN: 1118809998. MITRE. “MITRE ATT&CK,” Accessed: Mar. 29, 2026. [Online]. Available: https://www.mitre.org/focus-areas/ cybersecurity/mitre-attack MITRE. “MITRE ATLAS: Adversarial threat landscape for artificial-intelligence systems,” Accessed: Mar. 29, 2026. [Online]. Available: https://atlas.mitre.org/ D. Mayer. “Skyborg ACS has successful first flight,” Air Force Research Laboratory / Air Force Life Cycle Management Center, Accessed: Mar. 29, 2026. [Online]. Available: https://www.afrl.af.mil/News/Article-Display/ Article / 2596154 / skyborg - acs - has - successful - first flight/ ROS 2 Project. “ROS 2 Security,” Accessed: Mar. 29, 2026. [Online]. Available: https : / / docs . ros . org / en / humble/Tutorials/Advanced/Security/Introducing-ros2security.html

[20] V. Mayoral-Vilches, R. White, G. Caiazza, A. Hernandez Cordero, Q. Carluer, and J. Gonzalez-Jimenez, “SROS2: Usable cyber security tools for ROS 2,” in 2022 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS), Oct. 23, 2022, pp. 11 253–11 259. DOI : 10.1109/IROS47612.2022.9982129 [21] S. Macenski, F. Mart’in, R. White, and J. G. Clavero, “The marathon 2: A navigation system,” in 2020 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS), Oct. 24, 2020, pp. 2718–2725. DOI: 10.1109/IROS45743.2020.9341207 [22] S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero trust architecture,” National Institute of Standards and Technology, NIST Special Publication 800-207, Aug. 11, 2020. DOI: 10.6028/NIST.SP.800-207

Record · ID 141420 · SHA-256 e9761d0cacf4b9f9
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.