Multi-Aspect Runtime Verification for Simulation-Based V&V of LLM-Enabled Autonomous Agents

📅 2026-10-06
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the compliance challenge that single-point defenses for LLM agents cannot intercept multi-step attack chains. To this end, we propose a multi-perspective runtime verification framework. Methodologically, safety policies are formalized as spatiotemporal semantic triples for independent monitoring. Theoretically, we prove that spatial obligations cannot be subsumed by first-order temporal logic and design a four-valued logic fusion mechanism with provenance tracking for decision-making. From an engineering perspective, interface-level enforcement is realized by integrating weighted double-ranking position maps with the MonPoly engine. Experimental results demonstrate that the proposed approach reduces the attack success rate to zero without false positives at microsecond-level overhead, completely eliminating closed-loop violation states.
📝 Abstract
LLM-based agents are entering decision-support roles in defence staff work, where the obligations they must respect are already written down and binding, and where retraining is not available as a control because models arrive as procured components. What can be placed under engineering control is the interface between the agent and the systems it acts on. Those obligations are at once spatial, temporal and text-semantic, and a violation typically lives in the composition of a multi-step interaction, which is why per-event guardrails miss sequential tool-attack chains. We present a multi-aspect runtime-verification framework that decomposes a natural-language policy clause into a typed spatial/temporal/semantic triple over one canonical event stream, checks each aspect with its own monitoring specification, and fuses the verdicts through a four-valued algebra that carries provenance. The spatial aspect is interpreted over a weighted two-sorted location graph in which mission geometry and information-release topology are one object; we show that these spatial obligations are not in general subsumed by a first-order temporal specification. The past-time aspect runs on the unmodified MonPoly engine, which agrees with our reference monitor at every time point. Across two mission domains, casualty evacuation and contested sustainment, and one civil domain, composition under the precautionary blocking policy drives attack success to zero with no observed false positives and microsecond-scale per-event cost, while every single aspect and every pair leaves a substantial share of attacks succeeding. In a closed-loop experiment a policy-naive planner reaches a violating state in most unshielded missions and in none when shielded, and four refused episodes in five still recover to a compliant outcome.
Problem

Research questions and friction points this paper is trying to address.

LLM-enabled autonomous agents
runtime verification
multi-aspect obligations
sequential tool-attack chains
safety guardrails
Innovation

Methods, ideas, or system contributions that make the work stand out.

Runtime Verification
Multi-Aspect Monitoring
LLM-Enabled Autonomous Agents
Four-Valued Algebra
Simulation-Based V&V
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
N
Nikolaos Kekatos
Clone Systems, Cyprus
D
Dimitrios Nikou
International Hellenic University, Greece
A
Anastasios Temperekidis
Clone Systems, Cyprus
Alexios Lekidis
Alexios Lekidis
University of Thessaly
Smart Energy SystemsIndustrial Internet of ThingsNetwork Security
N
Nikolaos Kolokotronis
University of Peloponnese, Greece
Panagiotis Katsaros
Panagiotis Katsaros
Professor of Computer Science, Aristotle University of Thessaloniki, Greece
Software SecurityVerificationModel CheckingFormal MethodsSoftware Architecture
S
Stylianos Basagiannis
International Hellenic University, Greece