Defense-in-Depth at the Perception-Reasoning Interface of LLM-Centric Agentic UAV Swarms

πŸ“… 2026-10-02
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the security vulnerability of LLM-driven perception-reasoning interfaces for UAV swarms to sensor report tampering attacks. To mitigate this threat, it proposes a five-layer defense-in-depth architecture that integrates multi-tier verification mechanisms encompassing provenance validation, physical feasibility checks, and geometric consistency constraints. Furthermore, closed-form derivations are employed to establish detection boundaries for quantifying policy cost-effectiveness, while a deterministic fallback scheduler is activated upon anomaly detection to ensure system safety. The theoretical prediction boundaries demonstrate strong alignment with empirical measurements. Although the proposed framework incurs additional computational overhead, it substantially reduces mission losses caused by adversarial attacks, thereby achieving an optimized trade-off between security and operational efficacy.
πŸ“ Abstract
Large Language Models (LLMs) increasingly support Uncrewed Aerial Vehicle (UAV) swarm operations such as data collection scheduling, where the model reads structured sensor reports and decides which sensors to visit. An adversary who quietly manipulates those reports can redirect the swarm without modifying the model weights or the UAV. Defenses for this interface have been proposed architecturally but rarely implemented or evaluated. We implement and evaluate defense-in-depth at the perception-reasoning interface of LLM-Centric Agentic UAV Swarms. Five layers check the provenance of a report, whether its values are physically admissible, whether they agree with what swarm geometry and service history predict, whether the resulting schedule starves any sensor, and, when these fail, hand control to a deterministic scheduler that ignores the suspect input. We test each layer against an adversary strong enough to defeat the layer before it. For each of the three input-side layers, we derive in closed form how far a report can be distorted before that layer reacts, fixing each boundary from deployment parameters before any attack data is collected; across thirty matched simulation runs, predicted and measured boundaries agree. Separating attack detection from response is a well-established principle, and we quantify the cost of neglecting this distinction at the perception-reasoning interface. When the system rejects a report, it replaces it with the most recent accepted report. This prevents the adversary from controlling the UAV schedule, but it also increases cumulative cost by 79% and 74% for the two detectors, respectively, compared with the undefended system. The safety check does not detect any attacks, but it nevertheless reduces the attack-induced cost by 37.5%.
Problem

Research questions and friction points this paper is trying to address.

LLM-centric UAV swarms
perception-reasoning interface
adversarial manipulation
defense-in-depth
sensor data integrity
Innovation

Methods, ideas, or system contributions that make the work stand out.

Defense-in-Depth
LLM-Centric UAV Swarms
Perception-Reasoning Interface
Closed-form Detection Boundaries
Attack Detection and Response Separation
Mohammadhossein Homaei
Mohammadhossein Homaei
PhD student at Extremadura University, CΓ‘ceres, Spain
Digital TwinsCybersecurityInternet of ThingsMADMArtificial intelligence.
Y
Yousef Emami
Senior Member, IEEE
S
Sajad Homayoun
Senior Member, IEEE
R
Rahim Taheri
Senior Member, IEEE
H
Hao Zhou
Senior Member, IEEE
M
Miguel Gutierrez Gaitan
Senior Member, IEEE
B
Bo Wei
Senior Member, IEEE