Mission-Level Runtime Assurance for LLM-Assisted ISR Swarms over a Verification-Aware Fabric

๐Ÿ“… 2026-07-26
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
This work addresses the assurance gap in large language model (LLM)-assisted ISR swarms operating in adversarial environments, where individually compliant platforms may collectively violate mission-level policiesโ€”such as circumventing cross-platform constraints or exceeding shared resource limits. To resolve this, the authors propose a three-tiered (platform/squad/mission) compositional runtime verification framework. The approach decomposes mission policies into intra- and inter-agent constraints, employs verifiably aware message structures to aggregate evidence, and introduces a fusion judgment mechanism grounded in a dual-axis algebra of safety and integrity. This enables traceable detection of mission-level violations. Experiments demonstrate that the method effectively identifies indirect prompt injection attacks and multi-platform coordinated policy breaches undetectable by single-platform monitors, avoids silent false positives common in centralized monitoring under fault injection, and produces no spurious safety assurances.
๐Ÿ“ Abstract
Swarms of LLM-assisted autonomous robots are increasingly proposed for cooperative intelligence, surveillance, and reconnaissance (ISR) in contested environments. A growing class of their assurance failures arises not within any single platform but across the swarm: individually-compliant actions compose into a mission-level violation: a prohibited objective split across platforms to evade per-platform lim- its, or a collective budget quietly exceeded. Per-platform guardrails miss these by construction, and contested communications let the violation hide behind lost or delayed evidence. We present a three-tier (platfor- m/squad/mission) compositional runtime-verification framework that de- composes a mission policy into per-agent and cross-agent aspects, aggre- gates per-platform verdicts over a verification-aware messaging fabric, and fuses them with an evidence-aware, two-axis (security x complete- ness) algebra whose provenance names the platforms that jointly trig- gered a violation. Because the fabric makes evidence loss and silence observable, unsupported negative verdicts are downgraded to an explicit unknown rather than reported as mission-wide all-clears. On a simulated ISR mission, an indirect prompt injection that causes real LLM planners to split a prohibited collection task across four platforms is invisible to every per-platform monitor yet detected compositionally with full prove- nance; under an injected fault campaign a best-effort central monitor emits silent false all-clears while the verification-aware fabric emits none
Problem

Research questions and friction points this paper is trying to address.

LLM-assisted swarms
mission-level assurance
runtime verification
ISR missions
compositional violations
Innovation

Methods, ideas, or system contributions that make the work stand out.

runtime verification
LLM-assisted swarms
verification-aware fabric
compositional assurance
mission-level policy