Published September 2, 2026 | Version v1.0.0

Post-Compromise Security for Physical AI: Deterministic Runtime Enforcement of Physical Action Authority in Autonomous UAVs / 具身智能之攻陷後安全:自主無人機實體動作權 限之確定性運行時強制執行

Authors/Creators

  • 1. Top-Celestial Company Ltd

Description

Autonomous Physical AI systems increasingly connect learned or language-based controllers to cyber-physical actuators. This creates a security problem that differs from conventional model robustness: when a Physical AI controller is fully compromised, where does the last enforceable security boundary remain? We formulate the Post-Compromise Physical Action Authority Problem and investigate whether execution authority can be placed at the transition from autonomous intent to physical action, bounding action authority independently of cognitive controller integrity.
We present DROS-Kinetic, a reference implementation that places a deterministic authorization gate between an autonomous
control process and the flight-control command interface. The design separates cognitive compromise from physical execution authority through explicit action, principal, capability, and policy checks. We formalize three core properties: Unauthorized Command-Induced Actuation Invariance (UCIAI) (an enforcement property), Conditional Empirical Safety-Envelope Preservation (a conditional cyber-physical system property), and Delegation Non-Escalation (a multi-agent governance property) under explicitly stated vehicle, dynamic, and disturbance assumptions.
We evaluate the system using a six-stage experimental ladder (T1–T6) covering nominal execution, adversarial controller compromise, execution containment, physical safety-envelope enforcement, multi-agent delegation, and revocation under boundary-oriented stress workloads. Results are reported in terms of unauthorized-actuation containment, safety-envelope violations, delegation propagation depth, and decomposed latency layers (Lenforcement ≪ Ltransport ≪ Lphysical). The study provides an experimentally testable basis for evaluating postcompromise security at the boundary between autonomous cognition and physical actuation.

自主具身智能(Physical AI)系統日益將基於學習或大型語言模型(LLM/VLA)的認知控制器直接連接至網絡-實體致動器。這引發了一個與傳統模型魯棒性本質不同的安全挑戰:當具身智能的認知控制器被完全攻陷後,最後一道可強制執行的安全邊界究竟還剩在哪裡?我們形式化定義了「具身智能攻陷後物理動作權限問題」,並深入探討是否能將執行權限邊界精確錨定在「從自主意圖轉化為物理動作」的交界處,從而使實體動作權限獨立於認知控制器的完整性而受到確定性約束。
我們提出了DROS-Kinetic 作為該權限邊界的參考實作,在自主控制進程與飛控指令介面之間建立了一道確定性的二進位授權門禁。該設計透過顯式的動作、主體、能力與策略校驗,將認知層失陷與實體執行權限徹底解耦。我們形式化定義了三大核心性質:未授權命令致動不變量(UCIAI) (執行強制性質)、條件經驗安全包絡線保持(網絡-實體系統條件性質)、以及蜂群委託非擴權(多Agent 治理性質),並明確界定了車體動力學、致動極限與風場擾動假設。
我們使用涵蓋正常執行(T1)、對抗控制器攻陷(T2)、執行期遏制(T3)、物理安全包絡線強制執行(T4)、多節點委託傳播(T5)以及邊界極限負載撤銷(T6)的六階科研實驗階梯(T1–T6)對系統進行了全面評測。實驗結果從未授權致動遏制率、安全包絡線違規數、委託傳播深度以及解耦延遲層級(Lenforcement ≪ Ltransport ≪ Lphysical) 進行了客觀度量。
本研究為在自主認知與物理致動邊界處研究攻陷後安全,提供了一套可嚴格實驗證偽的科學方法學基底。

Files

DROS_PHYSICAL_AI_POST_COMPROMISE_SECURITY_IEEE.pdf

Files (578.3 kB)

Additional details

Related works

Cites
Preprint: 10.5281/zenodo.21833970 (DOI)
Preprint: 10.5281/zenodo.22092008 (DOI)
Preprint: 10.5281/zenodo.21903687 (DOI)
Is supplement to
Preprint: 10.5281/zenodo.22253147 (DOI)

Software

Repository URL
https://github.com/Top-Celestial-Company-Ltd/DROS-VEP-lite
Programming language
Rust , C++ , Python
Development Status
Active

References

  • R. Altawy and A. M. Youssef, "A comprehensive survey on security and privacy risks in unmanned aerial systems," IEEE Communications Surveys & Tutorials, vol. 19, no. 4, pp. 2853– 2876, 2017.
  • S. Bak, D. Chivukula, O. Adekunle, M. Sun, M. Caccamo, and L. Sha, "The system-level simplex architecture for real-time embedded systems," in IEEE RTAS, 2009, pp. 125–134.
  • C.-C. Chen, "DROS: Deterministic Runtime Governance Substrate for Autonomous Agentic Execution," IEEE ICA Technical Report Archive, Tech. Rep. 7782439, 2026.
  • Y. Liu, Y. Jia, R. Geng, J. Jia, and N. Z. Gong, "Prompt injection attacks and defenses in LLM-integrated applications," arXiv preprint arXiv:2310.12815, 2023.
  • J. B. Dennis and E. C. Van Horn, "Programming semantics for multiprogrammed computations," CACM, vol. 9, no. 3, pp. 143–155, 1966.
  • H. M. Levy, Capability-Based Computer Systems, Digital Press, 2014.
  • PX4 Autopilot, "PX4 Architectural Overview and Safety Failsafe Governance," PX4 User Guide, 2024
  • MAVLink, "MAVLink Micro Air Vehicle Communication Protocol v2.0 Specification," MAVLink Standard, 2024.