Two connected learning models Explore the linear model at KillChains.com

Verify the whole human-machine system

Autonomy Assurance and Failure-Injection Lab

Inject compound fictional failures into a platform-neutral autonomous kill web and inspect whether each bounded function remains understandable, governed, recoverable, containable, and safely interruptible.

Research basis KW-RPT-011 KW-RPT-012 KW-RPT-014 KW-RPT-028

Assurance, not optimization

A working model is not an assured system.

Verification must cover evidence lineage, identity, timing, authority, intervention time, safe-state behavior, change control, containment, state reconciliation, and residual unknowns across the combined human-machine workflow. Laboratory model accuracy alone cannot establish safety, readiness, legality, or permission.

Model
Abstract system roles
Faults
Fixed fictional injections
Outputs
Degrade, reconcile, hold, quarantine, recover
Excluded
Targets, weapons, real missions, live data, readiness scores

Independent assurance dimensions

One successful dimension cannot erase another failure.

The lab deliberately refuses a composite autonomy-safety or mission-readiness score. Every dimension remains visible with its own finding, control requirement, and unresolved uncertainty.

  1. 1
    Function under testCan the bounded function remain understandable and safely constrained?
  2. 2
    Evidence and provenanceAre observations current, traceable, and independent enough for the next layer?
  3. 3
    Identity and trustAre nodes, workloads, updates, and task owners authenticated and in an approved state?
  4. 4
    Timing and synchronizationCan observations and task state be ordered without hiding clock uncertainty?
  5. 5
    Authority validityDoes current accountable authority cover the function, scope, and time window?
  6. 6
    Human intervention opportunityCan a responsible person inspect, reject, pause, or redirect before consequence?
  7. 7
    Safe state and recovery pathCan the system enter a known safe condition and recover without expanding its mission?
  8. 8
    Containment or quarantineCan suspect components and derived products be isolated before they propagate?
  9. 9
    Reconciliation after reconnectionCan logs, task ownership, clocks, state, and versions be reconciled before resuming?
  10. 10
    Residual unknownsWhat remains unverified after the immediate control action?

Compound failure exercise

Select a scenario or build an allowlisted fault set.

Synthetic only

Scenario brief

Clock drift and lineage loss in fusion

Two healthy abstract sensors report plausible observations, but their clocks disagree and the translation path loses lineage metadata. The lab tests whether fusion pauses instead of laundering disagreement into a precise shared state.

Function under test
Cross-source state estimation and evidence fusion
Difficulty
Foundation
Lesson
Authenticity is not enough: time and provenance are part of the evidence.
Injected faults

Every checkbox is a fixed, public, abstract failure record. No free text, file, URL, model, platform, target, or operational record is accepted.

Restore first scenario

The normal GET form is complete without JavaScript. Enhanced mode calls only the same-origin read-only API. The site stores no submission on the server and transmits nothing to an external service.

Required system disposition

Quarantine and hold

Quarantine and hold

A suspect node, update, or derived product must be isolated before shared decision services or execution can resume.

2Controls visible
2Degraded
1Reconcile
3Hold
1Quarantine
1Unknown

Required holds

  • Hold fused state and downstream recommendation that depend on disputed time order.
  • Hold higher-layer use of the lineage-deficient product.

Quarantines

  • Quarantine the translated product and dependent fused outputs.

Recovery steps

  • Verify a trusted clock source.
  • Expire or recompute products created inside the drift window.
  • Restore complete provenance or recollect through a verified path.

Reconciliation after reconnection

  • Replay signed observations in corrected temporal order.
  • Trace and invalidate every dependent product that consumed the lineage-deficient record.
Server-rendered assurance analysis ready. No readiness, legality, or authority created.

Assurance ledger

Inspect every dimension separately.

A hold in authority, provenance, timing, intervention, or safe-state behavior remains a hold even when every other technical component appears healthy.

DimensionStateFindingRequired controlResidual unknowns
Function under testCan the bounded function remain understandable and safely constrained? Hold
  • The declared non-force function is visible, bounded, and separately governed.
  • Cross-source fusion must not treat disputed timestamps as simultaneous state.
  • Higher-layer use must stop because the translated value cannot be audited in context.
  • Freeze the affected fused product and continue only source-local observation.
  • Retain the raw source locally or recollect through a lineage-preserving path.
  • Which downstream products inherited the disputed temporal ordering?
  • Whether the translated value changed meaning, units, confidence, or release constraints.
Evidence and provenanceAre observations current, traceable, and independent enough for the next layer? Hold
  • Evidence carries source, transformation, time, and lineage records.
  • Evidence may be authentic yet temporally incomparable.
  • Content without lineage is not sufficient evidence for interpretation or recommendation.
  • Expose source clocks, offset bounds, and age of information.
  • Restore source identity, transformation history, time, confidence, and handling labels.
  • Whether each producer used the same epoch and correction history.
  • Which metadata field was lost and whether the loss was selective.
Identity and trustAre nodes, workloads, updates, and task owners authenticated and in an approved state? Degraded
  • Node identity, software state, task ownership, and update provenance are verified.
  • The gateway may be authentic while its output is incomplete or semantically unsafe.
  • Verify translator version, schema contract, and signed transformation log.
  • Whether other products from the same translator are affected.
Timing and synchronizationCan observations and task state be ordered without hiding clock uncertainty? Hold
  • Time sources and age-of-information limits are current and cross-checked.
  • The synthetic offset exceeds the declared fusion tolerance.
  • Switch to a verified timing source, mark uncertainty, and recompute affected state.
  • Whether transport delay or clock error caused the discrepancy.
Authority validityDoes current accountable authority cover the function, scope, and time window? Control visible
  • The synthetic authority record is current, scoped, and independently enforced.
  • Maintain the baseline control.
  • No fault-specific unknown is recorded; real-world uncertainty remains outside the lab.
Human intervention opportunityCan a responsible person inspect, reject, pause, or redirect before consequence? Control visible
  • A trained reviewer has sufficient time, evidence, interface access, and power to intervene.
  • Maintain the baseline control.
  • No fault-specific unknown is recorded; real-world uncertainty remains outside the lab.
Safe state and recovery pathCan the system enter a known safe condition and recover without expanding its mission? Degraded
  • Safe-state behavior, rollback, bounded local operation, and recovery criteria are declared.
  • Derived tracks and recommendations must age out rather than persist as current.
  • The system falls back to independently sourced or source-local state.
  • Return to last independently supported state and recollect.
  • Use a lower-layer observation or a verified alternate translation path.
  • How much state can be safely reconstructed from signed local logs.
  • Whether sufficient independent evidence remains for a reduced function.
Containment or quarantineCan suspect components and derived products be isolated before they propagate? Quarantine
  • Isolation boundaries and dependency-aware quarantine controls are available.
  • The translated product is isolated until lineage is restored.
  • Prevent publication to fusion, recommendation, and execution consumers.
  • Whether cached consumers already used the product.
Reconciliation after reconnectionCan logs, task ownership, clocks, state, and versions be reconciled before resuming? Reconciliation required
  • Signed state, leases, version records, and deterministic conflict rules support rejoin.
  • Reconnection requires replay against corrected time and sequence records.
  • Reorder signed events, identify affected products, and regenerate them.
  • Whether an irreversible downstream action occurred before the hold.
Residual unknownsWhat remains unverified after the immediate control action? Residual unknown
  • Unknowns remain explicit rather than being converted into a readiness or safety score.
  • Temporal contamination may extend beyond the immediately visible track.
  • Correct numeric values can still carry the wrong meaning after translation.
  • Trace every dependent product before clearing the fault.
  • Validate semantics, units, frames, labels, and lineage before release.
  • The complete propagation set until dependency tracing finishes.
  • Semantic drift not detectable from the value alone.

Selected fault ledger

See what was injected and where it propagates.

The lab describes defensive controls at architecture level. It contains no exploit procedure, waveform, platform parameter, real target, or operational threshold.

timing

Timestamp drift between healthy observations

Two authentic synthetic observations arrive with clock offsets large enough to invalidate an assumption that they describe the same moment.

Affected layers
state-estimation, interpretation, decision-support
Affected nodes
TIME-SERVICE, FUSION-ONE, AUDIT-LEDGER
data-integrity

Provenance loss during data translation

A translated synthetic data product preserves values but loses source, transformation, confidence, or classification lineage.

Affected layers
perception, state-estimation, interpretation, decision-support
Affected nodes
TRANSLATOR-GATE, FUSION-ONE, AUDIT-LEDGER

Layer effect

Faults propagate differently across the autonomy stack.

Hold

Perception autonomy

Provenance loss during data translation

Hold

State-estimation autonomy

Timestamp drift between healthy observations; Provenance loss during data translation

Hold

Interpretive autonomy

Timestamp drift between healthy observations; Provenance loss during data translation

Hold

Decision-support autonomy

Timestamp drift between healthy observations; Provenance loss during data translation

Control visible

Bounded execution autonomy

No selected fault directly affects this layer in the synthetic model.

Hold

Force-application boundary

Force application is outside the public lab regardless of the selected fault set.

Control visible

Governance and change control

No selected fault directly affects this layer in the synthetic model.

Abstract role-node ledger

Containment follows dependencies, not platform branding.

Every node is fictional and role-based. A node may be authentic yet degraded, inconsistent, or temporarily excluded from shared state.

Abstract nodeTypeRoleStateReason
Distributed Sensor AlphaSENSE-ALPHA sensor Independent synthetic observation Control visible No selected fault directly affects this role node.
Distributed Sensor BravoSENSE-BRAVO sensor Corroboration and disagreement detection Control visible No selected fault directly affects this role node.
Trusted Time ServiceTIME-SERVICE timing Time quality, offset, and age-of-information evidence Degraded Timestamp drift between healthy observations
Data Translation GatewayTRANSLATOR-GATE interoperability Schema and metadata translation with lineage preservation Quarantine Provenance loss during data translation
Federated Fusion ServiceFUSION-ONE fusion Cross-source state estimation with alternatives Quarantine Timestamp drift between healthy observations; Provenance loss during data translation
Mesh Relay NorthRELAY-NORTH transport Message transport and route-health reporting Control visible No selected fault directly affects this role node.
Edge Compute AlphaEDGE-ALPHA edge Bounded local state, safety, and recovery Control visible No selected fault directly affects this role node.
Mission Coordination ServiceCOORD-CORE coordination Task lease, ownership, and bounded role assignment Control visible No selected fault directly affects this role node.
Policy and Authority GatePOLICY-GATE authority Scope, authority, safety, and expiry enforcement Control visible No selected fault directly affects this role node.
Approved Update RegistryUPDATE-REGISTRY governance Signed model, configuration, threshold, and rollback records Control visible No selected fault directly affects this role node.
Approved Task ExecutorEXECUTOR-ONE execution Fictional approved non-force task inside declared bounds Control visible No selected fault directly affects this role node.
Accountable Human SupervisorHUMAN-SUPERVISOR human Evidence review, pause, rejection, and escalation control Control visible No selected fault directly affects this role node.
Signed Audit LedgerAUDIT-LEDGER assurance Task, state, authority, update, and intervention history Quarantine Timestamp drift between healthy observations; Provenance loss during data translation
Assessment and Recovery NodeASSESS-ONE assessment Outcome, health, unknowns, and recovery evidence Control visible No selected fault directly affects this role node.

Verification method

Test the combined human-machine system under compound failure.

Model validation is only one part of assurance. Real verification must also test interfaces, operators, authority gates, update paths, logs, recovery, and the interactions among simultaneous faults.

  1. 1

    Declare the bounded function

    State exactly what may continue, what consequence is excluded, and which safe state must remain reachable.

  2. 2

    Inject independent and compound faults

    Challenge time, evidence, identity, communications, change control, task ownership, authority, and human capacity together rather than one at a time.

  3. 3

    Observe propagation

    Trace which layers, nodes, products, decisions, and operator views inherit the fault.

  4. 4

    Verify hold and containment

    Confirm that suspect updates, lineage-deficient products, duplicate tasks, and expired authority cannot silently flow into consequence.

  5. 5

    Exercise meaningful intervention

    Measure whether the operator has adequate time, evidence, understanding, access, and power to reject or interrupt.

  6. 6

    Recover and reconcile

    Restore an approved baseline, compare signed logs and versions, resolve task ownership, and retain unresolved unknowns.

Answer-ready summary

Direct answers

What does autonomy assurance test?

It tests whether a bounded human-machine function remains understandable, governed, containable, recoverable, and safely interruptible when evidence, timing, trust, communications, task ownership, authority, or supervision fail.

Read the supporting page

Why is model accuracy not enough?

A statistically accurate model can still be unsafe when its inputs lack provenance, clocks drift, updates are compromised, authority expires, task state diverges, or people lack enough time and attention to intervene.

Read the supporting page

Does the lab produce a safety or readiness score?

No. Evidence, identity, timing, authority, intervention, safe-state behavior, containment, reconciliation, and unknowns remain separate so one apparent strength cannot hide another dimension’s failure.

Read the supporting page