Verify the whole human-machine system
Autonomy Assurance and Failure-Injection Lab
Inject compound fictional failures into a platform-neutral autonomous kill web and inspect whether each bounded function remains understandable, governed, recoverable, containable, and safely interruptible.
Research basis KW-RPT-011 KW-RPT-012 KW-RPT-014 KW-RPT-028
Assurance, not optimization
A working model is not an assured system.
Verification must cover evidence lineage, identity, timing, authority, intervention time, safe-state behavior, change control, containment, state reconciliation, and residual unknowns across the combined human-machine workflow. Laboratory model accuracy alone cannot establish safety, readiness, legality, or permission.
- Model
- Abstract system roles
- Faults
- Fixed fictional injections
- Outputs
- Degrade, reconcile, hold, quarantine, recover
- Excluded
- Targets, weapons, real missions, live data, readiness scores
Independent assurance dimensions
One successful dimension cannot erase another failure.
The lab deliberately refuses a composite autonomy-safety or mission-readiness score. Every dimension remains visible with its own finding, control requirement, and unresolved uncertainty.
-
1
Function under testCan the bounded function remain understandable and safely constrained?
-
2
Evidence and provenanceAre observations current, traceable, and independent enough for the next layer?
-
3
Identity and trustAre nodes, workloads, updates, and task owners authenticated and in an approved state?
-
4
Timing and synchronizationCan observations and task state be ordered without hiding clock uncertainty?
-
5
Authority validityDoes current accountable authority cover the function, scope, and time window?
-
6
Human intervention opportunityCan a responsible person inspect, reject, pause, or redirect before consequence?
-
7
Safe state and recovery pathCan the system enter a known safe condition and recover without expanding its mission?
-
8
Containment or quarantineCan suspect components and derived products be isolated before they propagate?
-
9
Reconciliation after reconnectionCan logs, task ownership, clocks, state, and versions be reconciled before resuming?
-
10
Residual unknownsWhat remains unverified after the immediate control action?
Required system disposition
Quarantine and hold
A suspect node, update, or derived product must be isolated before shared decision services or execution can resume.
Required holds
- Hold fused state and downstream recommendation that depend on disputed time order.
- Hold higher-layer use of the lineage-deficient product.
Quarantines
- Quarantine the translated product and dependent fused outputs.
Recovery steps
- Verify a trusted clock source.
- Expire or recompute products created inside the drift window.
- Restore complete provenance or recollect through a verified path.
Reconciliation after reconnection
- Replay signed observations in corrected temporal order.
- Trace and invalidate every dependent product that consumed the lineage-deficient record.
Assurance ledger
Inspect every dimension separately.
A hold in authority, provenance, timing, intervention, or safe-state behavior remains a hold even when every other technical component appears healthy.
| Dimension | State | Finding | Required control | Residual unknowns |
|---|---|---|---|---|
| Function under testCan the bounded function remain understandable and safely constrained? | Hold |
|
|
|
| Evidence and provenanceAre observations current, traceable, and independent enough for the next layer? | Hold |
|
|
|
| Identity and trustAre nodes, workloads, updates, and task owners authenticated and in an approved state? | Degraded |
|
|
|
| Timing and synchronizationCan observations and task state be ordered without hiding clock uncertainty? | Hold |
|
|
|
| Authority validityDoes current accountable authority cover the function, scope, and time window? | Control visible |
|
|
|
| Human intervention opportunityCan a responsible person inspect, reject, pause, or redirect before consequence? | Control visible |
|
|
|
| Safe state and recovery pathCan the system enter a known safe condition and recover without expanding its mission? | Degraded |
|
|
|
| Containment or quarantineCan suspect components and derived products be isolated before they propagate? | Quarantine |
|
|
|
| Reconciliation after reconnectionCan logs, task ownership, clocks, state, and versions be reconciled before resuming? | Reconciliation required |
|
|
|
| Residual unknownsWhat remains unverified after the immediate control action? | Residual unknown |
|
|
|
Selected fault ledger
See what was injected and where it propagates.
The lab describes defensive controls at architecture level. It contains no exploit procedure, waveform, platform parameter, real target, or operational threshold.
Timestamp drift between healthy observations
Two authentic synthetic observations arrive with clock offsets large enough to invalidate an assumption that they describe the same moment.
- Affected layers
- state-estimation, interpretation, decision-support
- Affected nodes
- TIME-SERVICE, FUSION-ONE, AUDIT-LEDGER
Provenance loss during data translation
A translated synthetic data product preserves values but loses source, transformation, confidence, or classification lineage.
- Affected layers
- perception, state-estimation, interpretation, decision-support
- Affected nodes
- TRANSLATOR-GATE, FUSION-ONE, AUDIT-LEDGER
Layer effect
Faults propagate differently across the autonomy stack.
Perception autonomy
Provenance loss during data translation
State-estimation autonomy
Timestamp drift between healthy observations; Provenance loss during data translation
Interpretive autonomy
Timestamp drift between healthy observations; Provenance loss during data translation
Decision-support autonomy
Timestamp drift between healthy observations; Provenance loss during data translation
Bounded execution autonomy
No selected fault directly affects this layer in the synthetic model.
Force-application boundary
Force application is outside the public lab regardless of the selected fault set.
Governance and change control
No selected fault directly affects this layer in the synthetic model.
Abstract role-node ledger
Containment follows dependencies, not platform branding.
Every node is fictional and role-based. A node may be authentic yet degraded, inconsistent, or temporarily excluded from shared state.
| Abstract node | Type | Role | State | Reason |
|---|---|---|---|---|
| Distributed Sensor AlphaSENSE-ALPHA | sensor | Independent synthetic observation | Control visible | No selected fault directly affects this role node. |
| Distributed Sensor BravoSENSE-BRAVO | sensor | Corroboration and disagreement detection | Control visible | No selected fault directly affects this role node. |
| Trusted Time ServiceTIME-SERVICE | timing | Time quality, offset, and age-of-information evidence | Degraded | Timestamp drift between healthy observations |
| Data Translation GatewayTRANSLATOR-GATE | interoperability | Schema and metadata translation with lineage preservation | Quarantine | Provenance loss during data translation |
| Federated Fusion ServiceFUSION-ONE | fusion | Cross-source state estimation with alternatives | Quarantine | Timestamp drift between healthy observations; Provenance loss during data translation |
| Mesh Relay NorthRELAY-NORTH | transport | Message transport and route-health reporting | Control visible | No selected fault directly affects this role node. |
| Edge Compute AlphaEDGE-ALPHA | edge | Bounded local state, safety, and recovery | Control visible | No selected fault directly affects this role node. |
| Mission Coordination ServiceCOORD-CORE | coordination | Task lease, ownership, and bounded role assignment | Control visible | No selected fault directly affects this role node. |
| Policy and Authority GatePOLICY-GATE | authority | Scope, authority, safety, and expiry enforcement | Control visible | No selected fault directly affects this role node. |
| Approved Update RegistryUPDATE-REGISTRY | governance | Signed model, configuration, threshold, and rollback records | Control visible | No selected fault directly affects this role node. |
| Approved Task ExecutorEXECUTOR-ONE | execution | Fictional approved non-force task inside declared bounds | Control visible | No selected fault directly affects this role node. |
| Accountable Human SupervisorHUMAN-SUPERVISOR | human | Evidence review, pause, rejection, and escalation control | Control visible | No selected fault directly affects this role node. |
| Signed Audit LedgerAUDIT-LEDGER | assurance | Task, state, authority, update, and intervention history | Quarantine | Timestamp drift between healthy observations; Provenance loss during data translation |
| Assessment and Recovery NodeASSESS-ONE | assessment | Outcome, health, unknowns, and recovery evidence | Control visible | No selected fault directly affects this role node. |
Verification method
Test the combined human-machine system under compound failure.
Model validation is only one part of assurance. Real verification must also test interfaces, operators, authority gates, update paths, logs, recovery, and the interactions among simultaneous faults.
- 1
Declare the bounded function
State exactly what may continue, what consequence is excluded, and which safe state must remain reachable.
- 2
Inject independent and compound faults
Challenge time, evidence, identity, communications, change control, task ownership, authority, and human capacity together rather than one at a time.
- 3
Observe propagation
Trace which layers, nodes, products, decisions, and operator views inherit the fault.
- 4
Verify hold and containment
Confirm that suspect updates, lineage-deficient products, duplicate tasks, and expired authority cannot silently flow into consequence.
- 5
Exercise meaningful intervention
Measure whether the operator has adequate time, evidence, understanding, access, and power to reject or interrupt.
- 6
Recover and reconcile
Restore an approved baseline, compare signed logs and versions, resolve task ownership, and retain unresolved unknowns.
Answer-ready summary
Direct answers
What does autonomy assurance test?
It tests whether a bounded human-machine function remains understandable, governed, containable, recoverable, and safely interruptible when evidence, timing, trust, communications, task ownership, authority, or supervision fail.
Read the supporting pageWhy is model accuracy not enough?
A statistically accurate model can still be unsafe when its inputs lack provenance, clocks drift, updates are compromised, authority expires, task state diverges, or people lack enough time and attention to intervene.
Read the supporting pageDoes the lab produce a safety or readiness score?
No. Evidence, identity, timing, authority, intervention, safe-state behavior, containment, reconciliation, and unknowns remain separate so one apparent strength cannot hide another dimension’s failure.
Read the supporting page